Skip to content

🏛️ Government & Public Sector

Federal/state/local government, law enforcement, NGOs and nonprofits · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed

Victims L30D7▼ −5
Prior 30D12
Active actor L90DQilin · 5
Active actor L90DThe Gentlemen · 5
Active actor L90DINC Ransom · 4

Today — 12 Sep 2026

Florida's DMV confirms the ShinyHunters intrusion this desk flagged as an unverified claim Sep 8 — and the root cause is a single officer's personal device.HighGovernment & Public SectorFLHSMV says it learned of the breach Sep 4, traced entry to a Plant City Police Department user account whose DMV/DAVID-database credentials were improperly stored on the officer's personal device rather than an agency-issued one, and calls the intrusion "quickly mitigated" with no further breach ongoing. ShinyHunters' own claim of 200,000+ driver records remains the attacker's figure, unconfirmed by the state; the intrusion vector (one non-agency device holding law-enforcement-grade database access) is the new, confirmed detail. The Record
Spain's national meteorological agency (AEMET) listed by Panzer, a RaaS brand that launched its leak site Aug 5 and already claims 16–21 victims across 11 countries.MediumGovernment & Public Sector🟥 Unverified DLS claim — roughly 5GB allegedly exfiltrated, 20–21 day publication deadline; no agency confirmation yet, verify before treating as a breach. EscudoDigital
A state government's most sensitive law-enforcement database access failing because one officer stored credentials on a personal phone is a policy problem no patch fixes, and it is happening in the same month a private identity-verification vendor (IDScan.net) leaked 153M+ driver's licenses for unrelated reasons.HighGovernment & Public SectorTechnology & SoftwareFlorida's DMV breach and IDScan.net's slow-walked disclosure are two separate incidents with one shared structural cause: identity-document infrastructure — public and private — runs on access-control assumptions (agency-issued devices, indexed disclosure) that keep failing in ordinary, boring ways rather than exotic ones. For portfolio companies serving government identity/DMV contracts, the audit question is device-issuance policy enforcement, not just encryption-at-rest. The Record

