Validated Containment Architectures are here. →Explore

Industry Category

Public Safety

Breach intelligence, attack campaigns, and threat reports targeting the Public Safety sector.

22 threat reports
Page 1 of 2

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Public Safety Threat Reports

Showing 112 / 22 reports
Iranian Cyberattacks Expose Vulnerabilities in U.S. Water Utilities
Impact· HIGH

Iranian Cyberattacks Expose Vulnerabilities in U.S. Water Utilities

In late July 2026, a coordinated series of cyberattacks targeted over 30 community water systems across Minnesota, with similar incidents reported in at least 12 other states. The attackers, suspected to be Iranian-affiliated hackers, exploited vulnerabilities in internet-exposed programmable logic controllers (PLCs) that manage critical water infrastructure. These breaches led to operational disruptions, including temporary shutdowns of water treatment plants and manual operation shifts, though no contamination of drinking water was reported. ([techradar.com](https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers?utm_source=openai)) This incident underscores the escalating threat to U.S. critical infrastructure from state-sponsored cyber actors. The attacks highlight systemic vulnerabilities in aging water systems, many of which lack adequate cybersecurity measures. The urgency for enhanced security protocols and infrastructure investment is paramount to prevent future disruptions and safeguard public health.

4 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Iranian Cyberattacks on Minnesota Water Systems: A 2026 Case Study
Impact· MEDIUM

Iranian Cyberattacks on Minnesota Water Systems: A 2026 Case Study

In late July 2026, over 30 community water systems across Minnesota were targeted in a coordinated cyberattack, believed to be orchestrated by Iranian-affiliated hackers. The attackers focused on operational technology controlling pumps, wells, water towers, and wastewater systems, rather than administrative networks. Affected communities included Braham, which experienced a temporary shutdown of its water treatment plant, and other towns like Plymouth, Maple Plain, and South St. Paul, which reported varying levels of disruption. The attack prompted a statewide incident response by Minnesota IT Services. ([techradar.com](https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers?utm_source=openai)) This incident underscores the escalating cyber threats to U.S. critical infrastructure, particularly targeting underfunded and understaffed municipal utilities. The attacks highlight the urgent need for enhanced cybersecurity measures to protect essential services from nation-state actors. ([tomshardware.com](https://www.tomshardware.com/tech-industry/cyber-security/iran-suspected-of-conducting-cyberattacks-on-us-water-suppliers-in-45-municipalities-small-towns-mostly-targeted-with-utilities-switching-to-manual-control?utm_source=openai))

5 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Minnesota Water Utilities Face Coordinated Cyberattacks in July 2026
Impact· MEDIUM

Minnesota Water Utilities Face Coordinated Cyberattacks in July 2026

In late July 2026, over 30 community water systems in Minnesota experienced a coordinated cyberattack targeting their operational technology (OT) systems. The attacks, occurring on July 26 and 27, led to temporary disruptions in water treatment and distribution processes. For instance, the City of Braham reported its water plant was taken offline due to a malicious cyberattack but managed to restore operations within hours. The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities, collaborating with federal, state, local, Tribal, and private-sector partners to investigate and mitigate the incident. This incident underscores the escalating threats to critical infrastructure, particularly in the water sector. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has emphasized the importance of isolating key OT systems to ensure continuity of critical services during cyberattacks. ([cyber.gov.au](https://www.cyber.gov.au/business-government/secure-design/operational-technology-environments/ci-fortify/ci-fortify-advice-for-isolating-vital-systems?utm_source=openai))

1 week ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Coordinated Cyberattack Disrupts 30+ Minnesota Water Systems
Impact· MEDIUM

Coordinated Cyberattack Disrupts 30+ Minnesota Water Systems

In late July 2026, a coordinated cyberattack targeted operational technology at over 30 community water systems across Minnesota, leading to service disruptions in cities including Braham, Plymouth, South St. Paul, and Maple Plain. The attacks affected automated controls and communications, with Braham's water plant temporarily going offline. State and federal agencies, including Minnesota IT Services (MNIT), the Cybersecurity and Infrastructure Security Agency (CISA), and the Environmental Protection Agency (EPA), initiated a comprehensive response to contain the incidents and restore services. The attackers' methods and identities remain under investigation, with no confirmed attribution to date. This incident underscores the escalating threat to critical infrastructure, particularly water systems, from cyberattacks. The similarities between this attack and previous campaigns targeting industrial control systems highlight the urgent need for enhanced cybersecurity measures and vigilance in protecting essential services.

