Hacktivism Evolves from Digital Defacer into Asymmetric Warfare Threat Actor
Hacktivism is becoming a disciplined component of global hybrid warfare that can bridge digital disruptions and defacements with physical impact, according to new research released this week from Flashpoint.
The cyber threat intelligence platform has been tracking a significant amount of hacktivist activity this year around the Russia and Ukraine war, the Iran conflict, and other state actors. It assessed that these groups are leveraging crowdsourced infrastructure to disrupt critical utilities, manipulate media narratives, and target public infrastructure.
What especially sets the modern hacktivist groups apart, Flashpoint explained in the research published on 26 August, is that they can serve as the “high-visibility arm of cyber conflict” to align with state geopolitical interests, like those in pro-Russian operations and Iranian-aligned cyber campaigns.
Ian Gray, vice president of intelligence at Flashpoint, says his firm tracks these hacktivist groups by monitoring their claimed channels and public-facing activity on platforms like Telegram. Groups will use these channels to announce targets, post evidence of their work, and coordinate with others.
“The term ‘hacktivist’ has to be used loosely here, since much of what’s labeled hacktivism is really state-supported or state-sponsored activity wearing a hacktivist mask, which gives adversaries deniability and blurs attribution,” Gray says. “It fits into a broader asymmetric warfare pattern, where low-cost, low-visibility operations—whether outright attacks or disinformation—produce outsized effects without triggering a proportionate military response, since any retaliation tends to stay in the cyber domain and often below the threshold either side can clearly observe.”
Changing Tactics
Modern hacktivist groups are now conducting campaigns that are both opportunistic and tied to global events. Flashpoint’s observed related activity in response to military operations like Operation Epic Fury in Iran, the Milan-Cortina Winter Olympic Games, and new aid packages for Ukraine.
The continued convergence of physical and cyberattacks—when real-world events and cyber effects bleed into each other—in the Russia-Ukraine and Iran conflicts stands out to Gray when looking at this latest activity.
“Cyber gives these actors an asymmetric advantage, where a low-level attack’s impact is really only as strong as the disinformation or misinformation built around it, or in some cases wiper attacks dressed up to look like a more serious cyber operation,” Gray adds. “What’s particularly notable is how much more formalized this has become over the last couple of years, and how it’s mobilized a much wider pool of sympathetic actors—whether that’s pro-Russian versus anti-Russian alignment, or the more complex Muslim and anti-Muslim currents running through the Iran-Israel dynamic—all willing to lend services or support to these campaigns.”
Flashpoint noted that modern hacktivist groups are gamifying cyberattacks, turning distributed denial of service (DDoS) attacks into community-based “patriotic online games” where participants can earn military-like ranks and cryptocurrency rewards for overwhelming critical infrastructure websites. One example of this is the DDoSia project, which the U.S. government has attributed to the Kremlin-created Center for the Study and Network Monitoring of the Youth Environment.
Hacktivist groups are also engaged media consumers, reposting coverage and news articles that reference themselves as a form of self-promotion—validating their work. This behavior is especially prominent in pro-Russian hacktivist groups, which treat media visibility itself as the measure of success since technical impact is hard to verify and often overstated, Gray says.
“Part of why this appeals so strongly to pro-Russian collectives specifically comes down to infrastructure like the DDoSia project, which literally gamifies and monetizes this behavior, paying out bounties based on how long a target site stays down—so the incentive structure itself is built around claiming and publicizing impact rather than achieving deep technical compromise,” he explains. “This stands in contrast to other hacktivist currents, for instance groups aligned with the Iran conflict, which have shown more willingness to pursue kinetic-adjacent or destructive objectives rather than just optimizing for a scoreboard.”
For instance, the Iranian-linked group CyberAv3ngers presents itself as a hacktivist collectively but routinely targets operational technology and industrial control systems, particularly water utilities and Israeli-made equipment, Gray adds.
In 2026, this targeting included exploiting programmable logic controllers across U.S. water systems, “incidents in Minnesota and elsewhere that forced utilities into manual operations and caused real pressure loss and flooding, not just a website going offline for a few hours,” he says.
This behavior is the clearest contrast with the pro-Russian media-focused model, Gray adds. “The objective isn’t visibility for its own sake, it’s disruption of physical infrastructure, even if the group still layers propaganda messaging on top, like the HMI defacements referencing Israel,” he says.
Ukraine continues to face the brunt of these hacktivist efforts, since pro-Russian groups frequently target Ukrainian infrastructure and morale. But there has not been a notable uptick in activity as Ukraine’s military has achieved some success with its drone program in 2026. Instead, Gray says Flashpoint has observed a sustained, steady-state level of activity targeting Ukraine over the past six months.
“What has changed is less the volume and more the character and reach of it: Campaigns have become more opportunistic, spiking around specific triggers like new military aid packages to Ukraine or diplomatic developments, and the target set has continued to widen well beyond Ukraine itself to more than 30 supporting nations,” he explains. “If anything, perceived Ukrainian battlefield gains seem to correlate with retaliatory spikes against Ukraine’s allies rather than any pullback, and it’s worth noting that even law enforcement disruptions of groups like NoName057(16) haven’t meaningfully dented the activity—these networks reconstitute quickly.”
Three European nations are especially lucrative targets for this type of activity: Germany, Spain, and the United Kingdom. They are attractive because they sit at the intersection of NATO membership and visible, tangible support for Ukraine.
Hacktivist groups have hit Spain with a coordinated DDoS campaign against government websites that the groups tied to Spanish government actions perceived as anti-Russian, Gray says.
“The UK has been targeted with attacks the groups justified by pointing to specific military aid announcements, for instance stepped-up production of Ukrainian drone interceptors,” he adds. “Germany fits the same pattern as one of Ukraine’s largest sustained military and financial backers within NATO. In each case, the targeting isn’t random—it tracks the news cycle almost in real time, where a new aid package or policy announcement tends to be followed within days by a retaliatory claim.”
Some of these retaliations include activity that manifests in the real world. Gray points to the pro-Russian group Z-Pentest, which hijacked Internet-connected surveillance cameras in a public swimming facility and a pub in Denmark. The activity is connected to a broader pattern Dutch intelligence has flagged of Russian-aligned actors systematically hijacking exposed security cameras in Europe. In some instances, those cameras were used to surveil military logistics routes and weapons shipments bound for Ukraine, he adds.
“This is that convergence point in action—a cyber intrusion into what looks like mundane consumer infrastructure that has both a propaganda value and a genuine operational surveillance value tied to the war itself,” Gray says.
Next Steps for Security Practitioners
This hacktivist activity is unlikely to wane anytime soon. But there are measures that security practitioners, especially those at critical infrastructure operators in the EU, can take to bolster their defenses against them.
Gray recommends keeping a close eye on the news cycle and remaining current on the actual capabilities of hacktivist groups relevant to your sector and region.
“For critical infrastructure operators specifically, the Iran-aligned activity targeting operational technology and industrial control systems is the one to take seriously, so run tabletop exercises that specifically model downtime and disruption scenarios—not just data breach response—so your organization has practiced what to do if a system goes down rather than figuring it out in the moment,” he adds.
“Ultimately, it comes down to understanding the threat well enough to reason clearly about what the actual impact would be to your specific operations, rather than reacting to every claim at face value,” Gray continues.
Megan Gates is the senior editor at Security Management. Connect with her at [email protected] or on LinkedIn.








