home.social

#govsec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #govsec, aggregated by home.social.

fetched live
  1. The city manager of the City of Coweta is refusing to even contact unnamed threat actors and says the city will not pay any ransom in response to a recent ransomware attack.

    Why? Because the city manager was with another city that was attacked; even though that city paid the ransom, it was reinfected two weeks later. So now she is very anti-paying.

    Read more at KTUL:
    ktul.com/news/local/city-of-co

    And as I previously reported on this incident, the city has an offsite backup they say they can use to restore all city files after they clean the servers of ransomware.

    Good for her and the city.

    #govsec #ransomware #cybersecurity #databreach

  2. Milford, New Hampshire seems to be dealing with a cyberattack since July 15, but they don’t call it that and haven’t revealed many details. A resident wonders whether the breach was caused by a vulnerability he reported to them in May that they did not address. My post about it all:

    databreaches.net/2026/07/21/mi

    #govsec #cybersecurity

  3. 🏛️ CISA Contractor AWS GovCloud Security Leak

    📝 CISA contractor exposed AWS GovCloud credentials and internal system details.

    schneier.com/blog/archives/202

    📰 Schneier on Security

    #GovSec #AI #CloudSec

  4. I may have to add Moldova to my list of countries I may not be able to visit. I just posted a two-fer involving two of their government portals:

    databreaches.net/2026/02/19/da is about a long-time IDOR incident that exposed the personal info of everyone who ever used the govt portal to apply for a job. The vulnerability was brought to my attention by a student who was frustrated with his government's lack of response to his attempts to get them to address it.

    and

    databreaches.net/2026/02/19/le discusses an alleged hack by Bashe Team of another portal used by Moldovan residents to apply for energy compensation.

    In May 2025, the government had denied claims that access to the compensation portal had been sold. "No evidence.... smoke and mirrors... " they claimed.

    Fast forward to January 2026, and data from that portal and timeframe was leaked after Bashe Team claimed to have hacked it. But while the data appear to be real, Bashe Team's claims about how and when they acquired it didn't check out.

    Bashe Team seems to be allergic to telling the truth about their listings. @cloudsek noted their less-than-honest claims in 2025; DataBreaches.net notes it now, and @amvinfe has also noted it in his new reporting on #SuspectFile.

    #databreach #leak #vulnerability #cariere #compensatii #govsec #cybersecurity #Bashe #APT73 #Eraleign

    @campuscodi @euroinfosec @lawrenceabrams

  5. I commented on an attack on Trumbull County, Ohio, by Anubis that @amvinfe reported this week. I will continue to try to follow up, but in the meantime, I posted this:

    "Tell the truth, or someone will tell it for you — Trumbull County, Ohio edition."
    databreaches.net/2025/12/09/te

    #databreach #ransomware #wiper #govsec #incidentresponse #transparency #Anubis #Trumbull_County

  6. Remember that frustrating situation where some of us couldn't get a vendor to respond to notifications that court-sealed records and sensitive files were exposed? One entity eventually reached the vendor by phone and was so angry at their response that they wound up canceling their account with them.

    Yesterday, I finally reached the second court entity. They, too, wound up telling the vendor to take the share down.

    How many other clients may still have exposed data because the vendor tells clients that everything's fine when it isn't? I don't know. If you know any entity using Software Unlimited Corp software (not Software Unlimited Inc, but Software Unlimited CORP), you may want to point them to my coverage:

    Original Report:
    databreaches.net/2025/10/13/mo

    Today's Update:
    databreaches.net/2025/10/31/ho

    #dataleak #vendor #incidentresponse #cybersecurity #SoftwareUnlimitedCorp #FTC #govsec

    @zackwhittaker @euroinfosec @campuscodi @JayeLTee

  7. Kaufman County, Texas has been the victim of TWO cyberattacks in October.

    The media now reports, "With two events in the same month, questions are now being raised about the overall security of Kaufman County’s computer systems and whether adequate safeguards are in place to prevent future compromises."

    Ya think?

    There's currently no information that has been disclosed as to whether the two attacks were carried out by the same attackers or if they involved the same means of access. But PII was impacted in the first one, and the second attack has affected county operations by encrypting files.