1 week ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Coordinated Cyberattack Disrupts Water Utilities in 30+ Minnesota Communities
Impact· MEDIUM

Coordinated Cyberattack Disrupts Water Utilities in 30+ Minnesota Communities

In late July 2026, over 30 Minnesota communities experienced disruptions in their water and wastewater utilities due to a coordinated cyberattack targeting operational technology systems. Cities such as Braham and Plymouth reported incidents where water treatment plants and related infrastructure were temporarily taken offline. While the attacks did not compromise water quality, they highlighted vulnerabilities in critical infrastructure. This incident underscores the escalating threat posed by state-sponsored cyber actors targeting U.S. critical infrastructure. The Cybersecurity and Infrastructure Security Agency (CISA) had previously warned of Iranian-affiliated groups, like CyberAv3ngers, exploiting internet-connected operational technology devices, including programmable logic controllers. ([epa.gov](https://www.epa.gov/newsreleases/epa-fbi-cisa-nsa-issue-joint-cybersecurity-advisory-water-system-regarding-iranian?utm_source=openai))

1 week ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Vulnerabilities in 6 GHz Wi-Fi AFC Systems Uncovered
Impact· HIGH

Critical Vulnerabilities in 6 GHz Wi-Fi AFC Systems Uncovered

In July 2026, researchers from Pennsylvania State University and Idaho National Laboratory identified significant security vulnerabilities in Automated Frequency Coordination (AFC) systems, which manage the 6 GHz Wi-Fi spectrum to prevent interference with critical infrastructure. The study revealed that AFC systems inherently trust client-side data, such as GPS coordinates and time synchronization inputs, without adequate verification. This trust model exposes the systems to potential attacks where adversaries could spoof location data or manipulate time synchronization, leading to unauthorized spectrum access, harmful interference with incumbent services, or denial-of-service conditions for legitimate 6 GHz Wi-Fi users. ([darkreading.com](https://www.darkreading.com/perimeter/6-ghz-wi-fi-flaws-disrupt-critical-systems?utm_source=openai)) The findings underscore the urgent need for enhanced security measures in AFC systems, especially as the adoption of 6 GHz Wi-Fi expands. Without addressing these vulnerabilities, critical communication infrastructures remain at risk of disruption, highlighting the importance of implementing robust authentication and validation mechanisms within AFC architectures to safeguard against potential exploits.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
DHS HSIN Breach 2026: Cyberattack on Information-Sharing Platform
Impact· MEDIUM

DHS HSIN Breach 2026: Cyberattack on Information-Sharing Platform

In late May to early June 2026, the Department of Homeland Security (DHS) experienced a cyberattack on the Homeland Security Information Network (HSIN), a platform for sharing sensitive but unclassified information among federal, state, local, and private-sector partners. An unknown threat actor accessed HSIN servers and a SharePoint system used for collaboration. DHS is investigating the breach to determine the extent of the intrusion and whether any documents were stolen. The department has not attributed the attack to any specific threat actor or foreign government. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/amp/?utm_source=openai)) This incident underscores the persistent threats to government information-sharing platforms and highlights the need for robust cybersecurity measures. As the United States oversees security for major events like the World Cup, ensuring the integrity of such systems is paramount to national security. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/amp/?utm_source=openai))

1 month ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Navigate360 P3 Global Intel Data Breach: A Wake-Up Call for Educational Cybersecurity
Impact· HIGH

Navigate360 P3 Global Intel Data Breach: A Wake-Up Call for Educational Cybersecurity

In March 2026, Navigate360's P3 Global Intel platform, an anonymous tip line used by over 30,000 schools and 5,000 public safety agencies, was reportedly breached by a hacker group known as Internet Yiff Machine. The attackers claimed to have exfiltrated approximately 93 gigabytes of data, including over 8 million law enforcement tips containing sensitive personally identifiable information (PII) of students and informants. This incident has raised significant concerns about the platform's security measures and the anonymity it promises to its users. The breach underscores the growing trend of cyberattacks targeting educational institutions, which have become increasingly frequent and sophisticated. The exposure of sensitive student data not only compromises individual privacy but also erodes trust in systems designed to enhance school safety. This incident highlights the urgent need for robust cybersecurity practices and compliance with data protection regulations within the education sector.

