When Hacktivists Escalate: Who Answers for the Gaps

A pro-Ukraine hacktivist group called Hacking Cat has moved beyond the low-level disruption that characterises most hacktivist activity. Researchers have publicly flagged that the group is now deploying methods they describe as more sophisticated and more destructive than its earlier operations — a shift that matters well beyond the immediate targets. Questions of hacktivist group malware accountability sit at the centre of this story, and current frameworks have no clean answer to them.

What happened

Hacking Cat built its profile on operations that security researchers typically classify as low-impact: website defacements, which replace a site’s content with a political message, and data leaks, which publish stolen files publicly. Neither is trivial, but neither causes lasting operational damage.

Researchers have now reported that the group has shifted toward attacks they describe as more sophisticated and more destructive. The targets are Russian organisations. The full technical scope of the new capabilities has not been disclosed in available reporting, so the precise nature of the malware involved is not confirmed publicly.

What is confirmed is the direction: the group has moved from nuisance-level disruption toward tools capable of causing lasting harm. That trajectory is what researchers flagged, and that trajectory is what deserves attention.

Who is affected

The direct targets are Russian organisations and infrastructure. Which specific sectors or entities have been hit has not been disclosed.

But the affected audience is wider than the immediate targets. Consider three groups:

  • Security teams at organisations with any exposure to conflict-zone cyber activity. Tools developed in one campaign do not stay in that campaign.
  • Policymakers and international bodies trying to set rules around state and non-state behaviour in cyberspace. Each escalation by an informal group tests whether those rules have any practical weight.
  • Researchers and analysts who track how conflict shapes cyber operations. The line between hacktivist groups and state-adjacent actors has been blurring for years, and this case is another data point.

If you sit in any of those categories, this is not a story happening somewhere else to someone else.

What the real risk is

The immediate risk is the damage the malware itself can cause. That damage has not been publicly quantified.

The structural risk is more significant and less discussed.

Normalisation

When a hacktivist group moves from defacement to destructive malware and no meaningful international response follows, it sets a precedent. Other informal groups observe that the ceiling is higher than they assumed. The next group starts one level above where Hacking Cat started.

Spillover

Destructive tools developed by non-state actors do not stay contained to their intended targets indefinitely. The 2017 NotPetya incident — widely attributed to a state actor but relevant as a reference point — caused collateral damage estimated in the billions of dollars to organisations that were not its intended targets. Non-state tools carry the same spillover risk, even when the group deploying them has no intention of causing that wider harm.

The accountability gap

This is the hardest problem. If a loosely organised group causes serious harm in the name of a cause that many governments quietly support, who is responsible? To whom do affected parties appeal? Current accountability frameworks — legal, diplomatic, and technical — are poorly equipped to answer that question when the actor is informal, distributed, and operating in a political context that discourages scrutiny.

What to do today

These are steps you can take this week, whether you work in security, policy, or neither.

If you work in security

  • Review your threat model. Not because Hacking Cat is targeting you, but because the tools developed in these campaigns migrate. Ask whether your current defences account for destructive malware, not just data theft or ransomware.
  • Expand who you monitor. Most threat intelligence focuses on state-sponsored actors. Add researchers who specifically track hacktivist group evolution — several publish openly on platforms like Mastodon and through independent blogs. The distinction between hacktivist and state-adjacent is increasingly thin, and your monitoring should reflect that.
  • Check your incident response plan for destructive scenarios. Destructive malware — software designed to permanently damage or destroy data and systems rather than steal it — requires a different response than a breach. If your plan does not address it, that is a gap worth closing now.

If you work in policy or governance

  • Use this as a concrete case study. Bring it to the people who write cyber norms frameworks. The question is not whether to condemn the group — it is whether your current accountability structures would function if the target were a hospital, a water system, or a financial institution rather than a Russian organisation.
  • Ask who has jurisdiction. Map out, on paper, which body would have the authority and the practical ability to impose consequences on a distributed informal group operating across multiple countries. If the answer is unclear, that is the gap to address.

If you are neither

  • Be sceptical of framing. When you read about hacktivist activity, notice whether coverage focuses only on the target and the cause, rather than on the methods and the precedent. Both matter.
  • Do not treat this as a single incident. Read it as evidence of a pattern. The pattern is: low-level disruption, no meaningful response, escalation to more destructive methods. Knowing the pattern helps you evaluate the next story more clearly.

Why this keeps happening

The cost of escalation for a distributed informal group is low. There is no international enforcement mechanism capable of reaching such a group, and the political will to build one does not exist when the group’s targets are adversaries of influential states.

States have made this worse by treating hacktivist activity as a useful complement to official policy without formally endorsing it. That posture gives groups room to operate while leaving accountability entirely unresolved. No one officially encouraged the escalation. No one officially permitted it. And no one is officially responsible for stopping it.

