Cyber Resilience

Observed threat map

Most maps with this name show blocked traffic. The arcs flying between continents are port scans and automated probes that a firewall stopped before anyone noticed, which is how the counters reach millions a day and mean nothing. Almost nothing on those maps happened to anybody.

This map only carries incidents that did. A mark needs a named victim, a consequence somebody had to deal with, and a source you can go and read for yourself.

Time window

All 3 windows currently hold the same 77 countries, because the captured corpus does not yet reach back 12 months. They are shown rather than hidden so the depth of the record is visible; they will diverge on their own as capture accumulates.

Filter victims by
Map shows
Layers Client-grade: confirmed by a filing or breach notice rather than claimed on a leak site · 9 of 839 observations, 2 countries
20082026

Shows landmark events up to the chosen year. Only the history layer moves — the observed-victim shading is a 90-day window and does not scrub.

United Arab Emirates — 3 observedUnited Arab Emirates — 1 state-attributed actorAfghanistanAfghanistan — no actors placed hereAlbaniaAlbania — no actors placed hereArmeniaArmenia — no actors placed hereAngola — 1 observed (below the 3 shading threshold)Angola — no actors placed hereArgentina — 18 observedArgentina — no actors placed hereAustria — 4 observedAustria — no actors placed hereAustralia — 14 observedAustralia — no actors placed hereAzerbaijan — 1 observed (below the 3 shading threshold)Azerbaijan — no actors placed hereBosnia and HerzegovinaBosnia and Herzegovina — no actors placed hereBangladesh — 1 observed (below the 3 shading threshold)Bangladesh — no actors placed hereBelgium — 5 observedBelgium — no actors placed hereBurkina FasoBurkina Faso — no actors placed hereBulgaria — 2 observed (below the 3 shading threshold)Bulgaria — no actors placed hereBurundiBurundi — no actors placed hereBeninBenin — no actors placed hereBruneiBrunei — no actors placed hereBoliviaBolivia — no actors placed hereBrazil — 18 observedBrazil — 1 criminal group (jurisdiction, not sponsorship)The BahamasThe Bahamas — no actors placed hereBhutanBhutan — no actors placed hereBotswanaBotswana — no actors placed hereBelarusBelarus — 1 state-attributed actorBelizeBelize — no actors placed hereCanada — 24 observedCanada — no actors placed hereDemocratic Republic of the CongoDemocratic Republic of the Congo — no actors placed hereCentral African RepublicCentral African Republic — no actors placed hereRepublic of the CongoRepublic of the Congo — no actors placed hereSwitzerland — 11 observedSwitzerland — no actors placed hereIvory Coast — 1 observed (below the 3 shading threshold)Ivory Coast — no actors placed hereChile — 5 observedChile — no actors placed hereCameroonCameroon — no actors placed herePeople's Republic of China — 8 observedPeople's Republic of China — 46 state-attributed actorsColombia — 5 observedColombia — 1 state-attributed actorCosta Rica — 1 observed (below the 3 shading threshold)Costa Rica — no actors placed hereCubaCuba — no actors placed hereCyprus — 2 observed (below the 3 shading threshold)Cyprus — no actors placed hereCzech Republic — 9 observedCzech Republic — no actors placed hereGermany — 42 observedGermany — no actors placed hereDjiboutiDjibouti — no actors placed hereDenmark — 2 observed (below the 3 shading threshold)Denmark — no actors placed hereDominican RepublicDominican Republic — no actors placed hereAlgeriaAlgeria — no actors placed hereEcuador — 1 observed (below the 3 shading threshold)Ecuador — no actors placed hereEstoniaEstonia — no actors placed hereEgypt — 2 observed (below the 3 shading threshold)Egypt — no actors placed hereWestern SaharaWestern Sahara — no actors placed hereEritreaEritrea — no actors placed hereSpain — 17 observedSpain — no actors placed hereEthiopiaEthiopia — no actors placed hereFinland — 6 observedFinland — no actors placed hereFijiFiji — no actors placed hereFalkland IslandsFalkland Islands — no actors placed hereFrance — 18 observedFrance — no actors placed hereGabon — 1 observed (below the 3 shading threshold)Gabon — no actors placed hereUnited Kingdom — 37 observedUnited Kingdom — no actors placed hereGeorgiaGeorgia — no actors placed hereGhana — 1 observed (below the 3 shading threshold)Ghana — no actors placed hereGreenlandGreenland — no actors placed hereThe GambiaThe Gambia — no actors placed hereGuineaGuinea — no actors placed hereEquatorial GuineaEquatorial Guinea — no actors placed hereGreece — 1 observed (below the 3 shading threshold)Greece — no actors placed hereGuatemalaGuatemala — no actors placed hereGuinea-BissauGuinea-Bissau — no actors placed hereGuyanaGuyana — no actors placed hereHondurasHonduras — no actors placed hereCroatia — 1 observed (below the 3 shading threshold)Croatia — no actors placed hereHaiti — 1 observed (below the 3 shading threshold)Haiti — no actors placed hereHungary — 5 observedHungary — no actors placed hereIndonesia — 9 observedIndonesia — no actors placed hereIreland — 4 observedIreland — no actors placed hereIsrael — 5 observedIsrael — no actors placed hereIndia — 18 observedIndia — 4 state-attributed actorsIraq — 1 observed (below the 3 shading threshold)Iraq — no actors placed hereIranIran — 17 state-attributed actors, 1 criminal group (jurisdiction, not sponsorship)Iceland — 1 observed (below the 3 shading threshold)Iceland — no actors placed hereItaly — 23 observedItaly — no actors placed hereJamaicaJamaica — no actors placed hereJordanJordan — no actors placed hereJapan — 10 observedJapan — no actors placed hereKenya — 1 observed (below the 3 shading threshold)Kenya — no actors placed hereKyrgyzstanKyrgyzstan — no actors placed hereCambodiaCambodia — no actors placed hereNorth KoreaNorth Korea — 8 state-attributed actorsSouth Korea — 6 observedSouth Korea — 2 state-attributed actorsKuwaitKuwait — no actors placed hereKazakhstanKazakhstan — no actors placed hereLaos — 1 observed (below the 3 shading threshold)Laos — no actors placed hereLebanonLebanon — 3 state-attributed actorsSri LankaSri Lanka — no actors placed hereLiberiaLiberia — no actors placed hereLesothoLesotho — no actors placed hereLithuania — 1 observed (below the 3 shading threshold)Lithuania — no actors placed hereLuxembourgLuxembourg — no actors placed hereLatviaLatvia — no actors placed hereLibyaLibya — no actors placed hereMorocco — 1 observed (below the 3 shading threshold)Morocco — no actors placed hereMoldova — 1 observed (below the 3 shading threshold)Moldova — no actors placed hereMontenegroMontenegro — no actors placed hereMadagascarMadagascar — no actors placed hereNorth Macedonia — 1 observed (below the 3 shading threshold)North Macedonia — no actors placed hereMaliMali — no actors placed hereMyanmarMyanmar — no actors placed hereMongoliaMongolia — no actors placed hereMauritaniaMauritania — no actors placed hereMalawiMalawi — no actors placed hereMexico — 13 observedMexico — no actors placed hereMalaysia — 5 observedMalaysia — no actors placed hereMozambiqueMozambique — no actors placed hereNamibiaNamibia — no actors placed hereNew CaledoniaNew Caledonia — no actors placed hereNigerNiger — no actors placed hereNigeria — 5 observedNigeria — 1 state-attributed actorNicaraguaNicaragua — no actors placed hereNetherlands — 6 observedNetherlands — no actors placed hereNorway — 1 observed (below the 3 shading threshold)Norway — no actors placed hereNepalNepal — no actors placed hereNew Zealand — 2 observed (below the 3 shading threshold)New Zealand — no actors placed hereOmanOman — no actors placed herePanamaPanama — no actors placed herePeru — 7 observedPeru — no actors placed herePapua New Guinea — 1 observed (below the 3 shading threshold)Papua New Guinea — no actors placed herePhilippines — 8 observedPhilippines — no actors placed herePakistan — 2 observed (below the 3 shading threshold)Pakistan — 3 state-attributed actorsPoland — 14 observedPoland — no actors placed herePuerto RicoPuerto Rico — no actors placed herePalestinePalestine — 3 state-attributed actorsPortugal — 8 observedPortugal — no actors placed hereParaguayParaguay — no actors placed hereQatarQatar — no actors placed hereRomania — 3 observedRomania — no actors placed hereSerbiaSerbia — no actors placed hereRussia — 3 observedRussia — 11 state-attributed actors, 2 criminal groups (jurisdiction, not sponsorship)RwandaRwanda — no actors placed hereSaudi Arabia — 6 observedSaudi Arabia — no actors placed hereSolomon IslandsSolomon Islands — no actors placed hereSudanSudan — no actors placed hereSweden — 9 observedSweden — no actors placed hereSloveniaSlovenia — no actors placed hereSlovakiaSlovakia — no actors placed hereSierra LeoneSierra Leone — no actors placed hereSenegalSenegal — no actors placed hereSomaliaSomalia — no actors placed hereSurinameSuriname — no actors placed hereSouth SudanSouth Sudan — no actors placed hereEl SalvadorEl Salvador — no actors placed hereSyriaSyria — no actors placed hereEswatiniEswatini — no actors placed hereChadChad — no actors placed hereFrench Southern and Antarctic LandsFrench Southern and Antarctic Lands — no actors placed hereTogoTogo — no actors placed hereThailand — 6 observedThailand — no actors placed hereTajikistanTajikistan — no actors placed hereEast TimorEast Timor — no actors placed hereTurkmenistanTurkmenistan — no actors placed hereTunisiaTunisia — no actors placed hereTurkey — 17 observedTurkey — 3 state-attributed actorsTrinidad and TobagoTrinidad and Tobago — no actors placed hereTaiwan — 9 observedTaiwan — no actors placed hereTanzania — 1 observed (below the 3 shading threshold)Tanzania — no actors placed hereUkraineUkraine — no actors placed hereUgandaUganda — no actors placed hereUnited States of America — 332 observedUnited States of America — 1 state-attributed actorUruguay — 1 observed (below the 3 shading threshold)Uruguay — no actors placed hereUzbekistanUzbekistan — no actors placed hereVenezuelaVenezuela — no actors placed hereVietnam — 5 observedVietnam — 1 state-attributed actorVanuatuVanuatu — no actors placed hereKosovoKosovo — no actors placed hereYemen — 1 observed (below the 3 shading threshold)Yemen — no actors placed hereSouth Africa — 9 observedSouth Africa — no actors placed hereZambiaZambia — no actors placed hereZimbabweZimbabwe — no actors placed here 2010 — Operation Aurora against Google and 20+ US companies (CN → US)2010 — Stuxnet sabotage of Natanz uranium enrichment (US → IR) — no state has ever acknowledged this operation2011 — RSA SecurID seed compromise and the Lockheed Martin follow-on (CN → US)2013 — DarkSeoul wiper against South Korean banks and broadcasters (KP → KR)2014 — Las Vegas Sands destructive attack (Iran, DNI-attributed) (IR → US)2014 — Indictment of five PLA Unit 61398 officers (CN → US)2014 — Sony Pictures Entertainment hack (KP → US)2015 — Anthem health-insurance breach (CN → US)2015 — TV5Monde broadcast blackout (RU → FR)2015 — German Bundestag network compromise (RU → DE)2015 — US Office of Personnel Management breach (CN → US)2015 — Ukrainian power-grid attacks (Sandworm) (RU → UA)2016 — Bangladesh Bank SWIFT heist (KP → BD)2016 — GRU operation against the DNC and the 2016 US election (RU → US)2016 — Industroyer attack on the Kyiv transmission substation (RU → UA)2017 — WannaCry global ransomware outbreak (KP → GB)2017 — NotPetya destructive wiper (RU → UA)2017 — NotPetya destructive wiper (RU → DK)2017 — NotPetya destructive wiper (RU → US)2017 — NotPetya destructive wiper (RU → GB)2017 — NotPetya destructive wiper (RU → FR)2017 — Triton attack on a Saudi petrochemical safety system (RU → SA)2018 — Olympic Destroyer at the Pyeongchang Winter Olympics (RU → KR)2018 — Norwegian county governor offices and Visma intrusion (CN → NO)2018 — Marriott / Starwood guest reservation breach (CN → US)2020 — Burisma Holdings phishing campaign (RU → UA)2020 — Attempted manipulation of Israeli water treatment controls (IR → IL)2020 — Shahid Rajaee port traffic disruption (IL → IR) — no state has ever acknowledged this operation2020 — Norwegian Parliament (Storting) email compromise (RU → NO)2020 — SolarWinds Orion supply chain compromise (RU → US)2021 — Microsoft Exchange Server mass exploitation (HAFNIUM) (CN → US)2021 — Stortinget Microsoft Exchange Server compromise (CN → NO)2021 — Irish Health Service Executive ransomware shutdown (RU → IE)2021 — JBS meat processing ransomware shutdown (RU → US)2021 — JBS meat processing ransomware shutdown (RU → CA)2021 — JBS meat processing ransomware shutdown (RU → AU)2021 — Compromise of New Zealand's Parliamentary Service (CN → NZ)2021 — Iran national fuel distribution disruption (IL → IR) — no state has ever acknowledged this operation2021 — Campaign against Pakistan's Ministry of Defence (IN → PK)2022 — Viasat KA-SAT satellite modem wiper (AcidRain) (RU → UA)2022 — Viasat KA-SAT satellite modem wiper (AcidRain) (RU → DE)2022 — Ronin Bridge cryptocurrency theft (KP → VN)2022 — Costa Rica government ransomware and national emergency (RU → CR)2022 — Intrusion into Uzbekistan's state hydropower operator (KZ → UZ)2022 — Denial-of-service campaign against Estonian state and financial services (RU → EE)2022 — Denial-of-service against Norwegian state digital services (RU → NO)2022 — Destructive attacks on the Government of Albania (HomeLand Justice) (IR → AL)2022 — NSA TAO intrusion into Northwestern Polytechnical University (US → CN)2022 — Medibank Private health data theft and extortion (RU → AU)2023 — CNCERT report of US intelligence theft from a Chinese technology firm (US → CN)2023 — Coordinated intrusion into 22 Danish energy operators (RU → DK)2023 — Storm-0558 forged-token access to government email (CN → US)2023 — Anonymous Sudan denial-of-service campaign and US indictment (SD → US)2023 — Anonymous Sudan denial-of-service campaign and US indictment (SD → GB)2023 — CyberLink software supply chain compromise (KP → TW)2023 — LockBit ransomware against ICBC Financial Services (RU → CN)2023 — CyberAv3ngers against US water utility control systems (IR → US)2023 — Kyivstar telecom outage (Solntsepyok / Sandworm front) (RU → UA)2024 — Midnight Blizzard access to Microsoft corporate email (RU → US)2024 — Volt Typhoon US critical-infrastructure pre-positioning (CN → US)2024 — Ukrainian military intelligence operations against Russian state systems (UA → RU)2024 — Synnovis pathology ransomware and London hospital disruption (RU → GB)2024 — CNCERT report of US intelligence theft from a Chinese materials firm (US → CN)2024 — Salt Typhoon intrusion into US telecommunications carriers (CN → US)2025 — Risevatnet dam floodgate manipulation, Bremanger (RU → NO)2025 — Bank Sepah and Nobitex destruction during the Israel-Iran exchange (IL → IR) — no state has ever acknowledged this operation2025 — SharePoint ToolShell mass exploitation (CN → US)2026 — Salt Typhoon compromise of Norwegian network devices (CN → NO)Albania — 1 landmark event, 20222022Australia — 2 landmark events, 2021–20222021–2022Bangladesh — 1 landmark event, 20162016Canada — 1 landmark event, 20212021Chile — 1 landmark event, 20182018People's Republic of China — 4 landmark events, 2022–20242022–2024Costa Rica — 1 landmark event, 20222022Germany — 3 landmark events, 2014–20222014–2022Denmark — 2 landmark events, 2017–20232017–2023Estonia — 1 landmark event, 20222022France — 2 landmark events, 2015–20172015–2017United Kingdom — 7 landmark events, 2015–20252015–2025Georgia — 1 landmark event, 20082008Ireland — 1 landmark event, 20212021Israel — 2 landmark events, 2013–20202013–2020Iran — 4 landmark events, 2010–20252010–2025South Korea — 2 landmark events, 2013–20182013–2018Netherlands — 2 landmark events, 2020–20262020–2026Norway — 7 landmark events, 2018–20262018–2026New Zealand — 1 landmark event, 20212021Pakistan — 1 landmark event, 20212021Poland — 1 landmark event, 20232023Serbia — 1 landmark event, 20242024Russia — 1 landmark event, 20242024Saudi Arabia — 2 landmark events, 2012–20172012–2017Thailand — 1 landmark event, 20212021Taiwan — 1 landmark event, 20232023Ukraine — 6 landmark events, 2015–20232015–2023United States of America — 34 landmark events, 2010–20252010–2025Uzbekistan — 1 landmark event, 20222022Vietnam — 1 landmark event, 20222022 Palestine — WIRTE: documented targeting of people inside this country (assessed evidence)Daggerfly reached its own nationals in India. The Tibetan exile community in India, reached through a watering-hole on a site serving the Monlam festival and through trojanised Tibetan-language translation software.People's Republic of China — Daggerfly: documented targeting of people inside this country (assessed evidence)Russia — APT28: documented targeting of people inside this country (attributed evidence)Magic Hound reached its own nationals in United Kingdom. Staff of Iran International, the London-based Persian-language broadcaster. Anchor Azadeh Shafiee was impersonated by the operators to reach the accounts of a relative and of a PraMagic Hound reached its own nationals in Czech Republic. A Prague-based Iranian filmmaker, approached through an impersonation of the Iran International anchor.Magic Hound reached its own nationals in Germany. An Iranian-born German academic, sent a fraudulent email impersonating Wall Street Journal correspondent Farnaz Fassihi and then asked to enter a Google password.Iran — Magic Hound: documented targeting of people inside this country (attributed evidence)APT32 reached its own nationals in Germany. Bui Thanh Hieu, a pro-democracy blogger exiled in Germany since 2013, targeted with spyware on four occasions between February 2018 and December 2019.Vietnam — APT32: documented targeting of people inside this country (forensic evidence)Palestine — Molerats: documented targeting of people inside this country (assessed evidence)United Arab Emirates — Stealth Falcon: documented targeting of people inside this country (forensic evidence)People's Republic of China — Axiom: documented targeting of people inside this country (assessed evidence)PROMETHIUM reached its own nationals in Belgium. Turkish citizens living in western Europe. Microsoft observed the operators spying on 'Turkish citizens living in Turkey and various other European countries'; the 2016 reporting oPROMETHIUM reached its own nationals in Italy. Turkish citizens living in western Europe, per the same Microsoft finding and the same 2016 victim geography.Turkey — PROMETHIUM: documented targeting of people inside this country (forensic evidence)Iran — Ferocious Kitten: documented targeting of people inside this country (assessed evidence)NEODYMIUM reached its own nationals in Belgium. Turkish citizens living in western Europe. Microsoft observed the operators spying on 'Turkish citizens living in Turkey and various other European countries'; the 2016 reporting oNEODYMIUM reached its own nationals in Italy. Turkish citizens living in western Europe, per the same Microsoft finding and the same 2016 victim geography.Turkey — NEODYMIUM: documented targeting of people inside this country (forensic evidence)Palestine — APT-C-23: documented targeting of people inside this country (assessed evidence)
Observed: last 90 days · Landmark: 2008–2026 3–456–89–1718+
Domestic surveillance

