Media & Journalism — Cyber Threat Activity

Media and journalism is attacked to identify sources, not to steal money, and our incident log holds no recorded claims for it at all. That absence is meaningful rather than reassuring: the operations that matter here target individual reporters and their devices, produce no corporate breach notification, and surface through forensic investigation by human rights labs rather than through extortion sites. The evidence we can show is the actor graph, where 74 groups carry a researched association with media targeting, including APT28, APT35, Kimsuky, Sandworm Team, Storm-0558 and NoName057(16), and 147 malware families are linked through those actors. Two threat models dominate. The first is mercenary spyware: Citizen Lab confirmed Paragon's Graphite deployed against European journalists through a zero-click iMessage exploit that required no interaction from the target, and Amnesty documented Pegasus against investigative reporters at the Balkan Investigative Reporting Network while they worked on state-linked corruption. Access Now has traced hack-for-hire phishing against journalists and government critics in the Middle East and North Africa. The second is disruption and intimidation of outlets themselves, where hacktivist groups deface or knock over publishers whose coverage offends a state or a cause. What unites them is that the target is a relationship rather than an asset. Compromising one journalist exposes every source who trusted them, which is why this sector's real victim count can never be read off a table of organisational incidents. Treat the zero here as a limit of our collection, and the actor associations as sourced from published research on each group rather than from incidents we have attributed ourselves.

All sectors

Threat actors targeting Media & Journalism

Malware used against Media & Journalism

Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.

Where these victims are

Recent incidents

Coverage. 94.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.

Read the full analysis on IntelFusions