The United States government is facing a new era of cybercrime, with cyberattacks becoming increasingly disruptive and costly. The average remediation cost for a single ransomware attack has more than doubled in the last year, and the public sector saw a 79% increase in average total cost. The government's vast network of employees and contractors are some of the most careless practitioners of credential hygiene, particularly with their .gov account passwords. Multi-factor authentication (MFA) is not enough to stop determined cybercriminals, as phishing and malware campaigns targeting government employee credentials and web session cookies have increased by 67% over the previous year. The government must brace itself for this new era of cybercrime and take preventative measures to protect its vast network of employees and contractors.