This map counts victims observed in our sources — leak-site claims, regulatory filings and press reporting — not all attacks everywhere. Countries with fewer than 3 observed victims are never shaded; they are listed on the shelf instead, so a single small business is not identified by its region. Country capture began recently, so the window is still filling: treat low counts as "not yet seen here", not "not happening here".

Actors attributed to this country 1+2+3+8+46+ criminal (jurisdiction, not sponsorship)

110 actors placed across 17 countries; 64 more have no defensible geography and are listed below rather than dropped. Tiers: 72 assessed · 25 attributed · 5 jurisdiction · 5 forensic · 2 contested · 1 unacknowledged.

Read this scale as a map of what has been published, not of what happens. Only 1 of 110 placed actors sit inside the Western alliance. That is not a finding about the world. Our strongest evidence is government advisories, indictments and sanctions — and no government attributes its own intelligence services. Stuxnet is the worked example: no state has ever claimed it, so it carries no solid mark here. The gap is disclosed rather than filled, because filling it would mean accepting evidence we reject for everyone else.

Landmark record, 2008–2026 hit in this record origin in this record not in it

This fill is presence, not volume. A country is coloured because it appears in the record at all — one event or twelve look identical. The pin on it carries the count, and the rail below lists every event with its date. 91 events across 32 countries hit and 13 named as origins.

A curation, not a census. “All attacks since 2010” is not a number anyone has, so a graduated scale here would claim a completeness we do not have — which is why the fill has exactly one step. 26 of these 91 events carry no origin at all: the incident is documented and the attribution is not, and those are shown rather than dropped.

All countries

1,505 incidents observed in the last 90 days · 839 placed in a country · 666 unplaced (44%)

77 countries with any observation · 45 shaded (≥3) · 9 client-grade · 590 claim-only

Industries hit

Manufacturing (general/industrial)113Professional and consulting services65Healthcare, hospitals, clinics63Software & AI product companies60Banking, lending, financial services45

Scenarios

Ransomware / extortion claim613Breach disclosure filing5Supply-chain compromise2Exploit campaign1Vulnerability management1

Select a country on the map for its detail.

