• Skip to main content
  • Skip to secondary menu
  • Skip to footer

Cybersecurity Market

Cybersecurity Technologies & Markets

  • Cybersecurity Events 2026-2027
  • Sponsored Post
  • Market Reports
  • About
    • GDPR
  • Contact

Thirteen Years of Cyberattacks Against the United States: The CRS Record

May 19, 2026 By admin

The Congressional Research Service released an updated inventory of significant cyberattacks against the United States spanning 2012 through 2025. The document, R46974, catalogues operations attributed to nation-states and foreign criminal actors with primary-source citations, drawing on indictments, grand jury findings, and official government statements. It is not a comprehensive threat ledger. It is a curated record of what the U.S. government has been willing to say publicly, which makes its silences as instructive as its disclosures.

The report organizes attacks into two categories. The first covers campaigns attributed to actors operating on behalf of nation-states — China, Russia, North Korea, and Iran account for the full roster. The second covers foreign criminal actors seeking personal financial gain, ranging from ransomware affiliates to botnet operators to business email compromise rings. The distinction matters operationally: nation-state actors tend to run longer, more patient campaigns oriented toward intelligence collection and infrastructure access, while criminals move faster toward monetization and are less likely to deploy novel zero-day techniques.

The Director of National Intelligence’s annual threat assessments, cited throughout the report, have consistently flagged all four adversary nations as leading cyber threats. What the CRS record adds is specificity — named APT identifiers, perpetrating entities, campaign dates, and the legal instruments used to establish attribution. An indictment unsealed by DOJ carries more evidentiary weight than a press briefing from a national security official, and the report is careful to reflect those gradations.

Attribution methodology receives its own section. Investigators combine tradecraft analysis, malware forensics, infrastructure mapping, and signals intelligence to construct attribution claims, then assign a confidence level. High confidence means no viable alternative theory survives scrutiny. Moderate confidence leaves open the possibility of alternative actors. Low confidence means the evidence points somewhere specific but contains significant gaps. Adversaries understand this framework and invest in complicating it — using new infrastructure per campaign, scrubbing logs, and routing operations through proxy networks.

The practical consequence for enterprise security teams is that this document represents the floor of known activity, not the ceiling. Every operation listed cleared a high threshold of public evidentiary disclosure. Countless others, presumably including some of greater sensitivity, remain classified or were never surfaced through indictment. Organizations that model their threat landscape around what has been formally attributed are operating with an incomplete picture by design. The CRS record is useful precisely because it anchors the public conversation to verified events rather than speculation — but it was never intended to substitute for classified threat intelligence.

The thirteen-year span of documented activity makes one trend unmistakable: the operational tempo of both state and criminal actors has accelerated, the target set has expanded from government networks to critical infrastructure and healthcare, and the financial ambitions of criminal groups have grown from thousands to hundreds of millions of dollars per campaign. The infrastructure of American digital life is contested space, and the CRS report is the government’s own acknowledgment of that fact.

Filed Under: News

Footer

Recent Posts

  • Glow Emerges From Stealth With $180 Million Series A At $1.2 Billion Valuation
  • Cisco Releases Antares-350M and Antares-1B Open-Weight AI Models for Vulnerability Detection
  • OpenAI Models Breached Hugging Face Infrastructure While Cheating on Cybersecurity Benchmark
  • Empirical Security Raises $25 Million Series A to Expand AI-Driven Threat Prediction
  • Synthetic Insiders: How AI-Generated Fake Employees Are Bypassing Corporate Cyber Defenses
  • China’s Kimi K3 Model Is Strong but Not Yet a Frontier AI Security Risk
  • Risk Ledger Raises £24 Million Series B for Supply Chain Cyber Risk Platform
  • Cribl Acquires Israeli Threat Detection Startup CardinalOps for $100 Million
  • Cybersecurity Stocks Rally as IBM CEO Flags Cyber Fears as a Top Customer Priority
  • Trump Administration Launches “Gold Eagle” Federal Clearinghouse for AI Cyber Threat Sharing