Last 14 days

A Sandworm-attributed implant (Cyclops Blink) resurfacing via a fresh Cisco FMC zero-day, in the same disclosure alongside a Qilin ransomware-affiliate cluster on the identical CVE, is a concrete data point for a broader pattern insurers and defense planners should be pricing: Russian state pre-positioning and Russian-speaking criminal ransomware crews increasingly share the same initial-access infrastructure and timeline, whether or not they coordinate.CriticalTechnology & SoftwareGovernment & Public SectorCyclops Blink was NCSC-UK/CISA/FBI-attributed to Sandworm (GRU Unit 74455) in 2022 on WatchGuard/ASUS edge devices; its reappearance on Cisco's flagship firewall-management platform shows the same actor rotating to whatever edge-management software has a fresh pre-auth RCE. Portfolio companies with Cisco FMC deployments should treat this as both an espionage and a ransomware precursor risk simultaneously, not sequentially. Talos Intelligence
ShinyHunters claims a second, unrelated US government-adjacent target within the same week: Florida's DAVID driver/vehicle database, ~200,000 records, via a password-reset flaw.HighGovernment & Public SectorThe group told BleepingComputer it compromised accounts belonging to DMV employees and an FBI agent, then pulled records by iterating IDs; as proof it released a screenshot of Jeffrey Epstein's DMV record. Florida's Highway Safety and Motor Vehicles agency (FLHSMV) has not confirmed the claim. 🟥 Unverified DLS-style claim — the leak-site deadline is Sep 11. A confirmed compromise of a law-enforcement lookup database would raise both public-safety and Driver's Privacy Protection Act liability questions distinct from a standard PII breach. BleepingComputer
ShinyHunters runs the same playbook twice in one week against very different targets — a Fortune 10 healthcare distributor and a state DMV — underscoring that its methodology (social-engineer or password-reset your way to a data store, then extort) doesn't require a specific tech stack.HighGovernment & Public SectorHealthcare & Life SciencesMcKesson via voice-phished Okta SSO into Salesforce/Snowflake; Florida DAVID via a password-reset flaw. See Intelligence Agency Alerts above for the group's other current AI-related news cycle context. BleepingComputer
A state DMV database breach claim, proven in part with a dead-and-notorious public figure's own record, is a reminder that government data has a specific credibility problem attackers exploit deliberately.MediumGovernment & Public SectorUsing Jeffrey Epstein's DMV file as proof-of-breach is a calculated choice: it is independently verifiable and generates press attention no ordinary citizen's record would. Government agencies holding law-enforcement-grade lookup data (DMV, voter rolls, benefits systems) should assume any high-profile individual's record in their systems is a standing target for exactly this kind of attention-maximizing proof-of-hack move, independent of the record's actual sensitivity. BleepingComputer
No new CISA/FBI/NSA/NCSC advisories in the Sep 7–8 window.MediumGovernment & Public SectorThe most recent KEV activity remains the Sep 2 seven-CVE batch and the Sep 4 Chrome V8 addition (both previously covered); FCEB deadlines from those batches remain in force — see Critical Vulnerabilities and the site's Dates to Watch panel for the Sep 9/14/18 remediation deadlines still open.
Berlin task force update: election infrastructure confirmed unaffected by the Rhysida data dump; forensic review of the 5.79TB continuesHighGovernment & Public SectorBerlin's Chief Digital Officer has stood up a task force combining the LKA, data-protection officials, and both affected Senate departments to assess the dumped data. Senator Iris Spranger stated no evidence of compromised election data and that the Sep 20 election's technical environment remains secure. BleepingComputer
Berlin Senate / Rhysida — 5.8 TB / 1.44M government files published Sep 4; critical infrastructure blueprints, police data, and federal defense plans now on the dark web; Sep 20 state election 13 days outCriticalGovernment & Public SectorRhysida's 7-day auction countdown ended ~15:35 local time Sep 4 after the Berlin Senate refused its 30 BTC (~EUR 2M) demand. The published dataset includes blueprints for Berlin's water and power grid infrastructure, police and LKA files, Bundeswehr documents, CBRN threat assessments, federal communication plans for a state of defense, and 12,000+ personnel records. Researchers confirmed critical infrastructure plans are in the dump. Berlin's interior administration has maintained that election-infrastructure systems are unaffected. 🟩 Data dump confirmed by independent researchers; the files are circulating on dark web mirrors. Cybernews · BankInfoSecurity
