The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Law Enforcement
Breach intelligence, attack campaigns, and threat reports targeting the Law Enforcement sector.
Explore Other Sectors
Law Enforcement Threat Reports
Critical Vulnerabilities Expose Botslab Dashcams to Complete Remote Takeover
CISA published advisory ICSA-26-267-01 detailing 13 critical vulnerabilities in Botslab G980H dashcams affecting two firmware versions worldwide. The vulnerabilities include authentication bypass, session hijacking, predictable session identifiers, hard-coded credentials, unencrypted communications, and path traversal flaws with CVSS scores up to 8.8. Attackers with adjacent network access can gain unauthorized device control, access sensitive recordings and location data, intercept WiFi credentials, and potentially install malicious firmware. Botslab has not responded to CISA's coordination efforts, leaving users without official patches or remediation guidance. This incident highlights the growing security risks in IoT devices within transportation infrastructure, as dashcams increasingly capture sensitive location data and connect to corporate networks through fleet management systems.
7 hours ago
Kill Chain
ShinyHunters Claims FBI Breach: Zero-Day Attack on Law Enforcement
In September 2026, the ShinyHunters cybercrime group claimed to have breached the FBI's systems using a zero-day vulnerability in Oracle PeopleSoft, allegedly stealing sensitive data on current and former FBI employees and job applicants. The attackers defaced the FBI jobs website and claimed access to Criminal Justice, HR, and Medlink services. This attack was reportedly conducted in retaliation for an FBI public service announcement warning against paying the group's ransom demands following their Canvas LMS attacks in May 2026. This incident highlights the escalating boldness of cybercriminal groups directly targeting law enforcement agencies and exploiting enterprise software vulnerabilities. The targeting represents a significant shift in threat actor behavior, moving beyond traditional corporate victims to challenge government authority directly.
1 day ago
Kill Chain
ShinyHunters Escalates to FBI Attack: When Ransomware Groups Target Law Enforcement
In December 2024, the notorious cybercrime group ShinyHunters claimed responsibility for attacking FBI systems, specifically targeting the FBIjobs.gov website and temporarily defacing the jobs portal. The group alleged they stole sensitive data on nearly all FBI agents and job applicants, marking a direct escalation against federal law enforcement. The attack was reportedly motivated by ShinyHunters' dispute with an FBI public service announcement that contained what they claimed were false allegations about their operations. This incident represents a significant escalation in the group's targeting strategy, moving from typical corporate victims to directly confronting law enforcement agencies. This attack highlights the growing boldness of ransomware groups in 2024, as threat actors increasingly target critical infrastructure and government entities. The incident underscores the evolving threat landscape where cybercriminals are willing to directly challenge law enforcement, potentially signaling a shift toward more brazen attacks on government systems.
1 day ago
Kill Chain
ShinyHunters Targets FBI: Zero-Day PeopleSoft Attack Exposes Government Cloud Vulnerabilities
In September 2026, the ShinyHunters extortion gang claimed to have breached FBI systems using a zero-day vulnerability in Oracle PeopleSoft, allegedly accessing FBI-managed AWS GovCloud infrastructure and stealing 2-3TB of sensitive data including employee and job applicant information. The threat actors defaced the FBI Jobs website and claimed access to Criminal Justice, HR, and Medlink services before the FBI quickly took affected systems offline. ShinyHunters stated the attack was retaliation against an FBI FLASH report published in May 2026 that detailed the group's activities and demanded corrections within one week. This incident highlights the growing trend of threat actors targeting government infrastructure through supply chain vulnerabilities and using high-profile breaches as leverage against law enforcement agencies. The exploitation of zero-day vulnerabilities in enterprise applications like PeopleSoft demonstrates the critical need for enhanced security measures in government cloud environments.
2 days ago
Kill Chain
Chinese State-Sponsored Hackers Exploit WordPress and ZyXEL Flaws in Massive Government Data Theft Campaign
A Chinese-speaking threat actor linked to the Red Heron group conducted a sophisticated multi-vector campaign from June to August 2026, exploiting critical vulnerabilities in WordPress Core (CVE-2026-63030, CVE-2026-60137) and ZyXEL GS1900 switches (CVE-2026-7273) to breach government and business organizations across 48 countries. The attackers compromised 996 devices and exfiltrated over 18,500 sensitive records containing government personnel data, law enforcement information, and plaintext credentials through advanced reconnaissance and database infiltration techniques. This incident highlights the growing sophistication of state-sponsored threat actors who leverage publicly available exploits within days of their release to target critical infrastructure and government entities. The campaign's timing coincided with increased geopolitical tensions and demonstrates how adversaries rapidly weaponize disclosed vulnerabilities to achieve strategic intelligence objectives.
2 days ago
Kill Chain
Flock Safety Camera Breach Exposes Critical Flaws in Smart City Surveillance Security
In 2026, security researchers successfully reverse-engineered Flock Safety's automatic license plate reader (ALPR) cameras, exposing critical security vulnerabilities in the widely-deployed surveillance infrastructure. The analysis revealed that while most sensitive data remained encrypted, poor security architecture left encryption keys stored on unencrypted partitions, allowing researchers to access extensive surveillance logs containing over one million captured images. The investigation uncovered that the cameras' computer vision software actively detects and catalogs people, vehicles, bicycles, and even specific details like bumper stickers and patches, generating dozens of images per passing vehicle. This breach of a major surveillance technology provider highlights significant privacy and security concerns in municipal and law enforcement surveillance systems. This incident demonstrates the growing vulnerability of IoT surveillance infrastructure as researchers and malicious actors increasingly target physical devices that municipalities and businesses rely on for security operations.
