Analysis shows decline in hacktivism

Analysis of 2022 cyber events shows decline in hacktivism around the war in Ukraine, but growth in cybercrime…
Ukraine

Share this article:

Analysis of 2022 cyber events shows decline in hacktivism around the war in Ukraine, but growth in cybercrime

  • Data compiled by Netskope’s Paolo Passeri indicates the wave of Russia-related incidents has broken, after surge of activity around the war in Ukraine
  • Hacktivist groups, such as Anonymous, also slowed efforts having initially focused activity on Russian oligarchs in Real Estate and Mining
  • Globally, cybercrime has continued to rise throughout the year with healthcare the most targeted sector

New data compiled by Paolo Passeri, Cyber Intelligence Principle, Netskope EMEA shows the wave of cyber attacks surrounding the Russian invasion of Ukraine has tailed off.

According to public data, there were 83 cyber events related to Russia between February 2022 and May 2022, accounting for almost 10% of all global cyber events in the period. However, this surge in activity was short-lived. There were just six incidents related to Russia in June and July, accounting for 1% of all cyber events globally. This dramatic fall in activity in the region suggests that cyber threat actors’ and hackivists’ efforts around the war in Ukraine have not been sustained throughout the conflict.

Cyber warfare has in fact been in steady decline globally since the beginning of the year, with 56% of all reported cyber warfare-related incidents taking place in February and March. The same pattern has been seen in hacktivism activities, which slowed across the board in June and July despite having actively targeted real estate and mining businesses owned by Russian oligarchs earlier in the year. However, Ukraine and its allied countries remain the constant target of cyber espionage operations carried out primarily by threat actors from Russia and Belarus.

Looking at the state of cyber events more broadly, Passeri’s analysis shows that financially motivated cybercrime remains the dominant form of cyber attack making up 72% of all incidents so far this year. Other findings include:

  • Healthcare continues to be the most targeted sector for cyber criminals, accounting for 14% of all cyber events so far this year. Of those attacks, just 0.5% could be attributed to cyber warfare with 99.5% of events being recorded as financially motivated cybercrime.
  • Public administration, including the defense industry, was also heavily targeted, accounting for 12% of all cyber events. 35% of these attacks were financially motivated cybercrime, with 26.7% hacktivism, 26.5% cyber espionage, and 10.5% cyber warfare.
  • Financial services, which comprises finance, insurance, and fintech, was targeted in 8% of all cyber events, with economic gain being the prevailing motivation for over 99% of attacks.

Paolo Passeri, Cyber Intelligence Principal at Netskope EMEA said; 

“The invasion of Ukraine sparked a flurry of cyber incidents relating to Russia in the early part of this year with a clear spike in cyber espionage, hacktivism, and cyber warfare targeting Russian businesses and individuals. The data shows however that this was short-lived with activity falling off considerably in recent months, most likely because hacktivist groups were not willing or able to sustain their efforts as the conflict continued.”

“In contrast, cybercrime incidents have continued to grow throughout the year. Despite the media attention received by cyber warfare and hacktivism campaigns, cybercriminals remain by far the biggest threat to businesses, particularly in healthcare, public services and financial services, which are consistently the sectors most frequently targeted.”

Passeri’s data is collated and expanded on his personal blog, Hackmageddon.com. The events analysed are gathered from OSINT sources, such as infosec blogs or news outlets, and are selected based on the impact (for example the profile of the target, the breadth and sophistication of the operation, and the financial loss or the number of leaked records in case of cybercrime events). Specific data is available on request.

For more news updates, check out our latest issue here.

Media contact

Rebecca Morpeth Spayne,
Editor, Security Portfolio
Tel: +44 (0) 1622 823 922
Email: [email protected]

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
OPTEX at Essen - securitybuyer.com

OPTEX to showcase perimeter solutions at Security Essen

OPTEX will present its latest perimeter and asset protection solutions at Security Essen 2026, one of Europe’s leading security trade fairs.
Dallmeier

Building Trust in Modern Video Security

Rebecca Spayne, Managing Editor of Security Buyer, speaks with Josua Braun, Chief Revenue Officer at Dallmeier electronic, about cyber resilience, trusted supply chains, the practical value of artificial intelligence and what security professionals should consider when investing in modern video technology. 
Verkada

Verkada Expands AI Security Platform

Verkada, a provider of AI-powered physical security and operations, has unveiled new capabilities for vehicle fleets, enterprise sound systems, and building operations during its annual customer conference, VerkadaOne.
Assa Abloy

“Mobile-first” access 

David Moser, of ASSA ABLOY Opening Solutions EMEIA explores how mobile digital access unlocks new possibilities for organizations everywhere.
Traka - securitybuyer.com

Integrating Digital and Physical Security

Tom Smith, Vice President and Head of EMEIA for Traka, discusses convergence and the expanding role of integrated key and asset management. 
Traka GSX

GSX Exhibitor Spotlight – Traka

Traka, an ASSA ABLOY company and the global leader in intelligent management solutions for keys and equipment, returns to GSX 2026 at Booth #1233. Traka experts will be available to provide personal demonstrations of how smart asset management systems are streamlining operations in numerous industry verticals. 
Rhombus GSX

GSX Exhibitor Spotlight – Rhombus

When it comes to modernising physical security, Rhombus stands out by making it smarter, simpler, and genuinely easier to manage; no matter the size or complexity of the business. 
Keynetics at Essen - securitybuyer.com

Keynetics to Debut at Security Essen 2026

The UK-based Keynetics will exhibit at Security Essen for the first time, showcasing SentriGuard, its smart key-management
Scroll to Top