<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Government on Security Blueprints</title>
    <link>https://securityblueprints.io/tags/government/</link>
    <description>Recent content in Government on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:44 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/tags/government/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Conduent Business Services Data Breach (January 2025)</title>
      <link>https://securityblueprints.io/data-breaches/conduent-business-services-data-breach-january-2025/</link>
      <pubDate>Mon, 13 Jan 2025 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/conduent-business-services-data-breach-january-2025/</guid>
      <description>Executive Summary Conduent Business Services, a business-process outsourcing provider for government agencies, health plans, and other enterprises, discovered on January 13, 2025 that an unauthorized third party had accessed a limited portion of its environment and that client-associated files had been exfiltrated. Subsequent investigation placed the beginning of unauthorized access on October 21, 2024. Conduent restored affected systems within days, and in some cases within hours, but the data review and notification process continued through 2025 and into 2026.</description>
    </item>
    <item>
      <title>U.S. Department of the Treasury BeyondTrust Breach December 2024</title>
      <link>https://securityblueprints.io/data-breaches/us-department-of-the-treasury-beyondtrust-breach-december-2024/</link>
      <pubDate>Mon, 02 Dec 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/us-department-of-the-treasury-beyondtrust-breach-december-2024/</guid>
      <description>Executive Summary Key facts:&#xA;Who: Treasury initially attributed the intrusion generically to &amp;ldquo;a China state-sponsored Advanced Persistent Threat (APT) actor&amp;rdquo; (wired.com ; bleepingcomputer.com ); a Wednesday Bloomberg report later attributed it to Silk Typhoon (formerly Hafnium); OFAC separately sanctioned contractor Yin Kecheng, a Shanghai-based, decade-active actor tied to China&amp;rsquo;s Ministry of State Security, on January 17, 2025, as &amp;ldquo;associated with the recent compromise&amp;rdquo; (bleepingcomputer.com ; techcrunch.com ; home.treasury.gov ). China&amp;rsquo;s embassy denied involvement (en.</description>
    </item>
    <item>
      <title>Army National Guard Salt Typhoon Network Compromise (March–December 2024)</title>
      <link>https://securityblueprints.io/data-breaches/army-national-guard-salt-typhoon-network-compromise-marchdecember-2024/</link>
      <pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/army-national-guard-salt-typhoon-network-compromise-marchdecember-2024/</guid>
      <description>Executive Summary Between March and December 2024, Salt Typhoon extensively compromised the Army National Guard network of an unidentified U.S. state. A June 11, 2025 Department of Homeland Security Office of Intelligence and Analysis memorandum, obtained through a Freedom of Information Act request and circulated in June, described the incident; public reporting began in July 2025 (bleepingcomputer.com ; nbcnews.com ). The intrusion persisted for approximately nine months, but the sources do not provide an exact discovery date or a separate resolution date (bleepingcomputer.</description>
    </item>
    <item>
      <title>Indian Council of Medical Research Data Breach 2023</title>
      <link>https://securityblueprints.io/data-breaches/indian-council-of-medical-research-data-breach-2023/</link>
      <pubDate>Mon, 09 Oct 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/indian-council-of-medical-research-data-breach-2023/</guid>
      <description>Executive Summary In 2023, the Indian Council of Medical Research (ICMR) experienced a significant data breach, resulting in the unauthorized access and theft of approximately 815 million records. The data compromised included sensitive personal information such as Aadhaar IDs, passport details, names, phone numbers, and addresses. The threat actor, identified as pwn0001, advertised the stolen data for sale on the dark web (source , source , source ).&#xA;Incident Details Discovery Date: October 9, 2023, when the data sale was announced on dark web forums.</description>
    </item>
    <item>
      <title>Microsoft Email Accounts Security Breach</title>
      <link>https://securityblueprints.io/data-breaches/microsoft-email-accounts-security-breach/</link>
      <pubDate>Mon, 01 May 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/microsoft-email-accounts-security-breach/</guid>
      <description>Executive Summary In May 2023, a data breach occurred at Microsoft when China-based hackers, identified as Storm-0558, used forged authentication tokens to gain unauthorized access to customer email accounts. This incident highlighted vulnerabilities in Microsoft&amp;rsquo;s authentication systems and raised concerns over national security implications.&#xA;Key Dates and Timeline Breach Date: May 2023 Discovery Date: June 2023, by the U.S. Department of State source . Public Disclosure Date: April 2024, following a thorough review by the Cyber Safety Review Board source .</description>
    </item>
    <item>
      <title>Consumer Financial Protection Bureau Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/consumer-financial-protection-bureau-data-breach/</link>
      <pubDate>Tue, 14 Feb 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/consumer-financial-protection-bureau-data-breach/</guid>
      <description>Executive Summary In 2023, the Consumer Financial Protection Bureau (CFPB) experienced a significant data breach due to internal security lapses. An employee transferred confidential records via email to a personal account, compromising the data of approximately 256,000 individuals. This incident underscores critical deficiencies in CFPB&amp;rsquo;s data protection protocols and has raised considerable concerns over internal security measures. Source Severity of Impact The breach affected records from seven financial institutions; however, some reports suggest this number could be higher.</description>
    </item>
    <item>
      <title>SolarWinds Supply Chain Attack</title>
      <link>https://securityblueprints.io/data-breaches/solarwinds-supply-chain-attack/</link>
      <pubDate>Sun, 01 Sep 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/solarwinds-supply-chain-attack/</guid>
      <description>Executive Summary The SolarWinds Supply Chain Attack represents a pivotal cyber incident with substantial global repercussions. This sophisticated breach resulted in the compromise of SolarWinds&amp;rsquo; software development infrastructure, spreading malicious updates within their Orion software. The attack, initiated in September 2019, culminated with the distribution of malicious updates starting in March 2020, which were installed by over 18,000 SolarWinds customers. This infiltration allowed attackers unauthorized access for data theft and espionage, as publicly disclosed in December 2020.</description>
    </item>
    <item>
      <title>Aadhaar Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/aadhaar-data-breach/</link>
      <pubDate>Mon, 01 Jan 2018 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/aadhaar-data-breach/</guid>
      <description>Executive Summary In January 2018, a significant data breach compromised Aadhaar, the world&amp;rsquo;s largest identification database, managed by the Unique Identification Authority of India (UIDAI). The breach affected personal information—biometric and financial data—of approximately 1.1 billion Indian citizens. The affected information was allegedly retailed for as little as ₹500 via WhatsApp, pointing to extensive security flaws (Legal Service India , FirstPost ).&#xA;Severity of Impact The exposure of biometric details like fingerprints and iris scans poses severe risks related to identity theft and fraud, thus threatening the privacy and security of citizens.</description>
    </item>
    <item>
      <title>Deep Root Analytics Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/deep-root-analytics-data-breach/</link>
      <pubDate>Mon, 12 Jun 2017 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/deep-root-analytics-data-breach/</guid>
      <description>Executive Summary In 2017, a data breach at Deep Root Analytics exposed the sensitive information of approximately 198 million U.S. voters. This information, linked to the Republican National Committee (RNC), was leaked due to a misconfigured Amazon Web Services (AWS) S3 bucket, which lacked adequate security settings. The breach included personal information such as names, addresses, birth dates, phone numbers, political affiliations, and predictive modeling data on ethnicities and religious orientations.</description>
    </item>
    <item>
      <title>Office of Personnel Management Data Breach 2015</title>
      <link>https://securityblueprints.io/data-breaches/office-of-personnel-management-data-breach-2015/</link>
      <pubDate>Wed, 01 Apr 2015 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/office-of-personnel-management-data-breach-2015/</guid>
      <description>Executive Summary In 2015, the U.S. Office of Personnel Management (OPM) faced a significant data breach resulting in the exposure of sensitive information of approximately 21.5 million individuals. This incident, one of the largest in U.S. government history, involved an initial breach affecting 4.2 million personnel records and a subsequent larger breach involving detailed background investigation data. This report details the technical and organizational failures that led to the breach and assesses its impact.</description>
    </item>
    <item>
      <title>Australian Immigration Department G20 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/australian-immigration-department-g20-data-breach/</link>
      <pubDate>Fri, 07 Nov 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/australian-immigration-department-g20-data-breach/</guid>
      <description>Executive Summary In 2015, the Australian Immigration Department was involved in a data breach releasing sensitive personal details of G20 world leaders due to an administrative error. The error occurred when an employee improperly used the autocomplete function in Microsoft Outlook, resulting in sensitive information being sent to an unintended recipient. This incident compromised data such as passport numbers, visa information, and birth dates of leaders including Barack Obama, Vladimir Putin, and Angela Merkel (ABC News ).</description>
    </item>
    <item>
      <title>Greece Government Data Breach 2012</title>
      <link>https://securityblueprints.io/data-breaches/greece-government-data-breach-2012/</link>
      <pubDate>Thu, 01 Nov 2012 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/greece-government-data-breach-2012/</guid>
      <description>Executive Summary In 2012, the Greece government experienced a significant data breach that led to the unauthorized exposure of 9,000,000 records, affecting approximately 83% of the nation&amp;rsquo;s population. This breach involved sensitive information, including addresses, ID card data, tax ID numbers, and license plate numbers.&#xA;A sophisticated hacking attack exploited vulnerabilities in the government’s IT infrastructure, with a 35-year-old hacker identified as the primary suspect who allegedly sought to monetize the stolen data.</description>
    </item>
    <item>
      <title>California Department of Child Support Services Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/california-department-of-child-support-services-data-breach/</link>
      <pubDate>Mon, 12 Mar 2012 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/california-department-of-child-support-services-data-breach/</guid>
      <description>Executive Summary Breach Name: California Department of Child Support Services Breach Date: 2012 Discovery Date: March 12, 2012 Disclosure Date: March 29, 2012 Incident Overview In 2012, the California Department of Child Support Services (DCSS) suffered a data breach due to the loss of magnetic tape cartridges, which occurred during a disaster recovery exercise managed by IBM and Iron Mountain Inc. Between Boulder, Colorado, and Sacramento, California, four of fifteen tapes went missing, containing the sensitive information of approximately 800,000 individuals.</description>
    </item>
  </channel>
</rss>
