Conflict
Seventy-four per cent espionage, twenty-eight per cent money
The motives add up to more than a hundred, and that is not an error in the arithmetic. It is the end of a category everyone still organises their thinking around.
Last reviewed August 30, 2026
- The category stopped predicting. The same people collect intelligence and steal money.
- Attribution changes the statement, not the week. Eviction, scoping and notification are the same.
- Most organisations are a route, not a target. The question is whose data you can reach.
- The announced catastrophe did not arrive. Persistent collection did, and it is harder to notice.
Who did this?
7 facts from one intrusion, none of them invented and none of them pointing anywhere in particular. Change the assumption about who was behind it and watch how little moves.
Entry through an unpatched appliance at the network edge, nine days after the fix was published.
Criminal reading: Opportunistic. Somebody scanned the internet for that version and you were on the list.
State reading: Deliberate. The same appliance was chosen for the same reason, and the list was shorter.
Activity concentrated between 01:00 and 09:00 local time, including weekends.
Criminal reading: Whoever it is works elsewhere, which is most of the planet.
State reading: Whoever it is works elsewhere, on a shift pattern, which is also most of the planet.
Publicly available remote administration software, plus tools already installed on the machines.
Criminal reading: Cheap and disposable, because the operation has to pay for itself.
State reading: Cheap and deniable, because anything custom is a signature.
Four months between first access and discovery, with two dormant periods of several weeks.
Criminal reading: Access was resold or queued behind other jobs.
State reading: Patience. There was nothing worth taking until there was.
Documents copied were narrow: one contract negotiation and one engineering directory.
Criminal reading: Whatever looked saleable to a specific buyer who had asked for it.
State reading: Exactly the collection requirement, and nothing that would signal what was wanted.
Three months of prior contact with an employee through a professional network, no malware.
Criminal reading: Recruitment of an insider, or preparation for a convincing invoice.
State reading: Recruitment of an insider, or preparation for a convincing invoice.
No encryption, no demand, no leak site. The access was simply abandoned.
Criminal reading: The buyer got what they paid for and there was nothing left to sell.
State reading: The requirement was met. Extortion would have burned the access.
What changes if you knew
- Removing the access and closing the way in — identical.
- Identical either way. The appliance needs patching, the credentials rotating and the persistence removing, and none of that consults the attacker's employer.
- Working out what was taken — identical.
- The same logs, the same gaps in them, the same uncomfortable conclusion that some of it cannot be established.
- Telling the people whose data it was — identical.
- Obligations attach to what left and whose it was, not to who took it. The clock runs the same.
- Deciding what to change afterwards — identical.
- Faster patching at the edge, better logging, a second factor that resists relaying. The list does not vary with the flag on the attacker.
- What the announcement says — changes.
- Here it changes a great deal, and rarely to the reader's benefit. A sophisticated state actor is a better sentence than an unpatched appliance, and both can be true.
- The insurance claim — changes.
- Policies have carried exclusions for hostile state action, and a formal attribution by a government can turn a covered loss into an argument.
- Who you report it to — changes.
- Espionage against a national interest attracts a different agency, a different level of help, and sometimes a request not to say anything yet.
The exercise is not a trick. Every fact genuinely admits both readings, which is why real attribution rests on intelligence gathered elsewhere rather than on what a victim can see in its own logs. A supplier naming a country in the first week is offering an inference, and the inference is frequently correct — but the confidence in the sentence is borrowed from somebody else's evidence.
Why has the distinction stopped working?
The mental model is thirty years old and was useful for most of them. Criminals want money and will leave if you are expensive to rob. Governments want information, do not care about cost, and will not be deterred by making the job harder. Each implies a different defensive posture, a different threshold for spending, and a different conversation with a board.
The arithmetic has quietly dissolved it. Espionage is the motive in roughly 74% of state-attributed incidents and financial gain in about 28%, with a further 26% serving some secondary purpose — access held for later, or a route into somebody else. Those percentages overlap because single operations carry several motives at once, and the overlap is the whole point: a substantial minority of state activity is also theft.
Several arrangements produce this. Some states run operations that must fund themselves, so the same teams collect intelligence and steal currency. Some contract the work to companies whose staff moonlight, or whose contracts permit keeping what they find. And some criminal groups operate with tolerance rather than direction, left alone provided they attack elsewhere, which is neither state-directed nor independent and does not fit either box.
The practical consequence for a defender is liberating rather than alarming. If the category cannot tell you what will happen, stop organising defence around it. What remains is the ordinary question of what you hold, who can reach it, and how long you would take to notice — which has the considerable merit of being answerable.
The catastrophe that kept not arriving
For two decades the public argument was dominated by a scenario: a sudden strike that would darken cities, empty accounts and stop hospitals, delivered without warning by a hostile government. It was described in testimony, in strategy documents and in a great many conference talks, and it was used to justify budgets, agencies and legislation.
It did not happen. Destructive operations have occurred, some of them serious, and they have stayed inside limits that look remarkably stable in hindsight: mostly confined to active conflicts, mostly reversible, mostly stopping short of the casualties that would invite a response nobody wanted. That restraint is not evidence of goodwill. It is evidence that the actors involved calculated the same way everybody else does, and found escalation unattractive.
Meanwhile the thing that did happen was almost too quiet to report. Continuous collection, in every direction, at a scale that makes the word campaign misleading — access obtained and held in telecommunications, energy, government and the suppliers of all three, sometimes for years, frequently with no observable use. Prepositioning is the ugly word for it, and it is the least dramatic activity in this field and probably the most consequential.
Which explains the change in vocabulary this archive records. The word cyberwar accounts for about 18% of this subject across the first half of the period and roughly 16% across the second, while the coverage of state activity itself did not fall. The predictions were not wrong about capability. They were wrong about incentive, and about how boring the real thing would look.
A word that thinned out
174 entries here concern state actors, espionage or conflict. 55 name a state-sponsored actor, 66 espionage, and 29 use the language of war.
The pale column is the subject and the solid part is the language of war. Coverage peaks in 2015 with 40 and the marked share falls, which is what a prediction looks like when it stops being repeated without anybody admitting it was wrong. The earliest piece here using that vocabulary, New Market Research Report: The Global Cybersecurity Market 2014, is arguing about a future that turned out differently.
A caution belongs on any reading of this shape. Coverage measures what was written about, and the language of catastrophe attracts attention in a way that patient collection never will. Some of the decline is the subject changing and some is simply a phrase going out of fashion, and no chart built from headlines can separate them.
Are you a target, or a route?
The question organisations ask is whether a government is interested in them, and for most of them the answer is no. Around 15% of external actors in breach data are state-affiliated and espionage is the motive in roughly 12% of breaches, which leaves a very large majority whose problems are ordinary and whose spending on this subject would be better placed elsewhere.
The better question is what you can reach. Suppliers, law firms, accountants, recruiters and small technology companies are attacked constantly, not for their own information but because they hold credentials, documents or network access belonging to somebody who is a target. A twelve-person firm with a maintenance connection into a utility is a state-actor target and does not feel like one, and the feeling is the problem.
Where that applies, the useful measures are unglamorous and identical to the rest of the discipline. Reduce what your access permits, so that a compromise of your systems does not deliver theirs. Keep logs long enough to answer questions about four months ago, because that is the interval these intrusions run at and most retention periods are shorter. Use a factor that cannot be relayed, since patient social engineering defeats everything softer.
And treat the long, friendly approach as the threat it is. Months of professional contact ending in a request that seems reasonable is the documented pattern in a quarter of espionage cases, and it survives every technical control because nothing malicious happens until the person decides to help. The defence is a culture where checking an unusual request is normal, which cannot be purchased and takes years.
