LIVE · cybersecurity feed
Live wire
ransomwarehigh

Government Agencies Face Daily Ransomware Attacks, Study Warns

A recent study indicates that government agencies are frequently targeted by ransomware attacks. Attackers exploit the critical nature of public services, knowing that disruptions can be particularly damaging and may increase the likelihood of ransom payments.

zeroday.news · 15d ago

Government agencies worldwide are experiencing ransomware attacks at an average rate of one per day, according to a recent analysis by Comparitech researchers. The study, which examined incidents targeting government entities between January and June 2026, recorded 187 attacks during this six-month period. This represents a 13% increase from the 165 attacks observed in the latter half of 2025.

Of the 187 incidents documented, just over half, specifically 89, were publicly confirmed by the affected organizations. The United States was the most frequent target, accounting for 31% of all reported attacks against government agencies. Other countries with notable, though significantly lower, percentages included Germany (7%), Spain (4%), and Italy (4%). The researchers suggest that the higher population of the US likely contributes to its disproportionate targeting.

Ransomware groups often target government bodies due to the potential for significant disruption to public services and the large volume of sensitive citizen data they hold. These factors increase the likelihood that a victim organization, especially one funded by taxpayers, might pay a ransom to restore critical services quickly.

The average ransom demand made to government agencies during the first half of 2026 was $100,000. This figure suggests attackers may be setting demands at a level they believe is more likely to be paid by public sector entities. However, there were exceptions, such as a $3.1 million demand made to the Land and Agricultural Development Bank of South Africa in January 2026. The bank refused to pay, and its systems were not restored until April.

While the Land and Agricultural Development Bank attack was attributed to an unknown assailant, many other incidents were linked to known ransomware groups. The most active groups identified during this period were The Gentlemen, responsible for 10% of attacks, followed by Qilin at 9%, and LockBit at 7%.

Cybersecurity experts emphasize that ransomware groups frequently exploit common and publicly known vulnerabilities. To mitigate these risks, organizations are advised to implement proactive cyber defense strategies. Key recommendations include keeping systems updated, promptly patching identified vulnerabilities, performing regular data backups, and ensuring continuous cybersecurity training and awareness for employees.

ransomwaregovernmentcybercrimepublic services
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]