Pre-positioning in critical infrastructure
SevereState-linked intruders increasingly enter power, water, port and telecom networks without stealing data — holding access for disruption during a future crisis rather than for espionage now.
Watch for: Living-off-the-land activity in operational technology networks; utility and port incident disclosures.
Ransomware as an industry
HighAffiliate models, initial-access brokers and leak sites have industrialised extortion. Hospitals, municipalities and logistics firms remain the highest-impact targets because downtime is intolerable.
Watch for: Double extortion against healthcare; attacks on managed service providers that cascade to hundreds of clients.
Supply-chain and dependency attacks
HighCompromising one vendor, update channel or open-source package reaches every downstream customer at once — the highest leverage available to an attacker.
Watch for: Signed-update abuse, malicious package publishing, and build-system compromise.
AI-accelerated influence operations
ElevatedGenerative tools cut the cost of persuasive text, voice and video to near zero. The change is scale and localisation rather than novelty: the same narratives, now in dozens of languages with synthetic personas.
Watch for: Cloned voices of officials in the final days before a vote; coordinated inauthentic networks on messaging apps.
Undersea cable and satellite interference
ElevatedAnchor drags, jamming and spoofing sit in a legal grey zone between accident and attack, making attribution slow and retaliation politically difficult.
Watch for: Repeated cable faults in the Baltic and Red Sea; GNSS jamming reports along conflict borders.
Hack-and-leak against political targets
ElevatedStolen material released selectively at the moment of maximum political damage remains the most reliable interference technique, because the documents themselves are usually genuine.
Watch for: Campaign and ministry mailbox compromises surfacing weeks later on forums or through proxies.