Concerns over full-scale cyberwar escalate, highlighting challenges in attack attribution
Cyberattacks are increasingly frequent, with espionage-driven attacks on the rise. Despite concerns over full-scale cyberwar, experts believe the current phase remains one of reconnaissance. Attack attribution is difficult, and enterprises need to strengthen defenses.

Malicious actors can exploit vulnerabilities at will, as seen in cases like Equifax, Yahoo, Sony, or Target.
Facing an active threat environment, executives have to consider whether their company's security can withstand waves of attacks.
Cyberattacks are increasingly common, mostly economically motivated. However, according to Verizon's analysis of over 2,200 data breaches and 53,000 security incidents, espionage aimed at stealing sensitive information is on the rise, impacting certain industries particularly severely.
Verizon data shows that over half of data breaches stem from organized crime, primarily carried out by external actors, while nation-states or state-affiliated actors account for 12% of breaches.
With increasing signs of nation-state cyber activity, concerns about full-scale cyberwar are emerging. Companies witnessing the complexity of cyberattacks have reason to be worried.
Although the internet seems to have become a battlefield, full-scale cyberwar has not yet broken out.
"War must be declared," Kathie Miley, COO of Cybrary, told CIO Dive. "If we have to define it, we are definitely in a period of heavy war reconnaissance, with many nation-states and organized crime looking for infrastructure weaknesses." When the time is right, these malicious actors can exploit previously discovered vulnerabilities at will.
However, cyberspace is the next battlefield domain. Nations are establishing independent cyber warfare units, legitimizing the conversation about escalation.
The United States has also adjusted its cybersecurity strategy. In May, the federal government elevated U.S. Cyber Command to a "combatant command," making its leader report directly to the Secretary of Defense.
"We have legitimized nation-state behavior, and the more you see it, the more you will encounter it." — Gus Hunt, Managing Director and Cyber Lead at Accenture Federal Services
Now, U.S. Cyber Command is one of the ten unified combatant commands led by combatant commanders, similar to Africa Command or European Command. Its mission is to "direct, synchronize, and coordinate cyberspace planning and operations" to defend and advance U.S. cyber interests.
However, one of the biggest concerns is that state-sponsored attacks are almost impossible to attribute or trace. With limited options, businesses find themselves in a quasi-cyberwar, becoming collateral damage as attackers clash with each other.
"We have legitimized nation-state behavior, and the more you see it, the more you will encounter it. This becomes the norm," Gus Hunt, Managing Director and Cyber Lead at Accenture Federal Services and former CTO of the CIA, told CIO Dive, putting greater pressure on organizations' cyber defenses.
The Attribution Race
Seemingly random cyberattacks may follow a pattern.
"Whenever international conflicts intensify, such as recent military actions, malicious activity on the internet always increases correspondingly," Alexander Heid, Chief Research and Development Officer at SecurityScorecard, told CIO Dive.
The international geopolitical landscape directly impacts cyberspace. For example, the collapse of the Iran nuclear deal earlier this month.
According to an email statement from Adam Meyers, Vice President of Intelligence at CrowdStrike, provided to CIO Dive, after the U.S. withdrawal, CrowdStrike observed Iran-related offensive cyber operations targeting diplomatic institutions and telecommunications companies of U.S. allies.
Meyers stated that if the U.S. reinstates sanctions against Iran, Iran might launch retaliatory cyberattacks.
"Whenever international conflicts intensify... malicious activity on the internet always increases correspondingly." — Alexander Heid, Chief R&D Officer at SecurityScorecard
Even as international conflicts persist, attribution and motive determination remain challenges. After an attack, some companies are quick to blame nation-state actors, such as U.S. adversaries like Russia or North Korea. But attribution is not just a blame game.
Hunt said: "If you understand the true source and origin of an attack, you can mobilize additional resources from government and law enforcement. If you don't know the actual source and location, who do you pursue?"
But true attribution requires catching malicious actors in the act.
Heid said: "Hacking is an intelligence espionage technique, and hiding the source and identity is part of it. Many reports say 'this malware is definitely Russian state-sponsored,' but that malware is public and anyone can use it. It just happens to have been written by a Russian group a long time ago, so you can't determine which nation is responsible."
Lowered Barrier to Attack
The most striking change in the cyber threat landscape is the reduced difficulty of executing attacks. "The barrier has been lowered," Heid said. With just a click of a button, a company could become the next victim.
Malicious actors use advanced hacker toolkits, such as those that emerged after the Shadow Brokers leaked NSA tools in 2016. Human error, constantly emerging vulnerabilities, and the introduction of more hardware and IoT devices together weave a vast and insecure internet environment.
Heid stated that universities and government organizations are often the least secure, "because they were among the first to use the internet." These industries have the oldest systems with long-dormant vulnerabilities that persist due to the scale and nature of the sectors.
Verizon's report shows that one in five cyberattacks against the education sector is espionage-motivated, driven by the sometimes sensitive nature of institutional research. The public sector also sees espionage as a major concern, accounting for 44% of breaches.
Although government security postures have improved, vulnerabilities still exist.
Beyond script kiddies and credential stuffers, increased nation-state activity and cyber espionage threats have begun to plague organizations across industries. Companies face threats of intellectual property loss and destructive breaches that can damage reputations and cause production disruptions.
As data breaches expose emails and passwords, experts expect an increase in credential stuffing attacks, which use stolen account credentials to access different websites.
Malicious actors sometimes use this for free access to Netflix accounts, but more dangerously, nation-state actors and organized crime groups may use corporate credentials for more nefarious system access.
Protecting Core Assets
For companies, the age-old advice for dealing with cyberattacks and breaches is to strengthen defenses and practice the basics: promptly updating system patches.
For companies protecting critical infrastructure, this advice has limited effect, as these facilities are particularly vulnerable and, if not properly maintained, can negatively impact quality of life.
Miley said that if companies cannot provide core services like healthcare, telecommunications, or electricity, a crisis will occur. Companies "should be extremely fearful of nation-state attackers, especially in the critical infrastructure sector."
Miley pointed out that lacking regulations like those in the healthcare industry, companies have no mandatory requirements to protect their organizations. The absence of regulations harms the entire cybersecurity industry.
Hunt said: "We really need to unite more effectively against threats, because nation-state attacks are increasingly evident, growing in speed and scale."
