Ransomware

Pennsylvania Office of Attorney General INC Ransom Attack

πŸ“… 2025-08-09 🏒 Citrix NetScaler (VPN/ADC) 🦠 INC Ransom πŸ”Ž CVE-2025-5777
Primary Source β†—

Incident Details

On August 9, 2025, the INC Ransom ransomware group attacked the Pennsylvania Office of the Attorney General, knocking its website, email, and phone lines offline for approximately three weeks. INC Ransom claimed responsibility on September 20, alleging theft of 5.7 TB of files and claiming access to an FBI internal network. Attorney General Dave Sunday confirmed the ransomware attack and refused to pay the ransom. Security researcher Kevin Beaumont identified vulnerable public-facing Citrix NetScaler appliances (CVE-2025-5777, ‘Citrix Bleed 2’) as the likely attack vector. Investigation confirmed files containing names, Social Security numbers, and medical information were potentially accessed; the number of affected individuals was not disclosed.

Technical Details

Initial Attack Vector
INC Ransom exploited CVE-2025-5777 (Citrix Bleed 2, critical) in public-facing Citrix NetScaler appliances at the Pennsylvania Attorney General's Office
Vendor / Product
Citrix NetScaler (VPN/ADC)
Malware Family
INC Ransom
CVE / GHSA References
CVE-2025-5777

Timeline

  1. 2025-08-09 Breach occurred
  2. 2025-09-05 Publicly disclosed
  3. 2025-11-01 Customers notified