Government & Public Sector — Cyber Threat Activity

Government and public sector is the widest threat surface in this dataset, attacked by criminals for disruption and by states for intelligence. Our log records more than 650 incidents across 80 countries, over 150 in the trailing 180 days, with 62 groups attributed at least one claim: Qilin (78), LockBit (67), INC Ransom (57), RansomHub (51), Medusa (30) and Rhysida (30) lead. Municipalities, school districts, courts and emergency services absorb most of that volume, because they hold citizen data and deliver services that cannot stop, while running on budgets that treat security as a capital project rather than an operating cost. Above that criminal layer sits the largest state-sponsored graph we hold: 398 groups are associated with the sector once profile-level research is counted, and hundreds of malware families are linked through those actors. State interest in government targets is durable rather than opportunistic, and the tradecraft reflects it. Operators have compromised cloud identity infrastructure to read government mailboxes directly, and Chinese state actors have been assessed by CISA, NSA and FBI as pre-positioning inside critical networks using living-off-the-land techniques, holding access for years without deploying malware that would give them away. That objective is optionality in a future crisis, not theft today, and it produces almost no incident-log signal, which is exactly why the measured count below understates the sector. Recorded geography is United States-led at 358 claims, then the United Kingdom, Canada, France, Brazil and Israel. Ransomware claims here are attacker assertions; the espionage activity that matters most to a national government rarely appears in any public dataset at all.

All sectors

Recent incidents

Threat actors targeting Government & Public Sector

Where these victims are

Malware used against Government & Public Sector

Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.

Coverage. 94.9% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.

Read the full analysis on IntelFusions