What would anyone want from a company like yours?
Executives asked to imagine a foreign intelligence service picture something national, and dismiss the idea within a sentence because they make packaging or sell insurance. The dismissal is usually right about the organisation and wrong about the holdings, because what gets collected is rarely the thing the company thinks it sells.
Negotiating positions, for one. A firm bidding against a foreign competitor for a contract carries its own reserve price, its concessions and its timetable, and that information has a value on a specific date and none afterwards. Engineering material, for another: not the finished product but the tolerances, the failures, the test results that took nine years to accumulate and would take a competitor the same nine without them.
People are a third category and the least anticipated. Personnel records, travel arrangements, security clearances, family details and internal directories are collected because they support the next operation rather than because they are interesting now. A breach that yields no financial data and no intellectual property can still have handed over exactly what was wanted, and the victim will report it as minor.
The fourth is simply reach, and it is the commonest. You are connected to somebody who matters, through a maintenance account, a shared document store, a software update you sign, or an email relationship trusted enough that your address opens doors. In that case nothing of yours is the objective, which is why the internal assessment concludes there is nothing worth taking, and why that assessment is answering the wrong question.
The layer nobody planned
Between the state and the keyboard there is now an industry. Companies sell intrusion capability, exploit brokers pay for flaws and resell them, and firms offering surveillance as a product have customers in dozens of countries. None of this was designed; it emerged because building this capability is expensive and buying it is not, and because a supplier can serve many governments with the same engineering.
The effect on the map is to flatten it. Capability that once required a large national programme is available to states with no such programme, and to some organisations that are not states at all. The tidy picture of a handful of sophisticated actors, still the organising assumption of most threat briefings, is an artefact of an era when the barrier to entry was construction rather than purchase.
It also confuses everything downstream. When capability is bought, its fingerprints say more about the vendor than the customer, and two unrelated governments running the same purchased tooling look like one actor to anybody analysing the technique. Attribution built on tradecraft was always inference; against a shared supply chain it becomes inference about the wrong party.
For a defender the consequence is a lowered bar to assume. The question is not whether an adversary sophisticated enough to use a purchased zero-day would bother with you, because the cost of that adversary has fallen to something a mid-sized organisation could afford. Planning around who could plausibly reach you was always weak; it is now closer to arbitrary.
What a government will and will not do for you
Organisations that suspect a state actor generally call somebody official, and the experience surprises them in both directions. National cyber authorities in most countries are genuinely helpful, staffed by competent people, and free — which is more than can be said for the alternative. They will often confirm whether the pattern matches something they have seen, which is the single most valuable sentence available at that moment.
What they will rarely do is tell you who it was, or explain how they know. The intelligence that supports confident attribution is protected far more carefully than the incident that prompted it, and a victim organisation is on the wrong side of that boundary regardless of how badly it wants a name for its board.
Occasionally the request runs the other way, and this catches people unprepared. An agency may ask an organisation to leave access in place while it is watched, or to delay an announcement, and both requests conflict with obligations to customers and regulators that are running on their own clock. Deciding that in the moment is awful; the organisations that handle it well have thought about who is entitled to agree to it long before anybody asks.
And the timescales do not match. Public attribution, where it comes at all, arrives months or years later as a diplomatic act rather than a technical one, chosen for when it is useful to say rather than when it became known. By then the organisation has rebuilt, notified everybody, argued with its insurer and moved on, which is a reasonable summary of why the answer matters less than it feels like it should.
The costume that keeps being worn
A word that once described something real has become the standard disguise. Hacktivism meant people with a grievance and modest skills defacing a website or knocking it offline for an afternoon, and it still occasionally means that. What it mostly denotes now is a persona: a freshly created account, a manifesto of a paragraph, a flag, and an operation whose competence sits some distance above the stated cause.
The disguise is worn because it works on several audiences at once. It gives the sponsoring government deniability that is thin but sufficient, since disproving it requires publishing intelligence. It gives journalists a narrative with a motive already attached. And it lowers the perceived seriousness of the event, because an organisation attacked by activists reads the incident as a nuisance rather than as the reconnaissance it may have been.
Two tells recur without ever being conclusive. The first is a mismatch between the claimed grievance and the target list, where the stated cause explains three victims out of nine and the remaining six share a supplier or a sector instead. The second is capability arriving fully formed: an account created a fortnight ago, using techniques that take years to develop, with none of the clumsy early attempts that genuine amateurs leave behind them.
For a victim organisation the useful posture is to ignore the costume entirely. The claim on a channel is the least reliable evidence available, it costs nothing to make, and acting on it means letting the attacker choose how seriously you take them. Investigate what was touched and how, treat the stated motive as marketing, and let anybody with better information than yours argue about the flag.
The same caution applies in reverse, and it is the harder half. Dismissing a defaced page or a brief flood as theatre is usually correct and occasionally expensive, because a noisy nuisance is a reasonable way to occupy a response team while something quieter proceeds elsewhere. The discipline is to treat the visible event as an event rather than as an explanation: log what it touched, then go and look at whatever nobody was watching while everybody watched the website. A response team is small, and its attention is the scarcest resource in the building. That makes the attention itself a target, and no product defends it. The only defence is a written rule that somebody keeps looking at the quiet places while the loud one is handled, which sounds obvious, costs nothing, and is abandoned within the first hour of almost every incident anybody has ever run. Writing the name of the person who holds that job, before the day arrives, is the cheapest single improvement available to a response plan, and the one most consistently left out of them.
Common questions
How much of the problem is actually state actors?
Less than the coverage implies. State-affiliated actors are around 15% of external actors in breach data, and espionage is the motive in roughly 12% of breaches with an external actor. For most organisations the honest answer to whether they are a target of a government is no.
Do state actors steal money?
Frequently, and this is the figure that breaks the usual mental model. Among incidents attributed to state-sponsored actors, espionage is the motive in about 74% and financial gain in some 28%. The percentages exceed one hundred because operations carry more than one motive, and more than a quarter of them are also robbery.
Why does that matter to a defender?
Because the category stops predicting behaviour. Briefings are organised around a line between political and financial attackers, and that line no longer tells you whether your data will be quietly copied, encrypted for extortion, or both by the same people in the same month.
How do these intrusions usually start?
Ordinarily. Social engineering appears in around 25% of espionage incidents, often as months of patient rapport-building through professional networks rather than a single deceptive message. The other common route is an unpatched device at the network edge, which is also how everybody else gets in.
Is attribution reliable?
Sometimes, rarely quickly, and almost never from evidence a victim organisation holds. Confident public attribution generally rests on intelligence gathered outside the incident — the sort of thing governments have and companies do not. A vendor naming a country in the first week is making an inference, not a finding.
Does it matter who it was?
For what you do that week, mostly not. Of the 7 responses considered on this page, 4 are identical either way and 3 change: the public statement, the insurance position and which authority you notify.
Can insurance refuse to pay for a state attack?
It is a live and unresolved argument. Policies have long excluded acts of war, wordings have been tightened specifically around hostile state action, and a formal government attribution can convert a covered loss into a dispute. Read the exclusion before the incident, not during it.
Did the predicted cyberwar happen?
Not in the announced form. Two decades of warnings described a sudden catastrophic strike on infrastructure, and what arrived was persistent espionage, occasional destructive operations kept within surprisingly stable limits, and a great deal of quieter interference. The predictions were not wrong about capability; they were wrong about incentive.
What is prepositioning?
Gaining and holding access to a system with no immediate use for it, so that the option exists later. It is the least dramatic and most consequential state activity in this area, because it looks exactly like a dormant intrusion and is discovered, when at all, by noticing something that has been quietly present for a very long time.
Do these actors use custom tools?
Less than they used to. Publicly available administration software and the tools already installed on the victim's machines do the job, cost nothing and leave far less to identify. The shift is deliberate: anything bespoke becomes a signature, and a signature becomes an attribution.
What should an ordinary organisation actually do?
The same things, done properly. Patch what is reachable from outside within days, use a factor that resists relaying, keep logs long enough to answer questions about four months ago, and know which suppliers can reach your data. Every one of those helps against a government and against everybody else.
Should smaller organisations worry at all?
They should worry about being a route rather than a target. Suppliers, professional advisers and small technology firms are attacked to reach somebody else, which means the relevant question is not whether your own information interests a government but whose information you can reach.
States and espionage in the archive
174 entries, peaking in 2015 with 40.
- New variants of Android spyware linked to advanced persistent threat
November 26, 2021 · securitybrief.asia
- U.S. Looks to Coordinate Global Cybersecurity
November 8, 2021 · eetasia.com
- Nation-state attacks fears grow, execs don’t trust governments to protect them from cyber threats
September 30, 2021 · helpnetsecurity.com
- Russian turla apt group uses new backdoor for attacks
September 24, 2021
- New DNS vulnerability allows 'nation-state level spying' on companies
August 6, 2021 · bleepingcomputer.com
- US seizes domains used by APT29 in recent USAID phishing attacks
June 2, 2021 · bleepingcomputer.com
- Project signal an iranian state sponsored ransomware operation emerges
May 4, 2021
- Sandbox evasion malware used for cyber espionage, new study shows
March 8, 2021 · securitybrief.eu
- State hackers rush to exploit unpatched Microsoft Exchange servers
March 4, 2021 · bleepingcomputer.com
- Unpatched Android App with 1 Billion Downloads Threatens Spying, Malware
February 17, 2021 · threatpost.com
- Protecting the COVID-19 Vaccine Supply Chain from ‘Cold’-hearted Phishers
February 15, 2021 · cisomag.eccouncil.org
- Malwarebytes Reports Being Hacked by SolarWinds Attackers
January 22, 2021 · cisomag.eccouncil.org
- Getting Past Cybersecurity In IoT Devices And Exploring Their Performance
January 13, 2021 · forbes.com
- China's APT hackers move to ransomware attacks
January 5, 2021 · bleepingcomputer.com
- Fireeye hit by possible nation state cyberattack
December 10, 2020
- Cybersecurity 2021: nation-state hacking, network vulnerability and social media manipulation
December 8, 2020 · siliconangle.com
- With Cyberwars, Cyber Espionage has Reached New Level
November 25, 2020 · cisomag.eccouncil.org
- Chinese E-Commerce Scammers Trade Customer PII and Payment Card Data on Dark Web
November 24, 2020 · cisomag.eccouncil.org
- Space becoming next front of cyber warfare
October 15, 2020
- Cyberwarfare the new frontier of wars between countries
September 15, 2020
- Covid Crimes: Espionage, Hackers And Why America Is Vulnerable
July 29, 2020 · forbes.com
- Cyberwarfare: The changing role of force
July 13, 2020 · helpnetsecurity.com
- Cyber Warfare Growing: From Academic Background to Current Events
June 1, 2020 · govtech.com
- Apt groups targeting covid 19 research cybersecurity agencies warn
May 22, 2020
- Financial gain now the main motivator for cybercrime
May 20, 2020 · itproportal.com
- Cybersecurity Firm Detects Android Malware That Has Been Spying and Stealing From Users Since 2016
May 19, 2020
- State-backed hackers behind wave of cyberattacks targeting coronavirus response, US and UK warn
May 6, 2020
- Artificial intelligence will be used to power cyber attacks, warn security experts
April 28, 2020
- Cybersecurity officials say state backed hackers taking advantage of pandemic
April 10, 2020
- Radio frequency an invisible espionage threat to enterprises
April 8, 2020