Observed threat map
Most maps with this name show blocked traffic. The arcs flying between continents are port scans and automated probes that a firewall stopped before anyone noticed, which is how the counters reach millions a day and mean nothing. Almost nothing on those maps happened to anybody.
This map only carries incidents that did. A mark needs a named victim, a consequence somebody had to deal with, and a source you can go and read for yourself.
Shows landmark events up to the chosen year. Only the history layer moves — the observed-victim shading is a 90-day window and does not scrub.
This map counts victims observed in our sources — leak-site claims, regulatory filings and press reporting — not all attacks everywhere. Countries with fewer than 3 observed victims are never shaded; they are listed on the shelf instead, so a single small business is not identified by its region. Country capture began recently, so the window is still filling: treat low counts as "not yet seen here", not "not happening here".
110 actors placed across 17 countries; 64 more have no defensible geography and are listed below rather than dropped. Tiers: 72 assessed · 25 attributed · 5 jurisdiction · 5 forensic · 2 contested · 1 unacknowledged.
Read this scale as a map of what has been published, not of what happens. Only 1 of 110 placed actors sit inside the Western alliance. That is not a finding about the world. Our strongest evidence is government advisories, indictments and sanctions — and no government attributes its own intelligence services. Stuxnet is the worked example: no state has ever claimed it, so it carries no solid mark here. The gap is disclosed rather than filled, because filling it would mean accepting evidence we reject for everyone else.
This fill is presence, not volume. A country is coloured because it appears in the record at all — one event or twelve look identical. The pin on it carries the count, and the rail below lists every event with its date. 91 events across 32 countries hit and 13 named as origins.
A curation, not a census. “All attacks since 2010” is not a number anyone has, so a graduated scale here would claim a completeness we do not have — which is why the fill has exactly one step. 26 of these 91 events carry no origin at all: the incident is documented and the attribution is not, and those are shown rather than dropped.
All countries
1,505 incidents observed in the last 90 days · 839 placed in a country · 666 unplaced (44%)
77 countries with any observation · 45 shaded (≥3) · 9 client-grade · 590 claim-only
Industries hit
Scenarios
Select a country on the map for its detail.
Table view — every placed country, with counts
| Country | Observed | Client-grade | Claims | Per million | Shaded |
|---|---|---|---|---|---|
| United States of America | 332 | 8 | 252 | 1.01 | yes |
| Germany | 42 | 0 | 26 | 0.51 | yes |
| United Kingdom | 37 | 1 | 30 | 0.55 | yes |
| Canada | 24 | 0 | 18 | 0.64 | yes |
| Italy | 23 | 0 | 12 | 0.38 | yes |
| Argentina | 18 | 0 | 9 | 0.40 | yes |
| Brazil | 18 | 0 | 12 | 0.09 | yes |
| France | 18 | 0 | 13 | 0.27 | yes |
| India | 18 | 0 | 18 | 0.01 | yes |
| Spain | 17 | 0 | 7 | 0.36 | yes |
| Turkey | 17 | 0 | 13 | 0.20 | yes |
| Australia | 14 | 0 | 12 | 0.55 | yes |
| Poland | 14 | 0 | 7 | 0.37 | yes |
| Mexico | 13 | 0 | 8 | 0.10 | yes |
| Switzerland | 11 | 0 | 11 | 1.28 | yes |
| Japan | 10 | 0 | 3 | 0.08 | yes |
| Czech Republic | 9 | 0 | 3 | 0.84 | yes |
| Indonesia | 9 | 0 | 6 | 0.03 | yes |
| Sweden | 9 | 0 | 5 | 0.88 | yes |
| Taiwan | 9 | 0 | 4 | 0.38 | yes |
| South Africa | 9 | 0 | 3 | 0.15 | yes |
| People's Republic of China | 8 | 0 | 5 | 0.01 | yes |
| Philippines | 8 | 0 | 6 | 0.07 | yes |
| Portugal | 8 | 0 | 4 | 0.78 | yes |
| Peru | 7 | 0 | 6 | 0.22 | yes |
| Finland | 6 | 0 | 5 | 1.09 | yes |
| HK | 6 | 0 | 5 | 0.00 | yes |
| South Korea | 6 | 0 | 6 | 0.12 | yes |
| Netherlands | 6 | 0 | 3 | 0.35 | yes |
| Saudi Arabia | 6 | 0 | 3 | 0.18 | yes |
| SG | 6 | 0 | 5 | 0.00 | yes |
| Thailand | 6 | 0 | 6 | 0.09 | yes |
| Belgium | 5 | 0 | 5 | 0.44 | yes |
| Chile | 5 | 0 | 5 | 0.26 | yes |
| Colombia | 5 | 0 | 3 | 0.10 | yes |
| Hungary | 5 | 0 | 2 | 0.51 | yes |
| Israel | 5 | 0 | 4 | 0.55 | yes |
| Malaysia | 5 | 0 | 3 | 0.16 | yes |
| Nigeria | 5 | 0 | 4 | 0.02 | yes |
| Vietnam | 5 | 0 | 3 | 0.05 | yes |
| Austria | 4 | 0 | 4 | 0.45 | yes |
| Ireland | 4 | 0 | 2 | 0.81 | yes |
| United Arab Emirates | 3 | 0 | 2 | 0.31 | yes |
| Romania | 3 | 0 | 2 | 0.15 | yes |
| Russia | 3 | 0 | 2 | 0.02 | yes |
| Bulgaria | 2 | 0 | 0 | 0.29 | no |
| Cyprus | 2 | 0 | 2 | 1.67 | no |
| Denmark | 2 | 0 | 1 | 0.34 | no |
| Egypt | 2 | 0 | 1 | 0.02 | no |
| New Zealand | 2 | 0 | 2 | 0.41 | no |
| Pakistan | 2 | 0 | 2 | 0.01 | no |
| AD | 1 | 0 | 0 | 0.00 | no |
| AI | 1 | 0 | 1 | 0.00 | no |
| Angola | 1 | 0 | 0 | 0.03 | no |
| Azerbaijan | 1 | 0 | 1 | 0.10 | no |
| Bangladesh | 1 | 0 | 0 | 0.01 | no |
| Ivory Coast | 1 | 0 | 1 | 0.04 | no |
| Costa Rica | 1 | 0 | 1 | 0.20 | no |
| Ecuador | 1 | 0 | 1 | 0.06 | no |
| Gabon | 1 | 0 | 0 | 0.46 | no |
| Ghana | 1 | 0 | 0 | 0.03 | no |
| Greece | 1 | 0 | 1 | 0.09 | no |
| Croatia | 1 | 0 | 0 | 0.25 | no |
| Haiti | 1 | 0 | 1 | 0.09 | no |
| Iraq | 1 | 0 | 1 | 0.03 | no |
| Iceland | 1 | 0 | 1 | 2.77 | no |
| Kenya | 1 | 0 | 1 | 0.02 | no |
| Laos | 1 | 0 | 1 | 0.14 | no |
| Lithuania | 1 | 0 | 0 | 0.36 | no |
| Morocco | 1 | 0 | 1 | 0.03 | no |
| Moldova | 1 | 0 | 1 | 0.38 | no |
| North Macedonia | 1 | 0 | 1 | 0.48 | no |
| Norway | 1 | 0 | 0 | 0.19 | no |
| Papua New Guinea | 1 | 0 | 0 | 0.11 | no |
| Tanzania | 1 | 0 | 1 | 0.02 | no |
| Uruguay | 1 | 0 | 0 | 0.29 | no |
| Yemen | 1 | 0 | 0 | 0.03 | no |
Landmark events (2008–2026)
Notable documented events, not a census. Selected for significance and public documentation; absence from this layer is not evidence of absence. Coverage is uneven by construction: no landmark event here targets Africa, which reflects what is documented in English-language sources, not where attacks happen.