CISA KEV — seven new entries Sep 2; SonicWall SMA1000 SSRF (CVSS 10.0) and command injection chain; federal deadline Sep 5 passedHighGovernment & Public SectorThe Sep 2 batch added CVE-2026-83548 (SonicWall SMA1000 SSRF, CVSS 10.0) and CVE-2026-83549 (OS command injection, CVSS 7.8) — chainable to unauthenticated RCE — alongside CVE-2026-9586 (Sangoma Switchvox SQL injection, CVSS 9.3), CVE-2026-82329 (JFrog Artifactory improper authentication), CVE-2026-48710 (Kludex Starlette HTTP smuggling), CVE-2026-49869 (Kestra OS command injection), and CVE-2026-59822 (BerriAI LiteLLM improper authentication). FCEB agencies had until Sep 5 to patch all seven. Non-federal organisations running SonicWall SMA1000 on 12.4.3 or 12.5.0 builds (models 6210, 7210, 8200v) should treat patch application as urgent — public PoC and in-wild exploitation confirmed before the KEV addition. CISA KEV · The Hacker News · Rapid7
Rhysida — Berlin data dump confirmed; shift from extortion actor to strategic disruptorCriticalGovernment & Public SectorWith 1.44M files now publicly available, Rhysida has completed the full extortion-and-publish cycle against a NATO-member capital government. The dataset's content (critical infrastructure blueprints, federal defense communication plans, CBRN assessments) makes this more than a data-theft event — the material is now freely accessible to any state actor or criminal operator interested in Berlin's infrastructure vulnerabilities. The group has demonstrated willingness to publish even when the ransom is structurally certain to be rejected (government non-payment policy). Cybernews
Qilin — rank 1 sustained; YTD 546; no new high-profile confirmed victims in Sep 6–7 window; Sep 9 McKesson watch (ShinyHunters) remains the week's operative deadlineHighGovernment & Public SectorQilin DLS continues active postings without a single named critical-infrastructure or government victim in the immediate window. YTD trajectory: 546 claims across 103 countries. The ATF major-incident claim (Aug 26) remains under DOJ investigation. 🟥 ATF claim unverified. Ransomware.live
Rhysida's publication of Berlin's critical infrastructure blueprints — water grid, power systems, CBRN assessments, federal defense plans — is not a ransomware incident that resolved; it is a permanent intelligence windfall for any state actor with an interest in Germany's capital.CriticalGovernment & Public SectorThe published files are now indexed, mirrored, and searchable. Every hostile foreign intelligence service with an interest in European capital-city infrastructure now has, at zero cost, operational intelligence that Berlin spent years securing. The thirteen-days-before-election timing is secondary to the strategic consequence: Bundeswehr documents and federal state-of-defense communication plans in a publicly accessible dark-web archive represent a national-security loss that cannot be remediated by patching. Germany's BSI and the BfV will need to assess which of the 12,076 named individuals are in sensitive roles and whether the infrastructure blueprints have been acted on before the data's publication became public knowledge. Cybernews · BankInfoSecurity
The IDScan.net breach is structurally different from a credential or PII leak: it places biometric-quality identity documentation for 153 million North Americans in criminal and state-actor hands, and it may have been ongoing for over a year before discovery.CriticalFinancial ServicesGovernment & Public SectorDriver's license images with infrared and UV scans are the exact materials used by government border agencies and financial institutions for identity verification. A state actor possessing this dataset can fabricate credentialed personas at scale, defeating document-based identity assurance in travel, financial services, and physical access systems. The breach's undiscovered duration — the seller claimed ongoing access for "over a year" — means the complete scope is unknown. The FBI investigation is the operative response action; until IDScan.net confirms the breach's full timeline and current access status, its verification pipeline should be treated as untrusted by clients. Krebs on Security · CSO Online

