❌

Normal view

Responsible AI in 2026: How we are adapting for what’s ahead

1 September 2026 at 16:49

Today, Microsoft published its 2026 Responsible AI Transparency Report. The report highlights the progress we’ve made in building and deploying AI responsibly, supporting our customers, and strengthening our responsible AI governance, tools, and practices. You can explore the report in its entirety here.

AI is moving fast, and so are societal expectations. The boundaries of what people can accomplish with AI are expanding, and communities are asking more questions about how AI systems are designed, built, and used. As AI becomes more integral to how we live and work, confidence that AI systems are operating reliably and securely is becoming an essential prerequisite to their broad and beneficial adoption.

At Microsoft, we have been building a responsible AI program for nearly a decade, rooted in two core beliefs: that trust is foundational to realizing the benefits of AI and that the empowerment of people and organizations must remain at the center of our strategy. As capabilities advance and adoption accelerates, that experience is helping us meet this moment and adapt for what comes next.

Our third annual Responsible AI Transparency Report shares how our program is evolving and the priorities that continue to shape our work. Over the last year, investing in three specific areas has enabled us to embed trust more deeply and at greater scale: adaptive governance and technical risk management, practical tools and capabilities, and shared practices and strong partnerships. These investments cut across five trends shaping the AI landscape, including the rapid expansion of agentic AI.

Taken together, these trends and investments underscore our view that model capability alone will not determine the impact of AI. That will depend on organizations that develop and deploy AI technologies that deliver real valueβ€”and govern them with the rigor and adaptability needed to earn and sustain trust.

Adaptive governance and technical risk management

As the frontiers of AI advance, we are making our governance more adaptive and more tightly integrated with engineering workflows. In practice, this means that we have updated our policies to better match the AI tech stack and AI value chain, evolved our risk management practices to address emerging AI capabilities and risks, and strengthened the readiness of our responsible AI community: the people who operationalize our program at enterprise scale.

This year, we re-engineered our Responsible AI Standard to make it more adaptive to evolving technical realities, uses, risks, and regulatory requirements. The new Standard is structured by reference to different components of the tech stackβ€”models, platform services, and applicationsβ€”and the role that Microsoft plays in developing or deploying those components. It combines core requirements that always apply with more targeted, scenario-specific requirements that can evolve as capabilities and risks change. For example, we apply some of our most rigorous risk management measures to AI systems with the most significant cyber capabilities, helping ensure that advances in AI favor the defenders responsible for securing critical digital infrastructure.

We are also evolving our technical risk management practices. Increasingly capable systems can retain memory, use tools, access data, and take actions on behalf of users. Governing these systems requires us to think beyond the behavior of an individual model or application to interactions among models, agents, applications, tools, data, and people. Our work increasingly focuses on controls such as agent identities, tool permissions, and monitoring of actions.

And governance only works when people can put it into practice. We have continued to build responsible AI capabilities across Microsoft, equipping thousands of engineers and product managers with training on topics such as agentic AI threat modeling and prompt injection defenses.

Together, these investments are helping us move toward a more continuous, lifecycle-based approach to AI governance. With agentic AI, risks can evolve as systems interact with their environments, users, and other systems. Our governance needs to evolve with these agentic capabilitiesβ€”and incorporate what we learn from their testing and deployment.

Practical tools and capabilities

Effective governance depends on tools that help translate policy goals into action. As developers and organizations navigate a more complex technical and regulatory environment, they need practical ways to identify risks, evaluate systems, establish controls, and monitor how AI behaves in the real world.

We are applying what we learn from governing AI at Microsoft into tools, capabilities, and resources that help developers and organizations beyond Microsoft do just thatβ€”whether they build on our platforms or leverage open-source projects.

We have expanded tools to evaluate AI systems across the lifecycle. A new AI Red Teaming Agent helps accelerate the identification and evaluation of risks. Agent evaluators help developers measure the quality, safety, and performance of agentic applications. RAMPART turns red team findings into repeatable tests, enabling more continuous coverage as systems change.