    #databreach #govsec #cybersecurity

  8. From the Minnesota Star Tribune:

    "Secretary of Defense Pete Hegseth considered sending an elite U.S. Army strike force to Portland, Ore., to quell protests that President Donald Trump has characterized as “lawless mayhem,” according to images of messages provided to the Minnesota Star Tribune.

    The messages, casually exchanged last weekend in a crowded, public space, show high-level officials in the Trump administration discussing the deployment of the Army’s 82nd Airborne, an infantry division that has been parachuted into combat zones in both world wars, Vietnam and Afghanistan. If the administration were to send in the Army division, it would almost certainly be challenged in court under federal laws limiting how the military can be used domestically."

    Read more at startribune.com/trump-official

    #NatSec #GovSec #IdiotsAbound #infosecurity

  9. Ok, so if anyone needs to raise their blood pressure, consider this:

    Remember the Rhysida cyberattack affecting Columbus, where a researcher attempted to refute the city's claims about the severity of the breach, and the city obtained an injunction gagging him, subsequently suing him, etc.?

    There was a class action lawsuit against the city over the breach that got dismissed.

    Why did the suit get dismissed? Because under state law, the city IT was immune.

    So, the whistleblower can be sued by the city for discussing the breach, but the city cannot be sued for its subpar cybersecurity that resulted in the theft of data from 500,000 people.

    myfox28columbus.com/news/local

    #govsec #ransom #databreach #cybersecurity #freespeech

  10. @chum1ng0 Thanks for that write-up.

    "The incident affected the National Health Plan Monitoring and Evaluation System (SIMEPLANS), which houses the Ministry's policies, regulations, and annual planning. The data contained in this system is public and does not include sensitive patient information."

    Passwords and login credentials are public? I agree with you that their statement sounds a bit "off."

    #databreach #govsec

  11. In early August, the Pennsylvania Office of the Attorney General was hit by a ransomware attack that left them unable to access archived emails, files, and internal systems crucial to pursuing cases on behalf of the commonwealth.

    There was a ransom demand, but the state refused to pay.

    Today, INC Ransom added the Office of the Attorney General to its dark web leak site, as per ransomlook[.io]. But the listing doesn't show up on the leak site at this time, so it's not clear whether INC Ransom has actually leaked any data or not at this point.

    The state indicated it's still trying to figure out who may need to be notified. They have only notified a few people at this point.

    The state's most recent update was on September 17:

    attorneygeneral.gov/taking-act

    #databreach #ransomware #govsec #INCransom #cybersecurity

  12. Cue "Breaking Up is Hard To Do" as background music for this one:

    Less than one hour after posting their "goodbye" message about how they're going silent, ShinyHunters/LAPSUS$/ScatteredSpider posted redacted screengrabs that look like were taken from CJIS.

    The group had claimed they have hit some gov agencies -- including "highly secured ones," but had not responded to inquiries about which agencies.

    And now they post this.

    So... it's unconfirmed at this point, but has CJIS been hacked by these threat actors? I've sent an inquiry to #DOJ, but I don't expect to hear back quickly on this one.

    #databreach #govsec #cybersecurity #CJIS

  13. @sebgogola I should probably post an update on the situation because I am now also totally disgusted with the FBI who have done NOTHING USEFUL AT ALL when all they should have done is pick up the g.d. phone or knock on the door of the vendor and tell them to lock down the clients' shares that are exposed before even more of them get locked by threat actors.

    (yes, I'm screaming)

    But did they contact the vendor? Not to my knowledge. In fact, the Mississippi FBI passed me over to IC3, who then didn't contact me and passed it back to Mississippi who then reportedly passed it to another office.

    Hey, Donald Trump and Kash Patel: this is your FBI. At least three court systems have their records exposed by a vendor who does not respond to alerts.

    #DataLeak #GovSec #Cybersecurity #IncidentResponse

  14. Well, I've had it. The firm responsible for exposed court and prosecution files from at least two states has not responded to phone calls, emails, LinkedIn messages, or contacts by their host.

    On Saturday, I called the FBI tip line and let them know what's going on. Maybe the FBI will call me and ask me for the IP addresses so they can call the firm and tell them to lock down the damned shares.

    Then today, I filed a formal #FTC complaint against the firm for violation of Section 5 of the FTC Act for its inadequate security, its failure to have any procedure to receive, evaluate, and escalate third -party alerts of security issues, and for using the same password in all client installations for a Msql SQL database.