Recent victim claims

Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.

September 2026

Sep 11 Agencia Estatal de Meteorología (AEMET) Panzer Ransomware · government · Spain Panzer, a newly observed RaaS operation running since Aug 5 2026 with 16-21 claimed victims across 11 countries in its first month, lists Spain's national meteorological agency, claiming roughly 5GB exfiltrated with a 20-21 day publication deadline. No agency confirmation yet; verify before treating as a breach. · Sources: EscudoDigital · Ransomware.live
Sep 08 Florida DAVID (Highway Safety and Motor Vehicles) ShinyHunters Extortion · Government · USA ShinyHunters claims access to Florida's DAVID driver/vehicle lookup database via a password-reset flaw compromising DMV-employee and FBI-agent accounts; ~200,000 driver records allegedly pulled by iterating IDs starting around Sep 3. Proof includes a screenshot of Jeffrey Epstein's DMV record. Verify before treating as a confirmed breach — FLHSMV has not confirmed the claim; leak-site deadline set for Sep 11. · Sources: https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/
Sep 04 Berlin Senate (urban development, transport, environment departments) Rhysida Ransomware · government · DE 5.79 TB / 1.44M files published to dark web after Berlin refused 30 BTC ransom. Data includes critical infrastructure blueprints for Berlin water/power grids, police/LKA files, Bundeswehr documents, federal defense communication plans, CBRN threat assessments, 12,000+ personnel records. Exfiltration Aug 7-12; detection Aug 14; auction countdown ended Sep 4; data dumped Sep 4-5. 13 days before Sep 20 state election. · Sources: https://cybernews.com/news/stolen-berlin-government-files-dumped-on-dark-web-rhysida/ https://www.bankinfosecurity.com/berlin-rejects-rhysida-ransomware-blackmail-a-32731