3 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
ZionSiphon Malware: A New Threat to Water Treatment Facilities
Impact· HIGH

ZionSiphon Malware: A New Threat to Water Treatment Facilities

In April 2026, cybersecurity researchers identified 'ZionSiphon,' a malware specifically designed to target operational technology within water treatment and desalination facilities in Israel. The malware aims to manipulate industrial control systems by increasing chlorine levels and adjusting hydraulic pressures to hazardous levels. Although the current version contains a flawed encryption logic that renders it non-functional, future iterations could rectify this issue, posing significant risks to critical infrastructure. This incident underscores the escalating threat landscape facing critical infrastructure sectors, particularly water treatment facilities. The emergence of specialized malware like ZionSiphon highlights the need for enhanced cybersecurity measures and vigilance to protect essential services from potential sabotage and disruption.

3 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Israel's Cyber Operation: Hacking Tehran's Traffic Cameras to Assassinate Khamenei
Impact· HIGH

Israel's Cyber Operation: Hacking Tehran's Traffic Cameras to Assassinate Khamenei

In early 2026, Israeli intelligence agencies executed a sophisticated cyber operation by infiltrating Tehran's traffic camera network and mobile phone systems. This prolonged surveillance enabled them to monitor the daily movements and routines of Iran's Supreme Leader, Ayatollah Ali Khamenei, and his security detail. The gathered intelligence facilitated a precision airstrike on February 28, 2026, resulting in Khamenei's death and the elimination of several high-ranking Iranian officials. ([theweek.in](https://www.theweek.in/news/middle-east/2026/03/03/israel-spent-years-hacking-irans-traffic-cameras-to-monitor-khameneis-movement.html?utm_source=openai)) This incident underscores the escalating use of cyber capabilities in state-sponsored operations, highlighting the vulnerabilities of critical infrastructure to cyber intrusions. The event has intensified geopolitical tensions and prompted nations to reassess their cybersecurity postures and defense mechanisms against similar threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Spain Arrests Anonymous Fénix Hacktivists for DDoS Attacks
Impact· MEDIUM

Spain Arrests Anonymous Fénix Hacktivists for DDoS Attacks

In February 2026, Spanish authorities arrested four members of the hacktivist group 'Anonymous Fénix' for orchestrating distributed denial-of-service (DDoS) attacks against government ministries, political parties, and public institutions. The group initiated its activities in April 2023, intensifying efforts after the October 2024 DANA storm in Valencia, which resulted in significant casualties and damage. They utilized social media platforms like X and Telegram to disseminate anti-government messages and recruit participants for their cyber campaigns. The arrests, conducted in May 2025 and February 2026 across various Spanish cities, led to the judicial seizure of the group's online accounts and the closure of their communication channels. ([web.guardiacivil.es](https://web.guardiacivil.es/en/destacados/noticias/Detenidos-los-cuatro-principales-integrantes-del-grupo-hacktivista-Anonymous-Fenix-por-ciberataques-contra-organismos-publicos/?utm_source=openai)) This incident underscores the persistent threat posed by hacktivist groups leveraging socio-political events to justify cyberattacks. The use of DDoS tactics to disrupt critical government services highlights the need for robust cybersecurity measures and proactive monitoring of online platforms for recruitment and coordination activities.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
Flock Cloud Misconfiguration Exposes AI Camera Surveillance Feeds in 2026
Impact· high

Flock Cloud Misconfiguration Exposes AI Camera Surveillance Feeds in 2026

In January 2026, Flock, a prominent provider of AI-enabled surveillance technologies, faced a significant cybersecurity incident due to a cloud misconfiguration. Unauthorized online access was discovered, revealing live video streams from Flock’s advanced Condor pan-tilt-zoom cameras deployed in public areas and private properties. These cameras, designed for AI-driven facial and movement tracking, unintentionally exposed high-resolution footage of civilians—including children—across multiple locations, highlighting considerable privacy and operational risks. No evidence suggests the exposure was caused by active exploitation; instead, the open access points were a direct result of insufficient cloud security controls and misapplied access permissions. The incident triggered regulatory and public concern around surveillance, data protection, and compliance obligations, emphasizing the criticality of proper cloud configurations in the era of AI-driven physical security systems. This breach is indicative of a broader rise in cloud infrastructure misconfigurations exposing sensitive, AI-powered surveillance data. Regulatory agencies and industry groups are increasing pressure on technology vendors to enforce robust controls, with cloud and IoT security now considered foundational to protecting physical as well as digital environments.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports