Government & Public Sector — Cyber Threat Activity
Threat actors, incidents and malware targeting the Government & Public Sector sector — 679 recorded incidents and 384 tracked groups.
- Recorded incidents: 679
- Incidents, trailing 180 days: 153
- Tracked threat actors: 384
- Malware families: 514
Recent incidents
- City of McMinnville OR 2026-08-06
- Sc Regional Housing Authority 2026-08-04
- Mairie de Rinxent (Municipality of Rinxent) 2026-08-02
- Mairie de Drancy 2026-08-02
- Kenaitze Indian Tribe 2026-07-31
- The Municipal Chamber of Serra 2026-07-31
- Municipalidad de San Luis 2026-07-31
- ASELSAN 2026-07-31
- Malaysian Nuclear Agency 2026-07-30
- The Garfield County Sheriff Office 2026-07-30
- L3HARRIS 2026-07-30
- Greene County, Georgia 2026-07-28
- City of Atlanta 2026-07-26
- City of Houston 2026-07-26
- Police National Legal Database 2026-07-26
- UK Department for Education 2026-07-26
- KeNHA 2026-07-25
- Ejército Argentino 2026-07-24
- Brooklyn Defender Services 2026-07-24
- Centre for Newcomers 2026-07-17
Threat actors targeting Government & Public Sector
- Qilin 75 incidents
- LockBit 67 incidents
- INC Ransom 57 incidents
- RansomHub 51 incidents
- Medusa Ransomware 30 incidents
- Rhysida 29 incidents
- FunkSec 24 incidents
- The Gentlemen 21 incidents
- BlackSuit 20 incidents
- SafePay 18 incidents
- RansomHouse 17 incidents
- Handala 14 incidents
- APT73 14 incidents
- Lynx Ransomware 14 incidents
- KillSec 13 incidents
- Stormous 13 incidents
- Hunters International 13 incidents
- DragonForce 11 incidents
- NightSpire 11 incidents
- Fog Ransomware 11 incidents
- Meow 9 incidents
- Akira 8 incidents
- Play Ransomware 8 incidents
- Krybit 6 incidents
Where these victims are
- United States 353
- United Kingdom 26
- Canada 24
- France 23
- Brazil 13
- Israel 13
- Germany 10
- India 9
- Mexico 8
- South Africa 8
- Malaysia 7
- Peru 7
Malware used against Government & Public Sector
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Akira Malware
- Black Basta Malware
- Clop Malware
- Cobalt Strike Malware
- Conti Malware
- Emotet Malware
- Impacket Tool
- Mimikatz Tool
- NotPetya Malware
- PlugX Malware
- PsExec Tool
- QakBot Malware
Coverage. 76.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.