Cyber Warfare: 70% of Attacks State-Sponsored in 2025

Listen to this article · 6 min listen

A significant escalation in global tensions is unfolding not on traditional battlefields, but in the digital area, as state-sponsored actors increasingly employ sophisticated cyber warfare tactics to conduct proxy conflicts. Recent intelligence reports from early 2026 indicate a sharp rise in nation-state involvement in cyberattacks targeting critical infrastructure, intellectual property, and government networks across multiple continents, blurring the lines between espionage and outright aggression. How will this new front reshape international relations and national security strategies?

Key Takeaways

  • Over 70% of significant cyberattacks in 2025 were attributed to state-sponsored groups, marking a 15% increase from the previous year, according to a report by the Council on Foreign Relations.
  • Critical infrastructure, including energy grids and financial systems, remains a primary target for disruptive and destructive cyber operations by state actors.
  • Attribution of cyberattacks is becoming more complex due to advanced obfuscation techniques, making retaliation and diplomatic responses challenging.
  • International efforts are underway to establish norms for state behavior in cyberspace, though consensus remains elusive among major powers.

Context and Background

The concept of proxy conflict, where larger powers support third parties to fight on their behalf, has long been a feature of geopolitical maneuvering. What’s new is the almost wholesale migration of these tactics into cyberspace. This isn’t just about stealing secrets anymore. It’s about sowing discord, disrupting economies, and even influencing political outcomes without direct military engagement. For instance, the recent breaches affecting several European energy suppliers in late 2025, while not definitively attributed to any single nation, exhibited hallmarks of state-sponsored attacks, including advanced persistent threat (APT) techniques and supply chain infiltration. According to a detailed analysis by Mandiant (now part of Google Cloud), the sophistication of these campaigns suggests resources typically only available to national intelligence agencies.

Historically, cyber operations were often viewed as a sub-component of traditional espionage. However, the past few years have seen a dramatic shift. We’re observing state actors developing and deploying custom malware designed not just for data exfiltration, but for sabotage. This evolution means that a digital intrusion can now have kinetic effects, such as the disruption of industrial control systems. This capability transforms cyber warfare from a reconnaissance tool into a potential weapon of mass disruption, a truly concerning development for global stability.

70%
of significant cyberattacks in 2025 were state-sponsored
15%
increase in state-sponsored attacks from previous year
25%
increase in cyber intrusions against U.S. water facilities

Implications for Global Security

The rise of cyber warfare as a primary tool in proxy conflicts carries deep implications. One of the most significant challenges is attribution. Unlike a missile launch, tracing the origin of a cyberattack can be incredibly difficult, often relying on circumstantial evidence, forensic analysis, and intelligence gathering. This ambiguity allows state actors to operate in a gray zone, achieving strategic objectives while maintaining plausible deniability. This makes traditional deterrence models, which rely on clear identification of an aggressor, far less effective. As one cybersecurity expert noted during a recent Chatham House discussion, “The fog of cyber war is thicker than any battlefield fog we’ve ever known.”

Plus, the targets are expanding beyond government and military networks. We’re seeing increasing attacks on civilian infrastructure, healthcare systems, and even democratic processes. A report from the Cybersecurity and Infrastructure Security Agency (CISA) in early 2026 highlighted a 25% increase in attempted cyber intrusions against U.S. water treatment facilities compared to the previous year, many bearing the hallmarks of foreign state involvement. This broad targeting demonstrates an intent to inflict societal disruption, not just gather intelligence. The economic fallout from such attacks can be enormous, impacting supply chains, financial markets, and public trust. It’s a low-cost, high-impact method for adversaries to exert pressure.

What’s Next?

Looking ahead, the trajectory suggests continued escalation and diversification of cyber warfare tactics. Nations are investing heavily in both offensive and defensive cyber capabilities, leading to an arms race in the digital domain. We can expect to see more sophisticated supply chain attacks, using vulnerabilities in widely used software and hardware. The integration of artificial intelligence (AI) into cyber operations will also accelerate, enabling faster attack generation, more effective reconnaissance, and adaptive malware. This presents a new layer of complexity, as AI-driven attacks could evolve autonomously, making them harder to predict and defend against.

There’s also a growing push for international cooperation and the establishment of clear norms of behavior in cyberspace. The United Nations Group of Governmental Experts (UN GGE) continues its work, but achieving consensus among major cyber powers remains a significant hurdle. Without clear rules of engagement and mechanisms for accountability, the risk of miscalculation and unintended escalation in the digital area will only grow. Nations will need to bolster their cyber defenses, enhance threat intelligence sharing, and develop strong response frameworks to mitigate the impact of these evolving threats. Ignoring the digital front is no longer an option. It’s where many of tomorrow’s conflicts are already being fought.

The growing reliance on cyber warfare by state actors to wage proxy conflicts demands immediate and sustained attention from policymakers, security experts, and the private sector. Understanding these evolving threats and investing in resilient digital infrastructure is not merely a technical challenge, but a fundamental imperative for national security and global stability in the coming years.

What is a state-sponsored cyberattack?

A state-sponsored cyberattack is a malicious digital operation conducted by individuals or groups acting on behalf of a national government. These attacks often aim to achieve strategic objectives like espionage, sabotage, intellectual property theft, or political influence, using resources and directives from the state.

Why are proxy conflicts moving into cyberspace?

Proxy conflicts are moving into cyberspace because it offers several advantages: plausible deniability, lower risk of direct military confrontation, cost-effectiveness compared to traditional warfare, and the ability to cause significant disruption to an adversary’s economy or infrastructure without physical invasion.

What types of targets are most vulnerable to state-sponsored cyberattacks?

Critical infrastructure (energy grids, water systems, transportation), government networks, defense contractors, financial institutions, and organizations holding valuable intellectual property are frequently targeted. Any system with significant societal or economic impact is a potential target.

How difficult is it to attribute a cyberattack to a specific state actor?

Attributing a cyberattack is extremely difficult due to the ability of attackers to use false flags, route attacks through multiple countries, and employ sophisticated obfuscation techniques. Attribution often requires extensive forensic analysis, intelligence gathering, and sometimes relies on geopolitical context rather than definitive digital fingerprints.

What can organizations do to defend against state-sponsored cyber threats?

Organizations should implement multi-factor authentication, regular security audits, employee training on phishing and social engineering, network segmentation, strong endpoint detection and response (EDR) solutions, and maintain up-to-date threat intelligence. Collaboration with government cybersecurity agencies is also essential for sharing threat indicators.

Christine Solomon

Senior Geopolitical Analyst M.A., International Security, Georgetown University

Christine Solomon is a Senior Geopolitical Analyst for the Centre for Global Futures, bringing over 15 years of experience to the field of international relations. His expertise lies in tracking and interpreting emerging power dynamics in the Indo-Pacific region, with a particular focus on cybersecurity and strategic alliances. Prior to his current role, he served as a Lead Correspondent for Global Insight News, where his investigative reports on regional conflicts garnered widespread acclaim. His seminal article, "The Digital Silk Road: Unpacking China's Cyber Influence," remains a foundational text for understanding contemporary geopolitical shifts