Hacktivism, 2021 to Today: From Steel Mills to Power Grids
Part 1 ended on a 70-gigabyte breach in 2021. Since then, hacktivists derailed trains, dumped molten steel on camera, and reached grids in three countries.
Part one of this series closed on the Gab breach in February 2021, seventy gigabytes of user data pulled out by a single attacker and handed to DDoSecrets for safekeeping, a large leak by the standards of that decade, but still, at bottom, a website getting broken into and its database walking out the door. Pick the story back up from that point and run it to today, and the ceiling on what a hacktivist operation can accomplish has moved further than it moved across the entire previous decade combined. A hacktivist collective has slowed real trains carrying real troops. A group claiming ideological motive has caused an industrial furnace to dump molten steel across a factory floor on camera. By 2025, hacktivist-branded groups were routinely reaching into the guts of water treatment plants, power substations, and dams, sometimes successfully, sometimes into a trap built specifically to catch them. And the label "hacktivist" itself has become something at least two governments now wear as a costume, which means the oldest question in this movement, who's behind the keyboard, matters more than it ever has.
This piece picks up exactly where Part 1 left off, February 2021, and runs the technical record forward to today, August 2026.
Crowdsourcing Reaches Industrial Scale
Two days after Russia's February 2022 invasion began, Ukraine's Vice Prime Minister and Minister of Digital Transformation, Mykhailo Fedorov, publicly called for volunteers to join what he named the IT Army of Ukraine, coordinated through a Telegram channel that grew to hundreds of thousands of subscribers within its first weeks. The model is the direct descendant of Operation Payback's crowdsourced DDoS approach from 2010, run at a scale and with a level of state endorsement LOIC's volunteers never had: rather than a loose IRC channel run by an anonymous operator, this is a government minister publishing a daily target list to an army of self-selected participants, largely aimed at Russian government sites, banks, and state media, with occasional pivots toward more targeted operations against specific infrastructure.
What makes the IT Army worth treating as a distinct case rather than only LOIC with better branding is the openness of the state relationship. Fedorov's ministry didn't merely tolerate the effort; it launched it, and continued publicly promoting participation throughout the war's opening year. That's a meaningfully different structure than Anonymous forming spontaneously out of 4chan, or Killnet claiming grassroots Russian sympathies while drawing scrutiny for state ties. The IT Army is openly, admittedly state-adjacent hacktivism, which raises its own question this movement hasn't had to answer before: once a government is directly organizing volunteer cyberattacks against another state, is "hacktivism" still the right word, or has the term become a convenient label for irregular warfare fought with civilian participants instead of soldiers.
When Hacktivists Inherites Ransomware Code
The strangest technical wrinkle in this entire five-year window belongs to NB65, Network Battalion 65, an Anonymous-affiliated group that pledged support for Ukraine within days of the invasion and spent its first month running conventional hacktivist operations: breaching Russian organizations, including the state broadcaster VGTRK, from which the group claimed to exfiltrate more than 780 gigabytes of data, roughly 900,000 emails among it, later published through the same DDoSecrets infrastructure that hosted the Gab breach data covered in Part 1. Targets accumulated quickly: Roscosmos, the Russian space agency; Tensor, a document-management operator; a scientific research institute in Ufa; a regional gas utility.
Then, in April 2022, NB65 did something no hacktivist group had attempted at this scale before: it started deploying ransomware built from another criminal group's own leaked source code. Weeks earlier, Conti, one of the most prolific ransomware-as-a-service operations in the world, had publicly pledged support for Russia's invasion, a statement that prompted a Ukrainian-aligned researcher with inside access to leak Conti's internal chat logs and, critically, its ransomware source code onto the open internet. NB65 took that code, and per analysis from the security firm Intezer, built a variant that retained roughly two-thirds of the original Conti codebase while modifying the encryption process specifically so that any decryptor Conti itself might later offer a victim, since Conti had sided with the invading country, wouldn't work against NB65's version. The result carried a new extension, .NB65, on every encrypted file, and a customized ransom note blaming Vladimir Putin directly for the war rather than demanding payment as its primary goal. NB65 stated its rules of engagement publicly and stuck to them for the roughly six months the group remained active: Russian targets only, no operations outside Russia, and a stated intent to stop entirely once the invasion ended.