We are also building greater visibility and control into agentic systems. With ASSERT and Agent Control Specification, developers can evaluate agents against their policies, place runtime controls at critical points in an agent’s workflow, and monitor behavior.

These tools and capabilities reflect a shift: as systems become more dynamic, governance needs to become more operational. Organizations need to be able to see what their systems are doing, test how they behave, and intervene when necessaryβ€”not just assess them before deployment.

Organizations also need confidenceβ€”and increasingly need to demonstrateβ€”that responsible AI practices are being implemented consistently. Microsoft is one of the few companies certified against ISO 42001 across a broad portfolio, including Microsoft 365 Copilot, Foundry, and GitHub Copilot. Over the last year, we have simplified and strengthened our internal processes that support that certification.

Ultimately, responsible AI governance is a shared responsibility across the AI value chain. Our goal is to help make the practices and capabilities needed to meet that responsibility more accessible, practical, and scalable.

Shared practices and strong partnerships

The challenges of governing AI are bigger than any one company, and increasingly interconnected AI systems make collaboration even more essential.

As AI adoption expands across borders and sectors, we need shared expectations for how systems are evaluated, monitored, and governed, as well as interoperable standards that enable visibility into interactions across tools, data, and systems. We also need to keep advancing the underlying science and technical practices so that we can benefit from rigorous, applied insights into what effective governance looks like and where the remaining gaps are.

That starts with research. Over the past year, we advanced our work with the US Center for AI Standards and Innovation and AI Safety and Security Institutes in Australia, Singapore, and the UK to strengthen the science and practice of AI evaluation. We also launched an External Red Team Alliance with 18 universities across six continents to expand understanding of priority risks.

Common technical practices and standards are critical. Through the Frontier Model Forum, OpenTelemetry, and the Appia Foundation, we are helping develop approaches spanning frontier cyber benchmarks, end-to-end observability for increasingly agentic systems, and AI assurance across supply chains and sectors. We are also contributing to efforts that make transparency reporting more interoperable across organizations and jurisdictions, including through an OECD-led informal task force that developed the Hiroshima AI Process Reporting Framework version 2.0.

We also need shared ways to measure progress. We cannot meaningfully assess progress if every organization measures AI risks differently. Through our work with MLCommons, we are helping expand AILuminate into a broader suite of reliability benchmarks, creating common approaches for evaluating areas such as jailbreak resilience, multilingual performance, and psychosocial risk in conversational AI.

Shared learning, shared practices and standards, and shared measurement can help the entire ecosystem develop while raising shared expectations for trust.

Meeting the moment and investing for the future

Our experience over the past year has reinforced that responsible AI cannot be static. It has to be embedded in development processes, supported by practical tools, and continually informed by what we learn. That is why our responsible AI investments extend from the systems we build, to the tools we provide our customers, to the research, practices, and measurement approaches we help develop with the broader ecosystem.

Our 2026 Responsible AI Transparency Report explores this work in more depthβ€”from how we re-engineered our Responsible AI Standard to how we are strengthening governance for agentic AI, advancing evaluation, and addressing AI misuse. We invite you to explore the report to see what we have learned, what we have changed, and how we are putting our priorities into practice.

As AI becomes more powerful and more present in people’s lives, our commitment is to keep listening and learning, to keep strengthening our safeguards, and to keep putting the empowerment of people and organizations at the center of our strategy.

Β 

The post Responsible AI in 2026: How we are adapting for what’s ahead appeared first on Microsoft On the Issues.

House passes historic reforms to rein in secret surveillance

31 August 2026 at 23:24

Today,Β theΒ House of RepresentativesΒ passedΒ historicΒ legislationΒ thatΒ willΒ protectΒ ourΒ customers’ most fundamentalΒ privacyΒ rightsΒ in the cloud.Β TheΒ bipartisanΒ NDO FairnessΒ ActΒ (H.R.6048)Β wouldΒ require that federal courts apply a rigorous standard when issuingΒ non-disclosure ordersΒ (NDOs),Β orΒ secrecy orders, that preventΒ technology providers fromΒ tellingΒ customersΒ when law enforcement accessesΒ theirΒ emails, texts, photos, and other personal information in the cloud.Β Microsoft has strongly supported these reforms, andΒ theyΒ are consistent with ourΒ commitmentΒ to protect our customers and ensureΒ trust in the digital services that are powering theΒ global economy.Β Β The House’s passage of the NDO Fairness Act marks a significant step forward. We now look forward to working with the Senate to advance these important reforms.