Table view — every placed country, with counts
CountryObserved Client-gradeClaims Per millionShaded
United States of America33282521.01yes
Germany420260.51yes
United Kingdom371300.55yes
Canada240180.64yes
Italy230120.38yes
Argentina18090.40yes
Brazil180120.09yes
France180130.27yes
India180180.01yes
Spain17070.36yes
Turkey170130.20yes
Australia140120.55yes
Poland14070.37yes
Mexico13080.10yes
Switzerland110111.28yes
Japan10030.08yes
Czech Republic9030.84yes
Indonesia9060.03yes
Sweden9050.88yes
Taiwan9040.38yes
South Africa9030.15yes
People's Republic of China8050.01yes
Philippines8060.07yes
Portugal8040.78yes
Peru7060.22yes
Finland6051.09yes
HK6050.00yes
South Korea6060.12yes
Netherlands6030.35yes
Saudi Arabia6030.18yes
SG6050.00yes
Thailand6060.09yes
Belgium5050.44yes
Chile5050.26yes
Colombia5030.10yes
Hungary5020.51yes
Israel5040.55yes
Malaysia5030.16yes
Nigeria5040.02yes
Vietnam5030.05yes
Austria4040.45yes
Ireland4020.81yes
United Arab Emirates3020.31yes
Romania3020.15yes
Russia3020.02yes
Bulgaria2000.29no
Cyprus2021.67no
Denmark2010.34no
Egypt2010.02no
New Zealand2020.41no
Pakistan2020.01no
AD1000.00no
AI1010.00no
Angola1000.03no
Azerbaijan1010.10no
Bangladesh1000.01no
Ivory Coast1010.04no
Costa Rica1010.20no
Ecuador1010.06no
Gabon1000.46no
Ghana1000.03no
Greece1010.09no
Croatia1000.25no
Haiti1010.09no
Iraq1010.03no
Iceland1012.77no
Kenya1010.02no
Laos1010.14no
Lithuania1000.36no
Morocco1010.03no
Moldova1010.38no
North Macedonia1010.48no
Norway1000.19no
Papua New Guinea1000.11no
Tanzania1010.02no
Uruguay1000.29no
Yemen1000.03no

Landmark events (2008–2026)

Notable documented events, not a census. Selected for significance and public documentation; absence from this layer is not evidence of absence. Coverage is uneven by construction: no landmark event here targets Africa, which reflects what is documented in English-language sources, not where attacks happen.

