Skip to main content

Just released: TrendAI™ Research reveals AI risks moving at machine speed

Return to TrendAI™ Security Blog
AI & emerging technologiesVulnerabilities and exploits

Global Public Sector Under Siege: Threat Intelligence for Q2 2026

In the second quarter of 2026, threats to the public sector have become increasingly persistent: from AI-generated ransomware, nation-state espionage, supply chain attacks, and many more, critical institutions face a rapidly growing range of risks.

AIExperts' view (Expert perspective)GovernmentExploits & Zero-Days

We've been tracking threats for more than three decades now, and the pattern observed in Q2 2026 is as striking as anything we've seen. The question is no longer whether government agencies or schools and universities will come under attack. The question is how fast the next wave will hit, and whether defenders will be ready. Our TrendAI™ threat intelligence platform has been monitoring these attacks in real time, and what we're seeing this quarter reinforces a critical reality: the public sector remains one of the most targeted, and most vulnerable, segments of the global economy.

This blog continues our quarterly series diving deep into the threats targeting government entities, educational institutions, and critical infrastructure globally. Here is what TrendAI™ has observed across the April through June 2026 timeframe, with particular attention to what we're seeing in the United States, where attack frequency is running well above the global average. We'll also share what I believe chief information security officers (CISOs) and practitioners need to prioritize right now to stay ahead of these threats.

Q2 2026 at a glance

Elevated U.S. attack frequency versus the global average | Security leaders expect daily AI-driven attacks | Rising government ransomware incidents | Mass student-record exposure in education ransomware attacks | Salt Typhoon telecom/congressional espionage campaign ongoing

The global public sector threat landscape

When I look at the global picture for Q2 2026, five threat types are dominating our TrendAI™ detection and response data across public sector environments. Understanding each one is essential for any organization that touches government services, public education, or critical infrastructure.

AI-enhanced ransomware: The game has changed

If there is one development that should reshape how every public sector CISO thinks about ransomware, it's this: agentic artificial intelligence (AI) is now doing the heavy lifting for ransomware operators. What previously required a skilled attacker to handle manually, including reconnaissance, vulnerability scanning, victim prioritization, and even ransom negotiation, is now being delegated to autonomous AI agents. This isn't theoretical. Our research team is observing this shift happening now, in active campaigns targeting government and education networks.

The practical implication is a dramatic increase in attack velocity. When a single malicious actor can deploy an AI agent that autonomously finds, exploits, and extorts victims at machine speed, the days of “slow” ransomware campaigns are over. The overwhelming majority of security leaders now expect to face daily AI-driven attacks. That's not paranoia. That's the emerging baseline.

Nation-state espionage targeting government and telecom

Beyond ransomware, let us spend some time on the espionage threat, because the scale of what China-aligned threat groups are achieving against Western government targets is genuinely alarming. The Salt Typhoon campaign, which we covered extensively in our Q1 2026 report, has not slowed down. The Federal Bureau of Investigation (FBI) confirmed in February 2026 that the operation is "still very much ongoing".

Salt Typhoon and affiliated groups such as UAT-7290, Volt Typhoon, Earth Estries, and Earth Krahang are executing a broad, patient, and highly sophisticated campaign against government agencies, telecommunications providers, and defense-adjacent organizations across the United States, Southeast Asia, Europe, and Africa. The common thread is persistent access, the kind that allows an adversary to sit quietly inside critical infrastructure for months, reading traffic, mapping networks, and waiting for the right moment.

Credential theft as a ransomware precursor

In January 2026, the new initial access tool Tsundere Bot emerged. This credential theft framework is specifically designed to automate the front end of a ransomware attack chain, harvesting credentials at scale to enable lateral movement and persistence before ransomware is deployed. It has been observed across government and education targets, and it represents the kind of modular, commoditized attack infrastructure that lowers the barrier to entry for even mid-tier cybercriminal groups.

Living-off-the-land techniques: Invisible by design

Nation-state actors such as Volt Typhoon have perfected the use of “living-off-the-land” (LOTL) techniques, using legitimate system tools to conduct malicious activity in ways that are extraordinarily difficult to detect with signature-based defenses. In public sector environments, where security teams are often understaffed and legacy systems are common, this approach gives adversaries a significant advantage.

