Skip to main content

The Story This Month

Critical infrastructure is firmly in the crosshairs: this period delivered a landmark Iranian cyberattack on British soil, a sustained hacktivist blitz that hammered Romanian government services, and 1,268 recorded incidents spanning ransomware, mass data theft, and relentless DDoS campaigns worldwide.

Stephen Green
Stephen Green

Threat Intelligence Lead | Cyber Risk

sgreen@thomasmurray.com

By the Numbers

  • 1,268 total attacks recorded globally over the 30-day period
  • 456 incidents categorised as data leak or exfiltration, making it the single largest attack category this period
  • 421 ransomware incidents, confirming encryption-based extortion remains a dominant and growing threat
  • 83 attacks attributed to NoName057(16), cementing its position as the most prolific threat actor for the second consecutive period
  • 315 attacks targeted the United States, accounting for roughly one in four of all recorded incidents worldwide
  • 54.1% period-on-period drop in total recorded attacks, reflecting a sharp contraction from the prior period's 2,761 incidents

What Changed

CategoryThis PeriodPrior PeriodChange
Total Attacks1,2682,761-54.1%
No. 1 Threat ActorNoName057(16) (83 attacks)NoName057(16) (195 attacks)Volume down 57%, rank held
No. 1 CountryUnited States (315 attacks)United States (506 attacks)Volume down 37.7%, rank held
No. 1 SectorProfessional and Technical Services (263 attacks)Professional and Technical Services (625 attacks)Volume down 57.9%, rank held
No. 1 Attack CategoryData Leak / Exfiltration (456)Data Leak / Exfiltration (1,272)Volume down 64.1%, rank held

The headline number demands context. A 54.1% drop in recorded attacks against the prior period does not signal a quieter threat environment. The top ranks held with striking consistency: the same leading threat actor, country, sector, and attack category occupied first place in both periods. What changed was volume, not composition. The threat landscape compressed rather than transformed.

The most meaningful shift sits at the category level. Data leak and exfiltration retained its top position, but ransomware's share of the total actually grew proportionally, climbing from roughly 26.5% of all prior-period attacks to 33.2% this period. DDoS activity also maintained a significant presence with 283 incidents, despite the overall volume drop. Hacktivist groups driving DDoS campaigns, particularly NoName057(16) and Dark Storm Team, kept up sustained pressure on European targets even as total incident counts fell.

Country-level shifts reveal an interesting reshaping of the target map. Romania surged to second place this period with 111 attacks, up from outside the prior period's top ten. France slipped from second to third, whilst Germany and Thailand, which ranked third and fifth previously, dropped entirely out of the top ten. Romania's rise is almost entirely DDoS-driven, with 104 of its 111 incidents in that category, reflecting a focused hacktivist campaign against Romanian government and public services infrastructure. Meanwhile, the emergence of Niue in fifth position, driven largely by CL0P ransomware activity, is a statistical artefact of attackers using offshore-registered domains rather than a genuine geographic concentration of victims.

Notable Incidents

Ukraine: Asset Recovery and Management Agency (ARMA)

Ukraine's Asset Recovery and Management Agency was struck twice within 24 hours in mid-August, with separate incidents recorded on 18 and 17 August. The second incident was classified as unauthorised access, suggesting attackers retained a foothold after initial intrusion. The targeting of a state agency responsible for managing seized assets carries clear geopolitical significance.

University of Texas at San Antonio

A data breach at one of the United States' largest public universities was confirmed on 16 August, placing sensitive personal data at risk. Higher education institutions continue to attract data-theft actors owing to the volume of research, financial, and student records held on-network. This incident fits a broader pattern of academic sector targeting visible across the period.

Douglas County Sheriff's Office

A cyber incident at the Douglas County Sheriff's Office, reported on 14 August, illustrates the growing pressure on US law enforcement agencies. Attacks on police and justice bodies carry unique risks, including exposure of sensitive case files, informant records, and personal data belonging to both staff and the public.

Administration de l'État de Berlin (Berlin State Administration)

Germany's Berlin state administration suffered an unauthorised access incident on 15 August, with attackers gaining entry to government systems. The incident highlights continued pressure on European public sector bodies and echoes a broader trend of nation-state and opportunistic actors probing government networks across the continent.

Ryomo Systems, Japan

Japanese IT systems integrator Ryomo Systems confirmed a data breach or exfiltration event on 14 August. Attacks on technology and systems integration firms are particularly consequential given the downstream access such companies hold into client networks, making them high-value targets for both espionage and ransomware-affiliated actors.

Recent Headlines

Bottom Line

The consistency of the threat landscape, with the same actors, sectors, and attack types dominating period after period, tells its own story: attackers have found a formula that works and they are not changing it. Critical infrastructure attacks are escalating from aspiration to execution, as the UK power plant incident confirms. Organisations that treat cyber resilience as a compliance checkbox rather than an operational priority are already behind the curve; the question is not whether they will be targeted, but when.

Sector by Country

SectorUnited StatesRomaniaFranceIsraelMexicoIndonesiaIndiaSpain
Professional and Technical Services284218282221319
Manufacturing3029732263
Real Estate Activities2711863060
Mining and Quarrying387530313
Wholesale and Retail Trade3011260012
Arts, Entertainment and Recreation380246051
Human Health and Social Work32764751
Financial and Insurance Activities150221520

Romania's Professional and Technical Services sector recorded the highest single cell in the matrix with 42 attacks, driven almost entirely by the hacktivist DDoS campaigns of NoName057(16) and Dark Storm Team targeting Romanian professional and government-adjacent services.

Cyber Risk

Threat Intelligence Reports

Our custom cyber threat intelligence reporting delivers strategic, operational, and tactical insights tailored to your organisation's unique needs. We help organisations understand and address specific threat landscapes across industries and geographies through detailed, actionable reports, enabling informed decisions to safeguard operations at all levels.

Learn more