The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Law Enforcement

Breach intelligence, attack campaigns, and threat reports targeting the Law Enforcement sector.

148 threat reports
Page 11 of 13

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Law Enforcement Threat Reports

Showing 121–132 / 148 reports
Law Enforcement Dismantles Cryptomixer, Deals Major Blow to Ransomware Laundering Networks
Impact· medium

Law Enforcement Dismantles Cryptomixer, Deals Major Blow to Ransomware Laundering Networks

In June 2024, a coalition of European law enforcement agencies successfully disrupted Cryptomixer, a cryptocurrency mixing service allegedly used to launder proceeds from ransomware and cybercrime. Authorities seized infrastructure and millions in digital assets linked to illicit transactions, following months of cross-border investigation and digital forensics. Cryptomixer was reportedly favored by ransomware groups to obfuscate the trail of stolen funds, complicating recovery efforts and hampering international financial tracking of illicit operations. This incident underscores the escalation of law enforcement action against cryptographic financial laundering tools, which remain instrumental to cybercriminal operations. Increasing scrutiny and regulatory collaboration highlight a growing intolerance for shadow financial ecosystems enabling ransomware and cyber extortion.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Law Enforcement Dismantles Cryptomixer: Major Blow to Crypto Laundering Networks
Impact· high

Law Enforcement Dismantles Cryptomixer: Major Blow to Crypto Laundering Networks

In June 2024, a coordinated operation between Swiss and German law enforcement agencies led to the shutdown of the Cryptomixer cryptocurrency-mixing service. Since its inception in 2016, Cryptomixer is believed to have laundered over €1.3 billion in Bitcoin, providing cybercriminals with tools to obfuscate illicit financial flows from ransomware, scams, and darknet market activities. The takedown included seizure of digital infrastructure and assets, disrupting one of the major cryptocurrency laundering platforms that aided threat actors operating globally. This collaborative international action highlights increased efforts by authorities to clamp down on crypto-enabled cybercrime. The incident reflects the growing focus on digital financial transparency and signals greater scrutiny of services aiding threat actors in anonymizing transactions.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Crisis24 Shuts Down CodeRED Emergency System Following Ransomware Breach
Impact· high

Crisis24 Shuts Down CodeRED Emergency System Following Ransomware Breach

In early June 2024, Crisis24 permanently shut down its OnSolve CodeRED emergency notification system after a ransomware attack severely damaged the platform's environment. The incident, attributed to the INC ransomware group, involved unauthorized access to and exfiltration of user data, including names, addresses, email addresses, phone numbers, and passwords. Forensic analysis indicated the attack was contained within the legacy CodeRED environment. The shutdown left dozens of municipalities and law enforcement agencies temporarily without emergency notification services, though the U.S. government's Emergency Alert System was unaffected. Crisis24 accelerated rollout of its new platform, conducted a security audit, and notified law enforcement. This breach underscores the increasing risk posed by ransomware groups targeting public safety infrastructure. With attackers leaking sensitive personal data and causing operational disruptions, organizations face mounting pressure to modernize legacy systems and enhance both incident response and segmentation controls in light of sophisticated, persistent threats.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
How the OnSolve CodeRED Cyberattack Disrupted America’s Emergency Alert Infrastructure
Impact· high

How the OnSolve CodeRED Cyberattack Disrupted America’s Emergency Alert Infrastructure

In June 2024, Crisis24 confirmed that its OnSolve CodeRED platform—used by state and local governments, police, and firefighting agencies—suffered a cyberattack disrupting emergency notification systems nationwide. Attackers gained unauthorized access to critical infrastructure, resulting in outages that hindered the timely dissemination of emergency alerts and public safety updates. While the investigation is ongoing, the breach demonstrates significant operational risks associated with service provider platforms in the public safety sector, impacting communities’ emergency preparedness and response effectiveness. This incident underscores growing threats targeting third-party vendors in critical sectors, where cyberattacks exploit platform dependencies to cause widespread and immediate disruption. With increasing regulatory scrutiny and a surge in ransomware and extortion campaigns against essential services, organizations must reassess supply chain, segmentation, and incident response controls to maintain operational and compliance resilience.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
NSO Group Faces 2024 Injunction Over WhatsApp Targeting—Legal and Compliance Impacts Revealed
Impact· high