    And oh, last night I learned that a court system in a third state was not only exposed, too, but was hit by ransomware in March. Lovely.

    #cybersecurity #infosec #incidentresponse #FTC #govsec #judiciary #dataleak #databreach

  15. Correcting this because it looks like this doesn't involve any federal court. But there are exposed sensitive records, some of which were ordered sealed.

    NEW: Federal judiciary says it is boosting security after cyberattack; researcher finds new leaks

    More of those frustrating leaks where, despite our best efforts, we have been unable to get the network shares locked down so far, even with the host's assistance.

    This one involves two courts: and yes, we saw some files that were supposed to be sealed or confidential.

    databreaches.net/2025/08/10/fe

    #dataleak #infosec #cybersecurity #databreach #govsec

  16. York County, Pennsylvania incident:

    An employee of a vendor that had been hired to develop software for York County Civil Courts was provided “with certain York County Civil Courts data to use for software development and testing purposes. The employee subsequently left the vendor’s employment without returning this data,” according to the county's press release.

    So it seems they gave the vendor's employee REAL data to use for development and testing -- with "contact information, Social Security numbers, driver’s license or state ID card numbers, financial and medical information"

    And of course, there's no evidence of misuse, but they have referred the matter to law enforcement.....

    h/t, pennlive.com/news/2025/05/cent

    #infosecurity #govsec #insiderthreat

  17. WBAL-TV11 started digging into the #Kairos attack on the State Attorney's Office for the City of Baltimore.

    Kairos had exfiltrated 325 GB of files, and none of it appeared to have been protected with any encryption. My previous report on the incident can be found here: databreaches.net/2025/04/19/ba

    The city has now confirmed they had a breach (they were notified by law enforcement as they hadn't detected it on their own, it seems). But they are not giving out any details or answering any questions. See WBAL-TV's coverage at wbaltv.com/article/baltimore-s

    So, of course, I have now filed a public records request under #MPIA to try to get answers to some questions because the state ignored all of my polite email inquiries.

    Did I ever mention that I hate not getting answers to questions? :)

    #databreach #govsec #cybersecurity

  18. So remember the ransomware attack discovered last July by Columbus, Ohio -- who raced to court to chill the speech of a researcher (David Ross, aka "Goodwolf") who disputed their claims about the breach?

    Well, now it comes out that there was also some medical info from emergency services involved in the breach:

    spectrumnews1.com/oh/columbus/

    They discovered the medical stuff in December and are first sending out letters to those affected now.

    #databreach #govsec #healthsec #ransomware #Rhysida

  19. It appears Brain Cipher did leak the RIBridges data on their leak site, and it appears to be the same data they had provided to me pre-leak and that I described yesterday:

    databreaches.net/2024/12/30/mo

    And no, none of the data I inspected was encrypted.

    The leak site is still iffy to connect to.

    #databreach #ransom #healthsec #govsec #Deloitte #cybersecurity

  20. From the Better-Late-Than-Never Department:

    "Washington County is preparing to implement a new policy on how to respond to future cybersecurity attacks after a ransomware strike crippled the county government for more than two weeks earlier this year.

    County solicitor Gary Sweat is asking the commissioners to consider approving a “business continuity and disaster contingency” plan that would have a protocol for county workers and its IT department to follow in the event of another cyber emergency."

    As a reminder, they paid $350k ransom to ransomware gang to get decryptor key.

    observer-reporter.com/news/loc

    #databreach #ransomware #govsec #riskassessment #disasterplan #IncidentManagement #cybersecurity

  21. In early October, Wayne County in Michigan announced it was the victim of a cyberattack that a source acknowledged involved disruption and a ransom demand.

    Today, Interlock has claimed responsibility for the attack and leaked data. They claim: "We offer you more than 130 SQL databases. A large collection of confidential criminal investigation files, personal data of residents. "

    The leak is 7.7 TB of data. There are six screencaps as POC, and a list of files that can be separately downloaded. From the list, it does look like there is a lot of PII and sensitive info. :(

    There doesn't seem to be anything on Wayne's website or FB page at this point about today's leak and claims.

    @brett

    #GovSec #ransomware #databreach