🏛️ Government & Public Sector¶
Federal/state/local government, law enforcement, NGOs and nonprofits · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed
Victims L30D7▼ −5
Prior 30D12
Active actor L90DQilin · 5
Active actor L90DThe Gentlemen · 5
Active actor L90DINC Ransom · 4
Today — 12 Sep 2026¶
Last 14 days¶
Recent victim claims¶
Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.
September 2026
Sep 11
Agencia Estatal de Meteorología (AEMET)
Panzer
Panzer, a newly observed RaaS operation running since Aug 5 2026 with 16-21 claimed victims across 11 countries in its first month, lists Spain's national meteorological agency, claiming roughly 5GB exfiltrated with a 20-21 day publication deadline. No agency confirmation yet; verify before treating as a breach. · Sources: EscudoDigital · Ransomware.live
Sep 08
Florida DAVID (Highway Safety and Motor Vehicles)
ShinyHunters
ShinyHunters claims access to Florida's DAVID driver/vehicle lookup database via a password-reset flaw compromising DMV-employee and FBI-agent accounts; ~200,000 driver records allegedly pulled by iterating IDs starting around Sep 3. Proof includes a screenshot of Jeffrey Epstein's DMV record. Verify before treating as a confirmed breach — FLHSMV has not confirmed the claim; leak-site deadline set for Sep 11. · Sources: https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/
Sep 04
Berlin Senate (urban development, transport, environment departments)
Rhysida
5.79 TB / 1.44M files published to dark web after Berlin refused 30 BTC ransom. Data includes critical infrastructure blueprints for Berlin water/power grids, police/LKA files, Bundeswehr documents, federal defense communication plans, CBRN threat assessments, 12,000+ personnel records. Exfiltration Aug 7-12; detection Aug 14; auction countdown ended Sep 4; data dumped Sep 4-5. 13 days before Sep 20 state election. · Sources: https://cybernews.com/news/stolen-berlin-government-files-dumped-on-dark-web-rhysida/ https://www.bankinfosecurity.com/berlin-rejects-rhysida-ransomware-blackmail-a-32731
August 2026
Aug 30
AFSARD
Qilin
Qilin ransomware DLS claim posted August 30 2026. Organization based in Milton Keynes UK. Attack date not confirmed. · Sources: https://www.hookphish.com/blog/ransomware-group-qilin-hits-afsard/
Aug 28
Berlin State Government (Senate Department for Mobility and Environment)
Rhysida
Rhysida DLS claim Aug 28, 2026: 5.79TB exfiltrated Aug 7-12 from Berlin's Senate Department for Mobility, Transport, Climate Protection and Environment; 80K administrative offence proceedings and 46.5K contracts claimed; 30 BTC ransom demand (approx EUR 2M); Berlin refuses to pay; auction countdown started Aug 28; September 20 Abgeordnetenhaus election context; Interior Senator says election data not affected · Sources: https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html
Aug 26
Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF)
Qilin
Qilin posted ATF (atf.gov) to DLS Aug 26. ATF confirmed 'major cybersecurity incident' on a standalone system isolated from enterprise network. DOJ designated it a major incident under federal guidelines. No data samples published by Qilin. Standalone system; eForms and enterprise network unaffected. · Sources: https://cybernews.com/news/qilin-ransomware-bureau-alcohol-tobacco-firearms-atf-cyberattack/
Aug 14
Direction Generale des Finances Publiques (DGFiP)
ZeroBytes (individual threat actor)
Hacker using alias ZeroBytes gained access via stolen internal VPN credentials in late June 2026; exfiltrated records of 678,000 individuals and businesses (names, reference income data, tax rates) in first breach (June); second theft (July) took 200,000 land-registry account details. DGFiP confirmed breach Aug 12 after ZeroBytes posted claim publicly. Data exposure creates targeted physical-robbery risk for high-income crypto holders in France given 30 violent wrench attacks in H1 2026. · Sources: https://therecord.media/french-tax-authority-dgfip-confirms-data-breach
Aug 11
Pennsylvania Attorney General's Office
Unknown
Ransomware attack struck communications systems; 1,200 staff affected; courts granted case extensions; recovery ongoing August 11 · Sources: https://therecord.media/pennsylvania-attorney-general-office-ransomware-attack-recovery
Aug 11
Otter Tail County
INC Ransom
INC Ransom DLS claim posted August 17, 2026; attack estimated August 11. County government (population ~60,000, west-central Minnesota). Scope unconfirmed. · Sources: https://www.ransomware.live/id/T3R0ZXIgVGFpbCBDb3VudHksIE1pbm5lc290YUBpbmNyYW5zb20=
Aug 10
Canopy Support Services
The Gentlemen
TheGentlemen DLS posting August 10, 2026; Canadian nonprofit; data scope unconfirmed · Sources: https://www.ransomware.live/
July 2026
Jul 30
Malaysian Nuclear Agency
The Gentlemen
TheGentlemen DLS claim July 30, 2026; Malaysian government nuclear research and technology organisation; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.breachsense.com/breaches/ · https://www.ransomware.live/
Jul 29
Administratia Nationala a Penitenciarelor (ANP)
Unknown
Romanian National Prison Administration posted to DLS July 29; group unconfirmed; data scope unknown · Sources: https://www.ransomware.live/
Jul 28
Swiss Federal IT Office (FOITT/BIT)
Unknown
SharePoint exploitation chain (CVE-2026-55040 JWT bypass + CVE-2026-56164 EoP); ~200 user and technical accounts compromised; attack detected July 28, external access blocked, passwords reset, servers being rebuilt; no confirmed data exfiltration beyond compromised credentials; attackers described as previously unknown · Sources: https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/
Jul 26
UK Police National Legal Database (PNLD)
ExfilSquad
Attack detected July 26 2026; PNLD confirmed breach; ExfilSquad claims 135,000 contact records of UK police officers, criminal justice staff, and government partners (names, organisations, email addresses); 14 total ExfilSquad victims across 5 countries in this wave; exposure of officers in sensitive investigations is primary concern · Sources: https://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info-of-over-100-000-uk-police-officers-staff/amp/ https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html
Jul 25
Traffic Control and Road Safety Services
Qilin
DLS posting July 25 2026 by Qilin. Sector and country unconfirmed from snippets. · Sources: https://www.ransomware.live/
Jul 25
Plitvicka Jezera Nacionalni Park
Qilin
Plitvice Lakes National Park (Croatia), UNESCO World Heritage Site. DLS posting July 25 2026 by Qilin. Data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 22
South Korean National Diplomatic Academy
Unattributed (suspected DPRK)
South Korean Ministry of Foreign Affairs diplomatic training academy compromised; ~10,000 current and former diplomat records exfiltrated (names, IDs, email, encrypted passwords, job titles, affiliations); dwell time ~9-10 months (Apr/May 2025 – Feb 2026); zero-day + misconfigured security settings; South Korean officials describe exfiltration scope as 'unprecedented'; North Korean link under investigation; 🟨 attribution unverified · Sources: https://therecord.media/south-korea-cyberattack-foreign-ministry
Jul 19
Dephub
Nova
Nova DLS posting July 19; Indonesian government transportation and ports authority entity; data claimed exfiltrated; unverified — no public statement from Dephub · Sources: https://www.ransomware.live
Jul 15
BRAC
The Gentlemen
World's largest NGO listed on The Gentlemen DLS July 15; no public statement from BRAC. Unverified claim. · Sources: https://www.ransomware.live/group/the-gentlemen
Jul 10
Commune de Castries
Payload
French municipality (Castries, Hérault); Payload DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/payload · Sources: [ransomware.live]
Jul 10
Envision Unlimited
MoneyMessage
Chicago-based nonprofit providing residential, day, and community-based services for adults with intellectual and developmental disabilities; MoneyMessage DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/moneymessage · Sources: [ransomware.live]
Jul 09
Greene County Government (GA)
Incrandom
Greene County Georgia government; county servers taken offline after incident detected July 9 2026; Incrandom DLS posting July 28 2026; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://hoodline.com/2026/07/cyber-scare-knocks-greene-county-computers-offline/
Jul 09
Canadian Armed Forces (forces.gc.ca)
Bavaqai
Bavaqai (MedusaLocker/BAVACAI variant) listed the Canadian Armed Forces domain forces.gc.ca on its 'File Manager' DLS on approximately July 9 2026. Some tracker feeds index this under the medusalocker group slug. DLS claim — scope and exfiltrated data not confirmed. · Sources: https://socradar.io/data-breach/forces-medusalocker-ransomware-2026/
Jul 07
YMCA of Western North Carolina
Interlock
Interlock DLS claim July 7, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/interlock · Sources: [ransomware.live]
Jul 04
Goodwill Manasota
Qilin
Qilin DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04
US government entity
Kairos
2TB of sensitive records exfiltrated including SSNs, fingerprints, financial data, and passport scans; ~$1M (~9.44 BTC) ransom paid July 4, 2026 to prevent publication; victim identity not publicly disclosed; pure data-extortion model — no encryption, no operational disruption; 🟨 payment confirmed, victim identity unconfirmed · https://thehackernews.com/2026/07/us-government-entity-paid-kairos-group.html · https://securityaffairs.com/194750/security/u-s-government-agency-paid-1m-to-data-extortion-group-kairos.html · Sources: [The Hacker News] · [Security Affairs]
Jul 04
Edgewood Police Department
Wallstreet
Edgewood Police Department, Pierce County, Washington; Wallstreet DLS claim July 4, 2026; law enforcement targeting during holiday window; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/ · Sources: [ransomware.live]
Jul 03
Prince George County
RansomHouse
county systems encrypted June 10 2026; phone, internet, and online payment systems disrupted; 911 unaffected; PII possibly exposed (names, addresses, DOBs, driver's licence numbers, SSNs); credit monitoring offered; FBI Cyber Crimes Division and CISA notified; RansomHouse claims encryption and posted evidence pack; county has not officially confirmed ransomware attribution or data theft; 🟥 unverified · https://www.wric.com/news/local-news/prince-george/county-government-cybersecurity-incident/ · https://www.govtech.com/security/prince-george-county-va-discloses-recent-cyber-attack · https://ransomware.live/id/UHJpbmNlIEdlb3JnZSBDb3VudHlAcmFuc29taG91c2U= · https://www.redpacketsecurity.com/ransomhouse-ransomware-victim-prince-george-county/ · Sources: [WRIC ABC 8News] · [GovTech] · [ransomware.live] · [RedPacket Security]
Jul 03
Oak Park
INC Ransom
Metro Detroit suburb in Oakland County; INC Ransom DLS claim July 3, 2026; attack estimated July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 03
City of Acworth, Georgia
INC Ransom
suburban Atlanta city northwest of the city; INC Ransom DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 02
AWO Kreisverband Südost e.V.
SafePay
German social welfare organization; SafePay DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/safepay · Sources: [ransomware.live]
Jul 02
COMHAR
WorldLeaks
Irish non-profit providing community mental health, disability, and social services; WorldLeaks DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/worldleaks · Sources: [ransomware.live]
Jul 01
Boyne City
The Gentlemen
City of Boyne City, northern Michigan municipality; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01
Penticton and District Society for Community Living
MedusaLocker
nonprofit organisation providing residential, employment, and social services for adults with developmental disabilities in the Penticton (BC) region; MedusaLocker DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/medusalocker-ransomware-victim-penticton-and-district-society-for-community-living/ · https://ransomware.live/id/UGVudGljdG9uIGFuZCBEaXN0cmljdCBTb2NpZXR5IGZvciBDb21tdW5pdHkgTGl2aW5nQG1lZHVzYWxvY2tlcg== · Sources: [RedPacket Security] · [ransomware.live]
June 2026
Jun 26
NSW Rural Fire Service
Nova
New South Wales Rural Fire Service; Nova DLS claim June 26, 2026; 300 GB claimed; RFS confirmed the breach June 24 but stated emergency operations were unaffected; no evidence of operational impact · https://www.cyberdaily.au/security/13817-exclusive-nova-ransomware-group-takes-responsibility-for-nsw-rfs-hack · https://www.ransomware.live/group/nova · Sources: [Cyber Daily] · [ransomware.live]
Jun 26
Life Bridges
INC Ransom
non-profit organisation supporting individuals with intellectual and developmental disabilities; INC Ransom DLS claim June 25-26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/incransom-targets-life-bridges-non-profit-in-ransomware-attack/ · https://www.breachsense.com/breaches/ · Sources: [DeXpose] · [Breachsense]
Jun 26
Policía de Turismo
KRYBIT
Dominican Republic tourist police force; KRYBIT DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/june/ · Sources: [Breachsense]
Jun 24
mlit.com.my
Stormous
DLS claim June 24, 2026; full 10GB data dump claimed including "highly sensitive internal information and financial records"; scope unconfirmed · https://www.redpacketsecurity.com/stormous-ransomware-victim-mlit-com-my-update-full-data-dump-new-link-10gb/ · Sources: [RedPacket Security]
Jun 23
Gov.br
APT73
official state digital platform and domain zone of the Brazilian Federal Government claimed on DLS; impact scope unconfirmed; APT73 previously targeted siapenet.gov.br (April 2026) · https://www.blackfog.com/cybersecurity-101/apt73-ransomware-group/ · https://www.ransomware.live/group/apt73 · https://www.redpacketsecurity.com/apt73-ransomware-victim-www-siapenet-gov-br/ · Sources: [BlackFog] · [ransomware.live] · [RedPacket Security]
Jun 22
Royal Thai Navy Housing Cooperative
The Gentlemen
cooperative managing housing projects, financial services, and welfare programs for Royal Thai Navy personnel and their families; The Gentlemen DLS claim June 22, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-royal-thai-navy-housing-cooperative/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 21
Texas Parks and Wildlife Dept.
Unattributed
3,087,721 individuals exposed: driver's license numbers, passport numbers, email, phone, residential address; no SSNs/DOB/financial data; actor unattributed · https://www.techtimes.com/articles/318790/20260621/texas-data-breach-hits-3-million-drivers-licenses-passport-numbers-stolen-hunting-vendor.htm · Sources: [TechTimes]
Jun 16
Kedah State Government
Nova
official state government portal providing public services for Kedah, Malaysia; Nova DLS claim June 16, 2026; estimated attack date June 16; data scope and impact unconfirmed · https://www.dexpose.io/nova-ransomware-group-targets-kedah-state-government/ · https://www.ransomware.live/id/S2VkYWhAbm92YQ== · Sources: [DeXpose] · [ransomware.live]
Jun 14
Council of Europe
ShinyHunters
297 GB published June 16, 2026, after ransom deadline not met; content: 409,000+ payslips (2011–2026), 3,700+ personnel files, 14,000+ CVs, and employee personal/financial records (names, DOB, home addresses, phone, salaries, bank account details, SSN/tax information, medical records) for 10,000+ staff; claimed access vector: Oracle PeopleSoft CVE-2026-35273; Council of Europe states investigation is ongoing; data authenticity not yet independently verified by forensics · https://www.securityweek.com/shinyhunters-claims-council-of-europe-hack/ · https://www.bleepingcomputer.com/news/security/council-of-europe-investigates-shinyhunters-data-breach-claims/ · https://cybernews.com/security/council-of-europe-data-breach-claim/ · Sources: [SecurityWeek] · [BleepingComputer] · [Cybernews]
Jun 14
Winona County
NightSpire
second ransomware attack on county in 2026; attack detected April 7; county network partially taken offline; MN National Guard assisted; NightSpire leaked data June 14 2026; county confirmed data leak same day; personal info affected pending review; 🟨 county-confirmed · https://www.govtech.com/security/cyber-criminals-leak-data-from-minnesota-ransomware-incident · https://www.dexpose.io/nightspire-ransomware-attack-on-k-county/ · Sources: [GovTech] · [DeXpose]
Jun 12
Blackbaud
Icarus
Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026; 🟨 scope unverified · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 11
National Association of Insurance Commissioners
ShinyHunters
3.1TB and 105,000+ files claimed; investigation confirmed (July 1): only publicly available statutory financial reports, outdated logs, and config files accessed; key systems SERFF/OPTins/UCAA/EDP/RDC confirmed intact; no consumer PII or payment data; breach via PeopleSoft CVE-2026-35273, access June 11; data published online by June 25; 🟩 breach confirmed, impact minimal (public regulatory data only) · https://www.insurancejournal.com/news/national/2026/06/24/875119.htm · https://www.bleepingcomputer.com/news/security/naic-says-public-data-stolen-in-shinyhunters-peoplesoft-breach/ · https://www.techradar.com/pro/security/naic-confirms-data-breach-with-shinyhunters-claiming-3-1tb-of-data-stolen-in-oracle-zero-day-attack · Sources: [Insurance Journal] · [BleepingComputer] · [TechRadar]
Jun 01
DHS Homeland Security Information Network
Unattributed
HSIN servers and an associated SharePoint collaboration system compromised; used by state/local law enforcement fusion centers and federal agencies to share threat intelligence; attack estimated late May–early June 2026; disclosed July 1, 2026; DHS confirmed attack and isolated affected systems; forensic investigation underway; no classified networks affected; sensitive law enforcement operational data (open investigations, facility-threat mappings, inter-agency partner identities) potentially exposed; actor unattributed · https://www.bleepingcomputer.com/ · https://www.nextgov.com/ · Sources: [BleepingComputer] · [Nextgov/FCW]
Jun 01
Department of Homeland Security (HSIN)
Unknown
DHS confirmed intrusion into Homeland Security Information Network (HSIN), the SBU inter-agency intelligence-sharing platform; attackers stole credential files, ran malicious code, and deleted logs; initial alerts were dismissed as false positives giving extended dwell time (late May - early June 2026); classified systems not affected; House Homeland Security Committee requested formal briefing; 🟩 confirmed by DHS · Sources: https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/ · https://www.nextgov.com/cybersecurity/2026/07/dhs-network-intrusion-was-twice-ruled-false-positive-breach-confirmed/414724/