August 2026

Aug 30 AFSARD Qilin Ransomware · Government · GBR Qilin ransomware DLS claim posted August 30 2026. Organization based in Milton Keynes UK. Attack date not confirmed. · Sources: https://www.hookphish.com/blog/ransomware-group-qilin-hits-afsard/
Aug 28 Berlin State Government (Senate Department for Mobility and Environment) Rhysida Ransomware · Government · DEU Rhysida DLS claim Aug 28, 2026: 5.79TB exfiltrated Aug 7-12 from Berlin's Senate Department for Mobility, Transport, Climate Protection and Environment; 80K administrative offence proceedings and 46.5K contracts claimed; 30 BTC ransom demand (approx EUR 2M); Berlin refuses to pay; auction countdown started Aug 28; September 20 Abgeordnetenhaus election context; Interior Senator says election data not affected · Sources: https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html
Aug 26 Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) Qilin Ransomware · Government & Defense · USA Qilin posted ATF (atf.gov) to DLS Aug 26. ATF confirmed 'major cybersecurity incident' on a standalone system isolated from enterprise network. DOJ designated it a major incident under federal guidelines. No data samples published by Qilin. Standalone system; eForms and enterprise network unaffected. · Sources: https://cybernews.com/news/qilin-ransomware-bureau-alcohol-tobacco-firearms-atf-cyberattack/
Aug 14 Direction Generale des Finances Publiques (DGFiP) ZeroBytes (individual threat actor) Ransomware · Government / Tax Administration · FRA Hacker using alias ZeroBytes gained access via stolen internal VPN credentials in late June 2026; exfiltrated records of 678,000 individuals and businesses (names, reference income data, tax rates) in first breach (June); second theft (July) took 200,000 land-registry account details. DGFiP confirmed breach Aug 12 after ZeroBytes posted claim publicly. Data exposure creates targeted physical-robbery risk for high-income crypto holders in France given 30 violent wrench attacks in H1 2026. · Sources: https://therecord.media/french-tax-authority-dgfip-confirms-data-breach
Aug 11 Pennsylvania Attorney General's Office Unknown Ransomware · Government · US Ransomware attack struck communications systems; 1,200 staff affected; courts granted case extensions; recovery ongoing August 11 · Sources: https://therecord.media/pennsylvania-attorney-general-office-ransomware-attack-recovery
Aug 11 Otter Tail County INC Ransom Ransomware · Government · USA INC Ransom DLS claim posted August 17, 2026; attack estimated August 11. County government (population ~60,000, west-central Minnesota). Scope unconfirmed. · Sources: https://www.ransomware.live/id/T3R0ZXIgVGFpbCBDb3VudHksIE1pbm5lc290YUBpbmNyYW5zb20=
Aug 10 Canopy Support Services The Gentlemen Ransomware · Nonprofit · CA TheGentlemen DLS posting August 10, 2026; Canadian nonprofit; data scope unconfirmed · Sources: https://www.ransomware.live/