3 days ago
Kill Chain
Court Orders Transfer of Radaris Domains in Landmark Data Broker Privacy Case
In August 2024, a New Jersey court ordered the transfer of radaris.com and over a dozen related data broker domains to Atlas Data Privacy Corp following a lawsuit under Daniel's Law. The case arose after Radaris, operated by Russian-born brothers Igor and Dmitry Lubarsky, repeatedly ignored removal requests from law enforcement officials and engaged in legal delay tactics including creating shell companies across multiple jurisdictions. The court found Radaris in default after the company failed to mount an adequate defense, resulting in the loss of domains generating approximately $42,000 monthly revenue for the primary site alone. This landmark case demonstrates how privacy laws with meaningful enforcement mechanisms can effectively shut down non-compliant data brokers who have historically operated with impunity by exploiting jurisdictional complexities and procedural delays.
1 week ago
Kill Chain
Critical Google Pixel Modem Flaw CVE-2026-58704 Exploited in Zero-Click Attacks
In September 2026, Google disclosed that CVE-2026-58704, a high-severity privilege escalation vulnerability in Pixel Cellular Modem components, was being exploited in the wild through limited, targeted attacks. The flaw allows remote attackers to bypass permission checks and escalate privileges without user interaction, making it exploitable as a zero-click attack. Google patched the vulnerability alongside 109 other security flaws in the September 2026 Pixel security update, with CISA adding it to the Known Exploited Vulnerabilities catalog and mandating federal agency remediation by September 19, 2026. This incident highlights the growing sophistication of mobile device attacks and the critical importance of securing cellular modem components that were previously considered peripheral attack surfaces. The zero-click nature of this exploit represents an evolution in mobile threat tactics, emphasizing the need for comprehensive mobile security strategies that extend beyond traditional application-layer protections.
1 week ago
Kill Chain
Florida DMV Breach Exposes Risks of Shared Government Database Access
In September 2026, the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed that its DAVID driver database was breached by the ShinyHunters extortion group, who claimed to have stolen over 200,000 driver records. The attack was executed using compromised credentials from a Plant City Police Department employee that had been improperly stored on a personal device. The breach was discovered on September 4, 2026, and quickly mitigated, with FLHSMV working alongside state law enforcement agencies in their response. This incident highlights the growing trend of cybercriminals targeting government databases through compromised credentials and the critical importance of proper credential management across interconnected systems.
1 week ago
Kill Chain
153 Million Drivers Licenses Exposed: The Largest Government Identity Data Breach of 2026
In September 2026, a massive database containing 153 million drivers' licenses was discovered for sale on the dark web, representing one of the largest exposures of government-issued identification data in history. The breach includes comprehensive personal information from drivers' licenses across multiple states, with threat actors actively marketing the dataset to cybercriminals for identity theft, fraud, and other malicious activities. The FBI has launched an investigation into the incident, which appears to involve data aggregated from multiple state motor vehicle departments or a centralized processing vendor. This breach demonstrates the vulnerability of critical identity infrastructure and the growing market for stolen personal identification data on underground forums. This incident highlights the escalating threat to government identity systems as cybercriminals increasingly target high-value datasets containing verified personal information for sophisticated fraud schemes and identity theft operations.
2 weeks ago
Kill Chain
BraZetsu Malware Transforms Compromised Networks Into Criminal Marketplace Assets
In February 2026, cybersecurity researchers discovered BraZetsu, a sophisticated Python-based malware framework developed by the Exilware threat group targeting Latin American organizations. The malware transforms compromised Windows hosts into commercial assets sold through the 'Infected Marketplace' for initial access brokerage operations. BraZetsu employs AI-enhanced reconnaissance capabilities to scan victim networks, extract financial data including Brazilian CNAB banking files, and maintain persistent command and control through WebSocket protocols. The framework represents a significant evolution in Initial Access Broker (IAB) operations, demonstrating how cybercriminals are leveraging artificial intelligence to automate target prioritization and commercialize network access at scale. This incident highlights the growing sophistication of IAB operations and the increasing use of AI in cybercrime, representing a critical shift in how threat actors monetize initial network access and scale their operations across regional markets.
3 weeks ago
Kill Chain
Historic Federal Detention: Maine Teen First Minor Charged in 764 Extremist Case
In December 2024, a 17-year-old from Maine became the first minor to be federally charged and detained for crimes related to involvement in 764, a nihilistic violent extremist collective. The teenager was convicted of multiple federal crimes including conspiracy to sexually exploit children, distributing child sexual abuse material, cyberstalking, and identity theft. This case represents a significant shift in federal law enforcement policy, as authorities have historically avoided prosecuting minors for extremist activities, creating what experts called a dangerous loophole that encouraged maximum harm before age 18. This prosecution signals law enforcement's evolved approach to addressing violent online extremism that increasingly targets and recruits minors. With the FBI investigating over 500 subjects nationwide connected to 764 and affiliated groups, this case establishes precedent for holding juvenile perpetrators accountable while disrupting recruitment strategies that exploit legal protections for minors.
3 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports