United States government and cybercrime - statistics & facts
A new approach to Russia in cyber
Another step toward confusion in the cybersecurity industry was the order by the U.S. secretary of defense Pete Hegseth to stop offensive cyber operations against Russia. Although not much information was shared in regard to this order, the new approach to cybersecurity in the frame of critical U.S. infrastructure seems abrupt and more likely a strategic move.Types of cyberattacks targeting the U.S. government
Governments are often targets of nation-state threat actors but also of non-state actors, such as terrorist groups, companies, political or ideological extremist groups, criminal organizations, and hacktivists. In 2023, improper use was the most common type of attack vector recorded by the U.S. government agencies. Overall, CFO Act agencies recorded more cyberattacks than non-CFO Act agencies.U.S. government data breaches
2023 was a year full of data breaches for U.S. government entities. Private data violation cases in 2023 affected 15 million people. By far, the most significant reported data breach involving the U.S. government was the breach at the U.S. postal service in 2018, which exposed 60 million data records. Cities were the government entities encountering the most data breach incidents.United States cybersecurity governance
Cybersecurity legislation or frameworks are crucial in establishing the resilient cybersecurity posture of a government unit. In the United States, cybersecurity governance is carried out at the state level through regulations, legislation, or statutes, and expenditures. In a 2024 survey, State Chief Information Security Officers in the United States stated that only a few had cybersecurity legislation, or statutes in place that were funded. Most states have not adopted any of the mentioned legislation. Moreover, the majority of U.S. states did not have a cybersecurity budget line item, and only 21 percent had it established by a statute or law.Cybersecurity spending
The overall estimated cybersecurity spending at U.S. CFO Act Agencies for the fiscal year 2025 was over 13 billion U.S. dollars. Non-CFO Act agencies had an estimated budget of 674 million U.S. dollars. Of selected federal departments, the Department of Homeland Security had the highest cybersecurity spending in 2023, 3.2 billion U.S. dollars, followed by the Department of Treasury, with 1.2 billion U.S. dollars.Following massive cyberattacks on the U.S. critical infrastructure, such as the Colonial Pipeline attack in 2021 and other supply chain attacks indirectly impacting government entities, the federal government should continue implementing new strategies dedicated to better protecting critical infrastructure.





































