The UK government is sounding the alarm again over an ongoing cyberattack campaign attributed to hacktivist groups with ties to Russia . Critical national infrastructure, public agencies and local government bodies are being targeted , with the main weapon being DDoS (Distributed Denial of Service) attacks , which aim to disrupt the digital operation of essential services.

Low complexity, high impact attacks
According to a recent alert from the National Cyber Security Center (NCSC), these attacks are primarily aimed at disabling websites and causing disruptions to online services. Although technically considered relatively simple, their effects can be disproportionately severe. An organization that suffers a successful DDoS attack is often forced to spend significant resources on analysis, defense, and remediation, with a direct cost in time, money, and operational resilience.
See also: Cybersecurity 2026: Cyberattacks top risk for British businesses
As the NCSC points out, even a “basic” DDoS attack can cripple critical systems, especially when the target is not adequately prepared or lacks rapid recovery mechanisms.
The hacktivist group NoName057(16) and the crowdsourcing model
Special mention is made of the NoName057(16), a pro-Russian hacktivist group active since March 2022. The group is known for managing the DDoSia, a crowdsourcing platform through which “volunteers” from around the world offer computing resources to carry out attacks, in exchange for monetary rewards or recognition within the community.

This model lowers barriers to entry and makes attacks more massive, increasing the volume of traffic that can be directed towards a target in a very short period of time.
"Operation Eastwood" and the return to action
In mid-July 2025, an international police operation codenamed “Eastwood” managed to disrupt the group’s activity, with arrests, warrants and the takedown of dozens of servers. However, the key operators are believed to be in Russia and remain out of reach of Western authorities. The result was the group’s relatively quick resurgence, as confirmed by the latest NCSC bulletin.
See also: Jordanian admits to selling access to 50 corporate networks
Ideological motivations and new goals
The NCSC emphasizes that the attacks of the hacktivist group NoName057(16) are not driven by financial gain, but by ideological and geopolitical motives. Another worrying element is the gradual broadening of targets, as the attacks begin to touch operational technology (OT) environments, with potential impacts on industrial and energy infrastructure.

How can organizations protect themselves?
To mitigate the risks, the NCSC recommends a number of practical measures. Organizations should services their and identify potential bottlenecks, strengthen upstream defenses with the help of providers, CDNs and third-party solutions, and invest in rapid scaling through cloud auto-scaling or virtualization. At the same time, it is critical to have proven response plans, continuous monitoring and regular testing of the effectiveness of defense mechanisms.
See also: Ingram Micro: Data breach affected 42,000 people
A threat that is here to stay
Since 2022, Russian hacktivists have posed an increased threat to public and private organizations in NATO and European countries. Cyberattacks have evolved into a tool of digital pressure, making cybersecurity a critical pillar of modern geopolitics.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