The NDO Fairness Act would finally correct the glaring disparity between covert searches in the physical and digital worlds. Law enforcement must meet a strict standard for secret physical searches, but these restrictions do not apply to secret searches for data stored by technology providers. Instead, law enforcement can obtain boilerplate secrecy orders under a 40-year-old law, the Electronic Communications Privacy Act (ECPA), enacted before the cloud even existed. This represents a fundamental shift from historical lawΒ  enforcement practices where secrecy was the exception, not the norm. Officers or agents would knock on your door with a warrant or serve your company with a subpoena. If you had an issue with that, you could go to court to object. But NDOs, often obtained without meaningful judicial review, allow law enforcement to skip going to you and instead go to your cloud provider for your data in secret. Β 

This is a problemΒ with far-reaching consequences.Β The overuse of secrecy ordersΒ erodesΒ trust inΒ and discourages adoption ofΒ the cloud,Β stifles transparencyΒ and accountability, and threatens our fundamental freedoms.Β Notice isΒ perhaps theΒ most foundational protection against government overreach. It is necessary to give meaning toΒ nearly everyΒ other right we enjoy. This is becauseΒ it is a lot more difficult to assert your rights when youΒ don’tΒ know they are at risk to begin with.Β Β 

Two investigations, two administrations, one case for reformΒ 

In recent years, Congress has learned this lessonΒ firsthand. Microsoft first testified and began working with Congress in support of the NDO Fairness Act following reports in 2021 that the first Trump Justice Department used NDOs in a leak investigation that prevented notice of legal demands to Members of Congress, their staff, and the press. In aΒ subsequentΒ review, the Justice Department’s Inspector GeneralΒ foundΒ that the NDOs used boilerplate justifications that did not include case-specific information and did not even inform the court that some accounts belonged to Members of Congress. The NDOs were then renewed for yearsβ€”some even after the investigation wasΒ publicΒ and individuals were no longer targets.Β Β 

This isΒ despite the fact that, under our Constitution, Congress is a separate branch of government and has unique Speech or DebateΒ privileges, and the press is entitled to heightened First Amendment protections.Β 

Separately, a recent Senate investigation revealed that the Biden Justice Department’s β€œArctic Frost” probe of the 2020 presidential election sought telephone records from more than a dozen Members of Congress. As first disclosed by Senator Grassley and recently reported in theΒ New York Times,Β the subpoenas were accompanied by NDOsΒ that, again, didΒ not inform the judgeΒ of the factΒ that the phone numbers belonged toΒ Members of Congress.Β 

The NDOs in these two investigations illustrate a core problem with NDOs. And it’s a problem that spans administrations and extends well beyond investigations involving Members of Congress: Too often, courts are not aware of the most basic facts needed to evaluate whether total secrecy is necessary. Β 

Microsoft’s record: Standing up for our customersΒ 

This is why Microsoft, for years, has fought to strengthen our customers’ rights and has challenged unlawful secret surveillance.Β We’veΒ stood up for our customers not just in the halls of Congress, but in courts across the country and in daily negotiations with law enforcement. We routinely challenge NDOs and convince the government toΒ modifyΒ secrecy orders toΒ permitΒ notice to our customers. When weΒ can’tΒ reach a reasonable agreement with the government, weΒ don’tΒ hesitate to go to court.Β Microsoft is currentlyΒ seekingΒ toΒ modifyΒ or vacate several NDOs in courts across the country. While the details of these challengesΒ remainΒ under seal, this includes aΒ now-public appeal brought by LinkedIn, a Microsoft subsidiary, that is scheduled for oral argument before theΒ USΒ Court of Appeals for the Fourth Circuit onΒ September 15.Β 

Our efforts over the years have led to policy changes at the Department of Justice, includingΒ guidanceΒ limiting the duration of NDOs after MicrosoftΒ filedΒ a lawsuitΒ against theΒ USΒ government in 2016 challenging indefinite NDOs as unconstitutional.Β Β 

Sometimes, challenges to secrecy orders are unsealed, and we’re able to shareΒ additional details; most often, we simply provide ourΒ customers with notice, allowing them to take steps to further protect their rights.Β But these efforts, no matter how successful, have not stopped the flow of overbroad NDOs.Β Β 

TheΒ NDOΒ FairnessΒ ActΒ 

Challenges in court cannot do the work of Congress.Β We needΒ theΒ legislative reformsΒ contained in the NDO Fairness Act. TheseΒ would:Β Β 

  • End boilerplate secrecy orders byβ€―requiring judgesβ€―toβ€―consider theΒ full facts andΒ circumstances of each order.β€―Β 
  • Ensureβ€―that theΒ NDOΒ statute is consistent with the First AmendmentΒ byΒ requiring courts toΒ strictlyΒ scrutinizeΒ requestsΒ for secrecy.β€―Β 
  • Codify restrictions to preventΒ indefiniteβ€―secrecy ordersβ€―andβ€―limit the length ofΒ extensionsβ€―byΒ requiringβ€―time-limitedβ€―orders.β€―Β 
  • Recognizeβ€―technologyΒ providers’ statutoryβ€―rightβ€―to challengeβ€―anβ€―orderΒ to ensureΒ providers can stand up for theirΒ rights andΒ their customers’ rights.Β Β 
  • Increase transparencyΒ reportingΒ around the government’sβ€―use ofβ€―secrecy orders.β€―Β 

Theβ€―NDO Fairness Actβ€―would notΒ eliminateΒ NDOs. Nor should it. Temporary secrecy isΒ appropriate inΒ some casesβ€”particularly those involving child exploitation, terrorism or other violent crimes, nation-stateΒ cyberattacks, orΒ cases where there isΒ clear evidenceΒ that notice would jeopardize a sensitive investigation. Microsoft is a strong partner with law enforcement in its efforts to protect our nation and the most vulnerable members of society. But these reforms would ensure that NDOs are consistent with our most fundamental rights and freedoms.Β Β 

TheΒ SenateΒ mustΒ now seizeΒ the momentΒ 

Congress has madeΒ significant progressΒ advancing these reforms. I want to thank Speaker Johnson and Majority Leader Scalise as well as Representatives Fitzgerald and Nadler for scheduling a vote and sponsoring this legislation. House Judiciary CommitteeΒ ChairmanΒ Jordan and Ranking Member Raskin also deserve our appreciation for championing this legislation through the House committee process. As consideration moves to the Senate, we look forward to working with Senators Lee and Coons and supporting their leadership and efforts to enact this bill into law.Β Β 

Microsoft has fought for the NDO Fairness ActΒ becauseΒ weΒ stand up for our customers and will fight for their rights.Β I am thrilled to see bipartisan support for these reforms culminate in today’s House passage of this legislation. But the work is not yet finished. The Senate now has an opportunity to build on this momentum and help enact these critical reforms into law.Β 

Β 

Β 

The post House passes historic reforms to rein in secret surveillance appeared first on Microsoft On the Issues.

An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation

2 September 2026 at 12:00

Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks.

The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42.

Cybercrime at Machine Speed: Key Takeaways from Flashpoint’s 2026 Midyear Threat Intelligence Briefing

1 September 2026 at 16:37

Blogs

Blog

Cybercrime at Machine Speed: Key Takeaways from Flashpoint’s 2026 Midyear Threat Intelligence Briefing

Threat actors are no longer just using automation to execute tasks, they are leveraging prepackaged, safeguard-free AI, weaponizing stolen session data, and directly targeting defenders’ security stacks.

SHARE THIS:
Default Author Image
September 1, 2026

In our latest webinar, Flashpoint Vice President of Intelligence, Ian Gray, briefed security leaders on the evolving threat environment, providing critical insights from the Flashpoint Global Threat Intelligence Report (GTIR): 2026 Midyear Edition.

