The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Law Enforcement

Breach intelligence, attack campaigns, and threat reports targeting the Law Enforcement sector.

148 threat reports
Page 1 of 13

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Law Enforcement Threat Reports

Showing 1–12 / 148 reports
Critical Vulnerabilities Expose Botslab Dashcams to Complete Remote Takeover
Impact· MEDIUM

Critical Vulnerabilities Expose Botslab Dashcams to Complete Remote Takeover

CISA published advisory ICSA-26-267-01 detailing 13 critical vulnerabilities in Botslab G980H dashcams affecting two firmware versions worldwide. The vulnerabilities include authentication bypass, session hijacking, predictable session identifiers, hard-coded credentials, unencrypted communications, and path traversal flaws with CVSS scores up to 8.8. Attackers with adjacent network access can gain unauthorized device control, access sensitive recordings and location data, intercept WiFi credentials, and potentially install malicious firmware. Botslab has not responded to CISA's coordination efforts, leaving users without official patches or remediation guidance. This incident highlights the growing security risks in IoT devices within transportation infrastructure, as dashcams increasingly capture sensitive location data and connect to corporate networks through fleet management systems.

7 hours ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
ShinyHunters Claims FBI Breach: Zero-Day Attack on Law Enforcement
Impact· CRITICAL

ShinyHunters Claims FBI Breach: Zero-Day Attack on Law Enforcement

In September 2026, the ShinyHunters cybercrime group claimed to have breached the FBI's systems using a zero-day vulnerability in Oracle PeopleSoft, allegedly stealing sensitive data on current and former FBI employees and job applicants. The attackers defaced the FBI jobs website and claimed access to Criminal Justice, HR, and Medlink services. This attack was reportedly conducted in retaliation for an FBI public service announcement warning against paying the group's ransom demands following their Canvas LMS attacks in May 2026. This incident highlights the escalating boldness of cybercriminal groups directly targeting law enforcement agencies and exploiting enterprise software vulnerabilities. The targeting represents a significant shift in threat actor behavior, moving beyond traditional corporate victims to challenge government authority directly.

1 day ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
ShinyHunters Escalates to FBI Attack: When Ransomware Groups Target Law Enforcement
Impact· HIGH

ShinyHunters Escalates to FBI Attack: When Ransomware Groups Target Law Enforcement

In December 2024, the notorious cybercrime group ShinyHunters claimed responsibility for attacking FBI systems, specifically targeting the FBIjobs.gov website and temporarily defacing the jobs portal. The group alleged they stole sensitive data on nearly all FBI agents and job applicants, marking a direct escalation against federal law enforcement. The attack was reportedly motivated by ShinyHunters' dispute with an FBI public service announcement that contained what they claimed were false allegations about their operations. This incident represents a significant escalation in the group's targeting strategy, moving from typical corporate victims to directly confronting law enforcement agencies. This attack highlights the growing boldness of ransomware groups in 2024, as threat actors increasingly target critical infrastructure and government entities. The incident underscores the evolving threat landscape where cybercriminals are willing to directly challenge law enforcement, potentially signaling a shift toward more brazen attacks on government systems.

1 day ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
ShinyHunters Targets FBI: Zero-Day PeopleSoft Attack Exposes Government Cloud Vulnerabilities
Impact· HIGH

ShinyHunters Targets FBI: Zero-Day PeopleSoft Attack Exposes Government Cloud Vulnerabilities

In September 2026, the ShinyHunters extortion gang claimed to have breached FBI systems using a zero-day vulnerability in Oracle PeopleSoft, allegedly accessing FBI-managed AWS GovCloud infrastructure and stealing 2-3TB of sensitive data including employee and job applicant information. The threat actors defaced the FBI Jobs website and claimed access to Criminal Justice, HR, and Medlink services before the FBI quickly took affected systems offline. ShinyHunters stated the attack was retaliation against an FBI FLASH report published in May 2026 that detailed the group's activities and demanded corrections within one week. This incident highlights the growing trend of threat actors targeting government infrastructure through supply chain vulnerabilities and using high-profile breaches as leverage against law enforcement agencies. The exploitation of zero-day vulnerabilities in enterprise applications like PeopleSoft demonstrates the critical need for enhanced security measures in government cloud environments.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Chinese State-Sponsored Hackers Exploit WordPress and ZyXEL Flaws in Massive Government Data Theft Campaign
Impact· HIGH

