Cyber Crime

Cyberattacks against law enforcement are on the rise

Experts observed an increase in malicious activity targeting law enforcement agencies at the beginning of Q2 2022.

Resecurity, a Los Angeles-based cybersecurity company protecting Fortune 500 companies worldwide, has registered an increase in malicious activity targeting law enforcement agencies at the beginning of Q2 2022. Threat actors are hacking email and other accounts which belong to police officers and their internal systems.

The emerging trend consists of threat actors sending fake subpoenas and EDR’s (Emergency Data Requests) to their victims from the hacked law enforcement email accounts. Using such capabilities, the threat actors are targeting major technology companies such as Apple, Facebook (Meta), Snapchat, and Discord are to name a few, to collect sensitive information about targets of interest. The replies received by the bad actors contain sensitive details which could/are being used for leverage extortion, or cyberespionage. Such incidents have become especially notable in cybercriminal group activities such as LAPSUS$ and Recursion Group.

Resecurity has been observing multiple Dark Web marketplaces where cybercriminals are monetizing their efforts by selling credentials belonging to police officers of various foreign countries (e-mails, VPNs, SSO, etc.). One example of an email account previously used to send fake EDR requests on behalf of the Bangladesh Police was recently covered in a Bloomberg article illustrating the risk of such tactics.

Based on experts’ opinion, one of the biggest concerns is the visible insecurity of the law enforcement IT infrastructure, such infrastructure creates significant risk to our society, not just in cyberspace but in real life too. Organized crime, terrorists and extremist groups may leverage such access for malicious purposes.

The trend is continuing to grow in popularity as more law enforcement organizations have been impacted by cyberattacks this month. Just recently, the Conti ransomware group claimed to attack the Intelligence Agency in Peru and leaked their data which created a significant precedent in the security community. DDOS Secrets – another notable group of threat actors, has released 285,635 leaked emails from Nauru Police.

The most typical scenarios involving attacks on law enforcement systems include:

  • Protest Activity (15%)
  • Unauthorized Access (25%)
  • Cyberespionage (40%)
  • Law Enforcement Systems and Applications Abuse (8%)
  • Data Theft (12%)

Based on the published research, such malicious activity is especially visible in countries of Latin America, South-East Asia, and offshore jurisdictions. Last year, Resecurity registered a targeted security incident related to one of the law enforcement organizations in the Middle East and its counterpart in the face of one of the international police organizations. 

“Sophisticated bad actors and APT groups are actively targeting law enforcement agencies worldwide. Traditional cybercriminals are also an important component in this process, as state-supported actors may be actively collaborating with them for further planned cyberattacks and targeted network intrusions. Investigation of such incidents is a complicated process due to the significant sensitivity involved” – said Christian Lees, CTO of Resecurity, Inc. 

Resecurity® is committed to protecting consumers and enterprises all over the globe, and is actively involved in public-private partnerships to share actionable cyber threat intelligence (CTI) with financial institutions, technology companies and law enforcement to ultimately minimize the risk of credentials being compromised and data breaches being executed.

For more details give a look at the original published on the Resecurity:

https://resecurity.com/blog/article/cybercriminals-are-targeting-law-enforcement-agencies-worldwide

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, cybercrime)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Operation Secure: INTERPOL dismantles 20,000+ malicious IPs in major cybercrime crackdown

INTERPOL announced that a joint operation code-named Operation Secure took down 20,000+ malicious IPs/domains tied…

54 minutes ago

Over 80,000 servers hit as Roundcube RCE bug gets rapidly exploited

A critical remote code execution (RCE) vulnerability in Roundcube was exploited days after patch, impacting…

11 hours ago

A flaw could allow recovery of the phone number associated with any Google account

A vulnerability could allow recovery of the phone number associated with a Google account by…

15 hours ago

Texas Department of Transportation (TxDOT) data breach exposes 300,000 crash reports

Hackers breached Texas DOT (TxDOT), stealing 300,000 crash reports with personal data from its Crash…

1 day ago

SAP June 2025 Security Patch Day fixed critical NetWeaver bug

SAP fixed a critical NetWeaver flaw that let attackers bypass authorization and escalate privileges. Patch…

1 day ago

U.S. CISA adds RoundCube Webmail and Erlang Erlang/OTP SSH server flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds RoundCube Webmail and Erlang Erlang/OTP SSH server flaws…

1 day ago