That's a new category of technical behavior for this movement. Every earlier case study in this series involved hacktivists finding and exploiting vulnerabilities themselves, HBGary's SQL injection, the phpBB and vBulletin architecture failures covered elsewhere on this site, or organizing volunteers around a simple flooding tool. NB65 instead inherited a fully weaponized criminal toolchain, built by a professional ransomware operation for profit, and repointed it at a political target with only modest technical modification. The line between "hacktivist collective" and "ransomware gang" had never been thinner, and it's a line worth watching, because the barrier to running a ransomware operation dropped considerably for the next group with a cause and access to somebody else's leaked source.
Hacktivism Learns Restraint
The Belarusian Cyber-Partisans formed in September 2020, in the aftermath of Alexander Lukashenko's disputed reelection to a sixth term, a vote most independent observers and Western governments considered rigged. The group describes itself as roughly twenty to thirty members of Belarus's IT community, working in exile, and their stated goal was straightforward: disrupt the regime's ability to function digitally, and expose evidence of state violence against protesters. Over the following two years they leaked recorded phone calls of Belarusian officials discussing violence against demonstrators, obtained internal police and security service databases, and built a reputation as one of the more technically capable groups operating anywhere in this space.
Their most consequential operation came in two parts, bracketing Russia's buildup toward the February 2022 invasion of Ukraine. In late January 2022, they breached Belarusian Railways' data-processing network, encrypting servers, databases, and workstations in a ransomware-style attack that took down online ticketing and disrupted internal systems for days. They'd already gained access to the railway's signaling and emergency control systems the previous December and made a specific, documented decision not to touch them, stating publicly that tampering with signaling could risk passenger safety and that they'd only reconsider "if we're confident innocent people won't get injured." That's an unusual restraint for an operation framed as sabotage, and it's worth noting because it cuts against the assumption that hacktivist groups escalate toward maximum damage by default.
They didn't hold that restraint forever. On February 27, 2022, three days into the invasion, the group struck again, this time compromising the railway's routing and switching devices directly and forcing the network into manual control, specifically to slow the movement of Russian troops and equipment transiting Belarus into northern Ukraine. Train operations in Minsk, Orsha, and Osipovichi were disrupted, some for days, and the group stated the goal explicitly: buy Ukrainian forces more time. A spokesperson later attributed part of the railway's exposure to something mundane and completely familiar to anyone who's read the earlier pieces in this series: parts of the signaling infrastructure were still running Windows XP, an operating system that reached end of mainstream support in 2014 and end of all support in 2019, left in place on systems controlling actual train movement years past the point any responsible operator should have migrated off it. The Cyber-Partisans didn't need a novel exploit. They needed a government that "prefers loyalism over professionalism," in the words of the group's spokesperson, running critical infrastructure on an operating system Microsoft stopped patching years earlier.
The group has continued operating since, including a claimed breach of Orlan, a Russian drone manufacturer, funneling internal company data directly to Ukrainian intelligence rather than publishing it, a shift from public leak toward private intelligence-sharing that's harder to verify independently but represents a meaningful change in how this generation of hacktivists is choosing to use what they steal.
Killnet and Anonymous Sudan
Part 1 touched briefly on the attribution problem modern hacktivism carries, and it's worth spending real time on it here, because the pattern has only gotten more pronounced. Killnet emerged in 2022 presenting itself as a pro-Russian hacktivist collective, running DDoS campaigns against government and infrastructure targets across Europe and the United States, including a claimed campaign against several major American airport websites in late 2022 that briefly took public-facing pages offline without touching actual flight operations. Anonymous Sudan followed a similar script starting in 2023, claiming Sudanese grassroots origins while running high-profile DDoS operations against Microsoft, X, and other major platforms, generating real disruption and real headlines under a name designed to invoke the same volunteer, grassroots identity Anonymous built its reputation on two decades earlier.
