// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
ColdRecon / Breach Radar / U.S. government agencies
Breach Record

U.S. government agencies

DISCLOSED 2026-09-16 · UNPATCHED CVE · RANSOMWARE

The Cl0p ransomware group exploited a SQL injection zero-day vulnerability in Progress Software's MOVEit Transfer tool, leading to mass data exfiltration. This attack affected over 2,500 organizations, including U.S. government agencies. The incident is considered one of the largest mass-exploitation events in cybersecurity history.

The record

What we know

Disclosed
2026-09-16
Attack vector
Unpatched Cve
Sector
government
Country
USA
RANSOMWARE
Sources

Cited reporting

Similar vector · recent

Other unpatched cve breaches on file

This page is the permanent ColdRecon entry for the U.S. government agencies disclosure. It updates if new public reporting emerges. All tracked breaches →

U.S. government agencies just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →