{"id":3454,"date":"2025-11-07T14:12:20","date_gmt":"2025-11-07T14:12:20","guid":{"rendered":"https:\/\/ft365.org\/index.php\/2025\/11\/07\/hacktivist-driven-ddos-dominates-attacks-on-public-sector\/"},"modified":"2025-11-07T14:12:20","modified_gmt":"2025-11-07T14:12:20","slug":"hacktivist-driven-ddos-dominates-attacks-on-public-sector","status":"publish","type":"post","link":"http:\/\/ft365.org\/index.php\/2025\/11\/07\/hacktivist-driven-ddos-dominates-attacks-on-public-sector\/","title":{"rendered":"Hacktivist-Driven DDoS Dominates Attacks on Public Sector"},"content":{"rendered":"<div>\n<p><img decoding=\"async\" src=\"https:\/\/ft365.org\/wp-content\/uploads\/2025\/06\/localimages\/ea721ff9-8ba4-4d88-b386-57e9e1606077.jpg?width=64&#038;height=64&#038;mode=crop&#038;scale=both&#038;format=webp\" alt=\"Photo of Phil Muncaster\" loading=\"lazy\"><\/p>\n<\/div>\n<div id=\"cphContent_pnlArticleBody\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"0\">\n<p>Distributed denial of service (DDoS) attacks largely driven by hacktivist groups represented the majority of cybersecurity incidents in the public sector last year, although data threats were more disruptive, ENISA said today.<\/p>\n<p>The EU\u2019s security agency made the claims in a new study detailing 586 publicly reported cyber incidents in the \u201cpublic administration\u201d sector last year. It warned that public sector management of large volumes of sensitive data and delivery of critical services makes it a key target.<\/p>\n<p>Some 60% of cybersecurity incidents impacting the sector last year were DDoS, and 63% were attributed to hacktivist groups. Cybercriminals (16%) and state actors (2.5%) accounted for most of the remainder.<\/p>\n<p>However, it is the latter two groups that\u00a0had the greatest impact on public services, particularly through \u201cdata-related incidents\u201d which were the second most common threat type. ENISA said 17% of all incidents in 2024 were classed as data breaches\u00a0and targeted \u201csensitive platforms\u201d like employment services and law enforcement portals.<\/p>\n<p>Ransomware comprised 10% of incidents in 2024, with\u00a0RansomHub, Lockbit 3.0 and 8Base among the main variants.<\/p>\n<p><em>Read more on ENISA reports:\u00a0Phishing Dominates EU-Wide Intrusions, says ENISA<\/em><\/p>\n<p>DDoS attacks mainly targeted municipal websites and government ministry portals, the report added. Central government accounted for the vast majority (69%) of overall cybersecurity incidents.<\/p>\n<p>\u201cCyber-securing public administrations is central to citizens\u2019 welfare and to the good functioning of the single market across the EU,\u201d said ENISA Executive Director, Juhan Lepassaar.<\/p>\n<p>\u201cPublic administrations provide reliable and effective public services, so it is essential to ensure a high-level of cybersecurity within their wider network of national, regional and local bodies.\u201d<\/p>\n<p>However, the sector\u2019s resilience to cyber-threats is still not where it should be, having been newly added to NIS2. An ENISA report from March 2025 put it in the \u201crisk zone\u201d for compliance, warning that public administrations \u201clack the support and experience seen in more mature sectors.\u201d<\/p>\n<h2>Advice For Public Sector Organizations<\/h2>\n<p>ENISA warned that the sector\u2019s \u201clow maturity\u201d and high value as a target would make more attacks highly likely in the mid- to long-term \u2013 especially hacktivist DDoS, state-backed cyber-espionage\u00a0and opportunistic ransomware and data breaches.<\/p>\n<p>ENISA advised public sector bodies struggling with NIS2 compliance and cyber-threats to consider:<\/p>\n<ul>\n<li>Improving \u201carchitectural resilience and operational readiness\u201d for DDoS by putting portals behind content delivery networks (CDNs) and web application firewalls (WAFs)<\/li>\n<li>Deploying multi-factor authentication (MFA) everywhere, alongside privileged access management (PAM) and data loss prevention (DLP) tools, to mitigate data-related risks<\/li>\n<li>Deploying endpoint detection and response (EDR), segmenting networks and backing up regularly to tackle ransomware threats<\/li>\n<\/ul><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Distributed denial of service (DDoS) attacks largely driven by hacktivist groups represented the majority of cybersecurity incidents in the public sector last year, although data threats were more disruptive, ENISA said today. The EU\u2019s security agency made the claims in a new study detailing 586 publicly reported cyber incidents in the \u201cpublic administration\u201d sector last<\/p>\n","protected":false},"author":2,"featured_media":3455,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3454","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"featured_image_urls":{"full":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/11\/3454-b544fdfa-3150-417c-999c-dc150b289695.jpg",300,300,false],"thumbnail":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/11\/3454-b544fdfa-3150-417c-999c-dc150b289695-150x150.jpg",150,150,true],"medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/11\/3454-b544fdfa-3150-417c-999c-dc150b289695.jpg",300,300,false],"medium_large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/11\/3454-b544fdfa-3150-417c-999c-dc150b289695.jpg",300,300,false],"large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/11\/3454-b544fdfa-3150-417c-999c-dc150b289695.jpg",300,300,false],"1536x1536":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/11\/3454-b544fdfa-3150-417c-999c-dc150b289695.jpg",300,300,false],"2048x2048":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/11\/3454-b544fdfa-3150-417c-999c-dc150b289695.jpg",300,300,false],"morenews-featured":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/11\/3454-b544fdfa-3150-417c-999c-dc150b289695.jpg",300,300,false],"morenews-large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/11\/3454-b544fdfa-3150-417c-999c-dc150b289695.jpg",300,300,false],"morenews-medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/11\/3454-b544fdfa-3150-417c-999c-dc150b289695.jpg",300,300,false],"crawlomatic_preview_image":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/11\/3454-b544fdfa-3150-417c-999c-dc150b289695-146x146.jpg",146,146,true]},"author_info":{"display_name":"henry","author_link":"http:\/\/ft365.org\/index.php\/author\/henry\/"},"category_info":"<a href=\"http:\/\/ft365.org\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","_links":{"self":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/3454","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/comments?post=3454"}],"version-history":[{"count":0,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/3454\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media\/3455"}],"wp:attachment":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media?parent=3454"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/categories?post=3454"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/tags?post=3454"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}