And even the second timeline of February 2022 is finally out with 92 records that, distributed on 12 days, bring the average number of events per day to 7.07, an increase compared with the 6.67 events of the previous fortnight. I wished I would never find myself to comment events similar to the ones that are happening in these troubled days, but unfortunately this is not the case. And you could easily guess that I am referring to the Russian invasion of Ukraine, which inevitably ended up affecting the cyber space.

Despite ransomware attacks continue, and in this timeline there is at least one very high-profile victim, it is the Russian-Ukrainian front that has shown the higher level of activity, with additional attacks against Ukrainian entities carried out via DDoS, spear phishing campaigns and a new destructive malware called HermeticWiper, and on the other front, the Anonymous collective that has declared war to the Russian government and has been leaking data and bombarding multiple Russian institutions (mainly news outlet, banks and even the Kremlin) with prolonged DDoS attacks (and yes the attacks will also characterize the next timeline I am afraid).

Ransomware continues to characterize the threat landscape, but its percentage drops to 17.4% (16 out to 92 events) from 23.4% of the previous timeline (but the real  percentage could be  higher since many victims do not disclose the details of the outage and these events are counted as “Unknown”. The exploitation of vulnerabilities is another aspect that is characterizing this period: 8 out 92 events (8.7% vs 10.2% of the previous timeline) have been carried out exploiting vulnerabilities that in some cases also fueled ransomware attacks.

And even the massive attacks against companies operating in the fintech space continue: 17 users of the NFT OpenSea platform learnt it the hard way, suffering a loss of $2M worth.

As usual, multiple cyber espionage operations appear in this timeline: a new stealthy backdoor of Chinese origin, called Daxin, has been uncovered, hidden for more than two years and deployed against multiple organizations. Similarly, multiple known actors populate the timeline such as: OilRig and MuddyWater (Iran), APT10 and APT27 (China), Sandworm (Russia). The list also includes two new operations carried out by an Iranian actor dubbed TunneVision (exploiting Log4j on VMware Horizon servers) and by Russian-backed attackers targeting U.S. cleared defense contractors (CDCs).

Expand for details

Enjoy the interactive timeline, and thanks for sharing it, and supporting my work in spreading the risk awareness across the community. Also, don’t forget to follow @paulsparrows on Twitter, or even connect on Linkedin, for the latest updates.



The “Breachometer” compares the current number of events/day with the max and min values recorded in the previous 12 months.

  • 2023 Stats Featrured Image2024 Cyber Attacks Statistics

    In 2023, there was a 35% increase in cyber attacks to 4,128 events, with the MOVEit CVE-2023-34362 vulnerability being heavily exploited. Cybercrime dominated as the main motivation at 79%, while malware led attack techniques with 35.9%. Healthcare remained a top target for ransomware. The data ...

  • network servers on an enclosureCVEs Targeting Remote Access Technologies

    In this first quarter of 2024, threat actors have been particularly busy in exploiting vulnerabilities (0-days but also old unpatched flaws) targeting traditional remote access technologies. In this blog post I summarized the main CVEs exploited so far in 2024.

  • computer program language text1-15 February 2024 Cyber Attacks Timeline

    In the cyber attacks timeline of February H1 2024, I collected 139 events dominated by malware attacks. Ransomware and vulnerabilities also played an important role in the threat landscape.

  • Q4 2023 Featured ImageQ4 2023 Cyber Attacks Statistics

    In Q4 2023, cyber attack events decreased by 7.1% to 1029 compared to the previous quarter. Cybercrime remains the primary motive, although slightly reduced, while malware tops attack techniques, increasing from the last quarter. Multiple industries and healthcare are the most targeted sectors. These statistics ...

  • January 2024 Cyber Attacks Statistics

    In January 2024 I collected 288 events, with Cyber Crime continuing to lead the motivations, and ransomware leading the known attack techniques, ahead of Malware.


Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.