- 2026-02-05 Odido customer data breach Reported as the largest cybersecurity incident in Dutch history by volume of affected customers, at the former T-Mobile Netherlands business. Recorded with no origin: no government or vendor has named a responsible party. Industrial Cyber — H1 2026 incident reporting
- 2026-02-01 Salt Typhoon compromise of Norwegian network devices PST's National Threat Assessment 2026 confirmed that the Chinese state-sponsored group Salt Typhoon had compromised network devices at Norwegian organisations. PST described China's primary intelligence threat to Norway as sitting in the cyber domain. The Record - Norwegian intelligence discloses Salt Typhoon activity
- 2025-10-15 F5 source code and vulnerability data theft A nation-state actor held long-term persistent access to F5's product development environment and took BIG-IP source code plus details of undisclosed vulnerabilities. CISA issued an emergency directive to federal agencies. F5 itself named no country; press reporting pointed to China, which is not a basis this map treats as attribution. CISA emergency directive on F5 devices Unit 42 — nation-state actor steals F5 source code
- 2025-08-31 Jaguar Land Rover production shutdown JLR halted global production for weeks after shutting down its IT systems, idling plants and a supply chain of thousands of smaller firms; the UK government extended a loan guarantee to suppliers. Among the most economically damaging single attacks ever recorded against a British company. Jaguar Land Rover cyberattack — overview and economic impact
- 2025-07-18 SharePoint ToolShell mass exploitation Chained SharePoint zero-days exploited against on-premises servers worldwide, including US federal agencies. Microsoft attributed exploitation to Chinese state-linked actors and opened an investigation into whether details leaked through its own vulnerability disclosure programme. Microsoft — disrupting active exploitation of on-premises SharePoint vulnerabilities
- 2025-06-17 Bank Sepah and Nobitex destruction during the Israel-Iran exchange Days after Israeli airstrikes, the persona Predatory Sparrow disabled the state-owned Bank Sepah and then drained roughly 90 million dollars from Iran's largest crypto exchange, sending the funds to unspendable addresses containing anti-regime slogans — destruction rather than theft. Widely assessed as Israel-linked; never acknowledged. CCDCOE cyber law toolkit — Predatory Sparrow operations against Iranian financial infrastructure (2025) TRM Labs — inside the Nobitex breach
- 2025-04-22 Marks & Spencer and Co-op retail intrusions Social-engineering of IT help desks led to a shutdown of online ordering, empty shelves and months of disruption at several major UK retailers. M&S put the cost at around 300 million pounds and the Co-op at 206 million. The UK National Crime Agency arrested four people; the activity is associated with the Scattered Spider cluster, which has no defensible geography. Infosecurity — top cyber-attacks of 2025
- 2025-04-07 Risevatnet dam floodgate manipulation, Bremanger Control of a fish-farm dam's industrial control system in western Norway; a floodgate was opened for roughly four hours at about 500 litres per second. PST chief Beate Gangas publicly attributed the incident to pro-Russian cyber actors in August 2025, its first formal attribution of this type, and in October 2025 tied the same alliance to a second Norwegian intrusion, noting indications of links to Russian state actors. Reuters - Norway spy chief blames pro-Russian hackers for dam sabotage
- 2024-10-01 Salt Typhoon intrusion into US telecommunications carriers Long-running access to at least nine US carriers, reaching the systems used to service lawful intercept requests — meaning the attackers could see who US law enforcement was surveilling. Call metadata and some intercepted content were exposed. CISA and the FBI confirmed the campaign; the US later sanctioned a contractor tied to it. CISA and partners — joint statement on PRC targeting of commercial telecommunications Congressional Research Service — Salt Typhoon hacks of telecommunications companies
- 2024-08-01 CNCERT report of US intelligence theft from a Chinese materials firm China's national CERT reported a further theft of trade secrets from an unnamed Chinese advanced-materials company, again attributed to unspecified US intelligence agencies. CNCERT public reporting (2024), via the EuRepoC incident record
- 2024-06-03 Synnovis pathology ransomware and London hospital disruption Qilin ransomware against the pathology provider for several London NHS trusts. Blood testing collapsed, over 800 operations and 700 outpatient appointments were cancelled, and a national appeal for O-type blood followed. An NHS trust later confirmed the disruption was a contributing factor in a patient's death — the clearest documented case of a ransomware attack contributing to loss of life. Synnovis incident notifications and NHS England response The Register — NHS supplier ends probe into ransomware attack that contributed to patient death
- 2024-04-14 Snowflake customer-tenant credential campaign Roughly 165 customer environments accessed using credentials harvested by infostealers, against tenants without multi-factor authentication. AT&T lost call and text metadata for about 110 million customers. Not a breach of Snowflake itself, which is why the mark is not placed on the vendor. Two suspects were arrested, in Canada and Turkey. Mandiant — UNC5537 targeting Snowflake customer instances
- 2024-02-21 NoviSpy and Cellebrite against Serbian journalists and activists Amnesty's Security Lab documented Serbian authorities using Cellebrite UFED to unlock phones during police stops and then installing NoviSpy, a previously unknown locally developed implant. Journalist Slaviša Milanov was detained on a pretextual sobriety check; forensics show the spyware was installed while his phone was in police possession, and he never supplied a passcode. Cellebrite subsequently suspended Serbia as a customer. Amnesty Security Lab — A Digital Prison: surveillance and the suppression of civil society in Serbia Amnesty International — Serbia: authorities using spyware and Cellebrite forensic tools
- 2024-02-21 Change Healthcare ransomware (ALPHV/BlackCat) ALPHV/BlackCat-attributed ransomware against UnitedHealth-owned Change Healthcare, the largest US healthcare-claims clearinghouse. Caused weeks of pharmacy + provider payment outages affecting ~1/3 of US patients. UnitedHealth confirmed $872M Q1-2024 cost. Triggered AHA congressional testimony + HHS public emergency. UnitedHealth Q1-2024 8-K filing CISA / HHS joint advisory March 2024
- 2024-02-08 Ukrainian military intelligence operations against Russian state systems Ukraine's Main Directorate of Intelligence publicly claimed a series of intrusions into Russian defence systems, including the Ministry of Defence and a drone control programme. Notable on this map as one of very few cases where a state announces its own offensive operations rather than being accused of them, which removes the attribution problem entirely. Ukrainian Main Directorate of Intelligence (GUR) public statements, 2024
- 2024-02-07 Volt Typhoon US critical-infrastructure pre-positioning PRC PLA-attributed living-off-the-land intrusion into US critical infrastructure (water utilities, energy sector, transportation, ports, comms). CISA AA24-038A: pre-positioning for "disruptive or destructive cyberattacks against US critical infrastructure in the event of a major crisis or conflict". First time CISA formally framed pre-positioning as strategic-level threat. CISA advisory CISA advisory CISA AA24-038A
