
Security Incidents Involving Family Members
Should an Employee Report Security Incidents Involving Family Members? Is your business or job at risk if a bad actor gets access to your family. Will they gain access to you?
Introduction
Over the past three years, the United States has witnessed a disturbing rise in cyberattacks targeting critical infrastructure. From water utilities and power grids to public transportation and healthcare systems, cybercriminals and nation-state actors have exploited vulnerabilities across sectors. These attacks not only jeopardize operational continuity but also threaten national security and public safety. Now, with substantial budget cuts planned for the Cybersecurity and Infrastructure Security Agency (CISA), the U.S. is poised to face even greater cyber risks.
1. Colonial Pipeline Ransomware Attack (May 2021)
The DarkSide ransomware group targeted Colonial Pipeline, the largest U.S. refined oil products pipeline. The shutdown led to panic buying, gas shortages, and a temporary disruption in the fuel supply chain across the East Coast. It marked a watershed moment, bringing the term “critical infrastructure” into mainstream cybersecurity conversations.
2. MOVEit Data Breach (May 2023)
A vulnerability in the MOVEit file transfer software was exploited by the Cl0p ransomware group, compromising the personal data of over 93 million individuals and affecting more than 2,700 organizations globally, including U.S. federal and state agencies.
3. Chinese Telecom Network Infiltration (2023–2024)
Hackers from Salt Typhoon, linked to China, infiltrated U.S. telecom networks, accessing communications and sensitive data tied to over a million individuals, including high-level officials. The breach revealed long-term espionage and the fragility of U.S. telecom infrastructure.
4. Yazoo Valley Electric Power Breach (Summer 2024)
This Mississippi power utility suffered a breach affecting 20,000 residents. Initially attributed to technical issues, the incident was later confirmed as a cybersecurity breach, raising alarms about smaller rural utility providers often overlooked in national security planning.
5. Volt Typhoon Power Grid Infiltration (2023–2024)
Chinese nation-state actors maintained covert access to U.S. electric grid utilities for nearly 300 days, targeting systems in Massachusetts and potentially across other states. The goal appeared to be pre-positioning for disruptive capabilities in the event of geopolitical conflict.
6. American Water Cyberattack (October 2024)
A cyberattack disrupted billing and customer service at the nation’s largest water utility. Though water quality remained unaffected, the event exposed key IT/OT integration vulnerabilities that, if exploited further, could threaten physical water systems.
7. Aliquippa Water Authority Attack (November 2023)
Pro-Iranian group Cyber Av3ngers targeted the Municipal Water Authority of Aliquippa, Pennsylvania, disabling a programmable logic controller (PLC) that controlled water pressure. The attack was politically motivated and showcased the potential for low-cost disruption of municipal utilities.
8. Solar Power System Vulnerabilities (2025)
Research exposed 46 zero-day vulnerabilities in solar inverters from multiple major manufacturers. These flaws could allow attackers to remotely disrupt power generation and tamper with grid frequency stability.
9. Trans-Northern Pipelines Ransomware Attack (November 2023)
Though based in Canada, this attack by the AlphV ransomware group on a critical fuel pipeline operator underscored the vulnerability of North American energy infrastructure and cross-border implications of cybersecurity.
10. Pittsburgh Regional Transit Ransomware (January 2025)
This attack delayed rail car schedules and disrupted operational logistics, showing how digital attacks can translate directly to physical disruption of transit systems.
11. Oahu Transit Cyberattack (June 2024)
Honolulu’s transit system was hit with a cyberattack that disabled GPS tracking and fare collection. Public frustration surged, and system-wide vulnerabilities were exposed due to lack of redundancy.
12. Kansas City Transportation Authority Attack (January 2024)
Ransomware disrupted communications and delayed services, affecting both bus and light rail networks. It served as a wake-up call for transportation agencies with legacy systems.
13. Nationwide Increase in Rail Cyberattacks (2021–2025)
Reports indicate a 200% increase in rail system cyber incidents globally, with the U.S. heavily impacted. Attacks have included interference with scheduling systems, SCADA infrastructure, and signal relay stations.
14. Hospitals and Healthcare Providers (Ongoing)
Healthcare systems in California, New York, and Texas faced repeated ransomware attacks from groups such as LockBit and Black Basta. Data theft and system outages delayed patient care and caused revenue losses in the millions.
Despite this surge in cyber threats, the recent U.S. administration has proposed a drastic reduction in CISA’s budget, including:
Elimination of nearly 75 contract positions from CISA’s key threat-hunting teams.
Up to one-third reduction in staffing across departments.
$10 million cut in funding for election infrastructure and information-sharing initiatives.
CISA officials have warned that a 25% reduction in their funding would be “catastrophic,” severely undermining their capacity to detect, mitigate, and respond to cyber threats. The loss of skilled staff, delayed incident response times, and reduced support for state and local partners could further erode national cyber resilience.
The pattern is clear: the frequency and severity of attacks on critical U.S. infrastructure are escalating. As the nation faces increasingly complex threats from criminal syndicates and foreign adversaries, gutting the primary federal cybersecurity agency is not just short-sighted—it’s dangerous. To secure our water, power, transport, and digital ecosystems, we must invest in stronger defenses, not scale them back. Redbot Security stands at the front lines of cyber resilience, and we urge policymakers and industry leaders to recognize the urgency of this moment before it’s too late.
