Hackers selling network access to multiple US police departments

New research that has found threat actors selling access to the networks of various US government organisations including access to the Chief of police in various states, and the VPN portal of a city in Arizona. This research comes after the news that the Washington DC police department suffered a ransomware attack by the Russian ransomware gang, Babuk

Andrey Yakovlev, Security Researcher at IntSights comments on the research:

“It’s simply another Monday for Russian hackers. Babuk is a relatively new ransomware group that does not target the Russian Federation or other CIS counties and hospitals (besides private plastic clinics and dentistry). They focus on Hyper-V and ESXi virtualisation technologies and accept only proficient partners.

With that being said, the hack of the Washington DC police is a clear cut, gangsomware case and usually in cases such as this one, there isn’t a lot of dark web chatter. Ransomware operators not only wait for a relevant application to come to an affiliate’s program, but they also actively monitor offers of access to internal networks which are constantly being sold on the dark web. While there is no data from this particular breach on the dark web, threat actors are actively targeting police departments across the US. For example, we have seen that there has been one threat actor targeting US government institutions and police departments.

Our research has found that one of the sales from this threat actor was published in February and the hacker offered access to a VPN portal of a city in Arizona that included access to the City Court System, City Government, Police Department, Fire Department, Solid Waste, Recreation Services, Engineering Services, Utility Services, Library, Fleet Services, Airport, Finance, Street Maintenance, Animal Control, Human Resources, Legal and Information Technology.

The second sale offers access to “Chiefs of Police (US State disclosed to buyer)”. The hacker also offers access to: “Sheriff’s Office in **, Ohio, USA”, “(gov) County of **, Pennsylvania, USA”, “(gov) County of **, Missouri, USA”, “(gov) City of **, Georgia, USA”, “(gov) City of **, Florida, USA”, “(gov) County of ** Water District, Arkansas, USA”.

Government organisations hold significant personal information on many people, some of which may be high profile personnel. Because of this, it is a prime target for threat actors and nation-state attackers alike.”

 

To stay up to date on the latest, trends, innovations, people news and company updates within the global security market please register to receive our newsletter here.

Media contact

Rebecca Morpeth Spayne,
Editor, Security Portfolio

Tel: +44 (0) 1622 823 922
Email: [email protected]

 

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne picture 2025

Rebecca Spayne

Managing
EDITOR

Georgina Turner image

Georgina Turner

Sales
Manager

Afua Akoto image - Security Buyer

Afua Akoto

Marketing Manager

Read the Latest Issue

Follow us on X

Follow us on X

Click Here

Follow us on LinkedIn

Follow us on LinkedIn

Click Here

Advertise here

Reach decision makers and amplify your marketing

Advertise here

Click Here

Related News

Sophos

Sophos Enhances Protection and Incident Response

Sophos announces an update to its Sophos Firewall, now including Sophos NDR Essential, which is free for all customers with an…
Copyright: Security Buyer

ASIS UK Launches “Security is You(th)” Hackathon

ASIS International UK has launched Security is You(th), an initiative designed to engage students and early-career professionals…
Image provided by Veeam

AI and Ransomware: Cutting Through the Hype

Rick Vanover, Vice President Product Strategy, Veeam discusses how It might be the great paradox: Artificial Intelligence (AI)….
Copyright: Security Buyer

AmiViz Partners with Titania

AmiViz announced a strategic distribution agreement with Titania. This collaboration underscores a shared commitment to enhancing…
Oil and Gas

Navigating Africa’s Oil & Gas Industry

A comprehensive analysis of security strategies in Africa’s oil and gas industry, covering physical, cyber, and remote surveillance measures.
blackhat

Black Hat Europe Starts Soon

Black Hat Europe starts Monday and now is the perfect time to start planning your experience. With a full lineup of Keynotes…

VIVOTEK’s All-in-One Software Boosts Operational Efficiency for Enterprises

As demand for high-efficiency security systems rises among large enterprises, the global leading…
Assa Abloy website

WTC Amsterdam enhances security and efficiency with digital access solution

The World Trade Center (WTC) Amsterdam, home to over 300 companies, has upgraded its building security with a streamlined, digital access solution from ASSA ABLOY.
John Maddison website

Fortinet launches Lacework FortiCNAPP to enhance cloud-native security

In an advancement in cybersecurity, Fortinet has announced Lacework FortiCNAPP, providing organisations with visibility and security.
Scroll to Top