  • 2026-02-05 Odido customer data breach — · origin not establishedNo origin. No government or vendor has named a responsible party, and this is the only 2026 event on the layer -- the year is thin here because attribution lags incidents by months, not because 2026 was quiet. → Netherlands Reported as the largest cybersecurity incident in Dutch history by volume of affected customers, at the former T-Mobile Netherlands business. Recorded with no origin: no government or vendor has named a responsible party. Industrial Cyber — H1 2026 incident reporting
  • 2026-02-01 Salt Typhoon compromise of Norwegian network devices — · CNPST's National Threat Assessment 2026 confirmed the Chinese state-sponsored group Salt Typhoon had compromised network devices at Norwegian organisations. A state body naming a state and a group, with no organ named. → Norway PST's National Threat Assessment 2026 confirmed that the Chinese state-sponsored group Salt Typhoon had compromised network devices at Norwegian organisations. PST described China's primary intelligence threat to Norway as sitting in the cyber domain. The Record - Norwegian intelligence discloses Salt Typhoon activity
  • 2025-10-15 F5 source code and vulnerability data theft — · origin not establishedNo origin, and this one is a deliberate refusal. F5 said only 'nation-state' and named no country; the China attribution comes from press reporting citing unnamed people. That is precisely the class of sourcing this map declined for Shamoon, and consistency costs us a mark we would probably like to have. → United States of America A nation-state actor held long-term persistent access to F5's product development environment and took BIG-IP source code plus details of undisclosed vulnerabilities. CISA issued an emergency directive to federal agencies. F5 itself named no country; press reporting pointed to China, which is not a basis this map treats as attribution. CISA emergency directive on F5 devices Unit 42 — nation-state actor steals F5 source code
  • 2025-08-31 Jaguar Land Rover production shutdown — · origin not established → United Kingdom JLR halted global production for weeks after shutting down its IT systems, idling plants and a supply chain of thousands of smaller firms; the UK government extended a loan guarantee to suppliers. Among the most economically damaging single attacks ever recorded against a British company. Jaguar Land Rover cyberattack — overview and economic impact
  • 2025-07-18 SharePoint ToolShell mass exploitation — · CNMicrosoft attributed the exploitation to Chinese state-linked actors in its own advisory. No organ named, so `assessed`. → United States of America (worldwide) Chained SharePoint zero-days exploited against on-premises servers worldwide, including US federal agencies. Microsoft attributed exploitation to Chinese state-linked actors and opened an investigation into whether details leaked through its own vulnerability disclosure programme. Microsoft — disrupting active exploitation of on-premises SharePoint vulnerabilities
  • 2025-06-17 Bank Sepah and Nobitex destruction during the Israel-Iran exchange — · ILSame persona and the same pattern as 2021, during an active military exchange between the two states. Widely assessed as Israel-linked and never acknowledged. Drawn dashed. → Iran Days after Israeli airstrikes, the persona Predatory Sparrow disabled the state-owned Bank Sepah and then drained roughly 90 million dollars from Iran's largest crypto exchange, sending the funds to unspendable addresses containing anti-regime slogans — destruction rather than theft. Widely assessed as Israel-linked; never acknowledged. CCDCOE cyber law toolkit — Predatory Sparrow operations against Iranian financial infrastructure (2025) TRM Labs — inside the Nobitex breach
  • 2025-04-22 Marks & Spencer and Co-op retail intrusions — · origin not establishedNo origin. The activity is associated with the Scattered Spider cluster, which sits on our unplaced shelf precisely because it has no defensible geography -- arrests have been made in the UK and the US and the membership is transnational and loose. → United Kingdom Social-engineering of IT help desks led to a shutdown of online ordering, empty shelves and months of disruption at several major UK retailers. M&S put the cost at around 300 million pounds and the Co-op at 206 million. The UK National Crime Agency arrested four people; the activity is associated with the Scattered Spider cluster, which has no defensible geography. Infosecurity — top cyber-attacks of 2025
  • 2025-04-07 Risevatnet dam floodgate manipulation, Bremanger — · RUPST chief Beate Gangas attributed the incident to pro-Russian cyber actors in August 2025, PST's first formal attribution of this type, and in October 2025 tied the same alliance to a second Norwegian intrusion with indications of links to Russian state actors. Attribution to ALIGNED actors rather than to the state, and the indications are explicitly hedged, so it is held at `assessed` exactly as NORWAY-PORTAL-2022 is. The group's own Telegram video is self-attribution and carries no weight here. → Norway Control of a fish-farm dam's industrial control system in western Norway; a floodgate was opened for roughly four hours at about 500 litres per second. PST chief Beate Gangas publicly attributed the incident to pro-Russian cyber actors in August 2025, its first formal attribution of this type, and in October 2025 tied the same alliance to a second Norwegian intrusion, noting indications of links to Russian state actors. Reuters - Norway spy chief blames pro-Russian hackers for dam sabotage
  • 2024-10-01 Salt Typhoon intrusion into US telecommunications carriers Salt Typhoon · CN → United States of America Long-running access to at least nine US carriers, reaching the systems used to service lawful intercept requests — meaning the attackers could see who US law enforcement was surveilling. Call metadata and some intercepted content were exposed. CISA and the FBI confirmed the campaign; the US later sanctioned a contractor tied to it. CISA and partners — joint statement on PRC targeting of commercial telecommunications Congressional Research Service — Salt Typhoon hacks of telecommunications companies
  • 2024-08-01 CNCERT report of US intelligence theft from a Chinese materials firm — · USA Chinese state body attributing to the United States with no organ named — CNCERT says 'a US intelligence agency' and does not identify which. That is `assessed` by the same rule that puts a US advisory saying 'Russian state-sponsored actors' at `assessed` rather than `attributed`. The tier is set by what the claim specifies, never by who is making it. → People's Republic of China China's national CERT reported a further theft of trade secrets from an unnamed Chinese advanced-materials company, again attributed to unspecified US intelligence agencies. CNCERT public reporting (2024), via the EuRepoC incident record
  • 2024-06-03 Synnovis pathology ransomware and London hospital disruption — · RUQilin is a Russian-speaking ransomware operation and is consistently reported as Russia-based. Hatched, not solid, and deliberately so: this is the event on the layer with the clearest human cost, and overstating who was behind it would be the worst place to do it. → United Kingdom Qilin ransomware against the pathology provider for several London NHS trusts. Blood testing collapsed, over 800 operations and 700 outpatient appointments were cancelled, and a national appeal for O-type blood followed. An NHS trust later confirmed the disruption was a contributing factor in a patient's death — the clearest documented case of a ransomware attack contributing to loss of life. Synnovis incident notifications and NHS England response The Register — NHS supplier ends probe into ransomware attack that contributed to patient death
  • 2024-04-14 Snowflake customer-tenant credential campaign — · origin not establishedNo origin. Two suspects were arrested, in Canada and Turkey, and hazard 5 is explicit that a defendant's location is not the group's geography. → United States of America (worldwide) Roughly 165 customer environments accessed using credentials harvested by infostealers, against tenants without multi-factor authentication. AT&T lost call and text metadata for about 110 million customers. Not a breach of Snowflake itself, which is why the mark is not placed on the vendor. Two suspects were arrested, in Canada and Turkey. Mandiant — UNC5537 targeting Snowflake customer instances
  • 2024-02-21 NoviSpy and Cellebrite against Serbian journalists and activists — · RSThe strongest operator linkage anywhere in this category: forensics show NoviSpy was installed while the phone was physically in police custody, during a detention on a pretextual sobriety check, with no passcode ever supplied. Most domestic cases infer the operator from tooling and targeting; this one places the device in the operator's hands. First European domestic-surveillance mark on the layer. → Serbia Amnesty's Security Lab documented Serbian authorities using Cellebrite UFED to unlock phones during police stops and then installing NoviSpy, a previously unknown locally developed implant. Journalist Slaviša Milanov was detained on a pretextual sobriety check; forensics show the spyware was installed while his phone was in police possession, and he never supplied a passcode. Cellebrite subsequently suspended Serbia as a customer. Amnesty Security Lab — A Digital Prison: surveillance and the suppression of civil society in Serbia Amnesty International — Serbia: authorities using spyware and Cellebrite forensic tools
  • 2024-02-21 Change Healthcare ransomware (ALPHV/BlackCat) MISP-e6c09b63 · origin not established → United States of America ALPHV/BlackCat-attributed ransomware against UnitedHealth-owned Change Healthcare, the largest US healthcare-claims clearinghouse. Caused weeks of pharmacy + provider payment outages affecting ~1/3 of US patients. UnitedHealth confirmed $872M Q1-2024 cost. Triggered AHA congressional testimony + HHS public emergency. UnitedHealth Q1-2024 8-K filing CISA / HHS joint advisory March 2024
  • 2024-02-08 Ukrainian military intelligence operations against Russian state systems — · UAUkraine's Main Directorate of Intelligence announced these operations itself. A state claiming its OWN offensive activity removes the attribution problem rather than solving it, and it is the only self-claimed state operation on the layer. Note the asymmetry it exposes: we accept this because the claimant is the operator, not because the claim is independently verified. → Russia Ukraine's Main Directorate of Intelligence publicly claimed a series of intrusions into Russian defence systems, including the Ministry of Defence and a drone control programme. Notable on this map as one of very few cases where a state announces its own offensive operations rather than being accused of them, which removes the attribution problem entirely. Ukrainian Main Directorate of Intelligence (GUR) public statements, 2024
  • 2024-02-07 Volt Typhoon US critical-infrastructure pre-positioning Volt Typhoon · CN → United States of America PRC PLA-attributed living-off-the-land intrusion into US critical infrastructure (water utilities, energy sector, transportation, ports, comms). CISA AA24-038A: pre-positioning for "disruptive or destructive cyberattacks against US critical infrastructure in the event of a major crisis or conflict". First time CISA formally framed pre-positioning as strategic-level threat. CISA advisory CISA advisory CISA AA24-038A
  • 2024-01-12 Midnight Blizzard access to Microsoft corporate email APT29 · RU → United States of America A password-spray against a legacy non-production tenant led to access to the mailboxes of Microsoft's senior leadership, cybersecurity and legal staff, and later to some source-code repositories. Microsoft named the actor as the Russian state group Midnight Blizzard, the same SVR-linked operator behind SolarWinds. Microsoft — actions following attack by nation state actor Midnight Blizzard
  • 2023-12-12 Kyivstar telecom outage (Solntsepyok / Sandworm front) Sandworm Team · RU → Ukraine Largest Ukrainian mobile operator (~24M subscribers) knocked offline for days. Sandworm front "Solntsepyok" claimed the attack. Disrupted air-raid alerts in some regions during active Russian missile strikes — first public cyber operation against civilian wartime communications at this scale. Reuters: Sandworm hackers caused Kyivstar outage
  • 2023-11-25 CyberAv3ngers against US water utility control systems — · IRCISA and partners issued a joint advisory and the US Treasury sanctioned six named officials of the IRGC Cyber-Electronic Command — a named organ, which clears `attributed`. → United States of America Internet-exposed Unitronics programmable logic controllers at a Pennsylvania water authority were defaced and taken offline by a group calling itself CyberAv3ngers, forcing manual operation. CISA issued an advisory and the US Treasury sanctioned six officials of Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command over the campaign. A small utility, which is the point. CISA advisory — IRGC-affiliated cyber actors exploiting PLCs US Treasury sanctions on IRGC-CEC officials over the water-sector attacks
  • 2023-11-08 LockBit ransomware against ICBC Financial Services — · RULockBit is a Russia-based criminal operation, later disrupted by an international law-enforcement action and subject to US, UK and Australian sanctions on named individuals. Hatched, not solid: this establishes where the crew operates, not that a state directed it. → People's Republic of China The US arm of the world's largest bank by assets was disrupted badly enough that it had to settle Treasury trades by sending settlement details on a USB stick carried by courier. Rare and valuable here as a case with a Chinese victim organisation, a category our Anglophone sourcing almost never surfaces. US Treasury and press reporting on the ICBC Financial Services ransomware incident
  • 2023-10-20 CyberLink software supply chain compromise — · KPMicrosoft Threat Intelligence attributed the compromise to a North Korean actor it tracks as Diamond Sleet. Vendor attribution, no organ named. → Taiwan (worldwide) A trojanised installer from a Taiwanese multimedia software vendor was signed with the company's own valid certificate and distributed to downstream users. Microsoft attributed it to a North Korean actor. Taiwan appears here as the compromised vendor, not the intended victim. Microsoft Threat Intelligence — Diamond Sleet supply chain compromise of CyberLink
