Ransomware
Pennsylvania Office of Attorney General INC Ransom Attack
Primary Source βIncident Details
On August 9, 2025, the INC Ransom ransomware group attacked the Pennsylvania Office of the Attorney General, knocking its website, email, and phone lines offline for approximately three weeks. INC Ransom claimed responsibility on September 20, alleging theft of 5.7 TB of files and claiming access to an FBI internal network. Attorney General Dave Sunday confirmed the ransomware attack and refused to pay the ransom. Security researcher Kevin Beaumont identified vulnerable public-facing Citrix NetScaler appliances (CVE-2025-5777, ‘Citrix Bleed 2’) as the likely attack vector. Investigation confirmed files containing names, Social Security numbers, and medical information were potentially accessed; the number of affected individuals was not disclosed.
Technical Details
- Initial Attack Vector
- INC Ransom exploited CVE-2025-5777 (Citrix Bleed 2, critical) in public-facing Citrix NetScaler appliances at the Pennsylvania Attorney General's Office
- Vendor / Product
- Citrix NetScaler (VPN/ADC)
- Malware Family
- INC Ransom
- CVE / GHSA References
- CVE-2025-5777
Timeline
- 2025-08-09 Breach occurred
- 2025-09-05 Publicly disclosed
- 2025-11-01 Customers notified