Multiple security research teams have since assessed Anonymous Sudan as more likely tied to Russian-aligned operators than to any genuine Sudanese activist movement, and Killnet's operational patterns, timing, and targeting have drawn similar scrutiny about how much daylight exists between "pro-Russian hacktivist collective" and "state-adjacent influence operation wearing a hacktivist mask." None of this is settled with the certainty a criminal indictment provides, and this piece won't pretend otherwise. What's verifiable is the operational effect: both groups get media coverage, both groups generate the appearance of grassroots outrage, and both groups let whoever's directing them deny formal responsibility for state-sponsored disruption while still achieving the disruption. A defacement in 1996 was unambiguously somebody's protest. A DDoS campaign in 2023 might be exactly that, or it might be professional information warfare borrowing a movement's aesthetic because the aesthetic itself has become useful cover.
We recommend reading The Slow Death of vBulletin, and Why It Isn't Over to continue reading our selection of content. It's a different kind of story, but the same underlying lesson about legacy infrastructure applies directly to the Belarusian Railways case above: software nobody bothered to retire on schedule keeps generating consequences years after the reason to upgrade first appeared.
Predatory Sparrow
If Belarusian Railways shows restraint and Killnet shows camouflage, Predatory Sparrow shows the ceiling this whole trajectory has been climbing toward since LOIC first flooded a PayPal login page in 2010: physical, kinetic damage, caused entirely through software.
Predatory Sparrow, Gonjeshke Darande in Persian, first surfaced publicly in July 2021 with an attack on Iran's national railway system using wiper malware researchers named Meteor, disrupting train services and displaying taunting messages on station departure boards. Later that same year, the group hit Iran's nationwide fuel payment system, disabling the majority of the country's gas station pumps and displaying anti-government messages on digital billboards along the way.
Predatory Sparrow, Gonjeshke Darande in Persian, first surfaced publicly in July 2021 with an attack on Iran's national railway system using wiper malware researchers later named Meteor, a class of malware designed to destroy data and render systems inoperable rather than encrypt it for ransom, meaning there was never a recovery path being held out for payment. The attack disrupted train services nationwide and, in a detail that reads like a deliberate taunt, replaced arrival and departure boards at stations with messages telling passengers to call the office of Iran's Supreme Leader for information, a message clearly meant to be seen by the public rather than hidden from it the way a typical criminal intrusion would be. Later that same year, the group hit Iran's nationwide fuel payment system, disabling the majority of the country's gas station pumps for days and hijacking digital roadside billboards to display anti-government messages, an operation with a real, measurable civilian impact on a scale most hacktivist operations from the previous decade never approached. Both operations shared a signature that would define every later Predatory Sparrow attack: reaching past a target's public-facing systems into infrastructure that ordinary citizens depend on daily, then making the intrusion as visible and attributable to the group as possible rather than working quietly.
The operation that defines the group came on June 27, 2022, against three of Iran's largest steel manufacturers: Khuzestan Steel Company, Mobarakeh Steel, and Hormozgan Steel, all state-owned and, per the group's own claims, affiliated with Iran's Revolutionary Guard Corps and Basij paramilitary force. Predatory Sparrow released CCTV footage from inside the Khuzestan facility showing an overhead crane discharging a load of molten steel directly onto the factory floor, igniting a fire and damaging equipment, alongside screenshots from the plant's own HMI, human-machine interface, industrial control screens, demonstrating they'd reached the production-control layer rather than only the corporate network sitting in front of it. Production at Khuzestan halted. The group stated publicly that it had timed the operation deliberately to avoid injuring workers, and no injuries were reported, an operational choice that mirrors the Cyber-Partisans' stated restraint around railway signaling, even as the target and the method sit in a completely different category of consequence.
This is the same broad category of attack as Stuxnet, malware that reaches past a network breach into the physical machinery a network exists to control, though Predatory Sparrow's steel mill operation was cruder and more visibly destructive than Stuxnet's quiet, patient sabotage of Iranian centrifuges a decade earlier. The group has kept escalating since: a December 2023 attack disrupting fuel stations nationwide again, and in June 2025, following Israeli airstrikes on Iran, claimed operations against Bank Sepah and the Nobitex cryptocurrency exchange. Predatory Sparrow presents itself, consistently, as a group of Iranian anti-government hacktivists. Multiple intelligence assessments and reporting from outlets including the BBC and the Washington Post have pointed toward Israeli state involvement, based on the operational sophistication required to reach ICS-layer control, the consistency of targeting with Israeli strategic interests, and reporting citing anonymous defense officials. Israel has never confirmed this.
