Mar 26, 2026 - An overview of recent major cyber incidents in the United States, followed by a sector-by-sector assessment of current vulnerabilities and resilience levels. Recommendations conclude the analysis.

Recent Major Incidents

In late June 2024, the MOVEit Transfer vulnerability (CVE-2023-34362) continued to wreak havoc across U.S. organizations. The Cl0p ransomware gang exploited the flaw to siphon sensitive data from the Colorado Department of Transportation and the Montana Department of Labor & Industry, exposing personal and financial records of millions. Despite rapid patches and guidance from CISA and the FBI, downstream service providers remain at risk as new instances surfaced in multiple states over a ten-day window.

Mid-June saw the Los Angeles Unified School District fall victim to a LockBit ransomware campaign. Attackers encrypted academic and administrative systems, disrupting online learning platforms and delaying examination results. Although no evidence pointed to significant data exfiltration, the incident highlighted persistent gaps in backup segregation and endpoint detection across large public education networks.

More recently, a suspected Black Basta ransomware intrusion targeted a Midwest petrochemical manufacturing plant in early July. Industrial control systems were partially locked, forcing a temporary shutdown of production lines. While physical safety systems remained unaffected, the event underscored ongoing threats to critical manufacturing facilities that rely on aging SCADA architectures lacking proper network segmentation.

Sector-Specific Security Posture

State Institutions
State governments continue grappling with legacy infrastructure and budget constraints. While many agencies have accelerated cloud migration and multi-factor authentication rollouts, patch management and third-party vendor risk remain pressing concerns. The MOVEit breaches exposed cascading dependencies across service providers, underlining the need for stronger supply-chain oversight.

Political System
With elections approaching, phishing and disinformation campaigns have intensified against campaign staff and volunteer networks. Recent spear-phishing attempts impersonated party leadership, aiming to harvest credentials and leak internal communications. Investment in secure communication platforms and continuous red team exercises is crucial to safeguard electoral integrity.

Civil Service
Federal civilian agencies have made strides in Zero Trust pilot programs, but adoption is uneven across departments. Cyber hygiene training has improved, yet social engineering continues to succeed against under-resourced local offices. A sustained emphasis on automated endpoint monitoring and user behavior analytics will help close visibility gaps.

Science & Education
Research universities and laboratories face high-impact data theft from both financial and geopolitical adversaries. Collaborative frameworks like Research and Education Networks (REN-ISAC) offer threat sharing, but inconsistent patch cycles on specialized equipment and IoT devices often become easy targets for cryptojacking and credential stuffing.

Military
The Department of Defense maintains robust perimeter defenses and threat hunting capabilities, yet supply chain compromises still loom large. Recent DoD advisories warned of firmware implants in critical microcontrollers. Strengthening hardware integrity checks and enhancing cross-domain solutions remain key to preserving operational resilience.

NGOs
Non-governmental organizations typically operate with smaller security teams and limited budgets. Threat actors exploit this by deploying phishing campaigns that mimic donor or partner communications. Centralized logging, basic network segmentation, and extended detection and response (XDR) subscriptions can substantially elevate their security baseline.

Critical Infrastructure
Utilities, power grids, and water treatment plants continue facing targeted ICS/SCADA threats. While CISA’s Industrial Control Systems Cybersecurity programs have raised awareness, many sites still lack modern anomaly detection. Implementing asset-level microsegmentation and regular Red/Blue team drills tailored to ICS environments is essential.

Telecommunications
Major carriers have fortified core networks against DDoS and signaling attacks, but 5G expansion and edge deployments introduce fresh supply chain and virtualization risks. Rigorous security assessments of Open RAN components and continuous monitoring of network slices will help mitigate emerging threats.

Financial Sector
Banks and payment processors exhibit strong security postures, leveraging advanced fraud detection and threat intelligence sharing through the FS-ISAC. Nevertheless, ransomware and BEC (Business Email Compromise) attempts persist. Faster execution of incident response playbooks and locking down high-value credentials are ongoing priorities.

Defence Industry
Prime contractors enforce strict CMMC compliance and network segmentation, yet subcontractors frequently lag behind. APT groups continue to target engineering design files and project documentation. Expanding continuous supply-chain audits and mandating real-time telemetry from all tiers can help close these gaps.

Critical Manufacturing
Automotive and aerospace manufacturers face persistent IP theft and ransomware pressures. Many production lines still run on Windows XP/7 for legacy controllers. Accelerating OS upgrades, enforcing network isolation for OT systems, and deploying dedicated ICS intrusion detection systems are urgent actions.

Corporate Sector
Large enterprises generally maintain mature SOCs and SIEM platforms, but remote work has widened the attack surface through unsecured endpoints and home networks. Ongoing phishing drills, device posture checks, and conditional access policies are crucial to reduce lateral movement risks.

Recommendations


A cohesive, layered defense strategy is imperative across all sectors. Organizations should prioritize rapid vulnerability remediation, adopt Zero Trust principles, and invest in advanced monitoring tools. Enhancing threat intelligence sharing—both sectorally through ISACs and publicly via CISA alerts—will increase collective resilience. Finally, regular incident response exercises and cross-sector collaboration form the backbone of a proactive security posture capable of withstanding evolving cyber threats.