Supply chain attacks: Hitting government through its vendors

No organization exists in isolation, and malicious actors targeting the public sector know that government agencies often have weaker indirect connections through contractors and vendors. We saw this play out clearly in the Anchorage Police Department incident in January 2026, where a law enforcement agency was compromised through a third-party supply chain attack. Every contractor who touches sensitive government data is a potential vector.

U.S. public sector spotlight

The U.S. continues to bear a disproportionate share of the global public sector threat load. Here is a walkthrough of what TrendAI™ observed in the April through June 2026 period, building on the alarming trajectory we documented in our Q1 2026 report.

Attack frequency: Still running hot

U.S. government bodies experienced a sharp year-over-year increase in ransomware incidents in the first half of 2025, a trajectory that has continued into 2026. We tracked a steep rise in confirmed government ransomware attacks over this period. The rate has not moderated. AI-enhanced attack tooling continues to drive higher volumes.

Metric Data point
U.S. attack frequency vs. global average Elevated
U.S. government ransomware increase (H1 2025) Sharp year-over-year rise
U.S. education share of global ransomware incidents Highest of any country
Student records exposed in education ransomware (2025) Millions of records; sharply higher
Average cost per education ransomware breach Millions per incident
Higher-ed institutions with full data exfiltration before encryption A large share

Education: America's most-targeted subsector

The numbers for the U.S. education sector are stark. U.S. schools and universities were targeted more than educational institutions in any other country, leaving the country with the largest share of global education ransomware. Millions of student records were exposed, a sharp year-over-year increase. A large share of affected higher-education institutions reported that attackers had already fully exfiltrated data before deploying ransomware. This means the extortion leverage exists whether or not a ransom is paid.

Breach costs per education incident routinely climb into the millions. For school districts and universities already operating on constrained budgets, this is a significant financial threat, not just a security problem.

Notable U.S. incidents from Q1 to Q2 2026

Several incidents from early 2026 are worth examining in depth because they illustrate the variety of attack vectors hitting U.S. public sector organizations simultaneously.

Date Incident Impact
Jan 9, 2026 Salt Typhoon—U.S. House Committee Email Breach PRC-aligned actors breached congressional staff emails on national security committees overseeing China policy; FBI confirmed the operation ongoing as of Feb 2026
Jan 3, 2026 Illinois Department of Human Services (IDHS) Misconfiguration Breach System misconfiguration exposed sensitive public assistance data and personal identifiable information (PII) for benefits recipients
Jan 21, 2026 Minnesota DHS Access Control Failure Excessive permissions led to improper disclosure of personal and financial data—nearly 1 million people affected (combined with Illinois)
Jan 2026 Anchorage Police Department Supply Chain Attack Law enforcement compromised via third-party contractor, exposing real-time public safety data access
Jan 2026 Sedgwick Ransomware Attack Government-adjacent contractor targeted, underscoring third-party risk to public sector supply chains
Feb 2026 AT&T/Verizon Block Salt Typhoon Reports U.S. Senator revealed major carriers blocked the release of Salt Typhoon security assessments, raising regulatory transparency concerns

Who is targeting the public sector?

I want to be specific about who's behind these attacks, because attribution matters for understanding the intent, capability, and likely trajectory of these campaigns.

Nation-state and advanced persistent threat (APT) groups

Threat actor Origin Primary targets Key activity
Salt Typhoon China-aligned U.S. Congress, telecom (AT&T, Verizon), federal agencies Breached House Committee staff emails (Jan 2026); FBI confirms operation “still very much ongoing”; focused on committees overseeing China policy
UAT-7290 China-aligned U.S. and allied telecom providers Exploiting edge network device vulnerabilities to establish persistent malware footholds
Volt Typhoon China-aligned U.S. critical infrastructure Infrastructure disruption focus; LOTL techniques using legitimate tools to evade detection
Earth Estries and Earth Krahang China-aligned Government agencies, telecom, non-governmental organizations (NGOs) globally Cross-government attacks exploiting intergovernmental trust; active in Southeast Asia, the Americas, Europe, and Africa

Ransomware and cybercriminal groups

On the cybercriminal side, the Rhysida ransomware group continues to be one of the most active threats against public sector organizations globally. Rhysida employs double-extortion tactics, encrypting data and threatening to publish sensitive information, and has demonstrated a clear preference for government and education targets. Its toolkit includes Cobalt Strike, PsExec, PowerShell, and SYSTEMBC, with shadow copy deletion to prevent recovery.

The operators deploying AI-enhanced ransomware tools are a broader category that includes both established groups adapting their tradecraft and newer entrants who are using commoditized AI attack platforms. The Tsundere Bot credential theft framework mentioned earlier falls into this category: purpose-built tooling that automates the front end of an attack chain and enables even less-experienced operators to run sophisticated campaigns.

Vulnerabilities being exploited right now

One of the most actionable things in a report like this is specific vulnerability intelligence. Here is what TrendAI™ is tracking as actively exploited in public sector environments as we move through Q2 2026.

CVE Product Flaw Status
CVE-2026-20349(High-severity) Cisco ASA & FTD Remote Access VPN An unauthenticated attacker can send a crafted request to force a reload, dropping VPN connectivity with no credentials or user interaction needed. Actively exploited
CVE-2026-20316(Medium-severity) Cisco Secure Firewall Management Center A hardcoded low-privilege account lets a remote, unauthenticated attacker log into the FMC web interface and view sensitive data. Actively exploited
CVE-2026-24061(Critical) GNU Inetutils telnetd A critical authentication bypass lets an attacker spawn a root shell instantly by setting "-f root" in the USER environment variable, no password required. Actively exploited
CVE-2026-1281(Critical) Ivanti Endpoint Manager Mobile Critical zero-click RCE via code injection grants full server control without user interaction; exploited alongside companion flaw CVE-2026-1340. Actively exploited
CVE-2026-20182(Maximum- severity) Cisco Catalyst SD-WAN Controller/Manager An authentication bypass in peering authentication lets an unauthenticated remote attacker send crafted requests to gain full administrative privileges, inject SSH keys, and manipulate NETCONF configuration. Actively exploited

Let us pay specific attention to CVE-2026-1281, a critical zero-click vulnerability that can grant an attacker full server control without requiring any action from the user. There were confirmed breaches within the European Commission's mobile device fleet. This vulnerability made such an impact that CISA mandated patching, while the Canadian Centre for Cybersecurity (CCCS) and England’s National Health Service Digital (NHS Digital) both issued advisories. TrendAITM Research confirmed that telecommunication, government, defense, and technology sectors were significantly affected by this wave of edge-device exploitation.

Beyond specific CVEs, the broader vulnerability trends for Q2 2026 tell a consistent story. AI is enabling malicious actors to discover and weaponize vulnerabilities faster than defenders can apply patches. Edge devices such as firewalls and virtual private network (VPN) gateways are the primary initial access vector for nation-state actors. And misconfigured application programming interfaces (APIs) and cloud environments are resurging as AI-enabled exploitation targets.

How TrendAI™ is defending the public sector

This is something I'm genuinely proud of, and I want to share it not as a product pitch but because it's directly relevant to what public sector defenders need to understand about the state of AI-driven protection.

Our threat intelligence platform is continuously monitoring for the exact threat patterns I've described in this report. Our detection capabilities span the initial access stage, where tools like Tsundere Bot are operating, through lateral movement, data staging, and ransomware deployment. We're using AI not just to detect known threats but to identify novel attack patterns consistent with agentic AI-driven campaigns.

Our research team actively tracks the nation-state groups operating against the public sector. The intelligence we publish on Salt Typhoon, Earth Estries, and Volt Typhoon comes from direct observation of their tooling, infrastructure, and tactics, techniques, and procedures (TTPs). This isn't aggregated open-source intelligence. It is primary research from the TrendAI™ global sensor network, and it directly informs the protections we deploy for our public sector customers.

We also want to acknowledge the transparency challenge. When security incidents occur in the public sector, the information flow to the broader defender community is often slow or incomplete. The revelation that AT&T and Verizon blocked the release of Salt Typhoon security assessment reports is a concerning signal for the community. Defenders need accurate, timely intelligence to protect against active threats, and suppressing that information serves no one except the adversary. At TrendAI™, we remain committed to publishing what we find, even when it's uncomfortable.

Forward-looking guidance for CISOs and practitioners

The threat landscape described here is serious, but it is not insurmountable. Here is our prioritized guidance for public sector security leaders heading into the second half of 2026.

Immediate priorities (act this week)

Audit and patch internet-facing Fortinet, Cisco, and VMware infrastructure with particular urgency on CVE-2020-12812, CVE-2026-20274, and CVE-2026-20860. If you cannot patch immediately, virtual patching via an intrusion prevention system (IPS) is a viable interim control. Every day these exposures remain unaddressed is a day a threat actor can use them.

Enforce multi-factor authentication (MFA) across all employee and contractor access, including remote access systems, cloud administration portals, and any system that touches sensitive government data. Salt Typhoon and related campaigns are exploiting credential theft at scale. MFA is not a silver bullet, but it raises the cost of attack significantly.

Near-term priorities (for this quarter)

Conduct formal supply chain security assessments of your top 20 government-serving contractors and vendors. The Anchorage Police Department and Sedgwick incidents demonstrate that adversaries are happy to enter through the side door. Know who has access to your systems, and verify that their security posture meets your requirements.

Deploy behavioral detection and AI-based anomaly analysis to counter LOTL techniques and the credential theft patterns associated with Tsundere Bot. Signature-based detection will miss these campaigns. You need tooling that can identify suspicious use of legitimate tools and flag unusual authentication and data access patterns.

Implement continuous threat exposure management scanning to maintain full asset visibility. The Illinois and Minnesota DHS incidents both stemmed from misconfiguration and excessive access permissions, problems that a continuous scanning program could surface before they lead to breaches. Shadow IT and AI are real in every organization, and both are particularly prevalent in government environments.

Strategic priorities (for H2 2026 planning)

Plan for an AI-versus-AI defense posture. The agentic AI capabilities now being used in ransomware campaigns will continue to mature through the rest of 2026. Security teams that are still relying on manual processes and analyst-driven detection will fall further behind. Your H2 2026 security roadmap needs to include AI-driven detection and response as a core capability, not a nice-to-have.

Assess election infrastructure risk now. With midterm election cycles approaching, federal, state, and local (FED/SLED) organizations connected to voter registration systems and election infrastructure face elevated targeting risk. A pre-election security assessment and tabletop exercise is not optional at this point.

Invest in threat intelligence sharing. The public sector's collective defense posture improves when agencies share information about the threats they're seeing. Information Sharing and Analysis Center (ISAC) membership and active participation in federal threat intelligence sharing programs pay dividends that individual agency security teams cannot generate on their own.

Threats on the watch list for Q3 2026

First, Salt Typhoon's confirmed access to U.S. telecom carriers and congressional systems sets the stage for potential scope expansion into federal contracting databases and classification-adjacent systems. The campaign is patient, and the access is established.

Second, the maturation of agentic AI in attack chains will likely produce its first fully autonomous, end-to-end ransomware campaigns before the end of 2026.

Third, supply chain cascade attacks, where a single vendor compromise enables access to dozens of downstream government agencies, represent an underappreciated risk that I think will produce a major incident in the second half of this year.

Closing thoughts

The Q2 2026 public sector threat picture is one of increasing automation on the attacker side, persistent nation-state access on the espionage side, and structural vulnerabilities that have gone unaddressed for too long on the defender side. TrendAI™ is watching all of it, researching it, and building protections against it.

If your organization is part of the public sector ecosystem and you want to understand how TrendAI™ threat intelligence can help you get ahead of these threats, we can help you. And if you have thoughts on what I've shared here, or your own observations from the front lines, I'd love to hear from you. You can reach me on Twitter at @JonLClay, and I continue to do bi-weekly blogs where we cover a wide range of topics for the public sector.

Take care, and have a safe and secure future.

Jon Clay | VP of Threat Intelligence, TrendAI™ | @JonLClay