July 2026

Jul 30 Malaysian Nuclear Agency The Gentlemen Ransomware · government / nuclear research · Malaysia TheGentlemen DLS claim July 30, 2026; Malaysian government nuclear research and technology organisation; data scope and impact unconfirmed; 🟥 unverified · Sources: https://www.breachsense.com/breaches/ · https://www.ransomware.live/
Jul 29 Administratia Nationala a Penitenciarelor (ANP) Unknown Ransomware · Government · RO Romanian National Prison Administration posted to DLS July 29; group unconfirmed; data scope unknown · Sources: https://www.ransomware.live/
Jul 28 Swiss Federal IT Office (FOITT/BIT) Unknown Ransomware · Government · CHE SharePoint exploitation chain (CVE-2026-55040 JWT bypass + CVE-2026-56164 EoP); ~200 user and technical accounts compromised; attack detected July 28, external access blocked, passwords reset, servers being rebuilt; no confirmed data exfiltration beyond compromised credentials; attackers described as previously unknown · Sources: https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/
Jul 26 UK Police National Legal Database (PNLD) ExfilSquad Ransomware · Law Enforcement / Government · UK Attack detected July 26 2026; PNLD confirmed breach; ExfilSquad claims 135,000 contact records of UK police officers, criminal justice staff, and government partners (names, organisations, email addresses); 14 total ExfilSquad victims across 5 countries in this wave; exposure of officers in sensitive investigations is primary concern · Sources: https://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info-of-over-100-000-uk-police-officers-staff/amp/ https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html
Jul 25 Traffic Control and Road Safety Services Qilin Ransomware · Government/Transportation · Unknown DLS posting July 25 2026 by Qilin. Sector and country unconfirmed from snippets. · Sources: https://www.ransomware.live/
Jul 25 Plitvicka Jezera Nacionalni Park Qilin Ransomware · Tourism/Government · HR Plitvice Lakes National Park (Croatia), UNESCO World Heritage Site. DLS posting July 25 2026 by Qilin. Data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 22 South Korean National Diplomatic Academy Unattributed (suspected DPRK) Ransomware · government · KR South Korean Ministry of Foreign Affairs diplomatic training academy compromised; ~10,000 current and former diplomat records exfiltrated (names, IDs, email, encrypted passwords, job titles, affiliations); dwell time ~9-10 months (Apr/May 2025 – Feb 2026); zero-day + misconfigured security settings; South Korean officials describe exfiltration scope as 'unprecedented'; North Korean link under investigation; 🟨 attribution unverified · Sources: https://therecord.media/south-korea-cyberattack-foreign-ministry
Jul 19 Dephub Nova Ransomware · government (transportation/ports authority) · Indonesia Nova DLS posting July 19; Indonesian government transportation and ports authority entity; data claimed exfiltrated; unverified — no public statement from Dephub · Sources: https://www.ransomware.live
Jul 15 BRAC The Gentlemen Ransomware · Humanitarian/NGO · Bangladesh World's largest NGO listed on The Gentlemen DLS July 15; no public statement from BRAC. Unverified claim. · Sources: https://www.ransomware.live/group/the-gentlemen
Jul 10 Commune de Castries Payload Ransomware · municipal government · France French municipality (Castries, Hérault); Payload DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/payload · Sources: [ransomware.live]
Jul 10 Envision Unlimited MoneyMessage Ransomware · nonprofit · human services/US Chicago-based nonprofit providing residential, day, and community-based services for adults with intellectual and developmental disabilities; MoneyMessage DLS claim July 10, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/moneymessage · Sources: [ransomware.live]
Jul 09 Greene County Government (GA) Incrandom Ransomware · Government · US Greene County Georgia government; county servers taken offline after incident detected July 9 2026; Incrandom DLS posting July 28 2026; data scope unconfirmed; 🟥 unverified DLS claim · Sources: https://hoodline.com/2026/07/cyber-scare-knocks-greene-county-computers-offline/
Jul 09 Canadian Armed Forces (forces.gc.ca) Bavaqai Ransomware · Government / Defense · CAN Bavaqai (MedusaLocker/BAVACAI variant) listed the Canadian Armed Forces domain forces.gc.ca on its 'File Manager' DLS on approximately July 9 2026. Some tracker feeds index this under the medusalocker group slug. DLS claim — scope and exfiltrated data not confirmed. · Sources: https://socradar.io/data-breach/forces-medusalocker-ransomware-2026/
Jul 07 YMCA of Western North Carolina Interlock Ransomware · non-profit · community services/US Interlock DLS claim July 7, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/interlock · Sources: [ransomware.live]
Jul 04 Goodwill Manasota Qilin Ransomware · nonprofit · thrift retail/US Qilin DLS claim July 4, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 04 US government entity Kairos Ransomware · government · US 2TB of sensitive records exfiltrated including SSNs, fingerprints, financial data, and passport scans; ~$1M (~9.44 BTC) ransom paid July 4, 2026 to prevent publication; victim identity not publicly disclosed; pure data-extortion model — no encryption, no operational disruption; 🟨 payment confirmed, victim identity unconfirmed · https://thehackernews.com/2026/07/us-government-entity-paid-kairos-group.html · https://securityaffairs.com/194750/security/u-s-government-agency-paid-1m-to-data-extortion-group-kairos.html · Sources: [The Hacker News] · [Security Affairs]
Jul 04 Edgewood Police Department Wallstreet Ransomware · government · law enforcement/US Edgewood Police Department, Pierce County, Washington; Wallstreet DLS claim July 4, 2026; law enforcement targeting during holiday window; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/ · Sources: [ransomware.live]
Jul 03 Prince George County RansomHouse Ransomware · government · US Virginia county systems encrypted June 10 2026; phone, internet, and online payment systems disrupted; 911 unaffected; PII possibly exposed (names, addresses, DOBs, driver's licence numbers, SSNs); credit monitoring offered; FBI Cyber Crimes Division and CISA notified; RansomHouse claims encryption and posted evidence pack; county has not officially confirmed ransomware attribution or data theft; 🟥 unverified · https://www.wric.com/news/local-news/prince-george/county-government-cybersecurity-incident/ · https://www.govtech.com/security/prince-george-county-va-discloses-recent-cyber-attack · https://ransomware.live/id/UHJpbmNlIEdlb3JnZSBDb3VudHlAcmFuc29taG91c2U= · https://www.redpacketsecurity.com/ransomhouse-ransomware-victim-prince-george-county/ · Sources: [WRIC ABC 8News] · [GovTech] · [ransomware.live] · [RedPacket Security]
Jul 03 Oak Park INC Ransom Ransomware · local government · city/US Metro Detroit suburb in Oakland County; INC Ransom DLS claim July 3, 2026; attack estimated July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 03 City of Acworth, Georgia INC Ransom Ransomware · local government · US suburban Atlanta city northwest of the city; INC Ransom DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 02 AWO Kreisverband Südost e.V. SafePay Ransomware · social welfare non-profit · Germany German social welfare organization; SafePay DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/safepay · Sources: [ransomware.live]
Jul 02 COMHAR WorldLeaks Ransomware · health and human services non-profit · Ireland Irish non-profit providing community mental health, disability, and social services; WorldLeaks DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/worldleaks · Sources: [ransomware.live]
Jul 01 Boyne City The Gentlemen Ransomware · local government · US City of Boyne City, northern Michigan municipality; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01 Penticton and District Society for Community Living MedusaLocker Ransomware · nonprofit · disability services/Canada nonprofit organisation providing residential, employment, and social services for adults with developmental disabilities in the Penticton (BC) region; MedusaLocker DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/medusalocker-ransomware-victim-penticton-and-district-society-for-community-living/ · https://ransomware.live/id/UGVudGljdG9uIGFuZCBEaXN0cmljdCBTb2NpZXR5IGZvciBDb21tdW5pdHkgTGl2aW5nQG1lZHVzYWxvY2tlcg== · Sources: [RedPacket Security] · [ransomware.live]

