
Like any research team a lot of our work emerges from pulling on threads. It’s curiosity that surfaces interesting questions and novel findings – the kind of work that really furthers our understanding of an issue. Over the last few years ,we’ve been pulling on several threads that all were eventually revealed to be connected. It started with an investigation of hacktivism, and has developed into a study of cognitive threats and impacts. We’ve spoken and published a lot on these issues separately, so we felt it might be time to pull those threads together to illuminate the bigger picture we see emerging. What follows is the story of how one line of thinking grew into something substantially larger than where it started.
The starting point was a recognition that something had changed in the threat landscape in a measurable way. Following Russia's 2022 invasion of Ukraine, hacktivist activity surged. But this was not the hacktivism of the 2000s, where Anonymous and LulzSec targeted governments and corporations out of ideological opposition. These new groups were supporting established state power.
The 2024 Security Navigator chapter - "Hacktivism: Victims & Impact" - documented this shift. Groups like Anonymous Sudan and NoName057(16) were executing campaigns that tracked closely with geopolitical developments: Ukraine support announcements, NATO summits, European elections. NoName057(16)'s attack patterns correlated almost proportionally with the level of military support their targets were providing to Ukraine.
But the more important insight was about what the attacks were for. A hacktivist group that temporarily disrupts a Swedish government website is not trying to disable the Swedish government. It is trying to create fear, uncertainty, and doubt - to make ordinary people wonder whether their institutions can protect them, and whether supporting Ukraine is worth the cost.
Anonymous Sudan amplified the fear and uncertainty surrounding the Quran-burning crisis, and contributed to decisions in Sweden to adopt a higher terrorist threat level and to legislative changes in Denmark’s – exacerbating the broader security and diplomatic crisis. The technical impact was modest but the impact on society was real.
Modern hacktivism is primarily a cognitive weapon, not a technical one. Its real output is not disruption - it is perception.
Hacktivism today: What three years of research reveal about its transformation
Hacktivism has shifted: the days of the idealistic, anti-authoritarian grass-roots movement are over. State-sponsoring and extremism dominate the scene now.
Europe top target for hacktivism, with groups shifting focus to cognitive warfare?
Orange Cyberdefense has released its sixth annual security research report, the Security Navigator 2025. The report uses extensive data analysis to provide a detailed view of the cybersecurity landscape, shaped by geopolitical conflict and the increasing sophistication of threat actors.
The 2025 Navigator chapter provided the most comprehensive open-source study of hacktivist communications. Over two years, a major pro-Russian Telegram channel was scraped, revealing 3,214 messages and 6,674 verified targets in 42 countries—96% in Europe, averaging 280 targets monthly. The data showed organized patterns: attacks rose and fell in response to political events. Farmer protests and elections in Europe, as well as the G7 summit, triggered coordinated attacks on government and transport websites. Hacktivist activity clearly operated as a rapid trigger-response to geopolitical events.
The chapter introduced a three-era framework: Digital Utopia Era (1980s–2000s, idealism), Anti-Establishment Era (mid-2000s, disruption), and Establishment Era (post-2014, state alignment). Now, hacktivists serve state interests. Importantly, 2025 research found hacktivists targeting operational technology like water plants and power grids. As societies adapt to attacks, hacktivists escalate to maintain psychological impact—a dynamic called "chasing the dragon."
With the empirical foundation established, a natural next question arose: how should analysts and policymakers actually classify these actors? Existing frameworks - "hacktivist," "cyber proxy," "cyber militia," "digital resistance movement," "cyber terrorist" - each captured something, but none captured the full picture.
The From Protest to Power Plant paper, submitted to the Journal of Cyber Policy, addressed this gap with the Cyber Alignment-Responsibility-Impact Spectrum (CARIS). Rather than forcing hacktivist groups into binary categories, CARIS treats three dimensions as continuous scales:
The result is an analogue framework that can accommodate both a civic hacker collective like the Chaos Computer Club and an IRGC-affiliated group conducting cyberattacks on water infrastructure. It can also track how a group's position shifts over time as new intelligence emerges.
Cognitive impact of the Iran war Blogpost
Cyberattacks linked to the 2026 U.S.–Israel–Iran conflict offer a useful way to understand the much wider threat of hacktivism and its cognitive impact. This is not a geopolitical assessment or a comprehensive threat-actor analysis. Our focus is the future role of Iranian state-aligned, or “Establishment,” hacktivists. We expect these groups to remain significant during the conflict and long after it ends.
With the frameworks in place, the Iran conflict provided a live test. Iran's strategic culture is a product of decades of asymmetric conflict experience: the Iran-Iraq War, the Tanker War, the JCPOA collapse, the killing of Soleimani. From this history emerged a doctrine centred on asymmetric, proxy-mediated, below-threshold pressure - what analysts describe as Sacred Defense and Forward Defense.
Crucially, Iran does not understand cyberspace as a technical domain. It understands it as a socio-political and cognitive space where culture, identity, and regime legitimacy are continuously contested.
The blog made two contributions that crystallised earlier thinking. First, it explained why hacktivism will persist as a structural feature of Iran's strategy, not an episodic crisis response. Second - and most consequentially - it introduced the "means follows the message" insight: because hacktivist attacks are designed to generate narratives rather than achieve specific operational objectives, any organisation that can plausibly be coopted into the adversary's story becomes a potential target.
Join Orange Cyberdefense and Charl van der Walt for a thought-provoking discussion exploring how disinformation and cognitive threats are becoming material business risks, and what organizations can do to address them.
This webinar gives a thorough review of the cognitive impact that is caused by disinformation campaigns, aiming to disrupt not only businesses but entire populations and civic society in general.
The whitepaper "Hacking the Human Layer" brings everything together - and then goes further. It takes the insight that hacktivism is a cognitive weapon and generalises it: all cyber attacks produce cognitive effects, regardless of the attacker's primary intent.
The Okta breach in 2023 - technically bounded to a limited subset of a support system - wiped roughly $2 billion from the company's market capitalisation. Shandler & Gomez's research on the 2020 Düsseldorf Hospital ransomware attack showed that simply being aware of the attack reduced confidence in government institutions, even among people who were not directly affected.
What to expect from the paper:
This offers essential guidance on how to prepare for and counter cognitive impacts in an age where minds are much more the target than just technology.