Chinese State-Sponsored Hackers Exploit WordPress and ZyXEL Flaws in Massive Government Data Theft Campaign

A Chinese-speaking threat actor linked to the Red Heron group conducted a sophisticated multi-vector campaign from June to August 2026, exploiting critical vulnerabilities in WordPress Core (CVE-2026-63030, CVE-2026-60137) and ZyXEL GS1900 switches (CVE-2026-7273) to breach government and business organizations across 48 countries. The attackers compromised 996 devices and exfiltrated over 18,500 sensitive records containing government personnel data, law enforcement information, and plaintext credentials through advanced reconnaissance and database infiltration techniques. This incident highlights the growing sophistication of state-sponsored threat actors who leverage publicly available exploits within days of their release to target critical infrastructure and government entities. The campaign's timing coincided with increased geopolitical tensions and demonstrates how adversaries rapidly weaponize disclosed vulnerabilities to achieve strategic intelligence objectives.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Flock Safety Camera Breach Exposes Critical Flaws in Smart City Surveillance Security
Impact· MEDIUM

Flock Safety Camera Breach Exposes Critical Flaws in Smart City Surveillance Security

In 2026, security researchers successfully reverse-engineered Flock Safety's automatic license plate reader (ALPR) cameras, exposing critical security vulnerabilities in the widely-deployed surveillance infrastructure. The analysis revealed that while most sensitive data remained encrypted, poor security architecture left encryption keys stored on unencrypted partitions, allowing researchers to access extensive surveillance logs containing over one million captured images. The investigation uncovered that the cameras' computer vision software actively detects and catalogs people, vehicles, bicycles, and even specific details like bumper stickers and patches, generating dozens of images per passing vehicle. This breach of a major surveillance technology provider highlights significant privacy and security concerns in municipal and law enforcement surveillance systems. This incident demonstrates the growing vulnerability of IoT surveillance infrastructure as researchers and malicious actors increasingly target physical devices that municipalities and businesses rely on for security operations.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Court Orders Transfer of Radaris Domains in Landmark Data Broker Privacy Case
Impact· HIGH

Court Orders Transfer of Radaris Domains in Landmark Data Broker Privacy Case

In August 2024, a New Jersey court ordered the transfer of radaris.com and over a dozen related data broker domains to Atlas Data Privacy Corp following a lawsuit under Daniel's Law. The case arose after Radaris, operated by Russian-born brothers Igor and Dmitry Lubarsky, repeatedly ignored removal requests from law enforcement officials and engaged in legal delay tactics including creating shell companies across multiple jurisdictions. The court found Radaris in default after the company failed to mount an adequate defense, resulting in the loss of domains generating approximately $42,000 monthly revenue for the primary site alone. This landmark case demonstrates how privacy laws with meaningful enforcement mechanisms can effectively shut down non-compliant data brokers who have historically operated with impunity by exploiting jurisdictional complexities and procedural delays.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Google Pixel Modem Flaw CVE-2026-58704 Exploited in Zero-Click Attacks
Impact· HIGH

Critical Google Pixel Modem Flaw CVE-2026-58704 Exploited in Zero-Click Attacks

In September 2026, Google disclosed that CVE-2026-58704, a high-severity privilege escalation vulnerability in Pixel Cellular Modem components, was being exploited in the wild through limited, targeted attacks. The flaw allows remote attackers to bypass permission checks and escalate privileges without user interaction, making it exploitable as a zero-click attack. Google patched the vulnerability alongside 109 other security flaws in the September 2026 Pixel security update, with CISA adding it to the Known Exploited Vulnerabilities catalog and mandating federal agency remediation by September 19, 2026. This incident highlights the growing sophistication of mobile device attacks and the critical importance of securing cellular modem components that were previously considered peripheral attack surfaces. The zero-click nature of this exploit represents an evolution in mobile threat tactics, emphasizing the need for comprehensive mobile security strategies that extend beyond traditional application-layer protections.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Florida DMV Breach Exposes Risks of Shared Government Database Access
Impact· HIGH