The threat landscape has developed at a striking pace with Flashpoint tracking over 22 million illicit AI discussions, 7.4 million compromised hosts yielding 1.7 billion stolen credentials, and over 21,600 disclosed vulnerabilities in just six months. Beyond these staggering numbers, the on-demand session detailed something even more alarming: a fundamental shift in adversary operational tradecraft.

Here are the five critical shifts every cyber threat intelligence (CTI), Vulnerability Management, and SOC team needs to know.

The Death of Signal: Threat Actors are Shifting to β€œPrivate AI”

The public discussion surrounding criminal artificial intelligence (AI) has reached a critical inflection point. Early in the AI boom, Flashpoint observed threat actors collaboratively experiment across underground forums, jailbreaking commercial frontier models or advertising surface-level tools like WormGPT and DarkGPT.

Today, adversaries are shifting from public forums to running fine-tuned, open-source models locally on private servers, which greatly hampers traditional signature-based detection. Flashpoint analysts are now seeing attackers generate unique, highly tailored malware variants, flawless phishing lures, and custom exploit scripts at extremely low costsβ€”completely offline and shielded from public monitoring.

β€œA few months ago, a lot of this was collaborative… public outsourcing. Now what we’re seeing is scarier: pre-packaged cybercrime models run locally on private infrastructure. Malicious code, exploit scripts, and targeted phishing are all being generated inside closed environments.”

Ian Gray, VP of Intelligence, Flashpoint

Weaponizing the Defender’s Own Tooling

Another eye-opening tactical insight shared during the session was how threat actors are repurposing defender infrastructure for automated initial access and extortion. In the webinar, we pointed to recent campaigns where adversaries specifically targeted misconfigurations and zero-day vulnerabilities inside open-source vulnerability scanners, secrets-detection tools, Kubernetes clusters, and Infrastructure-as-Code(IaC) environments.

What this means for defenders is that the attack surface is no longer bounded by traditional enterprise network boundaries: it extends directly into CI/CD pipelines, security orchestration tooling, and third-party SaaS integrations. Security teams are finding themselves in a race against attackers who use automated scanning scripts to weaponize vulnerabilities in the security tools themselves.

The Global Infostealer Threat and Identity-First Attacks

Flashpoint tracked 7.4 million hosts compromised by infostealers in H1 2026β€”a 27% increase period-over-periodβ€”harvesting 1.7 billion credentials and identity information.

While the top infostealer strains remain familiar, law enforcement operations have created vacuums that competitors rapidly fill.

map visualization

Threat actors are leveraging drive-by downloads, watering holes, and pirated software packages to plant stealers. Once a machine is compromised, the logs capture corporate SSO credentials, active browser cookies, VPN keys, and SaaS session tokens. This enables adversaries to simply log in without having to leverage complex technical exploits.

The Structural Failure of CVE/NVD and the Importance of KEV

The Common Vulnerabilities and Exposures (CVE) and National Vulnerability Database (NVD) have failed to keep pace with the velocity of AI-assisted vulnerability discovery. As such, vulnerability management teams are facing significant operational delays.

MetricFlashpoint GTIR Midyear H1 2026 DataOperational Impact
Total Disclosures21,667Remediation volume exceeds defender bandwidth.
Exploit Availability19% (4,015 CVEs)Functional code is ready before patches are deployed.
Public Catalog LagGrowing Backlog (NVD/KEV)Delay in official scoring leaves teams blind to active risk.

Therefore, waiting for NVD enrichment before prioritizing a patch is a dangerous strategy. To compensate, security teams require Vulnerability Intelligence (VI) that provides primary-source confirmation of weaponization, exploit availability, and actionable mitigation guidance long before public databases update.

Ransomware Evolution: From Encryption to Cloud Extortion

Ransomware-as-a-Service (RaaS) activity surged by 45% period-over-period, reaching 6,256 verified victim postings on data leak sites. However, total on-chain payout revenue dropped by 8% to $820 million, with victim pay-rates hitting a record low of 28%.