- 2024-01-12 Midnight Blizzard access to Microsoft corporate email A password-spray against a legacy non-production tenant led to access to the mailboxes of Microsoft's senior leadership, cybersecurity and legal staff, and later to some source-code repositories. Microsoft named the actor as the Russian state group Midnight Blizzard, the same SVR-linked operator behind SolarWinds. Microsoft — actions following attack by nation state actor Midnight Blizzard
- 2023-12-12 Kyivstar telecom outage (Solntsepyok / Sandworm front) Largest Ukrainian mobile operator (~24M subscribers) knocked offline for days. Sandworm front "Solntsepyok" claimed the attack. Disrupted air-raid alerts in some regions during active Russian missile strikes — first public cyber operation against civilian wartime communications at this scale. Reuters: Sandworm hackers caused Kyivstar outage
- 2023-11-25 CyberAv3ngers against US water utility control systems Internet-exposed Unitronics programmable logic controllers at a Pennsylvania water authority were defaced and taken offline by a group calling itself CyberAv3ngers, forcing manual operation. CISA issued an advisory and the US Treasury sanctioned six officials of Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command over the campaign. A small utility, which is the point. CISA advisory — IRGC-affiliated cyber actors exploiting PLCs US Treasury sanctions on IRGC-CEC officials over the water-sector attacks
- 2023-11-08 LockBit ransomware against ICBC Financial Services The US arm of the world's largest bank by assets was disrupted badly enough that it had to settle Treasury trades by sending settlement details on a USB stick carried by courier. Rare and valuable here as a case with a Chinese victim organisation, a category our Anglophone sourcing almost never surfaces. US Treasury and press reporting on the ICBC Financial Services ransomware incident
- 2023-10-20 CyberLink software supply chain compromise A trojanised installer from a Taiwanese multimedia software vendor was signed with the company's own valid certificate and distributed to downstream users. Microsoft attributed it to a North Korean actor. Taiwan appears here as the compromised vendor, not the intended victim. Microsoft Threat Intelligence — Diamond Sleet supply chain compromise of CyberLink
- 2023-08-25 Polish railway emergency-stop radio interference Around twenty trains were halted in north-west Poland by transmission of the unencrypted radio-stop signal, interspersed with the Russian national anthem and a recording of a Putin speech. Technically trivial — the protocol has no authentication — which is precisely why it is worth recording. Polish authorities detained two suspects; no state attribution was made. INCIBE-CERT — cyber-attack on the railway network in Poland
- 2023-06-05 Anonymous Sudan denial-of-service campaign and US indictment A prolific denial-of-service operation that took Microsoft 365 and other major services offline while presenting itself as Sudanese hacktivism. In 2024 the US District Court for the Central District of California indicted two Sudanese nationals and the operation's infrastructure was seized. Included because the self-presented identity and the charged identity actually matched here, which is unusual. US DOJ — indictment of Anonymous Sudan operators (2024)
- 2023-05-31 MOVEit Transfer mass-exploitation (Cl0p) Cl0p exploited a zero-day SQL injection in Progress Software's MOVEit Transfer to exfiltrate data from ~2,700 organisations including US OPM, US DOE, state governments, BBC, BA, Shell. Largest mass-exploitation campaign of 2023. CISA advisory CISA AA23-158A Mandiant MOVEit timeline + attribution
- 2023-05-15 Storm-0558 forged-token access to government email A stolen Microsoft signing key was used to forge authentication tokens and read email at around 25 organisations, including the accounts of the US Commerce Secretary and State Department officials. The US Cyber Safety Review Board later called the intrusion preventable and faulted Microsoft's security culture. Microsoft — analysis of Storm-0558 techniques for unauthorized email access US Cyber Safety Review Board report on the Microsoft Exchange Online intrusion
- 2023-05-11 Coordinated intrusion into 22 Danish energy operators Attackers exploited Zyxel firewall flaws at 16 companies simultaneously, then a second wave followed. SektorCERT called it the largest cyber incident in Danish history and reported evidence connecting part of the activity to Russia's GRU. Several operators disconnected from the grid and ran in island mode. SektorCERT report on the attack against Danish critical infrastructure (2023) The Record — nearly two dozen Danish energy companies hacked
- 2023-05-01 CNCERT report of US intelligence theft from a Chinese technology firm China's national CERT reported that US intelligence agencies had taken trade secrets from a major Chinese high-technology company. The victim is deliberately not named in the report. No US organ is identified, which is why this sits a tier below the Northwestern Polytechnical case. CNCERT public reporting (2023), via the EuRepoC incident record
- 2023-03-29 3CX desktop-app supply chain compromise DPRK-attributed double-supply-chain attack: trojanised 3CX desktop installer (distributed to ~600k orgs) traced back to an earlier compromise of Trading Technologies (X_TRADER software). First publicly-confirmed cascading-supply-chain compromise. Mandiant 3CX investigation CrowdStrike 3CX advisory
- 2022-10-12 Medibank Private health data theft and extortion The health records of roughly 9.7 million current and former customers were stolen and, when Medibank refused to pay, published — including data on terminations of pregnancy and addiction treatment. Australia used its cyber sanctions powers for the first time, naming Aleksandr Ermakov, and later sanctioned the ZServers hosting operation and five more Russian nationals. Australian Cyber Security Centre — cyber sanction for the Medibank compromise Australian Government — further cyber sanctions in response to the Medibank attack
- 2022-09-05 NSA TAO intrusion into Northwestern Polytechnical University China's National Computer Virus Emergency Response Center, with Qihoo 360, reported that the NSA's Tailored Access Operations unit had held access to Northwestern Polytechnical University since 2020, deploying more than forty bespoke malware families and taking around 140 gigabytes of data. The university itself disclosed the intrusion in June 2022, naming phishing of staff and students as the initial vector. The report identifies four IP addresses said to have been bought through cover entities and describes the anonymisation of domains and certificates. CVERC and Qihoo 360 report on the attack against Northwestern Polytechnical University (2022) SecurityWeek — how China pinned university cyberattacks on NSA hackers
- 2022-07-15 Destructive attacks on the Government of Albania (HomeLand Justice) Wiper attacks took down Albanian government websites and services, followed by a second wave in September. Albania severed diplomatic relations with Iran and expelled its embassy staff — the first time a state has broken off relations over a cyberattack. CISA and the FBI published a joint advisory and the US Treasury sanctioned Iran's Ministry of Intelligence and Security. CISA AA22-264A — Iranian state actors conduct cyber operations against the Government of Albania CCDCOE cyber law toolkit — HomeLand Justice operations against Albania (2022)
