The Containment Era is here. →Explore

Executive Summary

In June 2021, Catalin Dragomir, a Romanian national operating under the alias "inthematrixl," unlawfully accessed the Oregon Department of Emergency Management's network. He extracted personally identifiable information, including names, email addresses, dates of birth, and passport numbers, and sold this data alongside unauthorized network access to potential buyers. Dragomir extended his cybercriminal activities by compromising nearly a dozen other U.S. networks, resulting in cumulative losses exceeding $250,000. Following his arrest in Romania in November 2024 and subsequent extradition to the United States in January 2025, Dragomir pleaded guilty to charges of aggravated identity theft and obtaining information from a protected computer. In May 2026, he was sentenced to 56 months in federal prison and ordered to forfeit approximately 23 Monero (XMR) cryptocurrency, valued at roughly $8,500. This case underscores the persistent threat posed by cybercriminals targeting government infrastructures and the critical need for robust cybersecurity measures to protect sensitive data. The incident also highlights the importance of international cooperation in apprehending and prosecuting cyber offenders.

Why This Matters Now

This incident highlights the ongoing threat of cybercriminals targeting government infrastructures, emphasizing the need for robust cybersecurity measures and international cooperation to protect sensitive data and prosecute offenders.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach revealed vulnerabilities in access controls and data protection measures within the Oregon Department of Emergency Management, highlighting the need for enhanced security protocols to safeguard sensitive information.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Implementing Aviatrix Zero Trust CNSF would likely have constrained the attacker's ability to escalate privileges and exfiltrate sensitive data by enforcing strict segmentation and controlled access within the cloud environment.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's initial access would likely have been limited to a segmented portion of the network, reducing the potential for widespread compromise.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges would likely have been constrained, reducing the risk of obtaining administrative access.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Potential lateral movement would likely have been restricted, reducing the risk of the attacker accessing additional systems.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to maintain and monetize access would likely have been detected and disrupted, reducing the risk of prolonged unauthorized presence.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's data exfiltration efforts would likely have been identified and blocked, reducing the risk of sensitive information being leaked.

Impact (Mitigations)

The financial and data loss impact would likely have been mitigated, reducing the overall damage to the organization.

Impact at a Glance

Affected Business Functions

  • Emergency Response Coordination
  • Disaster Recovery Planning
  • Public Safety Communications
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Personal identifying information of an employee, including name, date of birth, Social Security number, and email address.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict access and limit lateral movement within the network.
  • Enhance East-West Traffic Security to monitor and control internal communications, preventing unauthorized data exfiltration.
  • Deploy Egress Security & Policy Enforcement to filter outbound traffic and block unauthorized data transfers.
  • Utilize Multicloud Visibility & Control to gain comprehensive insights into network activities and detect anomalies.
  • Establish Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious behaviors promptly.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image