Attack Distribution February H2 2023

No Data Found

Attack Techniques February H2 2023

No Data Found

The second cyber attacks timeline of February 2023 is out (first timeline here) and with 10.62 events/day confirms the sustained level of activity that is characterizing this first part of 2023.

Ransomware-driven events are stable at 24.6% (34 out of 138 events), whilst 11 events were characterized by the exploitation of vulnerabilities (corresponding to 8% vs 7.7% of the previous timeline), with the massive exploitation of CVE-2021-21974 targeting VMware ESXi servers continuing also in this fortnight.

Image by wastedgeneration from Pixabay

1-15 December 2023 Cyber Attacks Timeline

In early December 2023, event recordings decreased significantly to 135, with ransomware dominating 35.5% of incidents. The period saw a notable data breach at ESO Solutions, affecting 2.7 million patients, and a $2.7 million crypto theft at OKX. Geopolitical tensions spurred active cyber espionage, with APT28 exploiting critical vulnerabilities. The author encourages timeline review and community risk awareness support.

Continue Reading

In the fintech sector, Platypus and Hope Finance suffered two massive hacks netting a total of more $10M worth to the attackers. Hatch Bank was also hit thanks to the exploitation of the Fortra’s GoAnywhere CVE-2023-0669 zero-day, and the users of Coinbase and Trezor were hit by phishing campaigns.

RailYatri is the mega breach of this month, leading to the compromise of 31 million users.

Ukraine is still targeted by state-sponsored threat actor. In this fortnight a campaign by a threat actor named UAC-0056  was unearthed, using a backdoor implanted on multiple government websites since two years. Meanwhile, in a different side of the planet (Asia), two threat groups were discovered targeting the material research sector (Clasiopa) and COVID-19 research (Hydrochasma). But obviously these are not the only ones discovered in this period.

And last but not least, and once again unsurprisingly, the pro-russian hacktivists were quite active with multiple DDoS campaigns against the websites of several German airports and some hospitals in Denmark (Killnet and their affiliates of Anonymous Sudan), and multiple Italian websites (NoName057(16)). And the pro-Ukraine hacktivists fought back with DDoS attacks against All-Russia State Television and Radio Broadcasting Company (VGTRK), multiple Russian websites, and also several Radio stations across Russia, broadcasting fake air raid warnings.

But we are now used to the fact that the list is too long to be summarized in few words, so my suggestion is to enjoy the interactive timeline and the tabular format, and obviously thanks for sharing it, and supporting my work in spreading the risk awareness across the community. As always, don’t forget to follow @paulsparrows on Twitter, or even connect on Linkedin, for the latest updates.

Geo Map February H1 2023

No Data Found


No Data Found

The “Breachometer” compares the current number of events/day with the max and min values recorded in the previous 12 months.


No Data Found

  • Leaky Buckets in 2023

    Similarly to what I have done in 2022 and 2021, I am collecting the incidents due to cloud misconfigurations and leading to...

  • Leaky Buckets: a List of Cloud Misconfigurations

    Cloud services are playing a crucial role to guarantee business continuity during this complicated period...

  • 2021 Cyber Attacks Statistics

    And finally I have aggregated all the data collected in 2021 from the cyber attacks timelines. In the past year I have collected 2539 events, meaning...

  • November 2023 MotivationsNovember 2023 Cyber Attacks Statistics

    November 2023 saw a rise to 39 events, with Cyber Crime remaining dominant at 78.7%. Cyber Espionage increased to 9.7%, while Hacktivism fell to 5.4%. Malware was the leading attack technique at 42.1%, and Multiple Organizations were the most targeted at 17.7%.

  • 2022 Cyber Attacks Statistics

    And finally I have aggregated all the data collected in 2022 from the cyber attacks timelines. In the past year I have collected 3074 events...


Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.