Whether or not the attribution holds, the technical bar this operation cleared is the real story for anyone thinking about infrastructure security. Reaching an HMI screen controlling a steel mill crane requires a level of access far beyond a public-facing web vulnerability, deep reconnaissance of the target's operational technology network, understanding of the specific industrial control protocols in use, and enough persistence inside the network to reach a layer most external attackers never touch. That's a meaningfully different skill investment than a SQL injection into a CMS, and it shows a version of "hacktivism" that has fully absorbed nation-state-grade offensive capability, whoever is funding it.
ICS Stops Being the Exception
Predatory Sparrow's steel mill operation read, in 2022, like an outlier, one exceptionally capable group reaching a depth of access nobody else in this space could match. By 2025 it read like a preview. A joint advisory from CISA, the FBI, and the NSA, alongside international partners, identified pro-Russia hacktivist activity against operational technology and industrial control systems as one of the defining threats of the year, naming a group tracked as Z-Pentest as the most active ICS-focused hacktivist actor security researchers had measured. Z-Pentest's own numbers tell the story of how fast this escalated: fifteen claimed ICS intrusions in the first quarter of 2025, thirty-eight in the second, a jump of roughly 150% in three months. Unlike Killnet or Anonymous Sudan, Z-Pentest largely skips DDoS entirely, favoring direct OT intrusion, hack-and-leak disclosure, and on-camera defacement of the actual control interface, publishing video evidence of compromised HMI screens to prove the access was real rather than claimed. The group has operated alongside others in a loose pro-Russia coalition, including NoName057(16) and a group tracked as CARR, sharing infrastructure and occasionally co-branding claimed operations.
The consequences stopped staying theoretical. Between December 2025 and January 2026, roughly thirty energy sites across Poland were hit in a coordinated wave, operational technology disrupted and equipment physically damaged at multiple locations, though the country avoided a widespread blackout, an intrusion set researchers have attributed to a Russia-linked actor tracked as Electrum. In Norway, attackers remotely manipulated a valve at the Bremanger dam, opening it without authorization, an incident that stayed contained but demonstrated exactly the kind of direct physical control over water infrastructure that security researchers had spent years warning was possible in theory. Canada's Canadian Centre for Cyber Security documented a cluster of hacktivist intrusions across water, energy, and agricultural facilities in a single reporting period: attackers tampered with a pressure valve at a water treatment facility, manipulated an automated tank gauge at an oil and gas company, and altered temperature and humidity controls at a grain storage silo, three completely different industries, three completely different physical consequences, from the same broad category of actor.
Not every claimed win in this category has been real, and that nuance matters for how seriously to weigh any single claim. At least one Russian-aligned group's claimed access to a water utility turned out, on investigation, to be a honeypot, a deliberately exposed decoy system built specifically to draw in and study exactly this kind of attacker rather than a real utility at all. Hacktivist groups have every incentive to claim more than they've achieved, since the publicity itself is often the point, and a healthy read of any claimed ICS breach in this space treats the claim as unverified until independently confirmed, the same skepticism Part 1 applied to Anonymous Sudan's origin story.
The proliferation didn't stop with state-aligned actors either. A group tracked as Dark Engine, active across targets in the EU, Asia, and Latin America, breached the human-machine interface controlling a high-temperature industrial furnace in Vietnam, functionally the same category of access Predatory Sparrow used against Khuzestan Steel three years earlier, achieved by a considerably less resourced group, evidence that the technique itself, not only the capability of any one actor, has spread. Pro-Iran groups branded 313 Team and Handala Hack Team ran a mix of DDoS and hack-and-leak extortion operations through 2025 and into 2026, with Handala specifically built around intimidation through identity exposure rather than disruption for its own sake, and unconfirmed claims circulated linking Iranian-aligned hacktivists to a disruption at Stryker, a medical device manufacturer, in the aftermath of the June 2025 Israel-Iran conflict, a claim that, per the pattern above, hadn't been independently verified as of this writing. Threat intelligence firm Cyble's own assessment of the year captures the shift in one line worth taking seriously: hacktivism has evolved from a movement built on defacement and denial-of-service into a geopolitically charged, ICS-focused threat, increasingly indistinguishable in method from the nation-state operations it once stood apart from, with 2026 forecasts pointing toward continued escalation into HMI and SCADA takeovers as public exploit code and automated scanning make that layer easier for less sophisticated groups to reach.
