NGO & Civil Society — Cyber Threat Activity

NGO and civil society is targeted by governments for what it knows about them, and the shape of our data reflects how badly that activity fits an incident log. We hold 116 recorded incidents, all attributed to a single country and none in the trailing 180 days, so the sector passes our volume threshold while failing every recency and attribution test. The actor graph is the more honest evidence: 63 groups carry a researched association with civil-society targeting, including APT28, APT29, Gamaredon, HAFNIUM, Kimsuky, Mustang Panda, Salt Typhoon and Storm-0558, with 161 malware families linked through those actors. The motive is documented rather than inferred. Secureworks research on Chinese state-aligned targeting of NGOs found the selection driven by organisations whose work challenges governments on politically sensitive social, humanitarian and environmental questions, with operators harvesting documents and webmail and social media credentials over long periods. That is surveillance of a movement, not theft from a charity. Civil society is also the softest target class in this dataset by some margin: small teams, personal devices, volunteer infrastructure, no security budget and a working culture that requires being reachable by strangers. The consequences fall on people rather than balance sheets, since a compromised NGO exposes the activists, refugees, witnesses and grant recipients who trusted it. Mercenary spyware vendors serve the same demand commercially, which puts nation-state capability within reach of any government willing to buy it. Read the incident count here as an artefact of who reports breaches, and the actor list as published research associations rather than attributions we have measured.

All sectors

Recent incidents

Threat actors targeting NGO & Civil Society

Where these victims are

Malware used against NGO & Civil Society

Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.

Coverage. 94.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.

Read the full analysis on IntelFusions