NSO Group Faces 2024 Injunction Over WhatsApp Targeting—Legal and Compliance Impacts Revealed

In early 2024, NSO Group—the Israeli surveillance technology vendor behind Pegasus spyware—faced a permanent injunction from a U.S. federal court barring it from targeting WhatsApp with its tools. The injunction, part of a high-profile legal battle stemming from NSO's alleged exploitation of WhatsApp vulnerabilities to surveil users, forces NSO to halt, destroy, or refrain from deploying code that interacts with the messaging platform. NSO's defense highlights the existential threat to their business as they appeal, arguing that this could irreparably harm the company and restrict potential U.S. government usage of Pegasus for authorized investigations. This case underscores ongoing global debates around the regulation of commercial spyware, lawful intercept technologies, and privacy rights. With increased legislative and compliance scrutiny, and rising governmental and private sector concerns about surveillance abuse, the outcome may set significant legal and operational precedents for the global spyware ecosystem.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Operation Endgame 2025: Law Enforcement Disrupts Rhadamanthys, Venom RAT, and Elysium Botnet
Impact· medium

Operation Endgame 2025: Law Enforcement Disrupts Rhadamanthys, Venom RAT, and Elysium Botnet

Between November 10 and 13, 2025, international law enforcement agencies led by Europol and Eurojust conducted Operation Endgame, a sweeping crackdown targeting malicious cyber infrastructures. The operation succeeded in dismantling key components of the Rhadamanthys Stealer, Venom RAT, and Elysium botnet, disrupting networks that facilitated global credential theft, remote access, and command-and-control activities. The coordinated seizures involved simultaneous server takedowns across multiple countries and the arrest of key individuals behind these malware operations, significantly diminishing the power and reach of these cybercriminal networks. This incident highlights an increasing trend of robust international cooperation in targeting advanced malware and botnet ecosystems. The disruption of these criminal infrastructures sends a strong message to threat actors, demonstrating both the technical capabilities and resolve of law enforcement to combat cybercrime at scale.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
European Crypto Fraud Ring Dismantled in €600M Money Laundering Bust (2024)
Impact· high

European Crypto Fraud Ring Dismantled in €600M Money Laundering Bust (2024)

In early 2024, European law enforcement agencies dismantled a sophisticated cryptocurrency fraud ring responsible for laundering over €600 million across multiple countries. Nine suspects were arrested as part of coordinated raids targeting a network that deceived victims via fake crypto investment platforms. The ring used professional call centers and complex money laundering techniques, including anonymized cryptocurrency transfers and shell companies, to obfuscate financial trails. Victims were drawn in via social engineering and manipulated into making significant deposits, resulting in substantial financial losses for businesses and individuals. This incident highlights the escalation of large-scale crypto-based fraud and the growing cross-border collaboration required to counter such threats. The bust underlines the increased scrutiny and regulation of digital asset markets, as attackers adapt fraud and laundering methods to evade detection.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Survision LPR Cameras: Unauthenticated Access Vulnerability (CVE-2025-12108)
Impact· medium

Survision LPR Cameras: Unauthenticated Access Vulnerability (CVE-2025-12108)

In November 2025, a critical vulnerability (CVE-2025-12108) was disclosed in Survision License Plate Recognition (LPR) cameras, affecting all product versions globally. The flaw stems from missing authentication safeguards, allowing threat actors to remotely access device configuration wizards without credentials. This enables full system compromise—enabling attackers to alter settings, exfiltrate data, or use compromised cameras as entry points for broader attacks on commercial infrastructure. Researchers at Microsec identified the issue and notified stakeholders, prompting immediate remediation efforts and a firmware update (v3.5) from Survision. No confirmed active exploitation has been reported so far. With physical security increasingly integrated with digital management systems, unauthenticated access to surveillance infrastructure exposes environments to cyber-physical risks. The urgency of this disclosure reflects a broader industry trend: attackers actively seek exposed IoT and operational tech lacking basic authentication, prompting rising regulatory scrutiny and heightened compliance mandates.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
UNC6384 Strikes: Diplomatic Espionage Campaign Hits Europe via Windows Exploits
Impact· low