  • 2023-08-25 Polish railway emergency-stop radio interference — · origin not establishedNo origin recorded. The broadcast Russian anthem and Putin speech are a signature the perpetrators chose to leave, which is a reason for suspicion and not evidence -- a signature is the easiest thing in the world to fake. Polish authorities detained two suspects and no state attribution followed. → Poland Around twenty trains were halted in north-west Poland by transmission of the unencrypted radio-stop signal, interspersed with the Russian national anthem and a recording of a Putin speech. Technically trivial — the protocol has no authentication — which is precisely why it is worth recording. Polish authorities detained two suspects; no state attribution was made. INCIBE-CERT — cyber-attack on the railway network in Poland
  • 2023-06-05 Anonymous Sudan denial-of-service campaign and US indictment — · SDTwo Sudanese nationals were indicted by the US District Court for the Central District of California and the infrastructure was seized. Unusually, the self-presented identity and the charged identity matched — which is worth recording precisely because TV5Monde and Olympic Destroyer on this same layer show how often they do not. → United States of America, United Kingdom (worldwide) A prolific denial-of-service operation that took Microsoft 365 and other major services offline while presenting itself as Sudanese hacktivism. In 2024 the US District Court for the Central District of California indicted two Sudanese nationals and the operation's infrastructure was seized. Included because the self-presented identity and the charged identity actually matched here, which is unusual. US DOJ — indictment of Anonymous Sudan operators (2024)
  • 2023-05-31 MOVEit Transfer mass-exploitation (Cl0p) MISP-21b349c3 · origin not established → multiple countries (worldwide) Cl0p exploited a zero-day SQL injection in Progress Software's MOVEit Transfer to exfiltrate data from ~2,700 organisations including US OPM, US DOE, state governments, BBC, BA, Shell. Largest mass-exploitation campaign of 2023. CISA advisory CISA AA23-158A Mandiant MOVEit timeline + attribution
  • 2023-05-15 Storm-0558 forged-token access to government email — · CNMicrosoft identified Storm-0558 as a China-based actor and the US Cyber Safety Review Board's report treats the PRC nexus as established. No organ is named by either, so this stays `assessed`. → United States of America A stolen Microsoft signing key was used to forge authentication tokens and read email at around 25 organisations, including the accounts of the US Commerce Secretary and State Department officials. The US Cyber Safety Review Board later called the intrusion preventable and faulted Microsoft's security culture. Microsoft — analysis of Storm-0558 techniques for unauthorized email access US Cyber Safety Review Board report on the Microsoft Exchange Online intrusion
  • 2023-05-11 Coordinated intrusion into 22 Danish energy operators Sandworm Team · RU → Denmark Attackers exploited Zyxel firewall flaws at 16 companies simultaneously, then a second wave followed. SektorCERT called it the largest cyber incident in Danish history and reported evidence connecting part of the activity to Russia's GRU. Several operators disconnected from the grid and ran in island mode. SektorCERT report on the attack against Danish critical infrastructure (2023) The Record — nearly two dozen Danish energy companies hacked
  • 2023-05-01 CNCERT report of US intelligence theft from a Chinese technology firm — · USA state body attributing to a state, with NO organ named — CNCERT says 'US intelligence agencies' rather than a specific unit. That is the definition of `assessed` and it is the same treatment a US advisory saying 'Russian state-sponsored actors' would get. → People's Republic of China China's national CERT reported that US intelligence agencies had taken trade secrets from a major Chinese high-technology company. The victim is deliberately not named in the report. No US organ is identified, which is why this sits a tier below the Northwestern Polytechnical case. CNCERT public reporting (2023), via the EuRepoC incident record
  • 2023-03-29 3CX desktop-app supply chain compromise Lazarus Group · KP → multiple countries (worldwide) DPRK-attributed double-supply-chain attack: trojanised 3CX desktop installer (distributed to ~600k orgs) traced back to an earlier compromise of Trading Technologies (X_TRADER software). First publicly-confirmed cascading-supply-chain compromise. Mandiant 3CX investigation CrowdStrike 3CX advisory
  • 2022-10-12 Medibank Private health data theft and extortion — · RUAustralia named Aleksandr Ermakov under its cyber sanctions powers -- the first use of them -- and later sanctioned the ZServers hosting operation and five more Russian nationals. Held at `jurisdiction` rather than promoted: sanctioning named individuals establishes where they are, not that a state directed them, and hazard 5 says a defendant's nationality is not the group's sponsorship. → Australia The health records of roughly 9.7 million current and former customers were stolen and, when Medibank refused to pay, published — including data on terminations of pregnancy and addiction treatment. Australia used its cyber sanctions powers for the first time, naming Aleksandr Ermakov, and later sanctioned the ZServers hosting operation and five more Russian nationals. Australian Cyber Security Centre — cyber sanction for the Medibank compromise Australian Government — further cyber sanctions in response to the Medibank attack
  • 2022-09-05 NSA TAO intrusion into Northwestern Polytechnical University — · USCVERC is a Chinese state body and it names a specific foreign intelligence organ — the NSA's Tailored Access Operations unit — with published methodology (forty-plus malware families, four cover-purchased IP addresses, the anonymisation chain) and a named victim that corroborated the intrusion independently. Evaluated against the same three questions we ask of a CISA advisory naming FSB Centre 18, it clears, so it is placed at the same tier. This is the FIRST `attributed` US origin on the layer; the only other US mark is Stuxnet at `unacknowledged`. → People's Republic of China China's National Computer Virus Emergency Response Center, with Qihoo 360, reported that the NSA's Tailored Access Operations unit had held access to Northwestern Polytechnical University since 2020, deploying more than forty bespoke malware families and taking around 140 gigabytes of data. The university itself disclosed the intrusion in June 2022, naming phishing of staff and students as the initial vector. The report identifies four IP addresses said to have been bought through cover entities and describes the anonymisation of domains and certificates. CVERC and Qihoo 360 report on the attack against Northwestern Polytechnical University (2022) SecurityWeek — how China pinned university cyberattacks on NSA hackers
  • 2022-07-15 Destructive attacks on the Government of Albania (HomeLand Justice) — · IRThe strongest attribution in this batch. CISA and the FBI published a joint advisory naming Iranian state actors, the US Treasury sanctioned Iran's Ministry of Intelligence and Security -- a NAMED organ, which is what `attributed` requires -- and Albania severed diplomatic relations, the first time any state has done so over a cyberattack. → Albania Wiper attacks took down Albanian government websites and services, followed by a second wave in September. Albania severed diplomatic relations with Iran and expelled its embassy staff — the first time a state has broken off relations over a cyberattack. CISA and the FBI published a joint advisory and the US Treasury sanctioned Iran's Ministry of Intelligence and Security. CISA AA22-264A — Iranian state actors conduct cyber operations against the Government of Albania CCDCOE cyber law toolkit — HomeLand Justice operations against Albania (2022)
  • 2022-06-29 Denial-of-service against Norwegian state digital services — · RUNorway's National Security Authority attributed the campaign to a pro-Russian group. As with Estonia the same year, this is an attribution to aligned actors rather than to the state itself, and it is held at `assessed` for that reason. → Norway Norway's National Security Authority attributed a denial-of-service campaign against the national public service portal and other institutions to a pro-Russian group, following a labour dispute over Arctic transit. The second Norwegian entry on this layer, after the 2020 Storting compromise. Norwegian National Security Authority (NSM) statement on the June 2022 DDoS campaign
  • 2022-06-07 Denial-of-service campaign against Estonian state and financial services — · RUEstonian officials attributed the campaign to pro-Russian actors following the Narva monument removal. Held at `assessed`: the attribution is to actors aligned with a state rather than to the state, which is a weaker claim and is recorded as one. → Estonia A sustained denial-of-service campaign against Estonian institutions following the removal of a Soviet war monument in Narva, described by Estonian officials as the most extensive against the country since 2007. Estonia is where state-scale denial of service was first taken seriously, which makes its return worth marking. Estonian government statements and Avast analysis of the 2022 DDoS campaign
  • 2022-06-01 Intrusion into Uzbekistan's state hydropower operator — · KZCisco Talos attributed the campaign to a Kazakhstan-linked actor. A vendor technical report with no organ named, so `assessed`. Recorded partly because a Central Asian state targeting a neighbour is a relationship this map would otherwise never show at all. → Uzbekistan Cisco Talos documented a campaign against Uzbekistan's state hydroelectric company. Recorded largely because Central Asia is otherwise entirely absent from this map, and absence from a map reads as safety rather than as a gap in reporting. Cisco Talos Intelligence — campaign against Central Asian energy targets
  • 2022-04-17 Costa Rica government ransomware and national emergency Wizard Spider · RU → Costa Rica Conti ransomware crippled tax collection and customs processing and spread across 27 institutions. President Rodrigo Chaves declared a national state of emergency — the first time any country had done so over a ransomware attack. The United States later committed 25 million dollars toward recovery. CCDCOE cyber law toolkit — Costa Rica ransomware attack (2022) The Record — US commits $25 million to Costa Rica for recovery
  • 2022-03-23 Ronin Bridge cryptocurrency theft Lazarus Group · KP → Vietnam Around 625 million dollars in cryptocurrency taken by compromising validator keys — at the time the largest such theft on record. The US Treasury added the wallet address to its Lazarus Group designation, making this a formally sanctioned North Korean operation. The victim, Sky Mavis, is Vietnamese, which is why the mark sits on Vietnam rather than on the crypto ecosystem generally. US Treasury sanctions update tying the Ronin theft to Lazarus Group Elliptic — Lazarus Group identified behind the Ronin bridge heist
  • 2022-02-24 Viasat KA-SAT satellite modem wiper (AcidRain) Sandworm Team · RU → Ukraine, Germany (worldwide) Launched one hour before the invasion of Ukraine, the AcidRain wiper bricked tens of thousands of satellite modems, cutting Ukrainian command communications and simultaneously knocking out remote monitoring for thousands of German wind turbines. The EU and its member states formally condemned it as Russian state activity — one of the clearest cases of civilian spillover from a military cyber operation. Council of the EU — declaration attributing the KA-SAT attack to Russia CCDCOE cyber law toolkit — Viasat KA-SAT attack (2022)
  • 2021-11-01 Campaign against Pakistan's Ministry of Defence — · INVendor research attributes the campaigns to India-aligned actors, with no organ named. Recorded because Pakistan appears on this map almost only as an origin, and a map that shows a state attacking but never being attacked is telling half a story. → Pakistan Malwarebytes and later Zscaler documented campaigns against Pakistani defence and energy-regulatory bodies attributed to India-aligned actors. Pakistan appears on this map almost exclusively as an origin; recording it as a victim is part of not letting the map imply a one-way relationship. Malwarebytes Labs analysis of APT36-adjacent campaigns against Pakistani government targets
  • 2021-10-26 Iran national fuel distribution disruption — · ILIran blamed Israel and the United States and the Predatory Sparrow persona claimed responsibility. A claim by an anonymous persona is not attribution, and a victim state naming its adversary is a claim we record rather than adopt -- but the two together, plus the pattern across 2020-2025, put this at `unacknowledged` rather than nowhere. Drawn dashed. → Iran The subsidised-fuel card system used at filling stations nationwide was disabled, leaving drivers unable to buy petrol and prompting queues across the country. Iran blamed Israel and the United States; the persona Predatory Sparrow claimed responsibility. No state has acknowledged it. 2021 Iranian fuel cyberattack — overview
  • 2021-08-01 Compromise of New Zealand's Parliamentary Service — · CNNew Zealand's GCSB publicly attributed the activity to a Chinese state-sponsored actor and the government made a formal démarche. A state body naming a state with no organ named. → New Zealand New Zealand's Government Communications Security Bureau publicly attributed intrusions into parliamentary bodies to a Chinese state-sponsored group, and the government made a formal démarche to Beijing. A small state naming a major power directly, which is rarer than it should be. New Zealand GCSB statement on malicious cyber activity attributed to PRC state-sponsored actors
  • 2021-07-02 Kaseya VSA mass ransomware (REvil) MISP-24bd9a4b · origin not established → United States of America (worldwide) REvil exploited a zero-day in Kaseya VSA RMM software to push ransomware to ~1,500 downstream MSP customers — among them Coop (Sweden) which closed ~800 grocery stores for days. The July 4 timing maximised disruption. CISA advisory CISA AA21-209A
