<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>State-Sponsored Attack on Security Blueprints</title>
    <link>https://securityblueprints.io/tags/state-sponsored-attack/</link>
    <description>Recent content in State-Sponsored Attack on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:45 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/tags/state-sponsored-attack/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>U.S. Department of the Treasury BeyondTrust Breach December 2024</title>
      <link>https://securityblueprints.io/data-breaches/us-department-of-the-treasury-beyondtrust-breach-december-2024/</link>
      <pubDate>Mon, 02 Dec 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/us-department-of-the-treasury-beyondtrust-breach-december-2024/</guid>
      <description>Executive Summary Key facts:&#xA;Who: Treasury initially attributed the intrusion generically to &amp;ldquo;a China state-sponsored Advanced Persistent Threat (APT) actor&amp;rdquo; (wired.com ; bleepingcomputer.com ); a Wednesday Bloomberg report later attributed it to Silk Typhoon (formerly Hafnium); OFAC separately sanctioned contractor Yin Kecheng, a Shanghai-based, decade-active actor tied to China&amp;rsquo;s Ministry of State Security, on January 17, 2025, as &amp;ldquo;associated with the recent compromise&amp;rdquo; (bleepingcomputer.com ; techcrunch.com ; home.treasury.gov ). China&amp;rsquo;s embassy denied involvement (en.</description>
    </item>
    <item>
      <title>Salt Typhoon Intrusions into U.S. Telecommunications Carriers (2024)</title>
      <link>https://securityblueprints.io/data-breaches/salt-typhoon-intrusions-into-us-telecommunications-carriers-2024/</link>
      <pubDate>Wed, 25 Sep 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/salt-typhoon-intrusions-into-us-telecommunications-carriers-2024/</guid>
      <description>Executive Summary Salt Typhoon was a China-linked cyber-espionage campaign against U.S. telecommunications providers. The incident is dated 2024-09-25 for this report only; this is report metadata/designation, not a source-confirmed forensic breach date. Public reporting first described the broader compromise in September 2024, while later government statements said the campaign had likely operated for one to two years before disclosure (therecord.media ). By December 2024, officials said at least eight U.S. providers had been targeted; a ninth U.</description>
    </item>
    <item>
      <title>Army National Guard Salt Typhoon Network Compromise (March–December 2024)</title>
      <link>https://securityblueprints.io/data-breaches/army-national-guard-salt-typhoon-network-compromise-marchdecember-2024/</link>
      <pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/army-national-guard-salt-typhoon-network-compromise-marchdecember-2024/</guid>
      <description>Executive Summary Between March and December 2024, Salt Typhoon extensively compromised the Army National Guard network of an unidentified U.S. state. A June 11, 2025 Department of Homeland Security Office of Intelligence and Analysis memorandum, obtained through a Freedom of Information Act request and circulated in June, described the incident; public reporting began in July 2025 (bleepingcomputer.com ; nbcnews.com ). The intrusion persisted for approximately nine months, but the sources do not provide an exact discovery date or a separate resolution date (bleepingcomputer.</description>
    </item>
    <item>
      <title>Microsoft Email Accounts Security Breach</title>
      <link>https://securityblueprints.io/data-breaches/microsoft-email-accounts-security-breach/</link>
      <pubDate>Mon, 01 May 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/microsoft-email-accounts-security-breach/</guid>
      <description>Executive Summary In May 2023, a data breach occurred at Microsoft when China-based hackers, identified as Storm-0558, used forged authentication tokens to gain unauthorized access to customer email accounts. This incident highlighted vulnerabilities in Microsoft&amp;rsquo;s authentication systems and raised concerns over national security implications.&#xA;Key Dates and Timeline Breach Date: May 2023 Discovery Date: June 2023, by the U.S. Department of State source . Public Disclosure Date: April 2024, following a thorough review by the Cyber Safety Review Board source .</description>
    </item>
    <item>
      <title>Microsoft Exchange Server Breach</title>
      <link>https://securityblueprints.io/data-breaches/microsoft-exchange-server-breach/</link>
      <pubDate>Sun, 03 Jan 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/microsoft-exchange-server-breach/</guid>
      <description>Executive Summary In January 2021, Microsoft Exchange email servers were targeted in a significant cyberattack that exploited multiple zero-day vulnerabilities, affecting over 30,000 organizations in the United States. Initially detected by Volexity on January 3, 2021, the breach was publicly acknowledged by Microsoft on March 2, 2021, upon releasing emergency patches (source , source ).&#xA;Severity of the Impact Globally, the breach compromised up to 250,000 servers, impacting critical sectors such as government, banking, and infrastructure, thereby posing risks to operational integrity and data confidentiality (source , source ).</description>
    </item>
    <item>
      <title>SolarWinds Supply Chain Attack</title>
      <link>https://securityblueprints.io/data-breaches/solarwinds-supply-chain-attack/</link>
      <pubDate>Sun, 01 Sep 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/solarwinds-supply-chain-attack/</guid>
      <description>Executive Summary The SolarWinds Supply Chain Attack represents a pivotal cyber incident with substantial global repercussions. This sophisticated breach resulted in the compromise of SolarWinds&amp;rsquo; software development infrastructure, spreading malicious updates within their Orion software. The attack, initiated in September 2019, culminated with the distribution of malicious updates starting in March 2020, which were installed by over 18,000 SolarWinds customers. This infiltration allowed attackers unauthorized access for data theft and espionage, as publicly disclosed in December 2020.</description>
    </item>
    <item>
      <title>Marriott International Data Breach of 2018</title>
      <link>https://securityblueprints.io/data-breaches/marriott-international-data-breach-of-2018/</link>
      <pubDate>Fri, 30 Nov 2018 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/marriott-international-data-breach-of-2018/</guid>
      <description>Executive Summary In 2018, Marriott International suffered a data breach that compromised approximately 500 million guest records. This breach, dating back to 2014, primarily affected the Starwood guest reservation system, which was acquired by Marriott in 2016. Personal data exposed included names, addresses, phone numbers, email addresses, passport numbers, and credit card details (source , source ).&#xA;Severity of Impact This breach is noted for its wide scale, causing significant exposure of personal data and inflicting reputational damage on Marriott.</description>
    </item>
    <item>
      <title>NotPetya Ransomware Attack</title>
      <link>https://securityblueprints.io/data-breaches/notpetya-ransomware-attack/</link>
      <pubDate>Tue, 27 Jun 2017 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/notpetya-ransomware-attack/</guid>
      <description>Executive Summary The NotPetya ransomware attack in June 2017 is considered one of the most destructive cyber incidents on record. Originating through a compromised update of MeDoc, a Ukrainian accounting software, the malware propagated swiftly, impacting organizations across more than 65 countries within hours of being detected on June 27, 2017. The event highlighted significant vulnerabilities in software supply chains.&#xA;Severity of the Impact NotPetya inflicted damages exceeding $10 billion globally, with significant disruptions in healthcare, logistics, and government sectors.</description>
    </item>
    <item>
      <title>Office of Personnel Management Data Breach 2015</title>
      <link>https://securityblueprints.io/data-breaches/office-of-personnel-management-data-breach-2015/</link>
      <pubDate>Wed, 01 Apr 2015 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/office-of-personnel-management-data-breach-2015/</guid>
      <description>Executive Summary In 2015, the U.S. Office of Personnel Management (OPM) faced a significant data breach resulting in the exposure of sensitive information of approximately 21.5 million individuals. This incident, one of the largest in U.S. government history, involved an initial breach affecting 4.2 million personnel records and a subsequent larger breach involving detailed background investigation data. This report details the technical and organizational failures that led to the breach and assesses its impact.</description>
    </item>
    <item>
      <title>Anthem Data Breach Incident Analysis</title>
      <link>https://securityblueprints.io/data-breaches/anthem-data-breach-incident-analysis/</link>
      <pubDate>Wed, 04 Feb 2015 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/anthem-data-breach-incident-analysis/</guid>
      <description>Executive Summary The data breach at Anthem Inc. in 2015 stands as a critical incident in healthcare cybersecurity, involving unauthorized access to approximately 78.8 million records. The breach was disclosed publicly on February 4, 2015, illustrating significant weaknesses within the protection of Personal Identifiable Information (PII) in healthcare systems. This incident underscores a vital need for enhanced cybersecurity measures in the sector, emphasizing the risks associated with large-scale data compromises.</description>
    </item>
    <item>
      <title>Yahoo Data Breach August 2013</title>
      <link>https://securityblueprints.io/data-breaches/yahoo-data-breach-august-2013/</link>
      <pubDate>Thu, 01 Aug 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/yahoo-data-breach-august-2013/</guid>
      <description>Executive Summary Incident Overview In August 2013, Yahoo experienced a substantial data breach that compromised the account information of approximately 3 billion users. The exposed data included usernames, email addresses, telephone numbers, hashed passwords (MD5), as well as both encrypted and unencrypted security questions and answers. Payment card information and bank details remained secure (Yahoo data breaches ). The breach&amp;rsquo;s public disclosure occurred in December 2016, which emphasized the delayed recognition and broadcast of its full scope (Yahoo Security Notice December 14, 2016 ).</description>
    </item>
    <item>
      <title>Google Aurora Incident</title>
      <link>https://securityblueprints.io/data-breaches/google-aurora-incident/</link>
      <pubDate>Tue, 01 Dec 2009 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/google-aurora-incident/</guid>
      <description>Executive Summary The Google Aurora incident, occurring in December 2009, was a significant cybersecurity breach affecting Google and multiple other corporations in various industries, particularly technology. The attack aimed to steal intellectual property and unauthorized Gmail access of Chinese human rights activists. It is widely attributed to state-sponsored entities linked to the Chinese government, employing sophisticated cyber espionage tactics.&#xA;Major Threat Actors The attack is attributed to entities based in China, utilizing Advanced Persistent Threat (APT) techniques.</description>
    </item>
  </channel>
</rss>
