Defense

Industry

Cyberattack Slows Russia’s Drone Weaponization Effort

July 4, 2025

In July 2025, a cyberattack halted Russia’s drone weaponization network, disrupting the distribution of custom firmware that converts commercial drones into weapons and forcing hundreds of modification centers to pause operations. The attack marked a rare publicly reported cyber disruption of a militarily significant network.”

The attack impacted the volunteer group Russian Hackers for the Front, hundreds of drone modification centers, and Russian military operators reliant on the disrupted weaponized drone network

read more

US Nuclear Weapons Agency Caught up in Microsoft SharePoint Attack

July 19, 2025

Hours after Microsoft revealed that hacking groups affiliated with the Chinese government have been exploiting a flaw in its SharePoint software, Bloomberg reported that the National Nuclear Security Administration was also breached in the attacks. No sensitive or classified information has leaked according to Bloomberg. “The department was minimally impacted due to its widespread use of the Microsoft M365 cloud. As well as very capable cybersecurity systems,” a department spokesperson said in a statement to Bloomberg. “A very small number of systems were impacted. All impacted systems are being restored.”

read more

Cyberattack at French Warship Builder – Hackers Leak 1TB of Data

July 23, 2025

France’s state-owned defense firm Naval Group is investigating a cyberattack. A hacker using the moniker Neferpitou claimed to have stolen approximately 1TB of the company’s internal data. The Naval Group released a statement on July 26. “All of our teams and resources are currently mobilized to analyze and verify the authenticity, origin, and ownership of the data as quickly as possible. At this stage, no intrusion into our IT environments has been detected and there has been no impact on our activities.”

Naval Group was given 72 hours to negotiate an extortion payment. Soon after, Neferpitou leaked the entire 1TB dataset on the forum.

read more

Sensitive Argentine Defense Industry Information Compromised in Ransomware Attack

March 1, 2025

A cyberattack on Fabricaciones Militares, a key state-owned company for the Argentine defense industry, has resulted in the theft of over 300 GB of sensitive data. The compromised data includes plans for cutting-edge weapons projects. Negotiations are reportedly underway to recover the stolen information. The cyberattack was first reported by specialized publications FalconFeeds.io and Cyber Press, who identified it as a ransomware attack claimed by the “MONTI” group.

Fabricaciones Militares holds a crucial position in Argentina’s defense sector, as it oversees the Villa María Military Powder and Explosives Factory. The company’s current transition and the government’s privatization plans have created a delicate situation, especially considering the sensitive nature of the stolen data.

read more

Hungarian Defense Procurement Agency sees Sensitive Information Published

November 14, 2024

The Védelmi Beszerzési Ügynökséget (VBÜ), a Hungarian state-owned company responsible for defense and security procurement, was hit by a ransomware attack. The attackers, identified as the Inc. Ransomware group, gained access to sensitive information, including financial reports, organizational data, and procurement lists. The group demanded a $5 million ransom in exchange for the decryption key, and published some of the stolen data online, compromising the confidentiality and integrity of the information.

The VBÜ has stated that it is working to restore its systems and recover from the attack.

read more

Russian Drone Control Programs Breached by HUR

February 8, 2024

Ukrainian hackers working within Ukraine’s Military Intelligence (HUR) have successfully breached Russian drone control programs. The servers responsible for the “friend or foe” identification system for Russian drones ceased functioning, resulting in its military losing access to its drones.

read more

Snatch Claims it Breached Hemeria Group, partner of the French Space Agency CNES

April 18, 2022

The Snatch ransomware group has claimed in a post on February 17, 2023, that it has breached the systems of Hemeria Group, a partner of defense and space systems maker of the French Space Agency CNES in 2022. According to the leak site post, the operators of Snatch state they initiated talks with the Palace of Versailles to maintain caution because the company data is considered a state secret.

Cybersecurity researchers have posted about the Hemeria Group data breach with screenshots from the ransomware group’s post.
Hemeria management replied by denying having anything to do with the data that Snatch had. The firm also did not seem to be affected by the data breach news.

read more

Hackers Target Indian Defense Explosives Manufacturing Contractor, Solar Industries Limited India.

January 21, 2023

The parent company of a private defence ministry contractor manufacturing explosives, Solar Industries Limited India, has been the target of a ransomware attack, a government official said, in an incident that experts said could pose a threat to security if documents were leaked. “The government is investigating the extent of the data compromised and the source of the attack.” an official familiar with the matter said, asking not to be named. The official could not confirm if a ransom demand had been made so far, or whether data was stolen by the attackers.

A listing on the dark web by a group that calls itself Black Cat (Alphv) claimed to have stolen two terabytes of data. BlackCat published images of the stolen documents and pictures taken from the company’s security cameras as proof of the hack. The claims, however, could not be independently verified by HT.

read more

European defense contractor, Hensoldt, allegedly Victim of Snatch Ransomware Attack.

August 18, 2022

A French subsidiary of HENSOLDT AG, and part of its subsidiaries (“Nexeya”), have become the target of a serious cyber attack on its IT infrastructure in recent days. According to current information, both of Nexeya’s data centers in France have been affected, and it is likely that a significant amount of data has been accessed and systems have been encrypted. Nexeya’s ongoing operations have been impacted by this cyber attack.

A comprehensive investigation of the incident has been launched immediately, in close cooperation with the relevant authorities.

Work is proceeding at full speed to restore Nexeya’s ongoing operations as quickly as possible. According to current knowledge, the IT infrastructure and data of other companies of the HENSOLDT Group are not affected.

read more

Ransomware Attack on ForceNet Communication Platform used by Australian Military

September 10, 2022

Hackers attacked ForceNet’s communications platform used by Australian military personnel and defense staff. The ForceNet service is run by Dialog Information Technology. The Australian Dept. of Veteran Affairs’ website states: “Defence has announced that it has been informed that an external ICT service provider which facilitates ForceNet has been subject to a ransomware attack. ForceNet is a Defence e-communications platform used to connect registered users within secure online communities. To be clear, this is not an attack on Defence ICT”
ITWire in Australia reports on 31 October that Dialog was hit by an attack which used the Agenda ransomware that runs only on Windows. The group behind the attack, Qilin, announced it on the dark web on 19 September.

This is the 9th attack in little over a month, affecting Australia’s biggest companies, likely exposing the details of millions of customers.

read more