  • 2021-06-15 Pegasus against Thailand's pro-democracy movement — · THA state against its own citizens, so origin and target are the same country and no arc is drawn. Clears the three domestic criteria: Pegasus infections confirmed forensically on named devices, corroborated across Citizen Lab, iLaw, DigitalReach and Amnesty, and operator linkage that does not rest on the victims' own inference — Pegasus is sold government-exclusively and the targeting tracks the protest calendar. Same structure as the Mansoor case in the UAE. → Thailand Citizen Lab, with iLaw and DigitalReach, confirmed Pegasus infections on the phones of at least 30 Thai activists, academics, lawyers and NGO staff between October 2020 and November 2021, coinciding with mass pro-democracy protests. Protest leader Panusaya Sithijirawattanakul was infected repeatedly in June and again in September 2021. The investigation began with Apple's threat notifications to Thai civil society. Citizen Lab — GeckoSpy: Pegasus spyware used against Thailand's pro-democracy movement Amnesty International — Pegasus found on phones of Thai dissidents
  • 2021-05-30 JBS meat processing ransomware shutdown — · RUThe FBI publicly named REvil, a Russian-speaking criminal group operating from Russia. Hatched, not solid: a crew's country is where it is tolerated rather than who directs it, and nothing here claims state direction. → United States of America, Canada, Australia (worldwide) Slaughterhouses halted across the United States, Canada and Australia; JBS paid an 11 million dollar ransom. The FBI publicly identified REvil as responsible. A food-supply disruption rather than a data breach, which is why it is worth a mark. FBI statement attributing the JBS attack to REvil (2021)
  • 2021-05-14 Irish Health Service Executive ransomware shutdown Wizard Spider · RU → Ireland Conti ransomware forced the HSE to shut down every national IT system, cancelling appointments and reverting hospitals to paper for months. Ireland refused to pay. Recovery was estimated at over EUR 100 million and the HSE later offered compensation to affected patients. HSE — cyber attack and response CCDCOE cyber law toolkit — Ireland HSE ransomware attack (2021)
  • 2021-05-07 Colonial Pipeline ransomware shutdown MISP-f514a46e · origin not established → United States of America DarkSide ransomware caused 6-day shutdown of the US East Coast's largest fuel pipeline (~45% of East Coast supply). Triggered panic-buying + ~10,000 gas stations dry. Colonial paid $4.4M ransom; ~$2.3M recovered by DOJ. President Biden's response set precedent for treating ransomware as a national-security issue. FBI public attribution May 2021
  • 2021-03-10 Stortinget Microsoft Exchange Server compromise — · CNThe foreign minister said the attack was carried out FROM China and Norway joined the July 2021 coordinated attribution. PST has linked RELATED activity to APT31 and Hafnium, but related activity does not transfer to this incident, so no organ is named for this one. A state body naming a state, which is `assessed` on the New Zealand precedent. → Norway Data extracted from Stortinget systems during the global exploitation of on-premises Exchange. Norway joined the coordinated international attribution in July 2021; the foreign minister stated the attack was carried out from China. Reuters - Norway says attack on parliament carried out from China
  • 2021-03-02 Microsoft Exchange Server mass exploitation (HAFNIUM) HAFNIUM · CN → United States of America (worldwide) Four Exchange zero-days exploited at scale, with web shells left on tens of thousands of servers. In July 2021 the United States, the EU, the UK and NATO jointly attributed the campaign to actors affiliated with China's Ministry of State Security — a rare multi-government attribution naming an intelligence organ. Microsoft — HAFNIUM targeting Exchange Servers with 0-day exploits US and allied joint attribution to China's MSS (July 2021)
  • 2021-02-01 Watering-hole campaign against Hong Kong universities — · CNESET attributed the operation to a China-aligned actor. Hong Kong is recorded as the target separately from mainland China: the victims were reached through Hong Kong institutions, and collapsing the two would erase exactly the distinction the campaign was exploiting. → HK — not drawn on the map above; the geometry has no separate shape for it ESET documented a watering-hole operation on Hong Kong university websites delivering macOS implants to visitors, during the period of the national security law's introduction. Targets a population rather than an institution, which is the shape most of this map cannot draw. ESET Research — watering-hole campaign targeting Hong Kong users
  • 2020-12-13 SolarWinds Orion supply chain compromise APT29 · RU → United States of America Trojanised SolarWinds Orion software update distributed to ~18,000 organisations; ~100 received follow-on intrusions. The most consequential US-government cyber espionage incident of the decade. Triggered the May 2021 Cybersecurity EO 14028. CISA advisory CISA AA20-352A Microsoft Solorigate technical analysis (Dec 2020)
  • 2020-09-01 Dutch police infiltration of the Exclu encrypted phone network — · NLDutch police, acting under judicial authorisation, and publicly documented by them. Origin equals target because the state intruded into a network on its own territory. Included so the map does not imply that only adversaries conduct network intrusion. → Netherlands Dutch and Belgian police read Exclu traffic for five months before dismantling the network, arresting dozens and uncovering a drug lab and torture chambers. Included because law enforcement conducting network intrusion is a real category the map otherwise never shows, and because the operator and the attributing body are the same state. Dutch National Police (Politie) — Exclu investigation
  • 2020-08-24 Norwegian Parliament (Storting) email compromise APT28 · RU → Norway Email accounts of Norwegian MPs and staff were accessed. Norway's PST publicly assessed that actors linked to Russian military intelligence were likely responsible, and the Foreign Minister attributed it to Russia — a NATO member state naming Russia over an attack on its own legislature. Norwegian PST assessment and Foreign Ministry attribution (2020)
  • 2020-05-09 Shahid Rajaee port traffic disruption — · ILUS and foreign officials linked the disruption to Israel in contemporaneous reporting, and it is universally read as a response to the water-facility attempt days earlier, but Israel has never claimed it and no state has confirmed it. This is the second `unacknowledged` origin on the layer after Stuxnet, and it matters that both point at the same alliance -- the tier exists so those operations are visible rather than absent. → Iran Computers regulating maritime traffic at Iran's largest container port were disrupted, creating a days-long backlog of ships and road congestion. Reported by US and foreign officials as an Israeli operation, widely read as a response to the water-facility attempt days earlier. Israel has never claimed it. Washington Post — officials link Israel to disruptive attack on Iranian port
  • 2020-04-24 Attempted manipulation of Israeli water treatment controls — · IRIsraeli government officials publicly attributed the attempt to Iran. A state body naming a state, with no organ named, which is what the `assessed` tier is for. Recorded as attempted rather than successful manipulation, per Israel's own account. → Israel Attempts to alter chlorine levels at water treatment facilities. Israel's National Cyber Directorate issued sector-wide instructions to change control-system passwords, and Israeli officials attributed the attempt to Iran. Recorded as an attempted manipulation of a safety-critical process, which is the category the map otherwise never shows. Israel National Cyber Directorate advisory and subsequent official attribution (2020)
  • 2020-01-13 Burisma Holdings phishing campaign Sandworm Team · RU → Ukraine Credential-phishing against a Ukrainian energy company, using a redirect infrastructure attributed to the GRU. Area 1 Security — Phishing Burisma Holdings
  • 2019-03-19 Norsk Hydro LockerGoga ransomware — · origin not establishedNo origin. Dragos states plainly that there is insufficient data to place this as state-sponsored rather than criminal, and no attribution followed. → Norway Aluminium smelting and extrusion plants worldwide were forced to manual operation at a cost of around 70 million dollars. Norsk Hydro refused to pay and published daily updates including webcast briefings while still in the middle of the incident — the transparency benchmark other victims are still measured against. Microsoft — how Norsk Hydro responded to ransomware with transparency
  • 2018-11-30 Marriott / Starwood guest reservation breach — · CNUS officials linked the intrusion to China's Ministry of State Security in press briefings, and the pattern matches OPM and Anthem. But the linkage reached the public through unnamed officials rather than an indictment or sanction, and the investigation was never publicly concluded — so `assessed`, and MSS is not carried as a named organ. → United States of America (worldwide) Around 500 million guest records taken, including passport numbers, from a Starwood reservation system that had been compromised since 2014 — before Marriott acquired it, making this a due-diligence failure as much as a security one. US officials linked the intrusion to China's Ministry of State Security as part of a wider collection pattern alongside OPM and Anthem. NPR — Chinese hackers likely responsible for the Marriott data breach
  • 2018-08-01 Norwegian county governor offices and Visma intrusion — · CNPST attributed the operations to APT31, a China-linked group tied to Chinese intelligence. A state intelligence service naming a specific actor is stronger than a bare country claim, but APT31 is a threat-actor designation rather than a government body, so this stops short of the named organ `attributed` requires. → Norway Administrator access to shared systems used by Norway's county governor offices, with credential theft, alongside an intrusion at software supplier Visma. PST attributed the operations to APT31, a China-linked group tied to Chinese intelligence. The Record - APT31 behind 2018 Norwegian government hack
  • 2018-06-11 Banco de Chile destructive attack and SWIFT theft — · origin not established → Chile A wiper disabled thousands of workstations as cover for a SWIFT fraud that moved around 10 million dollars to Hong Kong. The destruction was a distraction rather than the objective, a pattern seen again in later financial-sector intrusions. First South American financial landmark on this layer. Banco de Chile disclosure and subsequent SWIFT-related reporting (2018)
  • 2018-02-09 Olympic Destroyer at the Pyeongchang Winter Olympics Sandworm Team · RU → South Korea Wiper malware took down the opening ceremony's IT systems, ticketing and Wi-Fi. It was deliberately salted with forensic artefacts imitating North Korean and Chinese tooling, and much of the industry initially attributed it accordingly. The DOJ later indicted GRU officers. The best-documented case of an attacker engineering a false attribution rather than merely hiding. US DOJ — six GRU officers charged over destructive malware including Olympic Destroyer
  • 2017-08-04 Triton attack on a Saudi petrochemical safety system — · RUThe US Treasury sanctioned TsNIIKhM, a Russian state research institute, by name for developing the malware, along with its director, deputy director and the researcher accused of writing it. A named state institution, which clears `attributed`. → Saudi Arabia Malware written to manipulate Triconex safety instrumented systems — the last-resort controls that shut a plant down before it explodes. The plant tripped safely and the attack was found only because the attackers made a mistake. The first known malware built to disable a safety system, and the closest a cyber operation has come to killing people. US Treasury — sanctions against TsNIIKhM over the Triton malware CyberScoop — Treasury sanctions Russian research center blamed for Trisis
  • 2017-06-27 NotPetya destructive wiper Sandworm Team · RU → Ukraine, Denmark, United States of America, United Kingdom, France (worldwide) GRU Unit 74455 (Sandworm) trojanised a Ukrainian tax-software update (M.E.Doc) to seed a destructive wiper masquerading as ransomware. ~$10B in global damages; Merck alone reported $870M loss. Insurance carriers cited "act of war" exclusions — precedent-setting Mondelez and Merck cases followed. CISA / US-CERT NotPetya advisory US DOJ Sandworm indictment (Oct 2020)
  • 2017-05-13 Equifax breach (PLA officers indicted) — · origin not established → United States of America Apache Struts flaw exploited; names, birth dates and social security numbers for 145 million Americans taken. In 2020 the DOJ indicted four members of China's People's Liberation Army for the intrusion. DOJ — Chinese Military Personnel Charged with Hacking Equifax Skybox — Another Lesson in Vulnerability Management: the Equifax Breach
  • 2017-05-12 WannaCry global ransomware outbreak Lazarus Group · KP → United Kingdom (worldwide) Worm-propagating ransomware leveraging the leaked NSA EternalBlue exploit; ~230,000 systems in 150 countries hit in 48 hours. UK NHS hospitals diverted ambulances and cancelled ~19,000 appointments. US, UK, Australia jointly attributed to DPRK 2017. US DOJ Park Jin Hyok indictment (2018)
  • 2016-12-17 Industroyer attack on the Kyiv transmission substation Sandworm Team · RU → Ukraine A framework built to speak grid protocols natively cut power to part of Kyiv — the first malware designed from the ground up to manipulate electricity transmission, as opposed to the manual operator hijack used against Ukraine a year earlier. Its successor was deployed again in 2022. ESET — Industroyer, the biggest threat to industrial control systems since Stuxnet
  • 2016-06-14 GRU operation against the DNC and the 2016 US election APT28 · RU → United States of America Material stolen from Democratic Party organisations was published through DCLeaks, Guccifer 2.0 and WikiLeaks during a presidential campaign. The DOJ indicted twelve GRU officers of Units 26165 and 74455 by name — the most detailed public attribution of a state cyber operation ever filed, down to individual search queries typed by the operators. US DOJ — indictment of 12 Russian GRU officers (US v. Netyksho et al.)
  • 2016-02-05 Bangladesh Bank SWIFT heist APT38 · KP → Bangladesh DPRK-attributed theft of $81M from Bangladesh Bank's Federal Reserve Bank of New York account via fraudulent SWIFT messages. A typo ("fandation" instead of "foundation") stopped a further ~$870M transfer. The recovered funds remain partially frozen with the Philippines authorities a decade later. US DOJ Park Jin Hyok indictment (2018) BAE Systems forensic report
