Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationgovernment-diplomatic-threatthird-party-vendor-breachoperational-disruption

Public Sector Cybersecurity Threats and Ransomware Trends

Updated 3mo agoFirst seen Oct 29, 20252 sources

Government organizations worldwide are facing escalating cyber threats, with ransomware and extortion attacks sharply increasing in frequency and sophistication. Over 117 US federal and state entities were impacted in 2024, and attackers are increasingly targeting third-party providers and leveraging new tactics such as data extortion without encryption. The MOVEit and GoAnywhere supply chain breaches have had lasting repercussions, exposing sensitive data from government-linked organizations. Attackers are also employing advanced techniques, including the use of AI for phishing and deepfakes for social engineering, further complicating defense efforts. International coalitions, such as the Counter Ransomware Initiative (CRI), are urging stronger supply-chain cyber defenses and coordinated global action, highlighting the immediate and urgent threat ransomware poses to national security and economic stability.

Despite some progress in reducing ransomware payments, attacks continue to disrupt major companies and public sector entities worldwide. The CRI, now comprising 61 countries and six international organizations, has released new guidance emphasizing the need for improved cyber hygiene and legislative action to address supply-chain vulnerabilities. Critics warn that legislative gaps persist, leaving critical systems exposed, while the ongoing digital transformation and prevalence of legacy systems in the public sector further increase risk. The convergence of these factors underscores the urgent need for comprehensive cybersecurity strategies and international cooperation to bolster resilience against evolving threats.

Share:
Public Sector Cybersecurity Threats and Ransomware Trends
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Oct 29, 20258mo ago

Trustwave reports 1H 2025 rise in ransomware, extortion, and AI-enabled attacks

In its public-sector resilience report, Trustwave SpiderLabs said first-half 2025 threat activity showed continued growth in ransomware and extortion, including third-party targeting and data-only extortion. The report also noted increasing attacker use of AI for phishing, evasion, and deepfake-enabled social engineering.

SharePoint exploitation campaign impacts multiple US federal agencies

Trustwave SpiderLabs reported that a Microsoft SharePoint exploitation campaign affected multiple U.S. federal agencies. The campaign was cited as a concrete example of how quickly zero-day exploitation can translate into public-sector operational impact.

State-linked actors rapidly exploit 2025 SharePoint and Citrix Bleed flaws

According to Trustwave SpiderLabs, state-linked groups quickly weaponized newly disclosed 2025 zero-days, including Microsoft SharePoint and Citrix Bleed vulnerabilities. The report says this rapid exploitation reflects a broader trend of shrinking defender response time.

Balada Injector compromises sites via Popup Builder XSS flaw

Trustwave SpiderLabs highlighted a case in which the Balada Injector campaign compromised websites by exploiting an XSS vulnerability in the WordPress Popup Builder plugin. The case was presented as part of broader public-sector threat trends and web-based compromise activity.

Oct 27, 20258mo ago

CRI calls for stronger supply-chain cyber defenses

The Cyber Risk Institute urged organizations to strengthen supply-chain cybersecurity defenses, reflecting concern over third-party and interconnected-service risk. The call aligns with broader industry focus on resilience against cascading impacts from supplier compromises.

MOVEit and GoAnywhere supply-chain incidents cause downstream public-sector impact

Supply-chain compromises involving MOVEit and GoAnywhere were cited as having long-lasting downstream effects on public-sector organizations and their interconnected service providers. The references describe these incidents as key examples shaping later calls for stronger supply-chain cyber defenses.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

39 LINKEDOpen in app
Affected products
7 linked
MoveitScreenconnectBingWordpressNetscaler AdcNetscaler AdcSharepoint
Organizations
30 linked
LevelBlueNZTAArgentinian PoliceGovDeliveryEuropean Union (EU) Joint Cyber Response UnitDPRKDubai MunicipalityPeople's Republic of ChinaNaTISCloudflareRomanian GovernmentDocuSignWordpressTrustwaveUS Federal and State Government EntitiesIndiana Department of Local Government Finance (DLGF)US National Cybersecurity StrategyCitrix SystemsState of Nevada Procurement DepartmentSocial Security Administration (SSA)ConnectwiseTxTagMicrosoft CorporationSwitzerland's Public AdministrationNorth Atlantic Treaty OrganizationRussiaIPapiGooglePopup BuilderCraft
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.