Darkreading Risks of Public Cyber Attribution Discussed at RSAC 2026
Article Content
- •Public attribution of cyberattacks can lead to diplomatic and reputational risks.
- •Attribution is often probabilistic, not definitive, complicating public statements.
- •Companies must consider strategic objectives before publicly blaming threat actors.
At the RSAC 2026 Conference, experts highlighted the complexities and risks associated with publicly attributing cyberattacks to specific threat actors. The panel emphasized that attribution is often probabilistic rather than definitive, with Brett Callow noting that naming a hacking group can lead to diplomatic retaliation or other consequences. Mike Egan pointed out that companies may mistakenly believe that attributing attacks to nation-states absolves them of responsibility, potentially increasing customer anxiety. Megan Stifel stressed the importance of strategic objectives in attribution decisions, as public statements can significantly impact a company's narrative and regulatory obligations. The discussion revealed that the rush to attribute can lead to unintended blowback and complicate the narrative surrounding cyber incidents.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Salt Typhoon and NotPetya in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
FamousSparrow Deploys SparroWocky Backdoor in Latin America The China-aligned cyberespionage group FamousSparrow has replaced its previous backdoor, SparrowDoor, with a new malware called SparroWocky, targeting governmental organizations in Latin America since August 2025. ESET Research attributes this campaign to a likely response to increased U.S. interests in the region.…
Dutch Intelligence Warns of Chinese Malware Targeting Edge Devices Dutch intelligence agencies have reported a surge in Chinese cyberattacks targeting edge devices such as routers and firewalls. A newly discovered malware can survive firmware updates and has compromised 20,000 network appliances globally. The Military Intelligence and Security Service (MIVD) and the General…