US Homeland Security Committee warns of rising cyber threats, as federal shutdown and ...
The U.S. House Committee on Homeland Security published an updated ‘Cyber Threat Snapshot,’ outlining the heightened threats posed by malign nation-states and criminals to U.S. networks and critical infrastructure since 2024. The current federal government shutdown, coupled with the lapse of the Cybersecurity Information Sharing Act of 2015, is significantly constraining the federal government’s ability to coordinate with industry and execute its defensive cyber mission.
The Homeland Security Committee snapshot identified that this gap in federal cyber capacity comes at a moment when cyber actors affiliated with the People’s Republic of China (PRC) are expanding their targeting of U.S. networks.
“Amid a heightened threat landscape, we must take a whole-of-society approach to countering escalating cyber threats from adversaries like the Chinese Communist Party, Iran, Russia, North Korea, and others,” Andrew Garbarino, a Republican from New York and chairman of the House Committee on Homeland Security, said in a media statement. “As the shutdown continues and a gap remains in our cyber information sharing authorities, a decrease in the visibility of cyber threats across public and private sectors could create blind spots in our networks.”
He added that Senate Democrats must reopen the government “so we can chart a better path forward for our nation’s collective cyber resilience.”
The Homeland Security Committee snapshot disclosed that roughly 70% of all cyberattacks in 2024 involved critical infrastructure . So far in 2025, major cyberattacks on state and local governments have been recorded in at least 44 U.S. states. The manufacturing sector experienced the highest number of cyber incidents at 26%, followed by finance and insurance at 23%, and professional, business, and consumer services at 18%. The energy sector accounted for 10% of attacks, transportation 7%, retail 5%, healthcare 5%, and wholesale 1%.
In 2024, the PRC’s cyber espionage efforts rose 150% compared to the year, according to CrowdStrike. China’s targeted attacks on the financial services, media, manufacturing, and industrial sectors increased 300%.
The Homeland Security Committee report identified that the most unprecedented of these intrusions, Salt Typhoon, compromised at least nine major telecommunications providers in 2024, reportedly to exfiltrate data and conduct espionage on law enforcement’s wiretapping requests. This included accessing the phones of presidential candidates. Salt Typhoon targeted 80 countries and potentially gained access to data from nearly every American.
Moreover, PRC-backed cyber actors maintained access for months within the networks of a public power utility in Littleton, Massachusetts, highlighting the persistent and sophisticated nature of these operations.
The federal government remains a target for PRC-backed cyber actors. In July 2025, three PRC-associated threat actors, Storm-2603, Linen Typhoon , and Violet Typhoon , compromised more than 400 organizations through Microsoft SharePoint, including the Department of Energy, the Department of Homeland Security, and the Department of Health and Human Services. These widespread threats underscore the need for enhanced interagency coordination throughout the government.
Cyber threats from other adversarial regimes are also escalating. Iranian-affiliated cyberattacks spiked 133% in May and June of this year, compared to March and April, amid U.S. and Israeli airstrikes. In July, the electronic case filing system managed by the Administrative Office of the U.S. Courts was reportedly breached, at least in part, by Russia-affiliated hackers.
With advancements in artificial intelligence (AI), North Korea has deployed undercover information technology (IT) workers to infiltrate U.S. companies by gaining remote jobs, in part, using AI as a force multiplier . One in six data breaches reported in 2025 involved attacks driven by AI.
The Homeland Security Committee snapshot disclosed that the average cost of a data breach in the U.S. reached ten million dollars in 2025, which is double the global average.
So far in 2025, at least 44 U.S. states have reported cyber incidents affecting state and local government systems. Communities from St. Paul, Minnesota, to Mission, Texas, declared states of emergency following major intrusions. State, local, tribal, and territorial governments often lack the dedicated resources and technical expertise needed to defend their networks, leaving them vulnerable to cyber threat actors.
The Interlock ransomware group attacked the local government of St. Paul, Minnesota, prompting the city to declare a state of emergency and completely shut down its networks for more than one month to prevent further damage. Numerous government services, including online water bill payments, parks and recreation payment systems, and public internet terminals, were affected by the cyberattack. After St. Paul officials refused to pay Interlock’s ransom, the attackers publicly posted 43 gigabytes of data from the St. Paul Department of Parks and Recreation, a fraction of the 153 terabytes of data that hackers potentially accessed.
In February, the city of Mission, Texas, suffered a cyberattack that caused its main and backup servers to be encrypted by ransomware. The attack caused city officials to lose access to systems at every single city department, freezing critical records such as birth certificates, police reports, contracts, and personnel files. Mission officials declared a state of emergency in response to the ransomware attack.
Outside of nation-state actors, decentralized cybercriminal groups, such as Scattered Spider , continue to launch ransomware and data extortion campaigns against major global companies. These financially motivated attacks are only growing more costly, with the average cost of a data breach in the U.S. reaching $10 million in 2025, more than double the global average.
Scattered Spider, discovered in 2023, is a decentralized cybercriminal organization known for ransomware and data theft extortion targeting major global companies for financial gain. Interlock, discovered in 2024, is a financially motivated group that claimed responsibility for high-profile attacks on a local government and a large manufacturing company. The Democratic People’s Republic of Korea (DPRK) was found in 2022 to have deployed undercover remote IT workers to infiltrate U.S. companies by securing employment in information technology roles.
The growing threat landscape prompted the Committee to advance a bill by Rep. Andy Ogles of Tennessee, titled the ‘Strengthening Cyber Resilience Against State- Threats Act,’ aimed at improving interagency coordination to counter threats from the PRC. Ogles’ ‘PILLAR Act’ to extend and improve the State and Local Cybersecurity Grant Program, and Chairman Garbarino’s ‘WIMWIG Act,’ to enhance and extend voluntary cybersecurity information sharing authorities, reinforcing a whole-of-society effort between the public and private sectors to defend against evolving cyber threats.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