June 2026

Jun 26 NSW Rural Fire Service Nova Ransomware · government · emergency services/Australia New South Wales Rural Fire Service; Nova DLS claim June 26, 2026; 300 GB claimed; RFS confirmed the breach June 24 but stated emergency operations were unaffected; no evidence of operational impact · https://www.cyberdaily.au/security/13817-exclusive-nova-ransomware-group-takes-responsibility-for-nsw-rfs-hack · https://www.ransomware.live/group/nova · Sources: [Cyber Daily] · [ransomware.live]
Jun 26 Life Bridges INC Ransom Ransomware · non-profit · social services/US non-profit organisation supporting individuals with intellectual and developmental disabilities; INC Ransom DLS claim June 25-26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.dexpose.io/incransom-targets-life-bridges-non-profit-in-ransomware-attack/ · https://www.breachsense.com/breaches/ · Sources: [DeXpose] · [Breachsense]
Jun 26 Policía de Turismo KRYBIT Ransomware · government · law enforcement/Dominican Republic Dominican Republic tourist police force; KRYBIT DLS claim June 26, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/june/ · Sources: [Breachsense]
Jun 24 mlit.com.my Stormous Ransomware · government · public sector/Malaysia DLS claim June 24, 2026; full 10GB data dump claimed including "highly sensitive internal information and financial records"; scope unconfirmed · https://www.redpacketsecurity.com/stormous-ransomware-victim-mlit-com-my-update-full-data-dump-new-link-10gb/ · Sources: [RedPacket Security]
Jun 23 Gov.br APT73 Ransomware · government · digital infrastructure/Brazil official state digital platform and domain zone of the Brazilian Federal Government claimed on DLS; impact scope unconfirmed; APT73 previously targeted siapenet.gov.br (April 2026) · https://www.blackfog.com/cybersecurity-101/apt73-ransomware-group/ · https://www.ransomware.live/group/apt73 · https://www.redpacketsecurity.com/apt73-ransomware-victim-www-siapenet-gov-br/ · Sources: [BlackFog] · [ransomware.live] · [RedPacket Security]
Jun 22 Royal Thai Navy Housing Cooperative The Gentlemen Ransomware · public sector · housing cooperative/Thailand cooperative managing housing projects, financial services, and welfare programs for Royal Thai Navy personnel and their families; The Gentlemen DLS claim June 22, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-royal-thai-navy-housing-cooperative/ · https://www.ransomware.live/group/thegentlemen · Sources: [RedPacket Security] · [ransomware.live]
Jun 21 Texas Parks and Wildlife Dept. Unattributed Breach · government · US 3,087,721 individuals exposed: driver's license numbers, passport numbers, email, phone, residential address; no SSNs/DOB/financial data; actor unattributed · https://www.techtimes.com/articles/318790/20260621/texas-data-breach-hits-3-million-drivers-licenses-passport-numbers-stolen-hunting-vendor.htm · Sources: [TechTimes]
Jun 17 SUNASS Nova Ransomware · government · water regulator/Peru Sources: ransomware.live DLS
Jun 16 Kedah State Government Nova Ransomware · government · Malaysia official state government portal providing public services for Kedah, Malaysia; Nova DLS claim June 16, 2026; estimated attack date June 16; data scope and impact unconfirmed · https://www.dexpose.io/nova-ransomware-group-targets-kedah-state-government/ · https://www.ransomware.live/id/S2VkYWhAbm92YQ== · Sources: [DeXpose] · [ransomware.live]
Jun 14 Council of Europe ShinyHunters Extortion · intergovernmental organisation · France 297 GB published June 16, 2026, after ransom deadline not met; content: 409,000+ payslips (2011–2026), 3,700+ personnel files, 14,000+ CVs, and employee personal/financial records (names, DOB, home addresses, phone, salaries, bank account details, SSN/tax information, medical records) for 10,000+ staff; claimed access vector: Oracle PeopleSoft CVE-2026-35273; Council of Europe states investigation is ongoing; data authenticity not yet independently verified by forensics · https://www.securityweek.com/shinyhunters-claims-council-of-europe-hack/ · https://www.bleepingcomputer.com/news/security/council-of-europe-investigates-shinyhunters-data-breach-claims/ · https://cybernews.com/security/council-of-europe-data-breach-claim/ · Sources: [SecurityWeek] · [BleepingComputer] · [Cybernews]
Jun 14 Winona County NightSpire Ransomware · government · US second ransomware attack on county in 2026; attack detected April 7; county network partially taken offline; MN National Guard assisted; NightSpire leaked data June 14 2026; county confirmed data leak same day; personal info affected pending review; 🟨 county-confirmed · https://www.govtech.com/security/cyber-criminals-leak-data-from-minnesota-ransomware-incident · https://www.dexpose.io/nightspire-ransomware-attack-on-k-county/ · Sources: [GovTech] · [DeXpose]
Jun 12 Blackbaud Icarus Ransomware · nonprofit · social-good CRM software/US Salesforce CRM data accessed via Klue OAuth integration; disclosed June 30, 2026; 🟨 scope unverified · https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/ · Sources: [SecurityWeek]
Jun 11 National Association of Insurance Commissioners ShinyHunters Extortion · insurance regulatory · US 3.1TB and 105,000+ files claimed; investigation confirmed (July 1): only publicly available statutory financial reports, outdated logs, and config files accessed; key systems SERFF/OPTins/UCAA/EDP/RDC confirmed intact; no consumer PII or payment data; breach via PeopleSoft CVE-2026-35273, access June 11; data published online by June 25; 🟩 breach confirmed, impact minimal (public regulatory data only) · https://www.insurancejournal.com/news/national/2026/06/24/875119.htm · https://www.bleepingcomputer.com/news/security/naic-says-public-data-stolen-in-shinyhunters-peoplesoft-breach/ · https://www.techradar.com/pro/security/naic-confirms-data-breach-with-shinyhunters-claiming-3-1tb-of-data-stolen-in-oracle-zero-day-attack · Sources: [Insurance Journal] · [BleepingComputer] · [TechRadar]
Jun 09 Cal Fresh Termite Ransomware · government benefits · US Sources: ransomware.live DLS
Jun 09 Mid-Cumberland Human Resource Agency Insomnia Ransomware · public services · US Sources: ransomware.live DLS
Jun 09 Katholiek Amersfoort Stormous Ransomware · religious org · Netherlands re-post "FOR SALE" · Sources: ransomware.live DLS
Jun 01 DHS Homeland Security Information Network Unattributed Breach · government · law enforcement information sharing/US HSIN servers and an associated SharePoint collaboration system compromised; used by state/local law enforcement fusion centers and federal agencies to share threat intelligence; attack estimated late May–early June 2026; disclosed July 1, 2026; DHS confirmed attack and isolated affected systems; forensic investigation underway; no classified networks affected; sensitive law enforcement operational data (open investigations, facility-threat mappings, inter-agency partner identities) potentially exposed; actor unattributed · https://www.bleepingcomputer.com/ · https://www.nextgov.com/ · Sources: [BleepingComputer] · [Nextgov/FCW]
Jun 01 Department of Homeland Security (HSIN) Unknown Ransomware · government-federal · US DHS confirmed intrusion into Homeland Security Information Network (HSIN), the SBU inter-agency intelligence-sharing platform; attackers stole credential files, ran malicious code, and deleted logs; initial alerts were dismissed as false positives giving extended dwell time (late May - early June 2026); classified systems not affected; House Homeland Security Committee requested formal briefing; 🟩 confirmed by DHS · Sources: https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/ · https://www.nextgov.com/cybersecurity/2026/07/dhs-network-intrusion-was-twice-ruled-false-positive-breach-confirmed/414724/

← All industries · Victim database →