惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
G
Google Developers Blog
Hugging Face - Blog
Hugging Face - Blog
博客园 - 【当耐特】
S
SegmentFault 最新的问题
宝玉的分享
宝玉的分享
博客园 - Franky
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
WordPress大学
WordPress大学
有赞技术团队
有赞技术团队
月光博客
月光博客
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
小众软件
小众软件
Microsoft Security Blog
Microsoft Security Blog
Last Week in AI
Last Week in AI
Vercel News
Vercel News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
爱范儿
爱范儿
J
Java Code Geeks
博客园 - 叶小钗
Engineering at Meta
Engineering at Meta
阮一峰的网络日志
阮一峰的网络日志

Check Point Blog

Reading the Signals in the OWASP LLM Top 10 2026 - Check Point Blog Ransomware Didn't Slow Down in Q2 2026. It Just Spread Out. - Check Point Blog July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens - Check Point Blog State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit - Check Point Blog Lazarus Hackers Exploit Windows Zero-Day in Fake Job Scam Native AI Security Comes to Claude: Why Anthropic's Inference Hooks Matter - Check Point Blog Claude AI Security: How Anthropic Inference Hooks Enable Real-Time Protection The Top Exposure Management Questions Security Leaders Ask (Part 1) - Check Point Blog Black Hat 2026: Check Point Research Takes the Stage - Check Point Blog Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security - Check Point Blog Three AI security disclosures, fourteen days: what the warnings signs are telling us - Check Point Blog When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context - Check Point Blog Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance - Check Point Blog Check Point Named a Visionary Leader in the 2026 Frost Radar™ for Enterprise Risk Mitigation and Management Platforms - Check Point Blog AI Escaped a Sandbox. That is Not What Should Worry You - Check Point Blog Introducing the Industry's First AI Network Firewall - Check Point Blog Attackers Are Turning Microsoft's Trusted Login System Into Their Latest Phishing Weapon - Check Point Blog AI Agent Security Just Had Its Catalyst Moment - Check Point Blog Your AI Governance Policy Should Survive Your Next Model Change - Check Point Blog The Branding and Attribution Behind Cybercrime - Check Point Blog Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report - Check Point Blog Security Advisory - Action Required - July 2026 Security Update - Check Point Blog What the 2026 Exposure Gap Report Reveals About Remediation - Check Point Blog Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention - Check Point Blog The State of Hybrid SASE: Built-In vs. Bolted-On - Check Point Blog AI Appreciation Day: Let's Be Honest About What We're Appreciating - Check Point Blog AI Security Is Never Finished: Building the Continuous Red Teaming Loop  - Check Point Blog AI Security Threats in 2026: Annual Insights from Check Point Research - Check Point Blog AI Agents are Only As Effective as Their Harness - Check Point Blog Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security - Check Point Blog How Check Point Email Security Stopped a Student Job Scam Before It Reached the Inbox - Check Point Blog Redefining the CISO Contract: From Securing the Business to Securely Doing Business - Check Point Blog
Hacktivists, Ransomware, and a 124% Surge Across DACH
lizwu@checkpoint.com · 2026-05-18 · via Check Point Blog

Hacktivism and ransomware targeting organizations across Germany, Austria, and Switzerland increased 124% in 2025, according to Check Point Exposure Management (based on published attacks on the web and dark web). Three distinct dynamics drove the surge, each with its own logic and its own implications for security teams in 2026. 

Germany Absorbed Most of It 

Germany accounted for more than 80% of regional incidents, with Switzerland at 12% and Austria at 8%. Across Europe, the DACH region represented 18% of all recorded attacks, placing Germany above France, Spain, and Italy by individual country share. 

The concentration reflects Germany’s economic and political profile. As one of the EU’s largest economies and a significant contributor to Ukraine-support efforts, it sits at the intersection of financial targeting and geopolitical signaling, two of the primary motivators behind 2025’s attack activity. 

  • Germany: 82% of DACH incidents 
  • Switzerland: 12% 
  • Austria: 8% 
  • DACH as a share of European incidents: 18% 
Hacktivists Dominated by Volume 

Defacement was the leading attack type in the region at 66% of incidents, driven almost entirely by hacktivist groups using website vandalism to amplify political messaging. NoName057(16), a pro-Russian collective focused on DDoS and web disruption, was among the most active throughout the year. Groups including Mr Hamza, chinafans, Dark Storm Team, and Hezi Rash contributed sustained defacement and DDoS activity against public-facing services. 

These campaigns were built for speed and visibility, hitting publicly accessible targets, claiming the activity on Telegram, and moving on. The volume they generated was significant: the region’s highest monthly attack figures coincided directly with periods of elevated hacktivist activity, particularly July and August following the Operation Eastwood law enforcement action against NoName057(16) infrastructure. 

What makes hacktivist activity difficult to plan around is its responsiveness to external events. A regulatory action, a political statement, or a law enforcement takedown can trigger a coordinated retaliation campaign within hours. 

Ransomware Groups Kept Steady Pressure On 

While hacktivists dominated by volume, ransomware accounted for nearly 30% of incidents, making it the most significant financially motivated threat in the region. Three groups were particularly active. 

  • Akira has operated since 2023 and targets Windows and Linux environments, frequently exploiting organizations without MFA in place. Researchers have identified tooling overlaps with the former Conti ecosystem
  • Qilin, originally known as Agenda, runs a RaaS model using a Rust-based cross-platform encryptor. It combines data theft with encryption and maintains a dedicated leak portal for extortion pressure
  • Safepay is an emerging double extortion group active since 2024, operating across dark web and TON-based channels. It exfiltrates data before encrypting and pressures victims through leak site publication

All three followed similar initial access patterns: compromised credentials, exposed remote access services, and unpatched enterprise platforms. Identity weaknesses were the common thread, not zero-days or novel techniques. 

Organizations that enforced MFA consistently, maintained patching discipline on internet-facing systems, and monitored for credential exposure were meaningfully harder targets. 

What to Do With This 

The 2025 data points to a straightforward set of priorities. Hacktivist exposure is largely a function of how much publicly accessible attack surface an organization presents, and how quickly anomalies on those surfaces get detected. Ransomware exposure comes down to identity hygiene, patch cadence, and whether credentials are being monitored across the open and dark web before they get used against you. 

Check Point Exposure Management tracks threat actor activity, IOCs, and attack surface exposure continuously, giving security teams the context to act on threats like Akira, Qilin, and NoName057(16) before they become incidents. The IOCs for all groups covered in the 2025 DACH report are available in the Threat Actor Intel Module. 

For complete threat actor profiles, sector breakdowns, and indicators of compromise, read the full report