Faced with declining payouts and resilient enterprise backups, extortion syndicates are adapting. Rather than relying exclusively on technical file-encrypting malware, groups are executing pure data extortion campaignsβ€”frequently targeting cloud platforms or extracting data through third-party vendor access.

Protect Your Organization Using Flashpoint

Defending against machine-speed attacks requires moving beyond reactive, post-incident telemetry. Flashpoint arms security, CTI, and vulnerability management teams with the primary-source intelligence required to preempt adversary operations:

  • Unrivaled Deep & Dark Web Visibility: Flashpoint’s Primary Source Collection actively monitors closed criminal communities, illicit Telegram channels, and private forums, giving you early warning when threat actors build custom AI toolkits or trade credentials targeting your organization.
  • Comprehensive Vulnerability Intelligence (VI): Flashpoint tracks zero-days and vulnerability disclosures independently, delivering immediate exploit availability data and threat-informed prioritization so you patch what actually matters.
  • Continuous Compromised Credential Monitoring: Instantly surface exposed enterprise credentials, active session tokens, and stealer logs tied to your domain or third-party supply chain before they lead to an account takeover (ATO).

Request a demo, or watch the full on-demand webinar to explore the data shaping today’s risk landscape.

See Flashpoint in Action

The post Cybercrime at Machine Speed: Key Takeaways from Flashpoint’s 2026 Midyear Threat Intelligence Briefing appeared first on Flashpoint.

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety

29 August 2026 at 00:00

New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security.

The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.

The Evolution of Hacktivism in Hybrid Warfare: Modern Tactics and Real-World Impact

Blogs

Blog

The Evolution of Hacktivism in Hybrid Warfare: Modern Tactics and Real-World Impact

In this post we examine how modern hacktivism has evolved into a tool of global hybrid warfare, analyzing crowdsourced attack tactics, media-driven propaganda, and real-world impacts across Ukraine, the Middle East, European Union, and NATO nations.

SHARE THIS:
Default Author Image
August 26, 2026

Hacktivism used to be perceived as digital graffiti, with lone-wolf threat actors defacing government websites or temporarily crashing banking portals to make a political point. However, Flashpoint is tracking a fundamental shift in how these groups operate.

Modern hacktivism is evolving into a disciplined component of global hybrid warfare, capable of bridging digital disruptions with tangible real-world impact. Today, these operations blur the line between volunteer activism and coordinated state interest, leveraging crowdsourced infrastructure to disrupt critical utilities, manipulate media narratives, and target public infrastructure on a global scale. Unpacking these modern hacktivist collectives reveals what their tactics look like in practice and their far-reaching consequences across dozens of nations.

What is Hacktivism?

Hacktivism is the use of cyberattacks to promote or advance a particular political or social cause, leveraging a wide range of tactics such as website defacement, distributed denial-of-service (DDoS) attacks, and data breaches. Modern hacktivist collectives serve as the loud, high-visibility arm of cyber conflictβ€”frequently aligning with state geopolitical interests, as seen most prominently in recent pro-Russian operations and Iranian-aligned cyber campaigns.

These pro-Russian hacktivist groups, such as NoName057 and Killnet, alongside pro-Iranian collectives and proxy ecosystems like Handala Hack, often react to the news cycle and target countries designated by state media or ideological narratives as enemies. As such, modern hacktivist campaigns are opportunistic and tied to global eventsβ€”from the escalation in the Middle East following military operations like Operation Epic Fury, to the Milan-Cortina Winter Olympics and new aid packages to Ukraine. These groups’ justification narratives typically mirror state messaging.

Modern Tactics: Gamifying Cyber Warfare

In tracking modern hacktivist groups, Flashpoint analysts identified a new method these groups are utilizing to convert ordinary devices into tools for hybrid warfareβ€”the gamification of cyberattacks. Flashpoint has observed groups like NoName057 turning DDoS attacks into community-based β€œpatriotic online games,” such as their β€œDDoSia Project,” with participants earning military-style ranks and cryptocurrency rewards for overloading the websites of government institutions, banks, and various infrastructure across various countries.

This model has enabled the scaling of operations by utilizing a large, low-skilled participant base rather than having to rely on sophisticated technical tradecraft. The model’s decentralized structure and ideological appeal continue to pose a significant challenge for international law enforcement.

