New research How Rover caught a PAN-OS authentication bypass attempt (CVE-2025-0108) Baku · Dubai

One forgotten subdomain can expose a whole agency.

Government bodies hold citizen records, run services people rely on, and draw attention from ransomware gangs and state-sponsored groups. Cypho finds the portals, APIs and domains you expose across departments, watches the dark web for leaked credentials and documents, and flags sites and accounts that impersonate you.

Overviewexample.com  /  last 30 days
Open issues
414 critical, 11 high
In review
6Waiting for triage
Time to acknowledge
2h 30mMean, last 30 days
Time to resolve
1d 4hMean, last 30 days

Open issues by category

  • Employee credentials in stealer logs12
  • Lookalike domains9
  • Company documents on file-sharing services7
  • Mentions in messaging channels5
  • Open ports and misconfigurations5
  • Certificates close to expiry3

Most affected assets

  • vpn.example.com7 findingsCritical
  • mail.example.com5 findingsHigh
  • dev-old.example.com4 findingsCritical
  • 203.0.113.243 findingsHigh
  • app.example.com2 findingsModerate
Fig. 1 The overview. Open issues by category, the assets with the most findings, and how long issues take to acknowledge and resolve. Sample data.
01The exposure

Shared citizen data means shared exposure.

Identity records, tax and health information, immigration files and public safety databases often move between agencies. Every copy is one more place it can leak from.

Ransomware gangs go after the services citizens depend on. State-sponsored groups want defense systems, policy data and diplomatic communications.

The openings are often ordinary: a misconfigured storage bucket, an exposed API, a subdomain nobody took down, legacy software that's hard to patch. Some attackers skip the network and spoof your domain instead, emailing citizens and staff with malware, disinformation or a way into internal systems.

02Where we look

What Cypho watches across your departments.

B / Attack Surface Management

Citizen-facing services

Web portals, citizen service platforms and government APIs, found from your domains and checked continuously for misconfigurations and unauthorized access.

B / Attack Surface Management

Forgotten assets

Subdomains, open ports, cloud services and external databases that outlived the project they were built for.

B / Attack Surface Management

Email authentication

SPF, DKIM and DMARC records on your domains, so a gap that lets someone send mail as you gets fixed.

C / Brand Protection

Leaked credentials and documents

Staff credentials and internal documents on dark web forums, paste sites and file-sharing services.

C / Brand Protection

Impersonation

Lookalike domains, fake sites and social accounts posing as your institution or its officials.

A / Threat Intelligence

Nation-state and ransomware groups

Profiles of the groups that target the public sector, with their tactics, linked CVEs and victims by country and sector.

A / Threat Intelligence

Older software

CVEs in the products you run, including legacy systems you add by hand, ranked by how likely they are to be exploited.

03What you get

Visibility that holds across departments.

Early leak alerts
Leaked credentials, exposed documents and impersonation attempts are flagged early and ranked by risk.
Public-facing assets in view
Portals, citizen services and APIs across departments are discovered and monitored continuously.
Strategic intelligence
Nation-state tracking and long-term risk analysis inform security decisions at policy level.
04Questions

What public-sector teams ask us.

How do you find assets we don't know about?

We start from your domains and find the subdomains, IPs, certificates and apps connected to them. Then we keep checking them for open ports, misconfigurations and exposed admin panels.

Do you track nation-state groups?

Yes. Threat actor profiles cover nation-state APTs, ransomware gangs, hacktivists and cybercriminals, with their tactics, linked CVEs and victim trends by country and sector.

Can you help with spoofed email?

We check SPF, DKIM and DMARC on your domains and flag weak settings. We also find lookalike domains that could be used to send phishing in your name.

Unknown threats are unstoppable. Until we expose them.

Send us your company domain. We'll walk you through what's already out there about you and how Cypho would handle it, with one of our analysts on the call.

Or write to [email protected]

We'll use your details to respond to your request. See our privacy policy.