  • 2015-12-23 Ukrainian power-grid attacks (Sandworm) Sandworm Team · RU → Ukraine First publicly-confirmed cyberattack causing electrical blackout (Dec 2015: ~225k customers without power for hours in Ivano- Frankivsk oblast). Repeated December 2016 with the more advanced Industroyer/CrashOverride malware against Ukrenergo's 330kV Pivnichna substation in Kyiv. Industroyer2 deployed April 2022. Dragos / SANS ICS analysis 2016
  • 2015-10-21 TalkTalk customer-data breach and ransom demand — · origin not established → United Kingdom SQL-injection against a UK telecom; roughly 157,000 customers' data taken, a ransom note sent, and a record ICO fine followed. RT UK — TalkTalk CEO receives ransom note
  • 2015-10-02 Scottrade brokerage breach — · origin not established → United States of America Contact details for about 4.6 million clients taken; disclosed after federal law-enforcement notification. Scottrade cyber security update (customer notice)
  • 2015-10-01 Patreon crowdfunding platform breach — · origin not established → United States of America Source code and user data taken via a debug server exposed to the internet, then published. Security Affairs — Patreon hacked and data leaked online
  • 2015-10-01 Experian breach exposing T-Mobile applicants — · origin not established → United States of America Records of roughly 15 million T-Mobile credit applicants taken from an Experian server. Experian — Unauthorized Acquisition of Personal Information
  • 2015-06-04 US Office of Personnel Management breach Deep Panda · CN → United States of America PRC-attributed theft of ~21.5M security-clearance background investigation records (SF-86 forms) covering current and former US federal employees, contractors, and family members, plus 5.6M fingerprints. Considered the most-damaging US counter-intelligence loss in cyber history. OPM public statement July 2015
  • 2015-05-08 German Bundestag network compromise APT28 · RU → Germany The entire parliamentary network was compromised and had to be rebuilt, with data taken from MPs including the Chancellor's constituency office. German federal prosecutors later issued an arrest warrant for a named GRU officer and the EU sanctioned him — a rare case of a European state pursuing an individual military intelligence officer by name. EU Council — sanctions over the cyber-attack against the German Federal Parliament
  • 2015-04-08 TV5Monde broadcast blackout APT28 · RU → France Eleven television channels were taken off air and the broadcaster's systems destroyed, with the attackers posing as the ‘Cyber Caliphate’ and posting Islamic State imagery. Investigators subsequently attributed it to APT28. The clearest false flag on this map: the visible claim of responsibility pointed at an entirely different actor, which is why a claim is never treated here as attribution. TV5Monde cyberattack — investigation and APT28 attribution
  • 2015-02-04 Anthem health-insurance breach Deep Panda · CN → United States of America PRC-attributed exfiltration of ~78.8M Anthem health-insurance member records including names, dates of birth, SSNs, addresses, employment and income data. Same cohort behind OPM 2015. Settled 2018 with $115M class-action — then the largest data-breach settlement in US history. ThreatConnect Anthem analysis Symantec Black Vine report
  • 2014-12-17 German steel mill blast-furnace damage — · origin not established → Germany Spear-phishing into the office network pivoted to plant control; a blast furnace could not be shut down properly, causing massive physical damage. Reported by Germany's BSI, which deliberately did not name the operator. SANS ICS — German Steel Mill Cyber Attack (Lee/Assante/Conway)
  • 2014-11-24 Sony Pictures Entertainment hack Lazarus Group · KP → United States of America DPRK-attributed retaliation against Sony's planned release of "The Interview". Combined data exfiltration + destructive wiper; ~100TB of email and unreleased films leaked. President Obama attributed publicly Dec 2014; first overt US-DPRK cyber attribution. FBI public attribution statement (2014)
  • 2014-09-08 Home Depot payment card breach — · origin not establishedNo origin, for the same reason as Target: the card-shop operator is not the intruder. → United States of America 56 million payment cards taken over five months using custom point-of-sale malware, entering through a third-party vendor's credentials — the same pattern as Target the year before, which is the uncomfortable part. Home Depot later paid 17.5 million dollars to settle with 46 states. Home Depot — findings of the payment data breach investigation CyberScoop — Home Depot to pay states $17.5 million
  • 2014-08-27 JPMorgan Chase data breach — · origin not established → United States of America Contact data for 76 million households and 7 million small businesses exposed. DataBreachToday — Chase breach: who else was attacked
  • 2014-05-19 Indictment of five PLA Unit 61398 officers — · CNThe strongest attribution on the entire layer. The US Department of Justice charged five named officers of PLA Unit 61398 — a NAMED military organ, with photographs — which is exactly what `attributed` requires and more than most rows here can offer. → United States of America The US Department of Justice indicted five officers of the People's Liberation Army by name, unit and photograph for economic espionage against American industrial firms — the first time any state's uniformed personnel were criminally charged for cyber operations. Unit 61398 is the same organisation Mandiant had documented as APT1 the year before. US DOJ — five Chinese military hackers charged with cyber espionage
  • 2014-02-10 Las Vegas Sands destructive attack (Iran, DNI-attributed) — · IRThe Director of National Intelligence told the Senate Armed Services Committee in February 2015 that the Iranian government was responsible. A state body naming a state, on the record, in testimony — our strongest evidence class. Held at `assessed` rather than `attributed` because no organ was named. No ATT&CK group is attached: routing this through some Iranian group to satisfy the data model would invent an attribution nobody made. → United States of America Wiper malware destroyed data across Sands' systems and took much of the company offline; customer credit-card, Social Security and driver's-licence data was also taken. In February 2015 the Director of National Intelligence told the Senate Armed Services Committee the Iranian government was responsible, putting it alongside the Sony hack as one of the first destructive state attacks on US soil. Reporting connects the targeting to the CEO's public statements on Israel. DNI Clapper, Senate Armed Services Committee testimony (Feb 2015), via CNN Bloomberg — Iranian hackers hit Sheldon Adelson's Sands casino
  • 2014-01-01 Yahoo account compromise (FSB officers indicted) — · origin not established → United States of America At least 500 million accounts compromised. The DOJ indicted two FSB officers (Dokuchaev, Sushchin) alongside criminal hackers Belan and Baratov — a documented state/criminal hybrid. DOJ indictment — US v. Dokuchaev, Sushchin, Belan, Baratov
  • 2013-12-18 Target payment card breach — · origin not establishedNo origin. The stolen cards were sold by a Russian-speaking vendor later identified by journalists, but the seller of the data is not the intruder, and hazard 5 says a defendant's nationality is not the group's origin. → United States of America 40 million payment cards and personal data on 70 million people taken after intruders entered through an HVAC contractor's credentials. The lateral path from a third-party supplier into a payment network made it the reference case for supply-chain risk in retail, and it cost the CEO and the CIO their jobs. US Senate Commerce Committee report on the Target breach
  • 2013-08-01 Yahoo breach of all three billion accounts — · origin not establishedNo origin. The 2013 intrusion was never attributed, and it is a DIFFERENT event from the 2014 one for which FSB officers were indicted. Merging them because the victim is the same company would be the alias-merge trap wearing a different hat. → United States of America The largest breach ever recorded by account count. Yahoo first disclosed it in December 2016 estimating one billion accounts, and only in October 2017 — after the Verizon acquisition had closed — confirmed that ALL three billion had been affected. Verizon cut its purchase price by 350 million dollars, from 4.83 to 4.48 billion, making this the clearest case on record of a breach directly repricing a corporate acquisition. Distinct from the 2014 intrusion for which FSB officers were later indicted. TechCrunch — Yahoo says all 3 billion accounts were impacted by the 2013 breach CBS News — Verizon slashes offer price for Yahoo over data breaches
  • 2013-04-07 #OpIsrael coordinated hacktivist campaign — · origin not established → Israel An annually repeating Anonymous-affiliated campaign of defacements, DDoS and credential dumps against Israeli government and commercial sites, timed to the eve of Holocaust Remembrance Day. Claimed figures were very large and the outcome was not; the Israeli National Cyber Bureau assessed the inaugural campaign as a failure, with no physical damage. Recorded because a hacktivist campaign is a real category this map otherwise never shows, and because the gap between claim and effect is the point. Wikipedia — OpIsrael (campaign history and assessments) The Hacker News — Anonymous calls for a massive attack against Israel
  • 2013-03-20 DarkSeoul wiper against South Korean banks and broadcasters Lazarus Group · KP → South Korea Roughly 48,000 machines wiped across three broadcasters and three banks in a single coordinated event. The South Korean government publicly attributed it to North Korea after investigation, and in 2015 said it had matched code patterns. Worth recording that the earliest attribution leaned on a Chinese IP address later shown to be misread. Secureworks — Wiper malware analysis, attacking Korean financial sector McAfee — Dissecting Operation Troy
  • 2012-08-15 Saudi Aramco / RasGas destructive wiper (Shamoon) — · origin not establishedIran is the near-universal assessment, but it rests on motive, on Shamoon resembling the Wiper malware used against Iran's own oil ministry months earlier, and on unnamed US officials. The only claim of responsibility came from an anonymous Pastebin persona, and no indictment or sanction has ever named a perpetrator. Recorded without an origin on purpose: the incident is certain, the attribution is not. → Saudi Arabia Shamoon overwrote the master boot record on roughly 30,000 Saudi Aramco workstations, taking the world's largest oil company off its own network for over a week; RasGas in Qatar was hit days later. Origin is deliberately NOT recorded. Iran is widely assessed as responsible, but that rests on motive, on Shamoon's resemblance to the Wiper malware used against Iran's own oil ministry months earlier, and on unnamed US officials. The only claim of responsibility came from "Cutting Sword of Justice", an anonymous Pastebin persona. No indictment or sanction has ever named a perpetrator. Jeffrey Carr, "Was Iran Responsible for Saudi Aramco's Network Attack?" (2012) CFR Cyber Operations Tracker — Compromise of Saudi Aramco and RasGas
  • 2011-03-17 RSA SecurID seed compromise and the Lockheed Martin follow-on — · CNA senior US official told Reuters that China was behind it and the NSA director said as much to Congress, but no indictment or sanction followed and no organ was named, so this stays `assessed` rather than `attributed`. → United States of America A phishing mail titled ‘2011 Recruitment Plan’, retrieved by an employee from a junk folder, carried a Flash zero-day that led to theft of the data underpinning SecurID two-factor tokens. Two months later Lockheed Martin was attacked using the stolen seed material. The canonical demonstration that compromising a security vendor is a route into everyone who trusts it. Schneier on Security — the story of the 2011 RSA hack Dark Reading — China hacked RSA, US official says
  • 2010-06-17 Stuxnet sabotage of Natanz uranium enrichment — · USBroad expert consensus holds this was a joint US-Israeli operation, and Kaspersky established technical links between the Equation Group and the authors of Stuxnet and Flame. But no state has ever acknowledged it, there is no indictment and no sanction. That is the `unacknowledged` tier exactly, and the arc is drawn DASHED so it cannot be mistaken for the indicted, sanctioned attributions beside it. Israel is not drawn as a second origin: the schema carries one, and picking one of two unacknowledged partners would be a guess dressed as a choice. → Iran Malware that crossed an air gap and altered the rotational speed of gas centrifuges at Natanz while replaying normal readings to operators, physically destroying an estimated 1,000 machines. The first widely documented case of code causing physical damage to industrial equipment. No state has ever acknowledged it, which is why it is recorded at the `unacknowledged` tier and drawn dashed rather than solid. Symantec — W32.Stuxnet Dossier Kaspersky — Equation Group, technical links to the Stuxnet and Flame authors
  • 2010-01-12 Operation Aurora against Google and 20+ US companies — · CNGoogle itself stated publicly that the attack originated from China, which is a victim naming an origin rather than a state attributing one, and no government followed with a formal attribution. Held at `assessed`. → United States of America Google disclosed a targeted intrusion originating from China that reached its source code and the Gmail accounts of Chinese human-rights activists, and said at least twenty other companies were hit. The first time a company of Google's size publicly attributed an intrusion to a state, and it led to Google withdrawing from the Chinese search market. Operation Aurora — overview and attribution
  • 2008-08-08 Cyberattacks on Georgia during the South Ossetia war — · origin not establishedNo origin. Russia is the universal assumption and the timing with the ground invasion is not subtle, but Russia denied it, no formal attribution was ever made, and the traffic ran through nominally civilian botnets and forum-recruited volunteers. Recording the incident without the arrow is the same call made for Shamoon. → Georgia Defacements and sustained denial-of-service against Georgian government, news and banking sites, running alongside the ground invasion and cutting the government's ability to communicate during it. Widely regarded as the first time network attacks were coordinated with conventional military operations. Russia denied involvement and no formal attribution ever followed. NATO StratCom COE — analysis of the cyberattacks on Estonia and Georgia

