A significant cybersecurity breach at the Federal Emergency Management Agency (FEMA) resulted in the exposure of sensitive employee data from both FEMA and U.S. Customs and Border Protection (CBP). The incident began on June 22, when attackers exploited compromised credentials to gain unauthorized access to FEMA's Citrix virtual desktop infrastructure. This access enabled the hackers to exfiltrate data from Region 6 servers, which are responsible for overseeing five southern states and nearly 70 tribal nations. The breach was facilitated by the CitrixBleed 2.0 vulnerability, a widely publicized flaw that allows attackers to bypass authentication controls in Citrix environments. The Department of Homeland Security (DHS) determined that FEMA's IT staff had failed to implement essential security measures, including multi-factor authentication, timely patching of critical vulnerabilities, and addressing known risks. As a result of these failures, multiple senior FEMA technology officers were dismissed on August 29, and the agency underwent a significant IT leadership restructuring. DHS Secretary Kristi Noem publicly criticized FEMA's technology leadership for resisting audits and providing misleading information to oversight officials. The breach was described as 'widespread,' with internal presentations and meeting notes confirming that the incident led to the theft of employee data from both FEMA and CBP. The compromised data resided on servers connected to states along the southern U.S. border, increasing the potential impact of the breach. In response, FEMA has initiated a comprehensive overhaul of its IT security posture, including the appointment of acting CIO Diego Lapiduz to lead recovery and remediation efforts. Additional security measures and staff restructuring are underway to prevent similar incidents in the future. The incident has drawn attention to the critical importance of enforcing basic cybersecurity hygiene and the risks posed by unpatched vulnerabilities in widely used remote access solutions. The breach underscores the need for federal agencies to maintain rigorous security controls and to respond swiftly to emerging threats. The exposure of employee data from both FEMA and CBP raises concerns about potential identity theft and further exploitation by malicious actors. The incident has also prompted broader scrutiny of cybersecurity practices across federal agencies, particularly regarding the use of Citrix and other remote access technologies. The failure to address the CitrixBleed 2.0 vulnerability in a timely manner was a key factor in the success of the attack. FEMA's response includes not only technical remediation but also significant organizational changes to restore trust and improve oversight. The breach serves as a cautionary tale for other government agencies and organizations relying on similar technologies. Ongoing investigations aim to determine the full scope of the data compromised and to identify the threat actors responsible. The event highlights the persistent challenges faced by large organizations in maintaining effective cybersecurity defenses against sophisticated attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Public reporting and follow-on coverage disclosed that FEMA employee data had been exposed in the breach. The later report reinforced that the incident involved compromised personnel information tied to the earlier disclosed attack.
A cyber breach affected the Federal Emergency Management Agency and U.S. Customs and Border Protection, allowing attackers to steal employee data. Reporting described the incident as widespread and impacting personnel information at both agencies.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.