- 2022-06-29 Denial-of-service against Norwegian state digital services Norway's National Security Authority attributed a denial-of-service campaign against the national public service portal and other institutions to a pro-Russian group, following a labour dispute over Arctic transit. The second Norwegian entry on this layer, after the 2020 Storting compromise. Norwegian National Security Authority (NSM) statement on the June 2022 DDoS campaign
- 2022-06-07 Denial-of-service campaign against Estonian state and financial services A sustained denial-of-service campaign against Estonian institutions following the removal of a Soviet war monument in Narva, described by Estonian officials as the most extensive against the country since 2007. Estonia is where state-scale denial of service was first taken seriously, which makes its return worth marking. Estonian government statements and Avast analysis of the 2022 DDoS campaign
- 2022-06-01 Intrusion into Uzbekistan's state hydropower operator Cisco Talos documented a campaign against Uzbekistan's state hydroelectric company. Recorded largely because Central Asia is otherwise entirely absent from this map, and absence from a map reads as safety rather than as a gap in reporting. Cisco Talos Intelligence — campaign against Central Asian energy targets
- 2022-04-17 Costa Rica government ransomware and national emergency Conti ransomware crippled tax collection and customs processing and spread across 27 institutions. President Rodrigo Chaves declared a national state of emergency — the first time any country had done so over a ransomware attack. The United States later committed 25 million dollars toward recovery. CCDCOE cyber law toolkit — Costa Rica ransomware attack (2022) The Record — US commits $25 million to Costa Rica for recovery
- 2022-03-23 Ronin Bridge cryptocurrency theft Around 625 million dollars in cryptocurrency taken by compromising validator keys — at the time the largest such theft on record. The US Treasury added the wallet address to its Lazarus Group designation, making this a formally sanctioned North Korean operation. The victim, Sky Mavis, is Vietnamese, which is why the mark sits on Vietnam rather than on the crypto ecosystem generally. US Treasury sanctions update tying the Ronin theft to Lazarus Group Elliptic — Lazarus Group identified behind the Ronin bridge heist
- 2022-02-24 Viasat KA-SAT satellite modem wiper (AcidRain) Launched one hour before the invasion of Ukraine, the AcidRain wiper bricked tens of thousands of satellite modems, cutting Ukrainian command communications and simultaneously knocking out remote monitoring for thousands of German wind turbines. The EU and its member states formally condemned it as Russian state activity — one of the clearest cases of civilian spillover from a military cyber operation. Council of the EU — declaration attributing the KA-SAT attack to Russia CCDCOE cyber law toolkit — Viasat KA-SAT attack (2022)
- 2021-11-01 Campaign against Pakistan's Ministry of Defence Malwarebytes and later Zscaler documented campaigns against Pakistani defence and energy-regulatory bodies attributed to India-aligned actors. Pakistan appears on this map almost exclusively as an origin; recording it as a victim is part of not letting the map imply a one-way relationship. Malwarebytes Labs analysis of APT36-adjacent campaigns against Pakistani government targets
- 2021-10-26 Iran national fuel distribution disruption The subsidised-fuel card system used at filling stations nationwide was disabled, leaving drivers unable to buy petrol and prompting queues across the country. Iran blamed Israel and the United States; the persona Predatory Sparrow claimed responsibility. No state has acknowledged it. 2021 Iranian fuel cyberattack — overview
- 2021-08-01 Compromise of New Zealand's Parliamentary Service New Zealand's Government Communications Security Bureau publicly attributed intrusions into parliamentary bodies to a Chinese state-sponsored group, and the government made a formal démarche to Beijing. A small state naming a major power directly, which is rarer than it should be. New Zealand GCSB statement on malicious cyber activity attributed to PRC state-sponsored actors
- 2021-07-02 Kaseya VSA mass ransomware (REvil) REvil exploited a zero-day in Kaseya VSA RMM software to push ransomware to ~1,500 downstream MSP customers — among them Coop (Sweden) which closed ~800 grocery stores for days. The July 4 timing maximised disruption. CISA advisory CISA AA21-209A
- 2021-06-15 Pegasus against Thailand's pro-democracy movement Citizen Lab, with iLaw and DigitalReach, confirmed Pegasus infections on the phones of at least 30 Thai activists, academics, lawyers and NGO staff between October 2020 and November 2021, coinciding with mass pro-democracy protests. Protest leader Panusaya Sithijirawattanakul was infected repeatedly in June and again in September 2021. The investigation began with Apple's threat notifications to Thai civil society. Citizen Lab — GeckoSpy: Pegasus spyware used against Thailand's pro-democracy movement Amnesty International — Pegasus found on phones of Thai dissidents
- 2021-05-30 JBS meat processing ransomware shutdown Slaughterhouses halted across the United States, Canada and Australia; JBS paid an 11 million dollar ransom. The FBI publicly identified REvil as responsible. A food-supply disruption rather than a data breach, which is why it is worth a mark. FBI statement attributing the JBS attack to REvil (2021)
- 2021-05-14 Irish Health Service Executive ransomware shutdown Conti ransomware forced the HSE to shut down every national IT system, cancelling appointments and reverting hospitals to paper for months. Ireland refused to pay. Recovery was estimated at over EUR 100 million and the HSE later offered compensation to affected patients. HSE — cyber attack and response CCDCOE cyber law toolkit — Ireland HSE ransomware attack (2021)
- 2021-05-07 Colonial Pipeline ransomware shutdown DarkSide ransomware caused 6-day shutdown of the US East Coast's largest fuel pipeline (~45% of East Coast supply). Triggered panic-buying + ~10,000 gas stations dry. Colonial paid $4.4M ransom; ~$2.3M recovered by DOJ. President Biden's response set precedent for treating ransomware as a national-security issue. FBI public attribution May 2021
- 2021-03-10 Stortinget Microsoft Exchange Server compromise Data extracted from Stortinget systems during the global exploitation of on-premises Exchange. Norway joined the coordinated international attribution in July 2021; the foreign minister stated the attack was carried out from China. Reuters - Norway says attack on parliament carried out from China
- 2021-03-02 Microsoft Exchange Server mass exploitation (HAFNIUM) Four Exchange zero-days exploited at scale, with web shells left on tens of thousands of servers. In July 2021 the United States, the EU, the UK and NATO jointly attributed the campaign to actors affiliated with China's Ministry of State Security — a rare multi-government attribution naming an intelligence organ. Microsoft — HAFNIUM targeting Exchange Servers with 0-day exploits US and allied joint attribution to China's MSS (July 2021)