Senior Level Hands-on-Keyboard
Manual Testing
Get a Project QuoteShould an Employee Report Security Incidents Involving Family Members? Is your business or job at risk if a bad actor gets access to your family. Will they gain access to you?
The likelihood of a cyber attack on a mobile platform is significantly high, but how difficult is it for a malicious actor to generate malware? You might be surprised.
Insecure Direct Object Reference (IDOR) vulnerabilities pose a significant risk to the security of web applications, allowing attackers unauthorized access to sensitive data and functionalities. By understanding the implications of IDOR and adopting secure coding practices, web developers can protect their applications and users from potential exploitation.
Mass Assignment Vulnerability occurs when a web application allows users to submit a more extensive set of data than is intended or safe. The potential consequences of this vulnerability can be severe
Attackers can manipulate the serialized data to execute malicious code, compromise the application, or gain unauthorized access.
Kerberos Authentication Service Response (AS-REP) Roasting, a technique similar to Kerberoasting, has gained prominence as a method for attackers to compromise Active Directory (AD) authentication systems.
Becoming proficient in Operational Technology (OT), Industrial Control Systems (ICS), and Supervisory Control and Data Acquisition (SCADA) network testing can appear daunting as there are fewer learning resources.
Machine Learning (ML) is a subset of AI, and, more than likely, closely aligns with what we consider to be AI in the media.
Recent reports of significant cybersecurity layoffs in the United States have raised concerns about the nation’s preparedness to defend against cyber threats
The FBI released its FY 2024 IC3 Annual Report on April 24, 2025, detailing 859,532 complaints and a record $16.6 billion in losses. In this post, we highlight how phishing, BEC, and cryptocurrency fraud continue to surge, why ransomware remains a top threat to critical infrastructure, and which demographics are most at risk. Plus, discover Redbot Security’s proven strategies,from manual penetration testing to red teaming, that can help you turn IC3 data into actionable defenses.
From API-server exploits to supply-chain threats, this checklist shows how the best penetration testing companies harden Kubernetes. Boost resilience now.
Cybercriminals are ditching malware and exploiting trusted tools already inside your systems. Learn how Living off the Land (LotL) attacks work, and how to stop them.
From pipelines and water systems to power grids and transit networks, U.S. critical infrastructure is under siege. With CISA budget slashed, is a national cyber disaster inevitable?
Understanding NIST 800 and Its Impact on Penetration Testing Requirements.
Internal network penetration testing is essential for identifying security gaps within an organization’s infrastructure. Attackers exploit misconfigured permissions, weak credentials, and unpatched vulnerabilities to escalate privileges and move laterally within networks. A thorough penetration test helps uncover these risks before they are exploited, ensuring stronger security controls, improved access management, and compliance with industry standards. Redbot Security’s expert-led penetration testing provides in-depth assessments to fortify your internal network against evolving threats.
Redbot Security’s senior-level cloud security team brings years of expertise in AWS, GCP, and Azure security. Our approach is rooted in manual-controlled testing and deep-dive security analysis, ensuring that we uncover hidden vulnerabilities that automated tools often miss.
Cymbiotic Hive: The Simple, Rapid-Deployment Solution to Access Management
With data breaches surging by 68% last year alone, cybersecurity has evolved from a low-key technical matter into a defining issue demanding top-level attention.
Increasingly, investors see proactive cybersecurity spending as a hallmark of strong corporate governance. It can be factored into how they value a company’s resilience and risk profile
Our nation is under attack and overwhelmed. Modern Security teams face numerous challenges in managing network and application security effectively.
Our nation is under attack and overwhelmed. Modern Security teams face numerous challenges in managing network and application security effectively.
Is your security team sharing sensitive data unknowingly?
Through repeated random sampling, allows us to simulate a wide array of social engineering attacks with a depth and breadth previously unimaginable.
While penetration testing is valuable in identifying technical vulnerabilities, red teaming provides a more holistic assessment by simulating realistic threat scenarios. By embracing red teaming, organizations can bolster their defenses, uncover weaknesses, and stay one step ahead of sophisticated adversaries.
Malicious actors leveraging OSINT to uncover confidential and sensitive information that is publicly available online. Learn how to prevent risks.
Client-side desyncs are a class of browser-powered HTTP smuggling attacks. What you need to know and how to prevent a malicious actor from taking advantage of this vulnerability.
Active Directory Certificate Services (AD CS) presents various security risks for organizations. This article will help you understand a Relay Attack.
What is an API? APIs, including local and remote, come in various forms and are fundamental to modern software development. They serve as the bridge between different software components, enabling them to work together seamlessly.
While plenty of articles cover the Modbus protocol with varying degrees of detail and usage, this article aims to examine the Modbus protocol with an offensive security lens.
Malicious actors prey on weak configurations like locusts. Microsoft, despite knowing that their operating systems, have inherent weaknesses have done little to enhance their initial security outside of remediation for publicly known vulnerabilities.
The following article is a discussion about helping you to best utilize your military skills to successfully transition into the commercial space.
The following article is a discussion that explores JavaScript Web Tokens
The following article is a discussion that explores Wave Behaviors to Locate Wireless Access Points and Devices
Today, cybercriminals have plenty of entry points to exploit. Therefore, it has become crucial for organizations to improve their attack surface visibility to have more effective protection. This is where attack surface management (ASM) comes into play. This article will explore all about attack surface management (ASM), including its importance, working principle, and benefits.
Our expert team will help scope your project and provide a fast and accurate project estimate.
Contact Redbot Security