Florida DMV Breach Exposes Risks of Shared Government Database Access

In September 2026, the Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed that its DAVID driver database was breached by the ShinyHunters extortion group, who claimed to have stolen over 200,000 driver records. The attack was executed using compromised credentials from a Plant City Police Department employee that had been improperly stored on a personal device. The breach was discovered on September 4, 2026, and quickly mitigated, with FLHSMV working alongside state law enforcement agencies in their response. This incident highlights the growing trend of cybercriminals targeting government databases through compromised credentials and the critical importance of proper credential management across interconnected systems.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
153 Million Drivers Licenses Exposed: The Largest Government Identity Data Breach of 2026
Impact· HIGH

153 Million Drivers Licenses Exposed: The Largest Government Identity Data Breach of 2026

In September 2026, a massive database containing 153 million drivers' licenses was discovered for sale on the dark web, representing one of the largest exposures of government-issued identification data in history. The breach includes comprehensive personal information from drivers' licenses across multiple states, with threat actors actively marketing the dataset to cybercriminals for identity theft, fraud, and other malicious activities. The FBI has launched an investigation into the incident, which appears to involve data aggregated from multiple state motor vehicle departments or a centralized processing vendor. This breach demonstrates the vulnerability of critical identity infrastructure and the growing market for stolen personal identification data on underground forums. This incident highlights the escalating threat to government identity systems as cybercriminals increasingly target high-value datasets containing verified personal information for sophisticated fraud schemes and identity theft operations.

2 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
BraZetsu Malware Transforms Compromised Networks Into Criminal Marketplace Assets
Impact· HIGH

BraZetsu Malware Transforms Compromised Networks Into Criminal Marketplace Assets

In February 2026, cybersecurity researchers discovered BraZetsu, a sophisticated Python-based malware framework developed by the Exilware threat group targeting Latin American organizations. The malware transforms compromised Windows hosts into commercial assets sold through the 'Infected Marketplace' for initial access brokerage operations. BraZetsu employs AI-enhanced reconnaissance capabilities to scan victim networks, extract financial data including Brazilian CNAB banking files, and maintain persistent command and control through WebSocket protocols. The framework represents a significant evolution in Initial Access Broker (IAB) operations, demonstrating how cybercriminals are leveraging artificial intelligence to automate target prioritization and commercialize network access at scale. This incident highlights the growing sophistication of IAB operations and the increasing use of AI in cybercrime, representing a critical shift in how threat actors monetize initial network access and scale their operations across regional markets.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Historic Federal Detention: Maine Teen First Minor Charged in 764 Extremist Case
Impact· CRITICAL

Historic Federal Detention: Maine Teen First Minor Charged in 764 Extremist Case

In December 2024, a 17-year-old from Maine became the first minor to be federally charged and detained for crimes related to involvement in 764, a nihilistic violent extremist collective. The teenager was convicted of multiple federal crimes including conspiracy to sexually exploit children, distributing child sexual abuse material, cyberstalking, and identity theft. This case represents a significant shift in federal law enforcement policy, as authorities have historically avoided prosecuting minors for extremist activities, creating what experts called a dangerous loophole that encouraged maximum harm before age 18. This prosecution signals law enforcement's evolved approach to addressing violent online extremism that increasingly targets and recruits minors. With the FBI investigating over 500 subjects nationwide connected to 764 and affiliated groups, this case establishes precedent for holding juvenile perpetrators accountable while disrupting recruitment strategies that exploit legal protections for minors.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports