Skip to content

Shutdown Sparks 85% Increase in US Government Cyberattacks

Darkreading Nate Nelson, Contributing Writer October 24, 2025

Attackers are pouncing on financially strapped US government agencies and furloughed employees. And the effects of this period might be felt for a long time hereafter.

Cyberattacks against federal employees have nearly doubled since the US government shut down on Oct. 1.

With vital agencies on pause, employees furloughed, and threat activity only ever rising, the federal government and its personnel have possibly never been weaker than they are right now, from a cybersecurity perspective. Predictably, threat actors have noticed. The month of October has seen a surge of meaningful attacks against government workers in limbo, with potential consequences for the agencies that employ them and, by extension, the nation they oversee.

Experts emphasize, too, that the most serious cyber consequences of the shutdown won't come in the form of immediate breaches. Threat actors targeting employees today might lie in wait until some future day. Add to that all of the recruiting challenges and eroding trust in government institutions and it's the long-term fallout that should worry everyone most.

Cyberattacks against US agencies were rising steadily even before Oct. 1, in anticipation of the shutdown. Researchers at the Media Trust then observed a spike of activity on its very first day.

At this point, they're projecting that the feds will experience north of 555 million cyberattacks by the end of the month — an 85% increase over the already more active than usual month of September.

Source: The Media Trust

To make matters worse, Media Trust CEO Chris Olson points out that those 555 million attacks aren't the cheap phishing chum one might expect to dominate such a dataset.

"These are targeted digital attacks through websites, apps, and targeted advertising. What we are detecting are actual interactions with employees," he says.

Justin Miller, associate professor of cyber studies at the University of Tulsa, knows well the kinds of financial hardships government employees face during shutdowns, having spent decades with the Secret Service.

"I remember last time, the DHS said, 'Hey, give this to your mortgage company. It's a letter saying you're a Homeland Security employee, in case you can't pay your mortgage.' And my mortgage company laughed at me. They're like, 'Yeah, that's great. I can appreciate your work for DHS, but your mortgage is due on the 15th and you need to pay it,'" he recalls.

Financially stressed employees are exactly the targets attackers are aiming for. Elaborating on his data, the Media Trust's Olson reports that nation-state actors, cybercriminals, and hacktivists are performing "a surge in deceptive ad campaigns and phishing lures designed to exploit financial anxiety during the government shutdown. Many of these spam campaigns promise quick cash, loan forgiveness, or job opportunities but lead to credential-harvesting sites or malware downloads."

An attack on a government employee sitting at today could be utilized later, once that employee goes back to work. An attacker could learn that employee in order to impersonate them later in phishing emails, or infiltrate the smartphone they'll bring to work again every day once the shutdown lifts.

Or attackers can do one better.

The Media Trust found that the most targeted agency during this shutdown, by far, has been the Department of Veterans Affairs (VA). In second place — again, some distance from third — is the Department of Justice (DoJ). The chart below shows the volume of attacks that reached each agency in the first week of October.

Though the VA and DoJ might sound like an arbitrary duo, there may well be some hidden logic underneath.

Source: The Media Trust

When a government shutdown happens, employees fall into two buckets. Many are furloughed — sent and barred from even checking their government email inbox. Some are deemed "essential," though, and they have to keep working.

Essential workers are just as unpaid, stressed, and vulnerable, yet they still have to walk into their workplace everyday. Miller points out how, especially in these cases, "you're going to have morale issues. And then with this minimal staffing, you're creating a higher burden on the personnel who are there having to do probably additional work," meaning cyber threats are more likely to slip through.

Because so many of them perform crucial medical and benefits work, 96.8% of employees at the VA are still going into work Monday through Friday. Similarly, 90% of DoJ employees are considered essential .

The White House has advised that, during the shutdown, "generally, agency cybersecurity functions are excepted as these functions are necessary to avoid imminent threat to Federal property," but agencies have discretion in how they interpret this guideline. And with two-thirds of the Cybersecurity and Infrastructure Security Agency (CISA) sitting at , agencies already lack the support they're used to at a time when they're at greatest risk.

Ilona Cohen, former general counsel for the US Office of Management and Budget (OMB), now chief legal and policy officer for HackerOne, worries that amid all the headlines, people might be missing the forest for the trees.

"I think people think, 'OK, a certain amount of damage will be done in a certain number of days, whatever. Congress and the president decide [it's over] and then we all go back to business.' But there is a long-term impact anytime you have a shutdown like this," she says.

Putting aside the threat of latent cyberattacks — like the 2015 Office of Personnel Management (OPM) breach — there are also less visible consequences. For example, the government already faces an uphill battle recruiting talent from the more lucrative private sector, which is only set to grow worse now.

"It is a challenge that has been difficult to address for years now and there has been some progress. But if you are constantly having federal workers who are nervous instability in the federal government and a failure to be paid, then you're just going to push skilled cyber professionals out of public service. That's going to be a problem not just when the shutdown ends, but for many, many weeks, months, years, depending on how many people you lose because of this instability," Cohen says.

Then there are all of the difficulties that come with discontinuity — paused projects, delayed modernization of legacy systems, and vulnerabilities going unaddressed.

Combine that with the expiration of the Cybersecurity Information Sharing Act of 2015 (CISA 2015) and the State and Local Cybersecurity Grant Program (SLCGP), "and the combination of the shutdown plus the expiration of critical laws means that you have a significant erosion of trust," Cohen says. "It just breaks down."

Nate Nelson, Contributing Writer

Nate Nelson is a writer based in New York City. He formerly worked as a reporter at Threatpost, and wrote "Malicious Life," an award-winning Top 20 tech podcast on Apple and Spotify. Outside of Dark Reading, he also co-hosts "The Industrial Security Podcast."

Miercom Test Results: PA-5450 Firewall Wins

Security Without Compromise Better security, higher performance and lower TCO

The Total Economic Impact™ Of Palo Alto Networks NextGeneration Firewalls

How Enterprises Are Harnessing Emerging Technologies in Cybersecurity

Worldwide Security Information and Event Management Forecast, 2025--2029: Continued Payment for One's SIEMs

The Cloud is No Longer Enough: Securing the Modern Digital Perimeter

Securing the Hybrid Workforce: Challenges and Solutions

Cybersecurity Outlook 2026

Threat Hunting Tools & Techniques for Staying Ahead of Cyber Adversaries

Measuring Ransomware Resilience: What Hundreds of Security Leaders Revealed

Extracted Entities