- 2021-02-01 Watering-hole campaign against Hong Kong universities ESET documented a watering-hole operation on Hong Kong university websites delivering macOS implants to visitors, during the period of the national security law's introduction. Targets a population rather than an institution, which is the shape most of this map cannot draw. ESET Research — watering-hole campaign targeting Hong Kong users
- 2020-12-13 SolarWinds Orion supply chain compromise Trojanised SolarWinds Orion software update distributed to ~18,000 organisations; ~100 received follow-on intrusions. The most consequential US-government cyber espionage incident of the decade. Triggered the May 2021 Cybersecurity EO 14028. CISA advisory CISA AA20-352A Microsoft Solorigate technical analysis (Dec 2020)
- 2020-09-01 Dutch police infiltration of the Exclu encrypted phone network Dutch and Belgian police read Exclu traffic for five months before dismantling the network, arresting dozens and uncovering a drug lab and torture chambers. Included because law enforcement conducting network intrusion is a real category the map otherwise never shows, and because the operator and the attributing body are the same state. Dutch National Police (Politie) — Exclu investigation
- 2020-08-24 Norwegian Parliament (Storting) email compromise Email accounts of Norwegian MPs and staff were accessed. Norway's PST publicly assessed that actors linked to Russian military intelligence were likely responsible, and the Foreign Minister attributed it to Russia — a NATO member state naming Russia over an attack on its own legislature. Norwegian PST assessment and Foreign Ministry attribution (2020)
- 2020-05-09 Shahid Rajaee port traffic disruption Computers regulating maritime traffic at Iran's largest container port were disrupted, creating a days-long backlog of ships and road congestion. Reported by US and foreign officials as an Israeli operation, widely read as a response to the water-facility attempt days earlier. Israel has never claimed it. Washington Post — officials link Israel to disruptive attack on Iranian port
- 2020-04-24 Attempted manipulation of Israeli water treatment controls Attempts to alter chlorine levels at water treatment facilities. Israel's National Cyber Directorate issued sector-wide instructions to change control-system passwords, and Israeli officials attributed the attempt to Iran. Recorded as an attempted manipulation of a safety-critical process, which is the category the map otherwise never shows. Israel National Cyber Directorate advisory and subsequent official attribution (2020)
- 2020-01-13 Burisma Holdings phishing campaign Credential-phishing against a Ukrainian energy company, using a redirect infrastructure attributed to the GRU. Area 1 Security — Phishing Burisma Holdings
- 2019-03-19 Norsk Hydro LockerGoga ransomware Aluminium smelting and extrusion plants worldwide were forced to manual operation at a cost of around 70 million dollars. Norsk Hydro refused to pay and published daily updates including webcast briefings while still in the middle of the incident — the transparency benchmark other victims are still measured against. Microsoft — how Norsk Hydro responded to ransomware with transparency
- 2018-11-30 Marriott / Starwood guest reservation breach Around 500 million guest records taken, including passport numbers, from a Starwood reservation system that had been compromised since 2014 — before Marriott acquired it, making this a due-diligence failure as much as a security one. US officials linked the intrusion to China's Ministry of State Security as part of a wider collection pattern alongside OPM and Anthem. NPR — Chinese hackers likely responsible for the Marriott data breach
- 2018-08-01 Norwegian county governor offices and Visma intrusion Administrator access to shared systems used by Norway's county governor offices, with credential theft, alongside an intrusion at software supplier Visma. PST attributed the operations to APT31, a China-linked group tied to Chinese intelligence. The Record - APT31 behind 2018 Norwegian government hack
- 2018-06-11 Banco de Chile destructive attack and SWIFT theft A wiper disabled thousands of workstations as cover for a SWIFT fraud that moved around 10 million dollars to Hong Kong. The destruction was a distraction rather than the objective, a pattern seen again in later financial-sector intrusions. First South American financial landmark on this layer. Banco de Chile disclosure and subsequent SWIFT-related reporting (2018)
- 2018-02-09 Olympic Destroyer at the Pyeongchang Winter Olympics Wiper malware took down the opening ceremony's IT systems, ticketing and Wi-Fi. It was deliberately salted with forensic artefacts imitating North Korean and Chinese tooling, and much of the industry initially attributed it accordingly. The DOJ later indicted GRU officers. The best-documented case of an attacker engineering a false attribution rather than merely hiding. US DOJ — six GRU officers charged over destructive malware including Olympic Destroyer
- 2017-08-04 Triton attack on a Saudi petrochemical safety system Malware written to manipulate Triconex safety instrumented systems — the last-resort controls that shut a plant down before it explodes. The plant tripped safely and the attack was found only because the attackers made a mistake. The first known malware built to disable a safety system, and the closest a cyber operation has come to killing people. US Treasury — sanctions against TsNIIKhM over the Triton malware CyberScoop — Treasury sanctions Russian research center blamed for Trisis
- 2017-06-27 NotPetya destructive wiper GRU Unit 74455 (Sandworm) trojanised a Ukrainian tax-software update (M.E.Doc) to seed a destructive wiper masquerading as ransomware. ~$10B in global damages; Merck alone reported $870M loss. Insurance carriers cited "act of war" exclusions — precedent-setting Mondelez and Merck cases followed. CISA / US-CERT NotPetya advisory US DOJ Sandworm indictment (Oct 2020)
- 2017-05-13 Equifax breach (PLA officers indicted) Apache Struts flaw exploited; names, birth dates and social security numbers for 145 million Americans taken. In 2020 the DOJ indicted four members of China's People's Liberation Army for the intrusion. DOJ — Chinese Military Personnel Charged with Hacking Equifax Skybox — Another Lesson in Vulnerability Management: the Equifax Breach
- 2017-05-12 WannaCry global ransomware outbreak Worm-propagating ransomware leveraging the leaked NSA EternalBlue exploit; ~230,000 systems in 150 countries hit in 48 hours. UK NHS hospitals diverted ambulances and cancelled ~19,000 appointments. US, UK, Australia jointly attributed to DPRK 2017. US DOJ Park Jin Hyok indictment (2018)
- 2016-12-17 Industroyer attack on the Kyiv transmission substation A framework built to speak grid protocols natively cut power to part of Kyiv — the first malware designed from the ground up to manipulate electricity transmission, as opposed to the manual operator hijack used against Ukraine a year earlier. Its successor was deployed again in 2022. ESET — Industroyer, the biggest threat to industrial control systems since Stuxnet
- 2016-06-14 GRU operation against the DNC and the 2016 US election Material stolen from Democratic Party organisations was published through DCLeaks, Guccifer 2.0 and WikiLeaks during a presidential campaign. The DOJ indicted twelve GRU officers of Units 26165 and 74455 by name — the most detailed public attribution of a state cyber operation ever filed, down to individual search queries typed by the operators. US DOJ — indictment of 12 Russian GRU officers (US v. Netyksho et al.)
