VYPR
advisoryPublished Sep 29, 2026· 1 source

Pro-Russia Hacktivists Intensify Attacks on EU Operational Technology

The European Union Agency for Cybersecurity (ENISA) reports a significant increase in intrusion claims targeting operational technology and industrial environments across the EU, with pro-Russia hacktivist groups like NoName057(16) leading the charge.

The European Union Agency for Cybersecurity (ENISA) has issued a stark warning regarding a notable surge in intrusion claims targeting operational technology (OT) and industrial control systems (ICS) throughout the European Union. These attacks increasingly focus on critical infrastructure sectors, raising concerns about the stability and security of essential services across member states.

According to ENISA's latest report, ideology-driven malicious cyberattacks were responsible for a significant portion of these incidents. Specifically, the agency found that such politically motivated campaigns accounted for 57.3% of all reported incidents impacting OT and industrial environments. This highlights a growing trend where cyber warfare and hacktivism are directly impacting physical infrastructure and essential services.

The report identifies the pro-Russia hacktivist group NoName057(16) as a primary perpetrator, claiming responsibility for a substantial 48% of the reported intrusion claims. This group has been observed to consistently target critical infrastructure, including energy, transportation, and government services, aligning with broader geopolitical tensions. Their activities underscore the evolving tactics of state-sponsored or state-aligned hacktivist entities.

The increasing focus on OT and ICS environments presents unique challenges compared to traditional IT security. These systems often have longer lifecycles, may run on legacy operating systems, and are designed for reliability and availability rather than security. Exploiting vulnerabilities in these systems can lead to physical disruptions, safety hazards, and widespread economic damage, making them attractive targets for disruptive actors.

ENISA emphasizes that these attacks are not merely opportunistic but are often part of coordinated campaigns aimed at destabilizing critical sectors. The agency is urging organizations operating in these critical sectors to bolster their defenses, implement robust monitoring, and ensure their OT security practices are up-to-date. This includes regular vulnerability assessments, patching where feasible, and enhancing network segmentation to isolate critical systems.

The trend also points to a broader geopolitical cyber conflict where hacktivism is being weaponized to exert pressure and sow discord. The targeting of critical infrastructure by groups like NoName057(16) serves as a potent reminder of the interconnectedness of cybersecurity and national security, demanding a heightened level of vigilance and collaborative defense strategies across the EU.

While the report focuses on intrusion *claims*, which may not always result in successful, deep compromises, the sheer volume and persistence of these claims indicate a significant increase in probing and attempted intrusions. This activity necessitates a proactive approach from defenders to identify and mitigate potential threats before they can escalate into actual disruptions.

Synthesized by Vypr AI