The technology itself has reduced the barrier. Moving from defacement scripts to deployable destructive malware is not the same technical leap it was a decade ago. Capability has become more accessible. Institutional capacity to respond has not kept pace.

But underneath all of this is a more fundamental problem. Online systems have no reliable way to tie actions to identifiable, responsible parties. A distributed hacktivist group can operate across jurisdictions, using infrastructure in multiple countries, with members who may never meet. Even well-designed oversight struggles to find a target when the actor is deliberately structured to have no single point of accountability. This is not unique to hacktivism — it is the same structural problem that makes accountability hard across many areas of online harm. But in the context of destructive malware deployed in an active conflict, the consequences of that gap are more immediate and harder to contain.

Until there is a credible mechanism — legal, diplomatic, or technical — that imposes real costs on non-state cyber actors regardless of whose side they are on, the pattern will repeat.

Frequently asked questions

Is Hacking Cat connected to any government?

Available reporting does not establish a formal connection between Hacking Cat and any government. The group is described by researchers as a hacktivist group — an informal actor motivated by a political cause rather than a state directive. Whether any government has informal awareness of or tolerance for the group’s activity has not been confirmed publicly.

Why does it matter if a hacktivist group upgrades its tools?

Because the tools migrate. Destructive malware developed for one campaign can be adapted, copied, or leaked and used in entirely different contexts. It also matters because each escalation that goes unanswered raises the implicit ceiling for every other informal group watching. The precedent is the problem, not just the immediate damage.

Can international law stop non-state cyber actors from escalating?

In theory, international law places obligations on states to prevent their territory from being used to conduct harmful cyber operations. In practice, enforcement depends on identifying actors, attributing actions, and finding a state willing and able to act — none of which is straightforward when the group is distributed and informal. No international body currently has direct jurisdiction over non-state cyber actors in the way it might over, say, a signatory government.

Originally reported by therecord.media. This article summarises that reporting and adds practical guidance.

Scams, fraud, bots and manufactured noise keep spreading because the internet was built with no reliable way to know who anyone actually is. Everyone deserves authenticity and accountability online, and that is the mission we are working on. Subscribe to stay informed as this story develops.

Grab Your Free Ebook

Subscribe to our mailing list and get your free copy of Escape the Plantation.

“No problem can withstand the assault of sustained thinking.”

                                                                                                                                                 — Voltaire

🔒 YOU own the information that identifies YOU.
The operation of this website is governed by the ordinances of the City of Osmio, including its Privacy Ordinance.
View Privacy Ordinance

No Tracking Pixels or Beacons

Today's internet has become infested with hidden trackers — tiny “pixel beacons,” scripts, and device tracking tools designed to follow you without your knowledge.

As a Member Enterprise of The Authenticity Alliance, the operator of this website uses no tracking pixels, no beacons, and no covert identity-reporting mechanisms of any kind.

If we want to know something about you, we’ll ask — we won’t spy.
Learn About Spyfree

What is Authenticity™?

The word “Authenticity™” identifies a digital or physical space of “accountable anonymity” in which people enjoy both privacy for themselves and accountability from others.

Authenticity™ is the condition that exists in a space where there are

  • Digital Signatures Everywhere backed by
  • Measurably Reliable Identity Certificates that are
  • Owned by their Users and which provide
  • Privacy via Accountable Anonymity.

 

Learn about digital signatures and identity certificates in this short video →

What is The Authenticity Alliance?

We are an Authenticity Growers Cooperative

Similar to familiar agricultural cooperatives in the physical world, The Authenticity Alliance is a network of enterprises and individuals whose purpose is to “grow” Authenticity and bring it to the digital world.

Each Authenticity Enterprise—that is, each Member Enterprise of the Alliance—solves a particular inauthenticity problem in its chosen target market or audience.

What Does The Authenticity Alliance Do?

The Alliance brings together independent enterprises that share a common mission: creating spaces of accountable anonymity where digital signatures, reliable identity certificates, and privacy protection work together to solve real-world inauthenticity problems.

WHO is the Authenticity Alliance?

The Authenticity Alliance is comprised of two groups working together to promote trust and transparency across digital ecosystems.

  • Enterprises: Authenticity Enterprises that provide Authenticity solutions for the inauthenticity pains in a specific market or industry.
  • Individuals: People who understand the problems of inauthenticity that plague the world’s information systems and who want to help implement and promote Authenticity™ principles.

Authenticity Enterprises

Each is an Enterprise Member of The Authenticity Alliance

Individual Enterprise in The Authenticity Alliance

Customers and members of an Authenticity Enterprise are automatically eligible to become Individual Members of The Authenticity Alliance.You may also join directly as an individual Member here.

 

© 2026 The Authenticity Alliance. All rights reserved. REAL Security | REAL Privacy | REAL Accountability