- 2016-02-05 Bangladesh Bank SWIFT heist DPRK-attributed theft of $81M from Bangladesh Bank's Federal Reserve Bank of New York account via fraudulent SWIFT messages. A typo ("fandation" instead of "foundation") stopped a further ~$870M transfer. The recovered funds remain partially frozen with the Philippines authorities a decade later. US DOJ Park Jin Hyok indictment (2018) BAE Systems forensic report
- 2015-12-23 Ukrainian power-grid attacks (Sandworm) First publicly-confirmed cyberattack causing electrical blackout (Dec 2015: ~225k customers without power for hours in Ivano- Frankivsk oblast). Repeated December 2016 with the more advanced Industroyer/CrashOverride malware against Ukrenergo's 330kV Pivnichna substation in Kyiv. Industroyer2 deployed April 2022. Dragos / SANS ICS analysis 2016
- 2015-10-21 TalkTalk customer-data breach and ransom demand SQL-injection against a UK telecom; roughly 157,000 customers' data taken, a ransom note sent, and a record ICO fine followed. RT UK — TalkTalk CEO receives ransom note
- 2015-10-02 Scottrade brokerage breach Contact details for about 4.6 million clients taken; disclosed after federal law-enforcement notification. Scottrade cyber security update (customer notice)
- 2015-10-01 Patreon crowdfunding platform breach Source code and user data taken via a debug server exposed to the internet, then published. Security Affairs — Patreon hacked and data leaked online
- 2015-10-01 Experian breach exposing T-Mobile applicants Records of roughly 15 million T-Mobile credit applicants taken from an Experian server. Experian — Unauthorized Acquisition of Personal Information
- 2015-06-04 US Office of Personnel Management breach PRC-attributed theft of ~21.5M security-clearance background investigation records (SF-86 forms) covering current and former US federal employees, contractors, and family members, plus 5.6M fingerprints. Considered the most-damaging US counter-intelligence loss in cyber history. OPM public statement July 2015
- 2015-05-08 German Bundestag network compromise The entire parliamentary network was compromised and had to be rebuilt, with data taken from MPs including the Chancellor's constituency office. German federal prosecutors later issued an arrest warrant for a named GRU officer and the EU sanctioned him — a rare case of a European state pursuing an individual military intelligence officer by name. EU Council — sanctions over the cyber-attack against the German Federal Parliament
- 2015-04-08 TV5Monde broadcast blackout Eleven television channels were taken off air and the broadcaster's systems destroyed, with the attackers posing as the ‘Cyber Caliphate’ and posting Islamic State imagery. Investigators subsequently attributed it to APT28. The clearest false flag on this map: the visible claim of responsibility pointed at an entirely different actor, which is why a claim is never treated here as attribution. TV5Monde cyberattack — investigation and APT28 attribution
- 2015-02-04 Anthem health-insurance breach PRC-attributed exfiltration of ~78.8M Anthem health-insurance member records including names, dates of birth, SSNs, addresses, employment and income data. Same cohort behind OPM 2015. Settled 2018 with $115M class-action — then the largest data-breach settlement in US history. ThreatConnect Anthem analysis Symantec Black Vine report
- 2014-12-17 German steel mill blast-furnace damage Spear-phishing into the office network pivoted to plant control; a blast furnace could not be shut down properly, causing massive physical damage. Reported by Germany's BSI, which deliberately did not name the operator. SANS ICS — German Steel Mill Cyber Attack (Lee/Assante/Conway)
- 2014-11-24 Sony Pictures Entertainment hack DPRK-attributed retaliation against Sony's planned release of "The Interview". Combined data exfiltration + destructive wiper; ~100TB of email and unreleased films leaked. President Obama attributed publicly Dec 2014; first overt US-DPRK cyber attribution. FBI public attribution statement (2014)
- 2014-09-08 Home Depot payment card breach 56 million payment cards taken over five months using custom point-of-sale malware, entering through a third-party vendor's credentials — the same pattern as Target the year before, which is the uncomfortable part. Home Depot later paid 17.5 million dollars to settle with 46 states. Home Depot — findings of the payment data breach investigation CyberScoop — Home Depot to pay states $17.5 million
- 2014-08-27 JPMorgan Chase data breach Contact data for 76 million households and 7 million small businesses exposed. DataBreachToday — Chase breach: who else was attacked
- 2014-05-19 Indictment of five PLA Unit 61398 officers The US Department of Justice indicted five officers of the People's Liberation Army by name, unit and photograph for economic espionage against American industrial firms — the first time any state's uniformed personnel were criminally charged for cyber operations. Unit 61398 is the same organisation Mandiant had documented as APT1 the year before. US DOJ — five Chinese military hackers charged with cyber espionage
- 2014-02-10 Las Vegas Sands destructive attack (Iran, DNI-attributed) Wiper malware destroyed data across Sands' systems and took much of the company offline; customer credit-card, Social Security and driver's-licence data was also taken. In February 2015 the Director of National Intelligence told the Senate Armed Services Committee the Iranian government was responsible, putting it alongside the Sony hack as one of the first destructive state attacks on US soil. Reporting connects the targeting to the CEO's public statements on Israel. DNI Clapper, Senate Armed Services Committee testimony (Feb 2015), via CNN Bloomberg — Iranian hackers hit Sheldon Adelson's Sands casino
- 2014-01-01 Yahoo account compromise (FSB officers indicted) At least 500 million accounts compromised. The DOJ indicted two FSB officers (Dokuchaev, Sushchin) alongside criminal hackers Belan and Baratov — a documented state/criminal hybrid. DOJ indictment — US v. Dokuchaev, Sushchin, Belan, Baratov
- 2013-12-18 Target payment card breach 40 million payment cards and personal data on 70 million people taken after intruders entered through an HVAC contractor's credentials. The lateral path from a third-party supplier into a payment network made it the reference case for supply-chain risk in retail, and it cost the CEO and the CIO their jobs. US Senate Commerce Committee report on the Target breach
- 2013-08-01 Yahoo breach of all three billion accounts The largest breach ever recorded by account count. Yahoo first disclosed it in December 2016 estimating one billion accounts, and only in October 2017 — after the Verizon acquisition had closed — confirmed that ALL three billion had been affected. Verizon cut its purchase price by 350 million dollars, from 4.83 to 4.48 billion, making this the clearest case on record of a breach directly repricing a corporate acquisition. Distinct from the 2014 intrusion for which FSB officers were later indicted. TechCrunch — Yahoo says all 3 billion accounts were impacted by the 2013 breach CBS News — Verizon slashes offer price for Yahoo over data breaches
- 2013-04-07 #OpIsrael coordinated hacktivist campaign An annually repeating Anonymous-affiliated campaign of defacements, DDoS and credential dumps against Israeli government and commercial sites, timed to the eve of Holocaust Remembrance Day. Claimed figures were very large and the outcome was not; the Israeli National Cyber Bureau assessed the inaugural campaign as a failure, with no physical damage. Recorded because a hacktivist campaign is a real category this map otherwise never shows, and because the gap between claim and effect is the point. Wikipedia — OpIsrael (campaign history and assessments) The Hacker News — Anonymous calls for a massive attack against Israel
- 2013-03-20 DarkSeoul wiper against South Korean banks and broadcasters Roughly 48,000 machines wiped across three broadcasters and three banks in a single coordinated event. The South Korean government publicly attributed it to North Korea after investigation, and in 2015 said it had matched code patterns. Worth recording that the earliest attribution leaned on a Chinese IP address later shown to be misread. Secureworks — Wiper malware analysis, attacking Korean financial sector McAfee — Dissecting Operation Troy
- 2012-08-15 Saudi Aramco / RasGas destructive wiper (Shamoon) Shamoon overwrote the master boot record on roughly 30,000 Saudi Aramco workstations, taking the world's largest oil company off its own network for over a week; RasGas in Qatar was hit days later. Origin is deliberately NOT recorded. Iran is widely assessed as responsible, but that rests on motive, on Shamoon's resemblance to the Wiper malware used against Iran's own oil ministry months earlier, and on unnamed US officials. The only claim of responsibility came from "Cutting Sword of Justice", an anonymous Pastebin persona. No indictment or sanction has ever named a perpetrator. Jeffrey Carr, "Was Iran Responsible for Saudi Aramco's Network Attack?" (2012) CFR Cyber Operations Tracker — Compromise of Saudi Aramco and RasGas
- 2011-03-17 RSA SecurID seed compromise and the Lockheed Martin follow-on A phishing mail titled ‘2011 Recruitment Plan’, retrieved by an employee from a junk folder, carried a Flash zero-day that led to theft of the data underpinning SecurID two-factor tokens. Two months later Lockheed Martin was attacked using the stolen seed material. The canonical demonstration that compromising a security vendor is a route into everyone who trusts it. Schneier on Security — the story of the 2011 RSA hack Dark Reading — China hacked RSA, US official says
