Hacktivism is an underestimated threat, especially in geopolitical crises
23 Jun 2026|

Hacktivists, while individually unsophisticated, are collectively generating persistent disruption, particularly during geopolitical crises. Their impact is being amplified by a wider accessibility of tools, faster mobilisation and alignment with real world events.

Cybersecurity experts and organisations need to take these actors much more seriously, detect their initial disruptions and treat those actions as precursors to more serious threats.

Since 2022, there has been a consistent surge in cyber activity during kinetic conflicts, geopolitical crises and regional tensions. Amid the ongoing Middle Eastern conflict, more than 149 hacktivist incident claims were recorded over a three-day period against governments, financial institutions, telecommunications and critical infrastructure.

Significantly, a large proportion of such disruption originates from loosely organised rudimentary cyber threat actors, known as hacktivists. These people, individually or in groups use hacking or disruptive cyber activity to promote a political, social, or ideological causes. An example in March in Australia was denial-of-service efforts linked to the Iran-Israel-US conflict and affecting a prominent Zionist foundation and Victoria Police.

The cybersecurity industry often dismisses hacktivists due to their informal communication style, lack of technical sophistication and long history of exaggerated claims. This is an analytical blind spot.

In detecting hacktivist disruptions, we can look out for some common characteristics. One is their informal communication methods. Also, they often have broken English, chant ad-hoc ideological slogans, conduct provocative messaging and post offensive memes. They make exaggerated claims of perceived compromise, which reduce their credibility. In February 2026, a pro-Russian hacktivist collective claimed access to an Australian wastewater treatment plant and irrigation management system, alleging they could manipulate pump readings and alarms without detection. Analysts should not dismiss these as clutter, noise or nuisance activity while solely focusing on high-end threats or advanced persistent threats. They should be aware that informality does not equal incapacity.

One reason to focus on informal activity is the surge in the availability of low-barrier, offensive capabilities online since 2022. These include denial-as-a-service platforms, public exploit kits, credential stuffing tools and open-source attack frameworks. Most problematically, using these tools and methods requires minimal technical skill. At the same time, hacktivists are improving their skills thanks to the increasing availability of generative AI.

These changes have resulted in a huge shift in threat modelling, and organisations now need to broaden their threat landscape horizons. They need to counter a surge in hacktivism as capability is commodified, participation surges, the barrier to entry lowers and the scale of activity increases.

Analysts should take note of the clear temporal alignment between geopolitical crises and surges in hacktivist activity. This pattern has been especially visible since February 2022 with the Russian and Ukraine conflict, which significantly increased the number of pro-Russian hacktivist groups targeting Ukrainian and allied infrastructure. This includes denial-of-service campaigns against government and critical services, website defacements tied to political messaging, data leaks framed as retaliation or ideological support, and recruitment drives for hacktivist collectives. These are driven by ideological alignment, nationalistic sentiment and opportunistic visibility. In these cases, hacktivists operate as ad-hoc digital militias mobilising rapidly in response to events, showing that they are reactive, but predictably so.

This makes hacktivist monitoring an early-warning function. It could include tracking Telegram mobilisation, campaign hashtags, target lists, denial-of-service claims, defacement posts and recruitment calls. These can all help identify likely targets before disruption occurs, allowing organisations to pre-position denial-of-service protection, harden exposed services, prepare communications and distinguish genuine compromise from inflated propaganda claims.

The challenge for observers is that the relationship between hacktivists and advanced persistent threats are shady at best. There is an indirect influence of narratives and target selection, opportunistic alignment with state interests and signal amplification of state-linked campaigns. This in turn adds volume and noise to the threat landscape, providing plausible deniability for state actors resulting in greater strategic effect. An example of this is a pro-Russian hacktivist group who claimed to support Russia’s position in Ukraine. A joint international advisory assessed that Russia’s GRU Unit 7445 likely supported its creation in 2022 and funded tools used by the group for denial-of-service activity until at least September 2024. The hacktivist group then used Telegram to organise attacks, claim responsibility for disruption against states supporting Ukraine, share ideological messaging, and publicise leaked information from hacks attributed to Russian state actors. Hacktivists are not advanced persistent threats, but they operate within an ecosystem shaped by advanced persistent threats.

Effect does not require deep compromise in the traditional sense but can include opportunistic intrusion, which sets conditions for potential digital footholds within target infrastructure. As we know, critical-infrastructure entities have a higher reliance on availability of their services, and, more often than not, they tune for sophisticated threats, not opportunistic mass disruption. But consequences of hacktivism can include erosion of public confidence, and operational degradation during sensitive time periods. Disruption at scale can rival more sophisticated intrusions and impact.

So how should cybersecurity experts, business owners, incident responders and risk owners respond? They need to consistently monitor open-source social media platforms, such as Telegram and X, to detect early indicators of mobilisation and early-stage activity as a potential precursor, not noise. They need to threat-model beyond advanced persistent threat-centric frameworks and include mass participation scenarios and coordinated low-skill campaigns in what they prepare for. They need to integrate cyber and geopolitical intelligence in risk analysis processes.

More broadly, they should assume hacktivist disruptions will occur and prioritise denial-of-service mitigation capabilities, redundancy, incident response speed and public communication readiness. Taking the hacktivist threat seriously requires a complete mindset shift.

The risk is not that these actors become more sophisticated, but that their simplicity, accessibility and scale continue to be underestimated. Cyber contestation should no longer be defined solely by elite operators but by the collective action of many.