Full Report
Cyberattacks on U.S. government and critical infrastructure surged in 2023, with over 420 million global attacks. Learn which states are most affected and discover how Huntress can help protect your organization
Analysis Summary
# Incident Report: Surge in US Critical Infrastructure & Government Attacks (2023)
## Executive Summary
In 2023, cyberattacks against U.S. government and critical infrastructure escalated significantly, totaling over 420 million global incidents—a 30% increase from the previous year. The United States remains the primary global target, with 168 identified threat actors exploiting vulnerabilities in state-level infrastructure and small-to-midsized businesses (SMBs).
## Incident Details
- **Discovery Date:** Ongoing (Reported August 26, 2024)
- **Incident Date:** January – December 2023
- **Affected Organization:** Multiple U.S. Government entities and Critical Infrastructure sectors
- **Sector:** Government, Healthcare, Technology, Finance
- **Geography:** United States (High-impact areas: Alaska, California, New York, Texas)
## Timeline of Events
### Initial Access
- **Date/Time:** Throughout 2023 (averaging 13 attacks per second)
- **Vector:** Phishing, session hijacking, and exploitation of unpatched vulnerabilities.
- **Details:** Attackers targeted "soft targets," specifically SMBs that form 99.1% of infrastructure in states like Alaska.
### Lateral Movement
- **Details:** Threat actors like "Silk Typhoon" utilized backdoors (over 88,000 on Exchange servers) to maintain access and move laterally through government and private networks.
### Data Exfiltration/Impact
- **Details:** Compromise of sensitive government data, disruption of dental healthcare practices, and high-volume data breaches in technology hubs like California.
### Detection & Response
- **How it was discovered:** Analysis by Forescout Research, the FBI Internet Crime Complaint Center (IC3), and Huntress security monitoring.
- **Response actions taken:** Federal arrests (e.g., Silk Typhoon investigation), deployment of Managed Endpoint Detection and Response (EDR), and statewide cybersecurity awareness campaigns.
## Attack Methodology
- **Initial Access:** Phishing, Credential Theft, and Session Hijacking.
- **Persistence:** Installation of web shells and backdoors (e.g., Microsoft Exchange vulnerabilities).
- **Defense Evasion:** Exploiting lack of security resources in SMBs to remain undetected.
- **Credential Access:** The use of "Unwanted Access" techniques and identity-based attacks.
- **Lateral Movement:** Spidering through identity providers for profit and disruption.
- **Impact:** Financial loss, operational downtime for healthcare, and reputational damage to government agencies.
## Impact Assessment
- **Financial:** Billions lost (FBI reports over $7 billion lost to criminal hacks recently, largely impacting small businesses).
- **Data Breach:** Over 1,338 reported incidents in California alone; millions of records compromised globally.
- **Operational:** Significant disruption to critical infrastructure and dental practices.
- **Reputational:** Decreased public trust in state-level data protection.
## Indicators of Compromise
- **Network Indicators:** Connections to known malicious command-and-control (C2) IPs (e.g., associated with Silk Typhoon—details redacted for security).
- **File Indicators:** Malicious web shells found on Exchange servers.
- **Behavioral Indicators:** Unusual session hijacking attempts and unauthorized credential usage.
## Response Actions
- **Containment:** FBI field offices (e.g., Anchorage) issuing direct warnings to SMBs.
- **Eradication:** Global manhunts leading to the arrest of key threat actors.
- **Recovery:** Implementation of Huntress Security Awareness Training and managed EDR to offset limited internal budgets.
## Lessons Learned
- **Key Takeaways:** SMBs are the "soft underbelly" of U.S. critical infrastructure; geographic location affects risk profile (e.g., Alaska's per capita risk vs. California's volume risk).
- **Shortcomings:** Cybersecurity spending in high-risk states like California has historically lagged behind the scale of the threat.
## Recommendations
- **Prevention:** SMBs should partner with digital agencies to implement advanced threat detection tools.
- **Hardening:** Prioritize patching of public-facing servers (specifically Exchange) to prevent backdoor installation.
- **Identity:** Move toward phishing-resistant MFA to combat the rise in session hijacking.
- **Training:** Implement continuous security awareness training to reduce the success rate of initial access vectors.