- 2010-06-17 Stuxnet sabotage of Natanz uranium enrichment Malware that crossed an air gap and altered the rotational speed of gas centrifuges at Natanz while replaying normal readings to operators, physically destroying an estimated 1,000 machines. The first widely documented case of code causing physical damage to industrial equipment. No state has ever acknowledged it, which is why it is recorded at the `unacknowledged` tier and drawn dashed rather than solid. Symantec — W32.Stuxnet Dossier Kaspersky — Equation Group, technical links to the Stuxnet and Flame authors
- 2010-01-12 Operation Aurora against Google and 20+ US companies Google disclosed a targeted intrusion originating from China that reached its source code and the Gmail accounts of Chinese human-rights activists, and said at least twenty other companies were hit. The first time a company of Google's size publicly attributed an intrusion to a state, and it led to Google withdrawing from the Chinese search market. Operation Aurora — overview and attribution
- 2008-08-08 Cyberattacks on Georgia during the South Ossetia war Defacements and sustained denial-of-service against Georgian government, news and banking sites, running alongside the ground invasion and cutting the government's ability to communicate during it. Widely regarded as the first time network attacks were coordinated with conventional military operations. Russia denied involvement and no formal attribution ever followed. NATO StratCom COE — analysis of the cyberattacks on Estonia and Georgia
Why almost every arrow starts in the same few countries. Of 110 actors we can place, 107 are attributed to states outside the Western alliance and 3 inside it — about 36 to 1. That is not a measurement of who conducts operations. Our strongest evidence is government advisories, indictments and sanctions, and governments do not attribute their own intelligence services. Stuxnet is the clearest case: consensus reporting attributes it jointly to the United States and Israel, neither has ever acknowledged it, and so it cannot meet the evidence bar this map applies to everyone else. Read the absence of Western-origin operations as a limit of the sourcing, not a finding about the world.
What we did about it. A state body naming a foreign intelligence organ is weighed the same whoever issues it — the alternative, taking a US advisory on the issuer's authority while demanding corroboration of a Chinese one, is the double standard that produced the ratio above. Every placement records who attributed it, and 1 carry the unacknowledged tier: broad expert consensus that no accountable body has ever confirmed. Equation Group is the defining case, and it is drawn as an outline rather than a solid mark for exactly that reason.
Targeting people inside their own country all 12 documented cases
States that surveil their own residents — journalists, activists, dissidents. This is drawn as a ring on the country rather than an arrow between countries, because the attacker and the victim are the same nation and an arrow would have nowhere to point. That is a large part of why this category is missing from most threat maps.
It also uses a different evidence standard, out of necessity: no government attributes its own security services, so these rest on independent device forensics (Citizen Lab, Amnesty Security Lab and similar) with corroboration by a second team. Where the operator link is described as circumstantial by the researchers themselves, it is recorded that way rather than promoted.
Small dots around a ring mark the countries where that state pursued its own nationals living abroad, and they point in the direction of each one. There is deliberately no arrow, because an arrow would say the host country was attacked. It was not — an exiled Vietnamese blogger in Germany is a Vietnamese victim who happens to be in Germany, and nothing here shades the host country on the map above. These also carry an extra evidence requirement: the victim’s nationality has to be established by named people or organisations, never by a device’s language setting. One case in this set was refused on exactly that point.
- Palestine APT-C-23 assessed Cybereason assesses with moderate-to-high confidence that APT-C-23 operates on behalf of Hamas. Alongside campaigns against Israeli targets, the group targets Fatah members and other Palestinian voices dissenting from Hamas. Cybereason 'Operation Bearded Barbie' (2022) and 2020 campaign researc
- Russia APT28 attributed 'APT28 espionage activity has primarily targeted entities in the U.S., Europe, and the countries of the former Soviet Union, including governments and militaries, defense attaches, media entities, and dissidents and figures opposed to the current Russian Gover FireEye, 'APT28: At the Center of the Storm' (2017); Trend Micro Pawn
- Vietnam APT32 forensic Amnesty Tech found that the Vietnam-backed group APT32 coordinated spyware attacks against Vietnamese human rights defenders between February 2018 and November 2020; blogger and pro-democracy activist Bui Thanh Hieu was targeted at least four times. Amnesty International Security Lab, 'Click and Bait: Vietnamese Human also reached its own nationals inGermanyAmnesty International Security Lab, 'Click and Bait: Vietnamese Human Rights Defenders Tar
- People's Republic of China Axiom assessed Novetta's Operation SMN report carries a dedicated 'Domestic Targeting' section: 'it also appears that Axiom has used Hikit internally to gather information on domestic Chinese targets... we have identified several instances of Hikit present on machines locate Novetta, 'Operation SMN: Axiom Threat Actor Group Report' (2014), with
- People's Republic of China Daggerfly assessed A China-aligned group whose objective is espionage against movements opposing China's interests: the Tibetan community, religious and academic institutions in Hong Kong, and supporters of democracy in China. Since at least September 2023 it has combined a wate ESET Research, 'Evasive Panda leverages Monlam Festival to target Tibe also reached its own nationals inIndiaESET Research, 'Evasive Panda leverages Monlam Festival to target Tibetans' (2024)
- Iran Ferocious Kitten assessed A six-year covert surveillance campaign against Persian-speaking individuals inside Iran, delivering the MarkiRAT implant through decoy documents and a backdoored build of Psiphon — a VPN used to bypass internet censorship. Victims appear to be Persian-speakin Kaspersky GReAT, 'Ferocious Kitten: 6 years of covert surveillance in
- Iran Magic Hound attributed Magic Hound conducts operations likely on behalf of the Islamic Revolutionary Guard Corps. Its campaigns are directed against dissident organisations and individuals — lawyers, journalists and human rights activists — both inside and outside Iran. MITRE ATT&CK (IRGC linkage); ClearSky and Reuters reporting on targeti also reached its own nationals inUnited KingdomCzech RepublicGermanyCertfa Lab, 'Fake Interview: The New Activity of Charming Kitten'; Reuters and Iran Intern
- Palestine Molerats assessed Campaigns targeting Palestinian authority figures and Palestinians alongside Israeli and regional targets, attributed with high confidence to Palestinian actors with Hamas-affiliated interests. Cybereason 'Spark'/'Pierogi' campaign research; Kaspersky; FireEye
- Turkey NEODYMIUM forensic An activity group that heavily targeted Turkish victims, using the Wingbird backdoor whose characteristics closely match FinFisher, the Gamma Group surveillance suite sold to governments. It burned the same Flash Player zero-day (CVE-2016-4117) at the same tim Microsoft, 'Analysis of FinFisher malware used by NEODYMIUM' (2016) also reached its own nationals inBelgiumItalyMicrosoft Security Intelligence Report (2016); contemporaneous campaign reporting on victi
- Turkey PROMETHIUM forensic Microsoft observed PROMETHIUM using a Flash Player zero-day to spy on Turkish citizens living in Turkey and in Europe. StrongPity has targeted Kurdish victims in Turkey and Syria, and in 2018 was delivered by injection at the ISP level inside Türk Telekom's ne Microsoft Security Intelligence Report (2016); Citizen Lab 'Bad Traffi also reached its own nationals inBelgiumItalyMicrosoft Security Intelligence Report (2016); contemporaneous campaign reporting on victi
- United Arab Emirates Stealth Falcon forensic A campaign of targeted spyware attacks carried out by a sophisticated operator called Stealth Falcon, conducted from 2012 onward against Emirati journalists, activists and dissidents. Circumstantial evidence suggests a link between Stealth Falcon and the UAE g Citizen Lab, 'Keep Calm and (Don't) Enable Macros: A New Threat Actor
- Palestine WIRTE assessed Check Point tracks WIRTE as a Hamas-affiliated threat actor which, since late 2023, has run espionage against the Palestinian Authority, Jordan, Egypt and Saudi Arabia while expanding into disruptive activity against Israel. Check Point Research (2024); Kaspersky Securelist WIRTE campaign analy
My country
Pick a country and this becomes a local briefing: what has been observed there, which industries took it, and who was named. The choice is remembered in this browser only — no account, nothing sent anywhere.
