State-Sponsored Threats Expand Amid Regional Instability
Geopolitical instability drove a significant increase in state-backed advanced persistent threat (APT) attacks and hacktivism last year, according to Group-IB. The threat intelligence specialist published its High-Tech Crime Trends 2025 report on February 26, 2025, detailing findings based on proprietary research, intelligence gathering, and real-world cybercrime investigations. The report revealed a 58% annual increase in state-sponsored APT incidents globally.
Europe experienced the largest regional surge in APT incidents, accounting for an 18% increase. The Middle East and Africa (MEA) region followed with a 4% rise. Group-IB attributed these increases to ongoing conflicts, specifically citing the Russia-Ukraine conflict as a primary driver of the heightened activity.
The government and military sector emerged as the most targeted area for APT attacks, comprising 16% of incidents. The manufacturing sector followed as the second most targeted industry, accounting for 5% of the total. These figures reflect the strategic focus of state-sponsored actors on critical infrastructure and defense-related entities in response to geopolitical tensions.
Hacktivism and Ransomware Activity Rise in Specific Regions
Geopolitical tensions also contributed to a notable increase in hacktivist activity. The Asia-Pacific (APAC) region accounted for 39% of hacktivist incidents, while Europe represented 36% of the total activity. Within Europe, Ukraine was identified as the top target for hacktivist attacks, comprising 17% of the region's total volume.
In terms of industry targeting, the government and military sector was the hardest-hit area for hacktivism, representing 6% of incidents. The manufacturing sector followed with 4%. These patterns align with the regions experiencing active geopolitical conflicts, where digital campaigns often support broader strategic objectives.
The report also highlighted a 44% increase in ransomware-as-a-service (RaaS) activity. Group-IB linked this rise to the geopolitical landscape, noting that many RaaS affiliates and developers are located in former Soviet states. The organization stated that these factors could explain the increase in such criminal enterprise activity during the reporting period.
Regional and Sectoral Breakdowns
The distribution of cyber incidents varied significantly across regions and sectors. In Europe, the combination of state-sponsored APT attacks and hacktivist campaigns created a dense threat environment. The 18% surge in APT activity, coupled with Ukraine's status as the primary target for hacktivism, underscores the intensity of digital confrontation in the region.
Meanwhile, APAC's dominance in hacktivist activity, at 39%, suggests a broader regional engagement in digital activism and state-aligned cyber operations. The concentration of RaaS operators in former Soviet states provides a structural explanation for the 44% rise in ransomware incidents, as these groups leverage existing networks to facilitate attacks globally.
Group-IB's data indicates that the intersection of political conflict and cybercrime infrastructure has created a complex threat landscape. The alignment of targeted sectors—primarily government, military, and manufacturing—with geopolitical flashpoints highlights the strategic nature of modern cyber operations.
Implications for Cybersecurity Posture
The findings from the High-Tech Crime Trends 2025 report suggest that cybersecurity strategies must account for geopolitical drivers. The 58% increase in state-sponsored APTs and the 44% rise in RaaS activity require organizations to monitor not only technical indicators but also political developments.
For entities in Europe, particularly those in Ukraine, the risk of hacktivist targeting remains high, with 17% of regional attacks directed at local interests. Organizations in the government, military, and manufacturing sectors across all regions face elevated risks from both state-backed actors and hacktivists.
The report underscores the need for continuous intelligence gathering to track the movements of RaaS affiliates in former Soviet states and the evolving tactics of APT groups operating in high-tension zones. As geopolitical instability persists, the correlation between political conflict and cyber activity is expected to remain strong.

