Skip to content
Pro-Russia Hacktivists Target EU Operational Technology Systems

Pro-Russia Hacktivists Target EU Operational Technology Systems

First seen 30 Sep 2026, 12:29 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 17:31 UTC
  • •Pro-Russia hacktivist groups increased OT cyberattacks in the EU in 2025.
  • •NoName057(16) was responsible for 48% of hacktivist attacks despite a prior takedown.
  • •Public administration was the most targeted sector, with 32% of incidents reported.

In 2025, pro-Russia hacktivist groups significantly increased cyberattacks against operational technology (OT) systems in the EU, as reported by the European Union Agency for Cybersecurity (ENISA). The agency's annual Threat Landscape report indicated that ideology-driven attacks accounted for 57.3% of all incidents, with 4,709 hacktivist claims made against EU member states. Most of these attacks were distributed denial-of-service (DDoS) attacks, which caused minimal disruption. However, unauthorized access attempts targeting OT systems have raised alarms, particularly in critical sectors like energy and transport. The pro-Russia group NoName057(16) was responsible for 48% of these attacks, despite a Europol-led takedown in mid-2025. The most notable incident involved data-wiping malware targeting the Polish power grid in December 2025. Public administration was the most affected sector, accounting for 32% of cases, followed by business services and transport. Cybercrime incidents, including ransomware and data breaches, also comprised a significant portion of reported attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-06-15
Europol-led takedown of NoName057(16)
Authorities attempted to dismantle the pro-Russian hacktivist group, which continued its activities despite the operation.
Bankinfosecurity
2025-12-31
Data-wiping malware targets Polish power grid
Security researchers linked the incident to Russian military intelligence, marking a significant attack on critical infrastructure.
Bankinfosecurity
Recent
ENISA releases Threat Landscape report
The report highlighted a significant rise in ideology-driven cyberattacks, particularly from pro-Russia hacktivist groups targeting OT systems.
Govinfosecurity

More articles in this cluster (2)