Ideologically motivated
Hacktivism
Hacktivists use attacks to make a statement. Activity often aims at visibility, such as defacing websites, leaking data or disrupting services.
Motivation: Publicity, for a political or social cause.
Overview
Hacktivism is the use of hacking as a form of protest. The aim is attention rather than money, so the actions are chosen to be visible: a website replaced with a message, a leak of documents, a service knocked offline. The groups involved range from loosely organised online communities to a few skilled individuals.
Targets are usually connected to an issue in the news: a government body, a company, an event or an industry. Because the goal is publicity, hacktivists usually announce what they have done, often exaggerating it. That makes verifying claims an important part of the response.
Most activity is simple but disruptive. The realistic defences are the basics done well: protecting public-facing websites, being ready for traffic floods, controlling who can change content, and having a communications plan for when a claim is made.
How it unfolds
- 1
Cause
A political or social issue drives the action.
- 2
Choose a target
An organisation linked to the issue, or simply an easy one.
- 3
Act
Defacement, a leak, or a flood of traffic.
- 4
Announce
The group publicises the result, often exaggerating it.
- 5
Repeat
New targets follow the news cycle.
Common techniques
Website defacement
Replacing a page with a message, usually via a weak admin login or outdated software.
Denial of service
Flooding a site with traffic so real visitors cannot get in.
Data leaks
Publishing internal documents or emails that were taken.
Doxxing
Publishing private details about individuals.
Social media amplification
Announcing and exaggerating actions to get attention.
Who is targeted
- Government agencies and public services
- Organisations connected to a controversial issue
- Companies in the news
- Poorly protected public websites
An example
During a controversial event, a company's public website is briefly replaced with a protest message, and a group posts about it online. No customer data was taken, but the site was unavailable and the message was widely shared before the company had confirmed what happened.
An illustrative scenario, not a report of a specific incident.
What to look for
- Mentions of your organisation in protest campaigns
- Sudden traffic spikes on public websites
- Unexpected changes to public pages
- Claims of a leak that need to be verified
How to defend
- Protect public websites with patching, strong admin controls and DDoS mitigation
- Monitor for mentions of your organisation during relevant events
- Verify claims before responding publicly
- Prepare a communications plan and contacts in advance
- Limit what personal information about staff is publicly linked to your organisation
Key terms
- Defacement
- Changing the content of a website without permission.
- DDoS
- A flood of traffic from many sources that makes a service unavailable.
- Doxxing
- Publishing private details about a person.
- Leak
- Publishing data that was taken or disclosed without permission.
This is a general profile of a type of threat. It does not attribute any specific incident to any named group.
Go deeper on hacktivism
- Hacktivism
Hacktivism: When Cyber Attacks Carry a Message
Hacktivists attack to make a point, not to make money. That changes who they target and what they do.
2 min read - Hacktivism
Data Leaks and Doxxing: When Private Information Goes Public
Publishing stolen or gathered information is a powerful way to pressure or embarrass. Here is how it works, and how to reduce the risk.
2 min read - Attacks
DDoS: When a Crowd of Fake Visitors Takes a Website Down
A DDoS attack does not steal anything. It just makes a service so busy that real users cannot get in.
2 min read - Threat Intelligence
Threat Actors: Who Is Actually Attacking, and Why
Not every attacker wants the same thing. Knowing the type of adversary helps you guess what they will do next.
2 min read