NGO & Civil Society — Cyber Threat Activity
NGO and civil society is targeted by governments for what it knows about them, and the shape of our data reflects how badly that activity fits an incident log. We hold 116 recorded incidents, all attributed to a single country and none in the trailing 180 days, so the sector passes our volume threshold while failing every recency and attribution test. The actor graph is the more honest evidence: 63 groups carry a researched association with civil-society targeting, including APT28, APT29, Gamaredon, HAFNIUM, Kimsuky, Mustang Panda, Salt Typhoon and Storm-0558, with 161 malware families linked through those actors. The motive is documented rather than inferred. Secureworks research on Chinese state-aligned targeting of NGOs found the selection driven by organisations whose work challenges governments on politically sensitive social, humanitarian and environmental questions, with operators harvesting documents and webmail and social media credentials over long periods. That is surveillance of a movement, not theft from a charity. Civil society is also the softest target class in this dataset by some margin: small teams, personal devices, volunteer infrastructure, no security budget and a working culture that requires being reachable by strangers. The consequences fall on people rather than balance sheets, since a compromised NGO exposes the activists, refugees, witnesses and grant recipients who trusted it. Mercenary spyware vendors serve the same demand commercially, which puts nation-state capability within reach of any government willing to buy it. Read the incident count here as an artefact of who reports breaches, and the actor list as published research associations rather than attributions we have measured.
- Recorded incidents: 242
- Incidents, trailing 180 days: 26
- Tracked threat actors: 99
- Malware families: 193
Recent incidents
- FBC 2026-08-24
- cedarridge.org 2026-08-22
- 3f 2026-08-14
- Acli 2026-08-14
- Community Connections 2026-08-14
- United Association Local Union 345 2026-08-12
- Impact Centre Chrétien 2026-08-08
- rosekennedygreenway.org 2026-08-07
- St Theresa Catholic Church 2026-08-06
- First Baptist Church of Belleview 2026-08-06
- Fanlore 2026-08-06
- CEN and Cenelec 2026-08-01
- Foundations to Freedom 2026-07-28
- Louisiana Coalition Against | Domestic Violence 2026-07-27
- sanaa 2026-07-16
- Abhay Prabhavana 2026-07-10
- Envision Unlimited 2026-07-09
- Sociedad Latina 2026-06-30
- katholiekamersfoort.nl UPDATE-FOR SALE 2026-06-09
- wwag.org 2026-05-15
Threat actors targeting NGO & Civil Society
- Qilin 19 incidents
- LockBit 14 incidents
- INC Ransom 10 incidents
- SafePay 9 incidents
- FunkSec 5 incidents
- Medusa Ransomware 5 incidents
- RansomHub 4 incidents
- The Gentlemen 4 incidents
- Akira 3 incidents
- Play Ransomware 3 incidents
- Rhysida 3 incidents
- Sarcoma 3 incidents
- Cl0p 2 incidents
- Deadlock 2 incidents
- DragonForce 2 incidents
- Hunters International 2 incidents
- L Group 2 incidents
- Orova 2 incidents
- 8Base 1 incident
- BianLian 1 incident
- Black X 1 incident
- BlackByte 1 incident
- BlackSuit 1 incident
- Coinbase Cartel 1 incident
Where these victims are
- United States 164
- Canada 9
- Germany 8
- France 7
- Italy 4
- United Kingdom 4
- Brazil 3
- Singapore 3
- Belgium 2
- Denmark 2
- Spain 2
- Argentina 1
Malware used against NGO & Civil Society
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Cobalt Strike Malware
- Impacket Tool
- Metasploit Tool
- Mimikatz Tool
- PlugX Malware
- PsExec Tool
- Sliver Tool
- SUNBURST Malware
- AADInternals Tool
- AdFind Tool
- Amadey Malware
- BloodHound Tool
Coverage. 94.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.