ZeroHour
The Recordpublished ()ingested

Pennsylvania attorney general says SSNs stolen during August ransomware attack

highRansomwareimportance 60CVE-2025-5777

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-5777
Out-of-Bounds Read (Memory Overread) in Citrix NetScaler ADC and Gateway

Citrix NetScaler ADC and NetScaler Gateway contain an out-of-bounds read (CWE-125) caused by insufficient input validation, which can cause the appliance to read beyond the intended memory buffer (a memory overread). The flaw is only triggerable when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, so attackers who can reach those services can potentially induce the overread and obtain sensitive memory contents. Such disclosure could aid follow-on compromise, for example by exposing session or authentication data, and CISA notes known ransomware use. Organizations running NetScaler ADC or NetScaler Gateway in the affected Gateway/AAA configurations are exposed. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-10 with known ransomware use and an EPSS of 100% (100th percentile), indicating active exploitation, while no public PoC is known and a CVSS score has not yet been assigned.

Do: Apply the fixed NetScaler ADC/Gateway builds per Citrix's security advisory (exact affected/fixed version ranges are not in the available data, so consult the bulletin); per CISA KEV, apply vendor mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable. Inventory appliances for Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server configurations, since unconfigured/other deployments are not triggerable. After patching, terminate active and idle VPN sessions and hunt for anomalous access, given the known ransomware exploitation and the information-disclosure nature of the flaw.

9.3100% KEV ransomware
  • Citrix NetScaler ADC
  • Citrix NetScaler Gateway
massplausibly hundreds of thousands of installed/internet-exposed NetScaler ADC and Gateway appliances (public scans have historically shown on the order of…
Full article453 words · extracted from therecord.media · click to collapse

A ransomware attack on the Pennsylvania Office of the Attorney General exposed the Social Security numbers and medical information of an undisclosed number of people. 

In a statement on Monday, the office confirmed that data was stolen during the attack, which caused chaos this summer for the state’s legal system, taking down the website, phone lines and email systems used by most employees.

“Based on the OAG's review of the data involved, for some individuals the information involved may have included name, Social Security number, and/or medical information,” Attorney General Dave Sunday said. 

“On November 14, 2025 we provided notice, via email, of this incident to individuals for whom we had been provided a valid email address. We have also notified the Federal Bureau of Investigation of the incident and are assisting their investigation.”

The statement confirms that the ransomware attack was discovered on August 9 and that a subsequent investigation confirmed that files were stolen from the office’s systems during the incident. 

A toll free number was created for victims with questions about the incident. 

The office did not respond to requests for comment about how many people were impacted. 

While the office’s statement claims it “has no evidence of the misuse, or attempted misuse, of any information that was potentially involved,” the attack was claimed by the INC ransomware gang in September. It is unclear whether the group published the stolen data.

Sunday previously confirmed that hackers encrypted files and systems used by his office but said officials did not pay the ransom issued.

The attack threw a wrench into Pennsylvania’s legal system for nearly a month, forcing courts to provide time extensions for certain criminal and civil cases. The office’s 1,200 staff members were forced to use “alternate channels and methods” to conduct work throughout August. 

“This situation has certainly tested OAG staff and prompted some modifications to our typical routines — however, we are committed to our duty and mission to protect and represent Pennsylvanians, and are confident that mission is being fulfilled,” Sunday said at the time. 

Researchers previously attributed the attack to internet-exposed instances of Citrix NetScaler that were vulnerable to CVE-2025-5777, known colloquially as Citrix Bleed 2, and several other related bugs.

Cybersecurity expert Kevin Beaumont shared evidence of twointernet-exposed Citrix NetScaler devices tied to the Office of the Attorney General that were later removed from the internet.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/pennsylvania-attorney-general-office-data-breach-ssns