The Propaganda Engine: Media Amplification and Validation

Beyond technical disruptions, publicity is the primary currency of modern hacktivism. Hacktivist groups demonstrate a consistent pattern of media-seeking behavior and self-promotion, likely intended to amplify their perceived impact and reinforce notoriety within the broader cyber threat landscape. Many of these groups repeatedly repost media coverage and news articles referencing themselves.

This serves as a curated self-promotion mechanism, allowing the group to selectively showcase external validation of its operations, including coverage from mainstream and security-focused outlets, to its followers. This behavior aligns with a broader trend observed with especially pro-Russian hacktivist collectives, in which media visibility is treated as a measure of operational success independent of verified technical impact. It also serves as a deliberate tactic for engagement and recruitment that reinforces β€œpatriotic” branding and sustains participant morale and visibility.

Beyond Propaganda: Aligning Cyber Disruption with Military Objectives

In some cases, the digital targeting of hacktivist collectives is more aligned with kinetic objectives, rather than public perception or propaganda initiatives. This is especially true for Iranian-aligned hacktivists and proxy groups who are more deeply intertwined with military operations in the Middle East. These groups have expanded their operations from website disruptions into claims of large-scale data wipers, extortion, and cyberattacks targeting key infrastructure across the Gulf.

The Far Reach of Modern Hacktivism

Major geopolitical flashpoints in the Middle East have triggered waves of hacktivist activity that has spread across North America, with threat actors targeting supply chains, financial infrastructure, and operational technology and control systems.

Simultaneously, pro-Russian hacktivist groups, particularly NoName057, have been extremely prolific within the last yearβ€”carrying out two major illicit campaigns heavily targeting Ukraine, which then spilled over to more than 30 nations globally. The following breakdown contains statistics and targeting dynamics of pro-Russian hacktivist groups observed between July 2025 and 2026:

Country-level targeting derived from Flashpoint intelligence. (Source: Flashpoint, graphic generated by Claude)

The Continuous Campaign Against Ukraine

Ukraine has been the primary target for pro-Russian hacktivist groups who seek to damage Ukrainian infrastructure and morale. Anti-Ukrainian content is constantly distributed through dedicated per-language channels, making it the most linguistically developed target spanning six languages. Involved channels each post near-identical translated content within minutes to hours of the Russian original, down to the same image file with identical SHA1 hashes, which suggests a sustained propaganda distribution operation.

This has resulted in alleged data breaches impacting Ukrainian General Staff, military enlistment offices, medical, and morgue databases to push a casualty-count narrative. It also has resulted in the defacement or disruption of websites of regional capitals and administrative centers, energy plants, water and power-adjacent infrastructure, and many more.

Spilling Over: Impact Across EU and NATO Allies

However, Ukraine is not the sole casualty of modern hacktivism. Recent pro-Russian hacktivist campaigns have spread to other EU nations and NATO members. Germany, the United Kingdom, and Spain have been observed to be priority targets, with threat actors targeting public transportation, federal and security agencies, municipal government and utilities, financial markets, and other infrastructure. In some cases, hacktivist campaigns manifest in the real-world, with physical sticker drives on municipal streets, alongside doxxing operations releasing alleged personal data and automated scans hijacking exposed CCTV camera systems across Europe.

Physical sticker campaigns (NoName057) in Spain identified by Flashpoint

Defend Against the New Wave of Hacktivism Using Flashpoint

As hacktivist operations continue to blur the boundary between digital disruption and real-world interference, organizations can no longer view DDoS attacks or low-level intrusions as simple background noise. Protecting critical assets requires proactive visibility into threat actor networks, early detection of targeting narratives, and primary source threat intelligence.

Request a demo today to see how Flashpoint provides actionable intelligence to help security teams, government agencies, and infrastructure providers identify, monitor, and mitigate emerging hacktivist campaigns before they impact operations.

See Flashpoint in Action

The post The Evolution of Hacktivism in Hybrid Warfare: Modern Tactics and Real-World Impact appeared first on Flashpoint.

❌