Why almost every arrow starts in the same few countries. Of 110 actors we can place, 107 are attributed to states outside the Western alliance and 3 inside it — about 36 to 1. That is not a measurement of who conducts operations. Our strongest evidence is government advisories, indictments and sanctions, and governments do not attribute their own intelligence services. Stuxnet is the clearest case: consensus reporting attributes it jointly to the United States and Israel, neither has ever acknowledged it, and so it cannot meet the evidence bar this map applies to everyone else. Read the absence of Western-origin operations as a limit of the sourcing, not a finding about the world.

What we did about it. A state body naming a foreign intelligence organ is weighed the same whoever issues it — the alternative, taking a US advisory on the issuer's authority while demanding corroboration of a Chinese one, is the double standard that produced the ratio above. Every placement records who attributed it, and 1 carry the unacknowledged tier: broad expert consensus that no accountable body has ever confirmed. Equation Group is the defining case, and it is drawn as an outline rather than a solid mark for exactly that reason.

Targeting people inside their own country all 12 documented cases

States that surveil their own residents — journalists, activists, dissidents. This is drawn as a ring on the country rather than an arrow between countries, because the attacker and the victim are the same nation and an arrow would have nowhere to point. That is a large part of why this category is missing from most threat maps.

It also uses a different evidence standard, out of necessity: no government attributes its own security services, so these rest on independent device forensics (Citizen Lab, Amnesty Security Lab and similar) with corroboration by a second team. Where the operator link is described as circumstantial by the researchers themselves, it is recorded that way rather than promoted.

Small dots around a ring mark the countries where that state pursued its own nationals living abroad, and they point in the direction of each one. There is deliberately no arrow, because an arrow would say the host country was attacked. It was not — an exiled Vietnamese blogger in Germany is a Vietnamese victim who happens to be in Germany, and nothing here shades the host country on the map above. These also carry an extra evidence requirement: the victim’s nationality has to be established by named people or organisations, never by a device’s language setting. One case in this set was refused on exactly that point.

  • Palestine APT-C-23 assessed Cybereason assesses with moderate-to-high confidence that APT-C-23 operates on behalf of Hamas. Alongside campaigns against Israeli targets, the group targets Fatah members and other Palestinian voices dissenting from Hamas. Cybereason 'Operation Bearded Barbie' (2022) and 2020 campaign researc
  • Russia APT28 attributed 'APT28 espionage activity has primarily targeted entities in the U.S., Europe, and the countries of the former Soviet Union, including governments and militaries, defense attaches, media entities, and dissidents and figures opposed to the current Russian Gover FireEye, 'APT28: At the Center of the Storm' (2017); Trend Micro Pawn
  • Vietnam APT32 forensic Amnesty Tech found that the Vietnam-backed group APT32 coordinated spyware attacks against Vietnamese human rights defenders between February 2018 and November 2020; blogger and pro-democracy activist Bui Thanh Hieu was targeted at least four times. Amnesty International Security Lab, 'Click and Bait: Vietnamese Human also reached its own nationals inGermanyAmnesty International Security Lab, 'Click and Bait: Vietnamese Human Rights Defenders Tar
  • People's Republic of China Axiom assessed Novetta's Operation SMN report carries a dedicated 'Domestic Targeting' section: 'it also appears that Axiom has used Hikit internally to gather information on domestic Chinese targets... we have identified several instances of Hikit present on machines locate Novetta, 'Operation SMN: Axiom Threat Actor Group Report' (2014), with
  • People's Republic of China Daggerfly assessed A China-aligned group whose objective is espionage against movements opposing China's interests: the Tibetan community, religious and academic institutions in Hong Kong, and supporters of democracy in China. Since at least September 2023 it has combined a wate ESET Research, 'Evasive Panda leverages Monlam Festival to target Tibe also reached its own nationals inIndiaESET Research, 'Evasive Panda leverages Monlam Festival to target Tibetans' (2024)
  • Iran Ferocious Kitten assessed A six-year covert surveillance campaign against Persian-speaking individuals inside Iran, delivering the MarkiRAT implant through decoy documents and a backdoored build of Psiphon — a VPN used to bypass internet censorship. Victims appear to be Persian-speakin Kaspersky GReAT, 'Ferocious Kitten: 6 years of covert surveillance in
  • Iran Magic Hound attributed Magic Hound conducts operations likely on behalf of the Islamic Revolutionary Guard Corps. Its campaigns are directed against dissident organisations and individuals — lawyers, journalists and human rights activists — both inside and outside Iran. MITRE ATT&CK (IRGC linkage); ClearSky and Reuters reporting on targeti also reached its own nationals inUnited KingdomCzech RepublicGermanyCertfa Lab, 'Fake Interview: The New Activity of Charming Kitten'; Reuters and Iran Intern
  • Palestine Molerats assessed Campaigns targeting Palestinian authority figures and Palestinians alongside Israeli and regional targets, attributed with high confidence to Palestinian actors with Hamas-affiliated interests. Cybereason 'Spark'/'Pierogi' campaign research; Kaspersky; FireEye
  • Turkey NEODYMIUM forensic An activity group that heavily targeted Turkish victims, using the Wingbird backdoor whose characteristics closely match FinFisher, the Gamma Group surveillance suite sold to governments. It burned the same Flash Player zero-day (CVE-2016-4117) at the same tim Microsoft, 'Analysis of FinFisher malware used by NEODYMIUM' (2016) also reached its own nationals inBelgiumItalyMicrosoft Security Intelligence Report (2016); contemporaneous campaign reporting on victi
  • Turkey PROMETHIUM forensic Microsoft observed PROMETHIUM using a Flash Player zero-day to spy on Turkish citizens living in Turkey and in Europe. StrongPity has targeted Kurdish victims in Turkey and Syria, and in 2018 was delivered by injection at the ISP level inside Türk Telekom's ne Microsoft Security Intelligence Report (2016); Citizen Lab 'Bad Traffi also reached its own nationals inBelgiumItalyMicrosoft Security Intelligence Report (2016); contemporaneous campaign reporting on victi
  • United Arab Emirates Stealth Falcon forensic A campaign of targeted spyware attacks carried out by a sophisticated operator called Stealth Falcon, conducted from 2012 onward against Emirati journalists, activists and dissidents. Circumstantial evidence suggests a link between Stealth Falcon and the UAE g Citizen Lab, 'Keep Calm and (Don't) Enable Macros: A New Threat Actor
  • Palestine WIRTE assessed Check Point tracks WIRTE as a Hamas-affiliated threat actor which, since late 2023, has run espionage against the Palestinian Authority, Jordan, Egypt and Saudi Arabia while expanding into disruptive activity against Israel. Check Point Research (2024); Kaspersky Securelist WIRTE campaign analy

My country

Pick a country and this becomes a local briefing: what has been observed there, which industries took it, and who was named. The choice is remembered in this browser only — no account, nothing sent anywhere.

Choose a country above to build the briefing. This part needs JavaScript; the map, shelf and table above do not.

Across the whole window we observed 13 named attackers. Matched to a group we track: 0. With a defensible country of origin: 0 (0%). That is not a gap we can close by guessing: the groups showing up in leak-site claims are ransomware brands, and a brand is not a jurisdiction. Where a group has no defensible geography we say so rather than drawing an arrow from somewhere plausible.

Who hits whom 0 arcs

An arc is drawn only where BOTH ends clear the bar: an actor observed hitting a country, resolving to a group we track, carrying an origin we can defend. The landmark layer above has its own arcs from curated history; these would come from the live 90-day corpus.

No flow arcs can be drawn from the live corpus right now, and the reason is the finding. Of 13 attacker names observed in the last 90 days, 0 resolve to a group we track and 0 carry a defensible country. Every one of them is a leak-site crew — ransomware and extortion brands that name their own victims. Criminal geography is exactly the class this map refuses to place without consensus, because a crew's country is where it is tolerated rather than who directs it. So the feed shows us attackers we can see and cannot site. Arcs will appear here on their own as state-attributed actors enter the observed corpus; drawing them sooner would mean guessing.

Through the supply chain 6

Events whose shape is one-to-many. These are listed apart because a single arc misrepresents them: SolarWinds was not an attack on SolarWinds, it was an attack through it, and for several of these the number of downstream victims is a figure nobody has. Where the record names no victim country we say so rather than pinning the event to the vendor's address, which would put the mark on the one organisation that was a route rather than a target.

  • 2017-06-27NotPetya destructive wiperUkraine, Denmark, United States of America, United Kingdom, France
  • 2020-12-13SolarWinds Orion supply chain compromiseUnited States of America
  • 2021-07-02Kaseya VSA mass ransomware (REvil)United States of America
  • 2023-03-293CX desktop-app supply chain compromisereach not countable
  • 2023-05-31MOVEit Transfer mass-exploitation (Cl0p)reach not countable
  • 2023-10-20CyberLink software supply chain compromiseTaiwan

Actors with no defensible geography 64

Every actor we track that the map cannot place. Forcing a country onto these would make the map look more complete and be less true, so they are listed instead. 42 have no country claim in any source we accept; 8 carry a bare country code in our own corpus with no evidence behind it, which is a lead and not a placement; and 14 were searched, read, and refused — those are decisions, and the reasoning is kept so the question does not get silently re-opened and answered differently.

  • BackdoorDiplomacyESET did not formally attribute it. The China reading arrives by merging it into APT15/Ke3chang, which IS state-attributed — but ATT&CK tracks G0135 and G0004 as separate groups, and adopting a press alias-merge to inherit someone
  • CarbanakNo single jurisdiction survives. Kaspersky found the crew Russian-speaking; Europol and Spain named the alleged leader as a Ukrainian national arrested in Alicante, running the operation with three Russian and Ukrainian accomplice
  • HEXANEBoth primary researchers decline. Secureworks and Dragos each say they do not attribute it to a country; the Iran reading comes from TTP resemblance to COBALT GYPSY and COBALT TRINITY, which is a chained mapping through two other
  • InceptionNobody attributes it; researchers note the operators went to unusual lengths to hide origin. The only geographic signal is UTC+2 working hours, shared by a dozen countries, and its heaviest targeting is Russia itself (30 percent),
  • LuminousMothKaspersky's moderate-to-high confidence is in the link to HoneyMyte /Mustang Panda, not in a country. Reaching China means LuminousMoth → Mustang Panda → China, and the direct evidence for LuminousMoth alone is Chinese-language ar
  • MacheteESET explicitly declines to link it to any government. The only country-level claim is Cylance's Brazil hypothesis, reasoned from the ABSENCE of Brazilian victims, which contradicts Kaspersky's Spanish-speaking finding — Brazil is
  • Poseidon GroupThe strongest of the declines, and the clearest illustration of the rule. Kaspersky reported the first publicly known Brazilian-Portuguese-speaking espionage campaign — a statement about compiler language codes and target locale,
  • Scarlet MimicUnit 42 states plainly it 'does not have evidence that directly links Scarlet Mimic attacks to the PRC' and offers only motive congruence with Beijing's stated position. Motive alignment is the weakest inference class there is. Al
  • StriderSource self-contradictory in a single sentence — 'widely attributed to a Western intelligence agency, with most researchers pointing to Russian origins'. Not `contested` either, because that tier needs two coherent readings and th
  • TA505Attributed only to 'Russia or former Soviet states' on linguistic and operational patterns. That is not a country, and language is not geography. This is also the case the policy already names by hand — TA505 is not simply Evil Co
  • ThripSymantec located the operational infrastructure — three computers on the mainland — and declined to blame the Chinese government. Where a machine sits is not where an actor is from; rented and compromised hosts are the norm. Neare
  • ToddyCatKaspersky states it was 'not able to attribute the attacks to a known APT group'. The China-nexus reading rests on Chinese-language artifacts and victim overlap with Chinese-speaking groups. Secondary press hardened this into 'Chi
  • WhiteflySymantec named the group for the SingHealth breach but not a sponsor, and the Singapore government said explicitly it would not disclose the attacker's identity. Absence of a claim, not a claim we are rejecting.
  • WindshiftNo origin claim exists. DarkMatter disclosed the group and offered no attribution; Unit 42 later found infrastructure overlap pointing at suspected Indian origins instead. Note also the provenance: DarkMatter is an Emirati firm th