Geopolitical DDoS Attacks: What Cybersecurity Teams Need to Know
Geopolitical tensions are increasingly spilling into the cyber domain, with DDoS attacks becoming a common form of retaliatory hacktivism. Unlike financially motivated attacks, these campaigns can be triggered by events such as military escalation, elections, sanctions, or other geopolitical developments—and can begin within hours.
For security teams, the challenge is not only understanding who may target the organization, but recognizing when geopolitical developments should trigger a heightened state of DDoS readiness.
When Geopolitical Conflict Moves Online
A recurring pattern is emerging: a conflict escalates, and a parallel cyber campaign follows soon afterward. DDoS attacks are particularly well suited to this type of activity because they can be launched quickly, require relatively limited technical sophistication, and can generate immediate, visible disruption.
Many of the groups involved are hacktivists motivated by political or ideological objectives rather than financial gain. NoName057(16), for example, has been active since Russia’s invasion of Ukraine in 2022 and operates DDoSia, a platform that enables volunteers to participate in coordinated DDoS campaigns. The group publishes target lists and recruits participants to generate attack traffic, lowering the technical barrier to entry for large-scale campaigns [5,6].
Hacktivist campaigns also differ from many other forms of cyberattack in their emphasis on visibility. Groups frequently publicize claimed attacks through their Telegram channels and other communication platforms. For defenders and threat-intelligence teams, this behavior can provide useful signals about claimed targets, timing, and motivations. At the same time, attack claims should be treated as intelligence rather than confirmation: publicly reported claims are not necessarily evidence that an intrusion or successful disruption actually occurred.
Operation Epic Fury: A Recent Example
In late February 2026, Israel and the US launched a military campaign against Iran, later referred to as Operation Epic Fury. Within 72 hours, security researchers had tracked 149 separate hacktivist DDoS claims against 110 organizations across 16 countries [2,3].
Radware: Retaliatory Hacktivist DDoS Activity Following Operation Epic Fury/Roaring Lion
Twelve different hacktivist groups participated in the activity. Three groups—Keymous+, DieNet, and NoName057(16)—accounted for roughly three-quarters of the reported activity [2,3]. Kuwait, Israel, and Jordan were among the primary countries targeted, while almost half of the affected organizations were government agencies [2,3].
Some groups made broader claims of compromise, including alleged access to Israeli military networks and components associated with the Iron Dome missile defense system [3]. These claims have not been confirmed, highlighting an important distinction for security teams: threat actors’ claims can provide valuable early-warning intelligence, but should be separated from independently verified incidents.
Which Industries Are Most Exposed?
Recent conflict-related DDoS activity points to several sectors that consistently attract attention as geopolitical tensions rise:
- Governments are among the most consistent targets. Cloudflare data from the first half of 2026 shows the government sector moving from the 29th to the 9th most-targeted industry in a single quarter, coinciding with the period following Operation Epic Fury [1].
- Critical infrastructure and energy providers repeatedly appear in advisories concerning pro-Russian hacktivist groups, whose stated objectives include disrupting countries and organizations perceived as hostile to Russian interests [4].
- Financial services remain a persistent target. ENISA’s finance-sector threat landscape reports that DDoS and service disruption accounted for 46% of reported incidents in the sector [7].
- Telecommunications, ISPs, and media organizations are also recurring targets.
Importantly, targeting is not necessarily limited to organizations directly involved in a conflict. Organizations can become targets because of their location, national affiliation, business relationships, or perceived alignment with one side of a geopolitical dispute.
What This Means for DDoS Readiness
For cybersecurity teams, geopolitical escalation should be treated as a potential DDoS risk indicator—not simply as background context. The objective is to translate threat intelligence and geopolitical developments into concrete changes in readiness.
- Incorporate geopolitical triggers into your DDoS playbook. Conflict anniversaries, elections, military escalations, sanctions, and other high-profile geopolitical events can increase the likelihood of hacktivist activity. Define in advance which developments should trigger increased monitoring, stakeholder notification, or a review of DDoS mitigation readiness.
- Test before you become a target. DDoS dashboards, mitigation policies, and vendor SLAs describe expected protection; they do not demonstrate how the production environment will perform under a coordinated, multi-vector attack. Realistic DDoS simulation testing can expose gaps in traffic filtering, architecture, capacity, operational procedures, and cross-team response before an actual campaign does.
- Monitor the threat ecosystem, not only your own telemetry. Track which groups are active, which targets they are claiming, the techniques they are using, and which industries are attracting increased attention. Red Button’s monthly DDoS Threat Pulse is designed to provide this type of context and help security teams identify changes in the DDoS threat landscape.
References
[1] Cloudflare, DDoS Threat Report, H1 2026 – blog.cloudflare.com/ddos-threat-report-2026-h1
[2] Radware, DDoS Activity Following Operation Epic Fury / Roaring Lion – radware.com/security/threat-advisories…
[3] The Hacker News, “149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries” – thehackernews.com/2026/03/149-hacktivist…
[4] CISA, Advisory AA25-343A – Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure – cisa.gov/news-events/cybersecurity-advisories/aa25-343a
[5] Bitsight, NoName057(16): DDoS Threat Intel & Defense Guide – bitsight.com/blog/noname057-16-ddos-threat-intelligence
[6] Imperva, Operation Eastwood: Measuring the Real Impact on NoName057(16) – imperva.com/blog/operation-eastwood-measuring…
[7] ENISA, Threat Landscape: Finance Sector – enisa.europa.eu/publications/enisa-threat-landscape