Media Partners

  • Defense Market
  • Technologies.org
  • Technology Conferences
Arkenstone Defense Emerges From Stealth With $35 Million to Fix Pentagon’s Commercial Onboarding Problem
Farnborough International Airshow from 20 to 24 July 2026 at the Farnborough International Exhibition & Conference Centre in Hampshire, UK
NATO to Begin Formal Negotiations with Saab for Up to Ten GlobalEye AEW&C Aircraft
SES Space & Defense Secures Five-Year Space Force Satellite Services Contract
Lockheed Martin and Rheinmetall Sign MOU for European ATACMS Co-Production
Advancing Rapid Defense Innovation Symposium (ARDIS) 2026, September 15-16, 2026, Ridgecrest, CA
Ondas (ONDS) Acquires Cyberhawk for $125 Million, Extending Its Defense Autonomy Platform Into Critical Infrastructure
Teledyne FLIR Defense Selected by U.S. Army for LASSO Loitering Munition Program
Heaviside Industries Raises $28M to Push Autonomous Warfare Into Its Next Phase
Israel Approves F-35 and F-15IA Squadron Purchases Worth Tens of Billions
South Korea’s July Chip Exports Surge 180.6% as AI Supercycle Accelerates
How CuspAI’s Inverse Design AI Turns Materials Discovery Into a Search Engine
Etched in Talks to Raise Funds at $20 Billion Valuation, With a Separate $10 Billion Round Led by Sequoia
Moonshot AI Unveils Kimi K3, Raising the Bar for Open AI Models
Nvidia’s Open-Source Bet Is Really a Wager on Where AI Margin Settles
TerraFirma Raises $100M Series A to Turn Heavy Construction Equipment Into Robots
PrismML, the Startup That Shrinks AI Models to Run on an iPhone, Is in Talks With Apple
OpenAI’s First Device Will Be a Moveable, Screenless AI Companion Speaker
IBM’s 25% Stock Fall Is Beginning of the End for Old School Software Giant
Why a Six-Axis Robot Arm Is Staring at a Green-Headed Tanager
2026 Esri User Conference — July 13–17, San Diego
HubSpot UNBOUND 2026: Analyst Day Set for September 17 in Boston
The Signal for the Event-Tech Sector
The 10 Most Significant Tech Events and Earnings to Watch This Summer
RAISE Summit, July 8-9 2026, Paris
CJS Securities 26th Annual New Ideas Summer Conference, July 9, 2026, White Plains, NY
SEMICON West 2026, October 13–15, San Francisco
Deutsche Bank Technology Conference 2026, August, Dana Point
ECOC 2026, September 20–24, Málaga
Citi Global Technology Conference 2026, September, New York

Media Partners

  • Market Analysis
  • Market Research Media
  • Analysis.org
Google Frozen v2 AI Chip Could Deliver 10x Efficiency Gains Over Current TPUs
The Case for Shorting Budget Airlines as Oil Prices Rise
Morgan Stanley’s $2.3 Billion Capital Markets Haul Signals the AI Boom Is Just Getting Started
Blackstone’s Futronic Deal Bets on Actuators as AI Robotics’ Physical Bottleneck
Zhongji Innolight’s $8 Billion IPO Is a Customer Event for Marvell, Not a Competitive One
Wall Street Splits Between Oversupply Fears and an AI-Proof Supercycle Thesis
The AI Iron Curtain: Xi’s Shanghai Keynote Is the Fulton Speech of the AI Cold War
Enterprise Money Is Leaving Old School IBM for AI Infrastructure Companies
Why EU Tech Is Falling Behind the US: A Structural Diagnosis, Not a Cultural One
The HyperLight Threat to Coherent and Lumentum Ends Where Indium Phosphide Begins
Getty Images Kills the $3.7 Billion Shutterstock Merger Rather Than Sell the Editorial Business the UK Demanded
Fox’s $22B Roku Deal: 4.6x Sales, Paid in 1.5x Stock
Tuesday Open: AI Earnings Engine Holds the Line as Iran Overhang Fades to Noise
China’s U.S. Treasury Holdings: The Great Repositioning (2021–2025)
Infographic: Why the 2025 CIPA Data Proves the APS-C Renaissance is Real
How WiFi Changed Media
Canva Acquires Simtheory and Ortto to Build End-to-End Work Platform
Netflix Price Hikes, The Economics of Dominance in a Saturated Streaming Market
America’s Brands Keep Winning Even as America Itself Slips
Kioxia’s Storage Gambit: Flash Steps Into the AI Memory Hierarchy
Super Micro Computer Q4 FY26: Gross Margin Guide Nearly Doubles to 15%-17%
Semiconductor Stocks Rebound After Confirming Bear Market Correction
Tempus AI to Acquire Personalis for $16.25 Per Share in $1.5 Billion MRD Deal
Unity (NYSE: U) Bets on Coding Agents With Unity 7: Does the Roadmap Move the Stock?
South Korean Retail Investors Face 70% Losses as Leveraged Chip ETFs Crash
Hidden Debt at Five AI Hyperscalers Hits $1.65 Trillion, Nikkei Study Finds
TSMC Q2 2026: A 15% Capex Hike Outweighs a Record Profit Beat
Micron’s $500 Million GlobalWafers Financing Points to a New Bottleneck
META Compute, Samsung, SK Hynix: Where AI Infrastructure Investors Think the Margin Actually Sits
AMD Acquired MEXT to Make Flash Behave Like DRAM. It Eases the Memory Crunch Without Threatening Micron or SanDisk.

Copyright © 2026 CybersecurityMarket.com

Media Partners: Technologies · Market Analysis · Market Research · Photography · API Coding · App Coding · Blockchaining · Referently