logo

Hacktivists Escalate Critical Infrastructure Attacks In 2025

ID: fe34565f-4593-5b27-be10-0b7ba40c336c

STIX ID: report--fe34565f-4593-5b27-be10-0b7ba40c336c

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2026-01-23

Date Updated: 2026-07-16

...
...

Cyble’s 2025 Threat Landscape reports a significant escalation in hacktivism: actors shifted from DDoS/defacements to targeted ICS/OT intrusions, ransomware and wiper operations, and large-scale data exfiltration (including an alleged 20TB Aeroflot breach), often aligned with or supported by nation-state interests; critical sectors (government, energy, transport, manufacturing) across Europe, Asia, and the Middle East were heavily impacted and attackers increasingly used custom tooling, RaaS, and automated PoCs to weaponize exposed HMI/SCADA and VNC interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.