Pro‑Russia Hacktivists Drive Surge in Unauthorized OT Access Across the EU
What Happened — ENISA’s 2025 Threat Landscape report shows a sharp rise in unauthorized access attempts against operational‑technology (OT) environments in the EU, with pro‑Russia hacktivist group NoName057(16) responsible for 48 % of those incidents. While most attacks were short‑lived DDoS floods, the increase in OT intrusions raises the risk of service disruption in critical sectors such as energy, telecoms and transport.
Why It Matters for Trust & Control Assurance
- Continuous monitoring of OT access controls is a core control objective that can detect and evidence unauthorized activity before it impacts operations.
- Mapping OT‑specific access‑control policies to a unified control framework provides a defensible audit trail for regulators and auditors.
- Verisq’s ACCESS_CONTROLS capability helps organizations collect, correlate, and retain OT access logs as evidence of control effectiveness.
Who Is Affected – Energy utilities, telecommunications operators, transport providers, and public‑administration bodies that rely on OT systems.
Recommended Actions
- Review and harden OT identity‑and‑access management (IAM) policies; enforce least‑privilege and multi‑factor authentication for all OT accounts.
- Deploy continuous OT log collection and integrate it with a control‑mapping platform to demonstrate ongoing compliance with access‑control objectives.
Source: ENISA Threat Landscape 2025 – Pro‑Russia Hacktivist OT Intrusions
Technical Notes – The attacks comprised mainly DDoS (89.5 %) and unauthorized access attempts; the latter targeted OT networks in energy, telecom and transport sectors. No specific vulnerability or CVE was disclosed, indicating the use of credential theft, mis‑configuration, or other opportunistic tactics.