UNC6384 Strikes: Diplomatic Espionage Campaign Hits Europe via Windows Exploits

In early 2024, advanced persistent threat group UNC6384 targeted multiple European diplomatic entities in a sophisticated cyber-espionage campaign. By leveraging highly convincing spear-phishing emails themed around the European Commission and NATO, attackers tricked foreign affairs officials into clicking malicious links crafted to exploit Windows vulnerabilities. Once compromised, victims' systems allowed for persistent access, resulting in unauthorized data exfiltration and significant risks to sensitive diplomatic communications. The attack underscores the vulnerability of trusted organizations to nation-state tactics and the dangers posed by zero-day Windows exploits in high-value targets. The incident highlights a growing trend of targeted attacks against governmental organizations, coinciding with increased geopolitical tension in Europe. As cyber threat actors continue to exploit social engineering and sophisticated malware, organizations must prioritize endpoint security, staff awareness, and aggressive detection measures to thwart emerging espionage campaigns.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(low)
Read Report
Arrest of 764 Group Leader Signals Crackdown on Online Child Exploitation and Extremism
Impact· medium

Arrest of 764 Group Leader Signals Crackdown on Online Child Exploitation and Extremism

In December 2023, Baron Cain Martin, alleged leader of the violent extremist group 764, was arrested in Tucson, Arizona, following an extensive federal investigation. Unsealed in June 2024, the indictment charges Martin with 29 counts, including producing and distributing child sexual abuse material (CSAM), cyberstalking, conspiracy to commit wire fraud, animal cruelty, and providing material support to terrorists. Federal law enforcement alleges that Martin not only led the illicit collective but also created detailed guides for grooming and exploiting minors. The operation exploited online anonymity, targeting vulnerable young individuals across the globe. At least nine victims, primarily minors, have been identified, with the group's activities linked to broader networks such as The Com. The Martin case spotlights alarming trends in cyber-enabled abuse and violent extremism, highlighting law enforcement’s ongoing efforts to dismantle depraved online collectives. The prosecution’s severity underscores rising societal and regulatory pressure to address digital child exploitation, encrypted criminal coordination, and psychologically manipulative methods used by such groups.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Operation ForumTroll: How Memento Labs Used a Chrome Zero-Day for Global Spyware Attacks in 2024
Impact· medium

Operation ForumTroll: How Memento Labs Used a Chrome Zero-Day for Global Spyware Attacks in 2024

In early 2024, a sophisticated cyber campaign, identified as Operation ForumTroll, exploited a Google Chrome zero-day vulnerability to deploy spyware linked to Memento Labs, an Italian commercial surveillance vendor. Attackers leveraged previously unknown browser flaws to quietly infect targets’ systems, enabling unauthorized espionage and data exfiltration. The malware was distributed through malicious websites and fully bypassed standard security defenses. This campaign has drawn special attention due to Memento Labs’ history—emerging from the notorious Hacking Team’s acquisition by IntheCyber Group—and its potential targeting of high-value individuals and organizations. This incident underscores the persistent threat of zero-day attacks sponsored by private spyware vendors, and signals an ongoing trend in commoditized surveillance. The rise of commercial spyware and browser-based exploits increases regulatory scrutiny and highlights gaps in enterprise endpoint and data-in-transit security.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
First Wap's SS7 Exploit: How Altamides Changed Global Surveillance in 2025
Impact· high

First Wap's SS7 Exploit: How Altamides Changed Global Surveillance in 2025

In 2025, surveillance-technology firm First Wap, based in Jakarta, was revealed to have quietly built and operated the 'Altamides' system, a covert platform leveraging SS7 telecom vulnerabilities for global phone tracking. Unlike conventional spyware, Altamides enabled real-time location tracking of mobile devices across regions—from the Vatican to Silicon Valley—without requiring user interaction, installation, or leaving traces on targeted phones. The technology exploited legacy telecom protocols to access cell tower information, bypassing most modern mobile security defenses. As a result, sensitive locations and communications were exposed to persistent surveillance risk, with broad geopolitical and privacy implications. This incident underscores a worrying rise in the commercial proliferation of offensive surveillance tools exploiting underprotected telecom infrastructure. It highlights the urgent need for stronger regulatory action and zero trust defenses, as targeted espionage techniques move further away from traditional malware and towards systemic protocol abuse.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports