Email security breaches in state services

Explore top LinkedIn content from expert professionals.

Summary

Email security breaches in state services refer to incidents where unauthorized individuals gain access to government email systems, often leading to the exposure of sensitive data, financial losses, or compromised public trust. These breaches typically occur through phishing attacks, compromised email accounts, or insufficient security measures, making government agencies and public institutions frequent targets.

  • Verify identities carefully: Always confirm the identity of anyone requesting sensitive information or changes to payment details by using established contact methods, not just email responses.
  • Limit data access: Restrict access to sensitive systems and information until proper verification steps, such as video calls or multi-person approval, are completed.
  • Monitor for unusual activity: Regularly review email usage and system behavior to catch signs of compromised accounts or suspicious requests early.
Summarized by AI based on LinkedIn member posts
  • View profile for Andy Jenkinson - WHITETHORN SHIELD

    Fellow Cyber Theory Institute. Director Fintech (FITCA). NAMED AN EXPERT IN INTERNET ASSET & DNS VULNERABILITIES AND THREAT INTELLIGENCE. IF I REACH OUT TO YOU - CHANCES ARE YOU HAVE A PROBLEM...

    39,936 followers

    UK Ministry of Defence Mail Servers Left Critically Exposed for Years: A Catastrophic Security Oversight. While the Defence Secretary hailed yesterday as the “first day of accountability” following a highly publicised email breach, the reality tells a much darker story. The notion that a single email error triggered a global security failure is possibly dangerously misleading. According to research shared today with both the UK Home Office and the UK Ministry of Defence, the UK Ministry of Defence’s critical Mail Exchange (MX) servers—handling all inbound and outbound email traffic—have been catastrophically insecure and exposed since at least February 2021. This scandal is far from an isolated human error. This is systemic negligence of the most basic cybersecurity principles. For over four years, long before the 'rogue email' was sent in 2022, the UK Ministry of Defence communications—potentially including military strategies, intelligence, personnel data, and international correspondence—have been traversing insecure infrastructure, easily intercept able by hostile states or cybercriminals. The UK Ministry of Defence have unsurprisingly suffered several cyber incidents over the last several years. Rather than owning this critical exposure, a single, unnamed individual has seemingly been scapegoated to divert attention from this continued catastrophic institutional failure. This is not accountability; it’s damage control and limitation. Meanwhile, the vulnerable MX servers remain exposed, perpetuating unacceptable risk. The implications are staggering: operational compromise, intelligence leaks, and reputational damage costing the UK taxpayer tens of billions. The real story here and threat isn’t a rogue email—it’s the ongoing failure to secure the nation's most sensitive digital communications.

  • View profile for Darren Mott, FBI Special Agent (Ret.), "The CyBUr Guy"

    Helping critical infrastructure organisations reduce exposure to costly hybrid cyber, physical & insider threats within 6 months through Former FBI & UK Military Intelligence-led Counter Threat Intelligence.

    7,702 followers

    $432,739.21. That's how much the City of Arab, Alabama just lost to a single phishing email. And municipalities, especially small ones, need to listen up! Not a sophisticated nation-state hack. Not a zero-day exploit. A fraudulent invoice. Someone impersonated an officer of the construction company building the city's new Recreation Center, redirected a payment, and walked away with nearly half a million dollars of taxpayer money. During my 20 years at the FBI, I investigated/managed cases exactly like this. Business Email Compromise (BEC) and invoice fraud schemes are one of the most financially devastating cyber threats in the country, and they don't require a single line of malicious code. Here's what makes this so dangerous: it exploits trust, not technology. The attacker didn't breach a firewall. They didn't deploy ransomware. They studied the relationship between the city and its contractor, crafted a convincing request, and let human nature do the rest. Three things every organization, should have in place RIGHT NOW: 1️⃣ Out-of-band payment verification. Any request to change banking details or redirect a payment gets confirmed by a phone call to a KNOWN number. Not the number on the email. A number you already have on file. 2️⃣ Dual authorization on payments above a threshold. No single employee should be able to approve a $432K transaction without a second set of eyes. 3️⃣ Regular social engineering awareness training. Not once a year. Not a checkbox exercise. Ongoing, scenario-based training that mirrors real-world attacks like this one. Five federal and state agencies, including the FBI, DHS, and Secret Service, are now investigating. Investigators have noted similar schemes targeting municipalities and school systems nationwide, with some originating overseas. If it can happen to a city government with law enforcement partners down the street, it can happen to your business. Knowledge is Protection. #CyberSecurity #PhishingAttack #BEC #BusinessEmailCompromise #TheCyBUrGuy #KnowledgeIsProtection #Alabama #InvoiceFraud #CyberAwareness

  • View profile for Alon Gal

    Co-Founder & CTO at Hudson Rock

    21,644 followers

    🚨 Community Warning: Hackers are using compromised corporate email accounts to socially engineer access to cybersecurity platforms. On August 9th, a threat actor requested a free preview API key from Hudson Rock using the email address pmm.cussetvichy-assistant.fct@def.gouv.fr. After the request, we confirmed that they were indeed the owner of that email address. We provided a free API key that does not display any sensitive information (we actually had it public until a week ago when it started being abused). As a standing principle, we do not show anyone private data until we've had a call with them and verified that they hold a relevant position in the company they claim to represent. As part of our routine checks for suspicious activities, we noted that the free key we provided was used extensively over a period of 24 hours. Along with another pre-scheduled task, we discovered that the email pmm.cussetvichy-assistant.fct@def.gouv.fr is associated with a computer that was infected by an Infostealer that same week. This confirmed our suspicion that the email address was in the possession of a threat actor. We immediately shut down their limited access and ensured that no one at our company accidentally granted them uncensored access. A scenario I can imagine was about to unfold is the threat actor trying to push the team to give them uncensored access because they "really want to close a deal but just need to check some data first" or some other excuse to cause urgency. Bottom line: we successfully fended off this attack before it materialized into anything significant. We also provided the French authorities with the data. Important Lessons: - Our policy of not providing uncensored access until a Zoom call is conducted has proven to be highly important. A simple email exchange isn’t enough; additional verification steps, such as video calls or cross-referencing with known contacts, should be employed. - The discovery of the compromised email account was partly due to routine checks and monitoring of usage patterns. Continuous monitoring and anomaly detection are vital for identifying unusual activity that could indicate a security breach. Always check if prospects are signing up with email addresses that have been involved in Infostealer infections. This is how threat actors often gain access. You can ask VX-Underground how many emails they receive from compromised email addresses belonging to government employees around the world; it is highly common. - The decision to provide a limited API key, which only exposed non-sensitive information, eliminated the potential damage. Restricting access to sensitive data and only granting it after thorough verification is a best practice. As a side note, just this week a threat actor acquired a commercial license to cybersecurity firm Socradar which led to a leak of 330,000,000 emails. It is evident that cybersecurity firms are being targeted by hackers and it's important to stay alert.

  • View profile for Serhii Demediuk

    Chairman of the Board at Institute of Cyber Warfare Research. National Security and Defence of Ukraine. Cyber Technologies and AI.

    3,684 followers

    Since the beginning of 2026, CERT-UA has recorded the mass distribution of phishing emails impersonating central executive authorities and regional administrations, allegedly regarding updates to applications used in civilian and military systems. These emails contain either an executable (EXE) file or a link to a website vulnerable to XSS (Cross-Site Scripting). Visiting such a website results in the execution of malicious JavaScript code and the subsequent download of an executable file onto the victim’s computer. The referenced EXE files and scripts are hosted on repositories within the legitimate GitHub service. The following malware tools have already been confirmed in these campaigns: • SHADOWSNIFF (GitHub-hosted stealer) • SALATSTEALER (MaaS stealer) • DEAFTICK (primitive backdoor written in Go) Additionally, during the analysis of GitHub repositories, researchers identified software exhibiting characteristics of ransomware (internally labeled “AVANGARD ULTIMATE v6.0”), as well as an archive containing an exploit for the WinRAR vulnerability (CVE-2025-8088). This activity has been associated with the Telegram channel “PalachPro.” The campaign is currently tracked under the identifier UAC-0252. Indicators of Compromise (IoCs) are available at: https://lnkd.in/dHZUf_wd

  • View profile for Saritha Valthati

    Co-Founder & CEO - Nexson IT Academy || Digital Marketing Expert || AI Expert || Training Advisor.

    2,187 followers

    🚨 BlindEagle Cyber Attacks: Government Agencies Under Targeted Threat Did you know that some cyberattacks today are not random — they are carefully planned and aimed at government agencies and public institutions? Recent threat activity linked to BlindEagle highlights how attackers use targeted phishing and malware campaigns to infiltrate official systems. What many people miss: These attacks often don’t look suspicious at first. Attackers typically use: • Emails that appear to come from trusted internal sources • Documents or links that look official • Multi-stage malware that activates silently after opening Once inside, attackers can gain long-term access, monitor activity, or steal sensitive data. Why this matters to everyone: • Government data breaches can impact public services • Stolen information may later fuel scams and fraud • These attacks show how trust is exploited, not just technology Simple awareness tips: ✔️ Treat unexpected emails carefully — even if they look official ✔️ Avoid opening attachments from unknown or unusual senders ✔️ Verify before clicking links related to “urgent” matters ✔️ Keep systems updated and security controls active Modern cyberattacks succeed by exploiting human trust, not just technical gaps. Awareness is still one of the strongest defenses. 👉 Share this to spread awareness. Disclaimer: This content is for educational and awareness purposes only. It does not promote hacking or unauthorized access. Always practice cybersecurity responsibly and within legal boundaries.

  • View profile for Supro Ghose

    CIO | CISO | Cybersecurity & Risk Leader | Fintech, Banking & Financial Services | Cloud & AI Security | NIST CSF/ AI RMF | Board Reporting | Digital Transformation | AI Governance | Banking & Reg Ops | Adjunct Professor

    16,961 followers

    𝗢𝗳𝗳𝗶𝗰𝗲 𝗼𝗳 𝘁𝗵𝗲 𝗖𝗼𝗺𝗽𝘁𝗿𝗼𝗹𝗹𝗲𝗿 𝗼𝗳 𝘁𝗵𝗲 𝗖𝘂𝗿𝗿𝗲𝗻𝗰𝘆 (𝗢𝗖𝗖) suffered a recent cloud email breach, that highlighted critical vulnerabilities in email security and access management that have broader implications for all federally regulated institutions. 𝚂̲𝚞̲𝚖̲𝚖̲𝚊̲𝚛̲𝚢̲ ̲𝚘̲𝚏̲ ̲𝚝̲𝚑̲𝚎̲ ̲𝙾̲𝙲̲𝙲̲ ̲𝙱̲𝚛̲𝚎̲𝚊̲𝚌̲𝚑̲ ̲An attacker gained unauthorized access to a privileged administrative email account within the Microsoft environment. The breach went undetected for 8 months, during which sensitive government communications were silently exfiltrated. More than 150K email messages were compromised, affecting around 100 officials. The incident exposed critical shortcomings in access control enforcement, monitoring, and response protocols. 𝙺̲𝚎̲𝚢̲ ̲𝙵̲𝚊̲𝚒̲𝚕̲𝚞̲𝚛̲𝚎̲𝚜̲ ̲𝙸̲𝚍̲𝚎̲𝚗̲𝚝̲𝚒̲𝚏̲𝚒̲𝚎̲𝚍̲ 1. Overprivileged Access – An administrative account with wide mailbox visibility was compromised, facilitating prolonged data exfiltration. 2. Delayed Detection – Anomalous behavior went unnoticed for months, raising concerns about the efficacy of real-time monitoring and alerting. 3. Stale and Unlocked Service Accounts: There were no policies in place for password rotation, inactivity lockout, or login attempt lockout for service accounts, making them vulnerable to brute-force or credential stuffing attacks. 4. Unaddressed Internal Warnings – Known risks flagged in prior audits related to email and access security had not been remediated in time. 5. Insufficient Conditional Access Policy Enforcement – The compromised account, linked to Azure, bypassed MFA and geo restrictions due to a poorly enforced conditional access framework. VPN usage further masked malicious activity.   𝙻̲𝚎̲𝚜̲𝚜̲𝚘̲𝚗̲ ̲𝚕̲𝚎̲𝚊̲𝚛̲𝚗̲𝚎̲𝚍̲:̲ 1. Enforce Microsoft Conditional Access Policies – Ensure all accounts, including service accounts, are subject to robust Conditional Access, MFA, and geo-restrictions. 2. Tighten Access Control – Limit and monitor privileges of administrative and service accounts; apply just-in-time access models. 3. Audit and Harden Service Accounts – Eliminate hardcoded credentials, enforce regular password rotation, enable account lockouts after failed login attempts, and setinactivity thresholds. 4. Strengthen Detection – Invest in behavioral analytics, adaptive authentication, and cloud-native threat detection tools. 5. Review and Limit Privileges – Conduct a review of privileged accounts and implement RBAC and JIT access where possible. 6. Ensure compliance with secure baseline configurations like those in DHS CISA BOD 25-01 - Secure Cloud Baseline [SCuBA] (stated in OCC response) The 𝗢𝗖𝗖 𝗯𝗿𝗲𝗮𝗰𝗵 is a cautionary tale—reactive controls alone are insufficient in today’s environment. Proactive hardening of identity, access, and cloud email infrastructure must be a top priority. https://lnkd.in/ef_4DQ3V

  • View profile for Dave Schroeder, PhD

    🇺🇸 Strategist, Cryptologist, Cyber Warfare Officer, Space Cadre, Intelligence Professional. Personal account. Opinions = my own. Sharing ≠ agreement/endorsement.

    28,983 followers

    Hackers exploited a major security flaw in widely used Microsoft server software to launch a global attack on government agencies and businesses in the past few days, breaching U.S. federal and state agencies, universities, energy companies and an Asian telecommunications company, according to state officials and private researchers. The U.S. government and partners in Canada and Australia are investigating the compromise of SharePoint servers, which provide a platform for sharing and managing documents. Tens of thousands of such servers are at risk, experts said, and Microsoft has issued no patch for the flaw, leaving victims around the world scrambling to respond. The “zero-day” attack, so called because it targeted a previously unknown vulnerability, is only the latest cybersecurity embarrassment for Microsoft. Last year, the company was faulted by a panel of U.S. government and industry experts for lapses that enabled a 2023 targeted Chinese hack of U.S. government emails, including those of then-Commerce Secretary Gina Raimondo. This most recent attack compromises only those servers housed within an organization — not those in the cloud, such as Microsoft 365, officials said. Microsoft has suggested that users make modifications to SharePoint server programs or simply unplug them from the internet to stanch the breach. Microsoft issued an alert to customers but declined to comment further. “Anybody who’s got a hosted SharePoint server has got a problem,” said Adam Meyers, senior vice president with CrowdStrike, a cybersecurity firm. “It’s a significant vulnerability.’’ The Federal Bureau of Investigation (FBI) said in a statement that it was aware of the matter. "We are working closely with our federal government and private sector partners,” it said. “We are seeing attempts to exploit thousands of SharePoint servers globally before a patch is available,” said Pete Renals, a senior manager with Palo Alto Networks Unit 42. “We have identified dozens of compromised organizations spanning both commercial and government sectors.’’ With access to these servers, which often connect to Outlook email, Teams and other core services, a breach can lead to theft of sensitive data as well as password harvesting, Netherlands-based research company Eye Security noted. What’s also alarming, researchers said, is that the hackers have gained access to keys that may allow them to regain entry even after a system is patched. “So pushing out a patch on Monday or Tuesday doesn’t help anybody who’s been compromised in the past 72 hours,” said one researcher, who spoke on the condition of anonymity because a federal investigation is ongoing. https://lnkd.in/geCnaEHG

  • View profile for Alex W.

    DFIR Executive | Ransom Negotiator | Threat Hunter | Strategic Advisor | Speaker

    14,489 followers

    Ever think cyber threats are more flash than impact? Think again. The Pennsylvania Attorney General’s Office just confirmed a ransomware attack caused a multi‑week outage—knocking out their website, email, and phone systems. And no, they didn’t pay a dime.   Here’s the breakdown: The incident began around August 11, with systems down across public-facing and internal channels. Gradual recovery is underway—emails and phone lines are being restored, and staff are working via alternate methods. Courts stepped in, offering extensions for civil and criminal cases. Still, prosecutors say there’ll be no lasting legal impact No ransom was paid. The attack was clearly designed to encrypt files and force payment—but the office stood firm.   What this means for all of us in cybersecurity: 🔐No org is too institutional to be sidelined by ransomware. Even state-level agencies aren’t immune. 🛡️Recovery isn’t simple. When core channels are down, agencies pivot—but these workarounds aren’t sustainable long-term. 📊Not paying ransom is principled—but rebuilds are costly. You need resilience, not just prevention. ⚖️Legal and procedural flows matter. Courts offering delays helped—but only because they could.   My two cents as someone deep in the field: Plan for the offline reality. Design IR strategies that assume even basic systems might be inaccessible. Communications contingency = mission-critical. If email and phones go down, how will your team stay coordinated? Resilience wins over reaction. Prevention matters—but expect to bounce back, not just button-up. Transparency preserves trust. Being candid internally—and externally—during an incident matters more than keeping silence.   I believe readiness isn't just about tech—it’s about mindset, coordination, and adaptability. If Pennsylvania’s breach reminds us of anything, it’s that mission continuity depends on more than just good firewalls—it requires readiness for the unknown. Let’s talk resilience before it becomes your crisis. Read more here: https://lnkd.in/ejZk4Haz #cybersecurity #ransomware #incidentresponse #DFIR #cyberresilience Tributech ⚡wirespeed Rotate Simulint DTG | Cybersecurity & IT Solutions Provider

Explore categories