Choose a country above to build the briefing. This part needs JavaScript; the map, shelf and table above do not.
Across the whole window we observed 13 named attackers. Matched to a group we track: 0. With a defensible country of origin: 0 (0%). That is not a gap we can close by guessing: the groups showing up in leak-site claims are ransomware brands, and a brand is not a jurisdiction. Where a group has no defensible geography we say so rather than drawing an arrow from somewhere plausible.
Who hits whom 0 arcs
An arc is drawn only where BOTH ends clear the bar: an actor observed hitting a country, resolving to a group we track, carrying an origin we can defend. The landmark layer above has its own arcs from curated history; these would come from the live 90-day corpus.
No flow arcs can be drawn from the live corpus right now, and the reason is the finding. Of 13 attacker names observed in the last 90 days, 0 resolve to a group we track and 0 carry a defensible country. Every one of them is a leak-site crew — ransomware and extortion brands that name their own victims. Criminal geography is exactly the class this map refuses to place without consensus, because a crew's country is where it is tolerated rather than who directs it. So the feed shows us attackers we can see and cannot site. Arcs will appear here on their own as state-attributed actors enter the observed corpus; drawing them sooner would mean guessing.
Through the supply chain 6
Events whose shape is one-to-many. These are listed apart because a single arc misrepresents them: SolarWinds was not an attack on SolarWinds, it was an attack through it, and for several of these the number of downstream victims is a figure nobody has. Where the record names no victim country we say so rather than pinning the event to the vendor's address, which would put the mark on the one organisation that was a route rather than a target.
- 2017-06-27NotPetya destructive wiperUkraine, Denmark, United States of America, United Kingdom, France
- 2020-12-13SolarWinds Orion supply chain compromiseUnited States of America
- 2021-07-02Kaseya VSA mass ransomware (REvil)United States of America
- 2023-03-293CX desktop-app supply chain compromisereach not countable
- 2023-05-31MOVEit Transfer mass-exploitation (Cl0p)reach not countable
- 2023-10-20CyberLink software supply chain compromiseTaiwan
Actors with no defensible geography 64
Every actor we track that the map cannot place. Forcing a country onto these would make the map look more complete and be less true, so they are listed instead. 42 have no country claim in any source we accept; 8 carry a bare country code in our own corpus with no evidence behind it, which is a lead and not a placement; and 14 were searched, read, and refused — those are decisions, and the reasoning is kept so the question does not get silently re-opened and answered differently.
- BackdoorDiplomacyESET did not formally attribute it. The China reading arrives by merging it into APT15/Ke3chang, which IS state-attributed — but ATT&CK tracks G0135 and G0004 as separate groups, and adopting a press alias-merge to inherit someone
- CarbanakNo single jurisdiction survives. Kaspersky found the crew Russian-speaking; Europol and Spain named the alleged leader as a Ukrainian national arrested in Alicante, running the operation with three Russian and Ukrainian accomplice
- HEXANEBoth primary researchers decline. Secureworks and Dragos each say they do not attribute it to a country; the Iran reading comes from TTP resemblance to COBALT GYPSY and COBALT TRINITY, which is a chained mapping through two other
- InceptionNobody attributes it; researchers note the operators went to unusual lengths to hide origin. The only geographic signal is UTC+2 working hours, shared by a dozen countries, and its heaviest targeting is Russia itself (30 percent),
- LuminousMothKaspersky's moderate-to-high confidence is in the link to HoneyMyte /Mustang Panda, not in a country. Reaching China means LuminousMoth → Mustang Panda → China, and the direct evidence for LuminousMoth alone is Chinese-language ar
- MacheteESET explicitly declines to link it to any government. The only country-level claim is Cylance's Brazil hypothesis, reasoned from the ABSENCE of Brazilian victims, which contradicts Kaspersky's Spanish-speaking finding — Brazil is
- Poseidon GroupThe strongest of the declines, and the clearest illustration of the rule. Kaspersky reported the first publicly known Brazilian-Portuguese-speaking espionage campaign — a statement about compiler language codes and target locale,
- Scarlet MimicUnit 42 states plainly it 'does not have evidence that directly links Scarlet Mimic attacks to the PRC' and offers only motive congruence with Beijing's stated position. Motive alignment is the weakest inference class there is. Al
- StriderSource self-contradictory in a single sentence — 'widely attributed to a Western intelligence agency, with most researchers pointing to Russian origins'. Not `contested` either, because that tier needs two coherent readings and th
- TA505Attributed only to 'Russia or former Soviet states' on linguistic and operational patterns. That is not a country, and language is not geography. This is also the case the policy already names by hand — TA505 is not simply Evil Co
- ThripSymantec located the operational infrastructure — three computers on the mainland — and declined to blame the Chinese government. Where a machine sits is not where an actor is from; rented and compromised hosts are the norm. Neare
- ToddyCatKaspersky states it was 'not able to attribute the attacks to a known APT group'. The China-nexus reading rests on Chinese-language artifacts and victim overlap with Chinese-speaking groups. Secondary press hardened this into 'Chi
- WhiteflySymantec named the group for the SingHealth breach but not a sponsor, and the Singapore government said explicitly it would not disclose the attacker's identity. Absence of a claim, not a claim we are rejecting.
- WindshiftNo origin claim exists. DarkMatter disclosed the group and offered no attribution; Unit 42 later found infrastructure overlap pointing at suspected Indian origins instead. Note also the provenance: DarkMatter is an Emirati firm th