• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Blogs » Think Tank » How Hackers Target the Public Sector, and 10 Ways to Fight Back

Think Tank
Think Tank RSS FeedRSS

How Hackers Target the Public Sector, and 10 Ways to Fight Back

Cybersecurity
Source: Bloomberg
February 17, 2021
David Lukic, SCB Contributor

Thanks to its vast collection of private data, the public sector is often a top target for cybercriminals. Federal, state and local governments collect Social Security Numbers, contact information, health information, work history, financial information and many other data points. This can make their databases full of attractive information for cybercriminals, such as those who want to commit SSN theft. Data breaches can result in the theft of millions of individual records.

Some criminals want to target the government directly. They may try to steal information about private citizens or steal government secrets that they sell to the highest bidder. In other situations, sensitive information is stolen in order to commit tax fraud. 

Complex Malware

Cyberattacks on public sector organizations can occur in many different ways, but they are often part of complex criminal networks that exploit vulnerabilities in systems. One notable tool that cybercriminals have used is called TrickBot, which originated as a banking trojan but evolved to provide a number of tools to conduct various cyber crimes, such as credential harvesting, crypto-mining, ransomware deployment and point-of-sale data procurement. Domain Name System tunneling was also used as an associated tool, which sent and received data from compromised victim machines.

BazarLoader and BazarBackdoor used similar technology in early 2020 and infected victim networks. Many of these attacks involved the introduction of ransomware — a type of malware that demands ransom payment for personal files or private data.

Another popular form of ransomware that has been used on these types of organizations is called Ryuk, which first appeared in 2018 as a derivative of another popular type of ransomware. This tool was used to steal credentials and encrypt files and then lock out legitimate users.

Detect and Defend

Governments may be able to implement a number of strategies that can help identify, detect and respond to potential cyberattacks. Some of the most effective strategies include:

  • Establishing strong passwords and regularly changing passwords to avoid giving hackers access to multiple accounts
  • Using multi-factor authentication whenever possible
  • Disabling unused remote access to devices and networks
  • Installing security patches
  • Operating the latest version of software, operating systems and firmware
  • Controlling which individuals will have access to sensitive information
  • Identifying sensitive data and updating backups for this data
  • Automatically updating antivirus and anti-malware programs
  • Regularly backing up data
  • Providing training to key personnel on cybersecurity threats

In addition to following these best practices, public sector organizations are encouraged to create a cyber incident response plan that recognizes the nature of the interconnectedness of the web and the organization’s function to society. A response plan can identify key figures who should be notified in case of an attempted data breach, as well as the physical and virtual tools that can be used to respond to the security threat.

If you have been the victim of a data breach attack, report this immediately to management. Then, take all mitigation steps that are part of your data breach plan. By developing a cyber incident response plan and recovery plan before there is ever an attack, you can minimize damage to your organization and have a concrete plan in place to assist you.

Cooperate with authorities to try to find the wrongdoers and prevent similar attacks in the future. You may also wish to join a healthcare information sharing organization or similar organization with which you can share best practices and information. Generally, governmental agencies do not recommend paying ransoms to regain access to sensitive data because there are no guarantees the hacker will relinquish control even if you do pay the ransom.

The public sector contains a treasure trove of sensitive data, so those responsible for safeguarding these networks must take all potential threats seriously. By increasing cybersecurity efforts and recognizing signs of attempted attacks, you can help protect your organization against the latest threats. 

David Lukić is an information privacy, security and compliance consultant at IDstrong.com.

Technology Data Management (Big Data/IoT/Blockchain) Supply Chain Security & Risk Mgmt

RELATED CONTENT

RELATED VIDEOS

Subscribe to our Daily Newsletter!

Timely, incisive articles delivered directly to your inbox.

Featured Product

Popular Stories

  • Businessman using AI agent system on laptop computer.

    AI in Supply Chain Can’t Succeed Without Foundational Systems

    Artificial Intelligence
  • A LARGE CYLINDRICAL OBJECT SHRINK-WRAPPED IN WHITE PLASTIC IS LOWERED BY CRANE ONTO A FLAT BED TRUCK ON A DOCK

    AI Boom Has European Buyers Paying Extra to Secure Gas Turbines

    Technology
  • DOMINO EFFECT FINANCIAL MONEY KNOCK-ON CONSEQUENCES iStock-Devrimb-1500012566.jpg

    Podcast | The Tariff Conundrum for Supply Chains: Pass Along, or Absorb?

    Supply Chain Finance & Revenue Management
  • 016_ai_and_data_transformation_in_distribution_v1-(540p).png

    Watch: AI and Data Transformation in Distribution

    Artificial Intelligence
  • TWO WORKERS DISCUSS DATA SHOWN ON COMPUTER SCREENS

    Gartner: Gap in SC AI Talent Cannot Be Closed by Hiring Alone

    Artificial Intelligence

Digital Edition

2026 esg cover main scb q2 2026 cover

SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

VIEW THE LATEST ISSUE

Case Studies

  • Recycled Tagging Fasteners: Small Changes Make a Big Impact

  • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

    Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

  • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

    Moving Robots Site-to-Site

  • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

  • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

Visit Our Sponsors

4flow Arkieva Blue Yonder
Carton Cloud CoEnterprise Dassault
Duravant E2Open General Logistics Systems
Hy-Tek iGPS Korber
Lyngsoe Procurability Quinyx
SAP Sikick Systech
S&P Global Mobility TADA TransImpact
US Bank Werner Enterprises WSI
  • More From SCB
    • Featured Content
    • Video Library
    • Think Tank Blog
    • SupplyChainBrain Podcast
    • Whitepapers
    • On-Demand Webinars
    • Upcoming Webinars
  • Digital Offerings
    • Digital Issue
    • Subscribe
    • Manage Email Preferences
    • Newsletters
  • Resources
    • Events Calendar
    • 2026 Event Coverage
    • SCB's Great Supply Chain Partners
    • Supplier Directory
    • Case Study Showcase
    • Supply Chain Innovation Awards
    • 100 Great Partners Form
  • SCB Corporate
    • Advertise on SCB.COM
    • About Us
    • Privacy Policy
    • Contact Us
    • Data Sharing Opt-Out

All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

Design, CMS, Hosting & Web Development :: ePublishing