The European Union Agency for Cybersecurity (ENISA) warned in a recent report that hacktivists are increasingly adopting cybercrime tactics. This comes as DDoS and ransomware attacks pose the greatest threats to EU member states. Geopolitical tensions, particularly relating to the Ukraine conflict, have led to an increase in these attacks.
Important findings
- DDoS attacks and ransomware are the most common threats to the EU.
- State-backed hacktivists are the most active actors behind DDoS attacks.
- Geopolitical tensions, especially since Russia’s invasion of Ukraine, have intensified cyberattacks.
- Ransomware is increasingly used by hacktivists to raise awareness of political concerns.
Rise of Cyber Attacks
Between July 2023 and June 2024, ENISA observed a "significant escalation" of cyberattacks. The agency noted that DDoS attacks are the primary threat affecting all sectors. Ransomware attacks and privacy-related threats come second.
The Role of Hacktivists
State-aligned hacktivist groups are the most active threat actors behind DDoS attacks. ENISA attributes the increase to geopolitical tensions triggered by Russia’s invasion of Ukraine in 2022. Groups such as NoName057 and the Russian Cyber Army are particularly active, carrying out DDoS attacks against EU agencies.
Geopolitical Events as Catalysts
The upcoming EU elections in June and the Olympic Games in Paris in July have also led to an increase in DDoS attacks as attackers try to disrupt processes.
Ransomware and political concerns
In the field of ransomware, financial theft is the main driver. However, some hacktivist groups use ransomware to raise awareness of their political concerns. ENISA warns that hacktivists will increasingly adopt cybercrime tactics, often with direct or indirect support from state-aligned groups.
Active ransomware groups
LockBit was one of the most active ransomware groups until its disruption by law enforcement in February. Other active ransomware-as-a-service groups targeting EU organisations are Clop and Play.
Conclusion
ENISA’s warning highlights the growing threat posed by the link between hacktivism and cybercrime. The Agency stresses the need to prepare for these new threats and to take appropriate measures to ensure the security of EU Member States.
Sources
- ENISA Warns About Hacktivist, Ransomware Crossover, BankInfoSecurity.