What Changed, and What Didn't
Line up HBGary Federal against Belarusian Railways, Predatory Sparrow's steel mill operation, and the wave of ICS intrusions running through Poland, Norway, and Canada in 2025 and 2026, and the pattern of underlying causes hasn't moved at all: an unpatched or end-of-life system, a network segmentation failure that let attackers walk from wherever they landed toward something more sensitive, and organizations that assumed their obscurity or their sanctions-driven isolation counted as security. What's changed is the ceiling on consequence, and how many separate groups can now reach it. A decade ago the worst outcome most organizations planned for was a leaked email archive and a public apology. Today, per CISA's own advisory naming Z-Pentest specifically, a growing roster of hacktivist-branded actors has demonstrated the ability to reach the physical layer of critical infrastructure, across three continents, at a pace that tripled within a single year.
We recommend reading What Is Supply Chain Security? to continue reading our selection of content. The gap between a corporate network and an operational technology network, the exact gap Predatory Sparrow crossed to reach that steel mill's crane controls and Z-Pentest's coalition has been crossing at scale since, is a supply chain and segmentation problem before it's anything else, and it's worth understanding on those terms if you're responsible for anything touching industrial control systems.
Defending Against a Threat That No Longer Announces Its Budget
Every case in this piece maps to a defense that has nothing to do with guessing at motive or affiliation, because the technical entry points didn't change even as the consequences did. Belarusian Railways fell to an end-of-life operating system nobody had migrated off a full three years past its final security patch, which means asset inventory and a real patching cadence for operational technology, not only corporate IT, would have closed that door regardless of who eventually walked through it. NB65's pivot to ransomware only worked because Conti's source code became public in the first place, a reminder that threat actor leaks and takedowns don't only remove a threat, they occasionally hand a fully built toolkit to the next group with a grievance and a target list, which argues for treating any major leaked malware codebase as a live threat to a broader set of victims than the original gang's, not a closed chapter. Predatory Sparrow's steel mill operation, and Dark Engine's near-identical furnace breach in Vietnam three years later, depended entirely on a lack of segmentation between the network an attacker could reach and the operational technology network running physical equipment, the single most consequential architecture decision any facility with both an office network and an industrial control system will make. And the honeypot that caught a Russian-aligned group claiming a water utility breach is worth remembering as its own kind of defense: sometimes the correct response to this threat category isn't only locking a real system down, it's building a convincing fake one and letting the next Z-Pentest-style claim walk straight into it.
None of that requires correctly guessing whether the next operation against your organization is run by twenty volunteers, a criminal ransomware crew wearing a political mask for a few months, or an intelligence service that will never publicly claim it. It requires treating every one of them as capable of reaching as far into your systems as your own segmentation, patching, and access control allow, because on the evidence of the five years since Part 1's last case study, that's exactly how far the ones with real capability behind them have already gone, and how many more groups now have that capability than did in 2021.
If there's one practical lesson worth carrying out of five years of escalation, it's that the "hacktivist" label tells you almost nothing useful about how seriously to take a threat anymore. It doesn't tell you whether you're facing twenty volunteers coordinating over Telegram or a state intelligence service borrowing a movement's branding for deniability. It doesn't tell you whether the group in your logs is capable of a defaced homepage or an HMI reaching all the way to a factory floor. The only thing worth trusting is the same thing it's always been: what systems you have exposed, how current they are, and how far an attacker could travel once they're past the front door. Everything else is narrative, and narrative has never been the part of this story that determines the outcome.