← Back

The Physical Consequences of Hacktivism: Inside NoName057(16)’s Expanding OT Campaign

DDoS can interrupt a service. Access to an industrial control system can alter the process behind it. Fifty-three OT/ICS access claims tracked by iQBlack show how NoName057(16) is pushing that distinction into increasingly sensitive territory.

Leer en Español
Print Share

Hacktivism stopped being synonymous with website defacement and distributed denial-of-service attacks a long time ago. Data theft, intrusions, credential exposure, ransomware-like disruption, and cooperation with technically specialized actors have progressively expanded a field once dominated by highly visible but mostly digital effects.

Operational technology changes that equation again. When an attacker reaches the system controlling a water pump, a hydroelectric turbine, a boiler, a chemical dosing process, an irrigation network, or an industrial furnace, the target is no longer simply information or availability. The digital system becomes the interface to a physical process.

That distinction is becoming increasingly visible in the activity of groups such as NoName057(16). As part of its continuous monitoring of actor-controlled sources and threat ecosystems, iQBlack recorded 53 OT/ICS access claims published by NoName057(16) between December 19, 2025 and August 13, 2026, spanning 16 countries. The material reflects activity declared by the actor itself and provides a longitudinal view of an operational direction that extends well beyond DDoSia and the traditional model of hacktivist disruption.

 

The target is no longer the website

NoName057(16) remains strongly associated with DDoS operations, but the group’s own description of its evolution had already suggested that this characterization was becoming insufficient.

During an interview conducted by iQBlack in July 2026, NoName057(16) said that both the number and range of its attacks had increased after Operation Eastwood and explicitly stated that the group had begun targeting industrial systems. It also described DDoS as one tool within a broader set of capabilities.

The 53 OT/ICS cases observed by iQBlack give that statement a measurable dimension. They do not represent a short-lived cluster associated with a single geopolitical event. The activity spans almost eight months: six cases were recorded in December, eight in January, seven in February, six in March, five in April, six in May, five in June, seven in July, and three during the first half of August.

That persistence matters more than any individual incident. It indicates that OT/ICS has become a recurring component of the actor’s publicly declared operational activity rather than an occasional experiment.

 

Fifty-three cases, one emerging pattern

The systems involved are heterogeneous, but their functions reveal a clearer pattern.

For analytical purposes, iQBlack grouped the 53 cases into six broad operational categories. Systems related to water, wastewater, pumping, and flood control account for 16 cases. Industrial manufacturing and process-control environments account for 13. Agriculture, food production, and cold-chain systems represent 10. Heating and thermal-process systems account for seven cases, energy for another six, with one additional building-automation environment.

That distribution matters because it moves the discussion beyond a narrow definition of critical infrastructure.

Some of the systems involved are clearly associated with essential services: municipal water, wastewater treatment, hydroelectric generation, district heating, flood control, and pumping infrastructure. Others belong to agriculture, industrial production, refrigeration, environmental control, or manufacturing, where criticality depends heavily on context.

But almost all of them share one characteristic: commands executed through software ultimately influence a physical process.

The chronology includes water-treatment and supply systems in France, Poland, Italy, Spain, Canada, and Ukraine; hydroelectric facilities in Germany and the Czech Republic; biogas and cogeneration systems; industrial boilers and thermal infrastructure; irrigation and fertigation platforms; agricultural refrigeration; greenhouse automation; pumping systems; furnaces; CNC equipment; and other industrial control environments.

Georgetown Water System in Canada, which received greater attention following July activity involving NoName057(16) and Z-Pentest, therefore represents one visible element of a substantially broader pattern rather than its starting point.

 

Water is only part of the problem

Water provides a particularly clear example because the connection between a digital control and a civilian population is immediate. Pressure, pumping, filtration, storage, and chemical dosing are operational variables whose manipulation can move the consequences of an incident beyond the organization operating the system. But the same principle applies to other sectors.

In October 2025, months before several of the cases in this dataset, the Canadian Centre for Cyber Security reported multiple incidents involving Internet-accessible industrial control systems. One involved manipulation of water pressure that degraded service to a community. Another affected an automated tank gauge at an oil and gas company and generated false alarms. A third involved manipulation of temperature and humidity at a grain-drying silo, creating potentially unsafe conditions had the activity not been detected.

These examples help explain why OT security cannot be assessed using the same consequence model applied to a conventional website compromise. The entry point may be a computer. But the consequence does not necessarily end there.

 

When a digital command changes a physical process

The idea is not new. Stuxnet remains the historical reference because it demonstrated with exceptional clarity that malicious code could deliberately manipulate an industrial process to produce physical consequences for equipment.

The comparison should not be stretched beyond what is useful. Stuxnet was a highly sophisticated operation with characteristics substantially different from contemporary hacktivist campaigns. But its most enduring lesson is narrower and, for that reason, more relevant: the separation between cyber consequence and physical consequence disappears when software controls machinery.

That principle remains valid whether the affected process involves centrifuges, water pressure, a turbine, heating, chemical dosing, or industrial refrigeration. The technical sophistication, intent, and potential magnitude may vary enormously; the cyber-physical relationship remains.

This is where the evolution of hacktivism becomes more consequential. An actor does not need Stuxnet-level capabilities to generate risk in an environment where exposed interfaces, weak authentication, insufficient segmentation, or vulnerable components already provide access to process controls.

 

Security was supposed to be part of the system

Perhaps the least novel aspect of the problem is also one of the hardest to explain. The security community has spent years documenting how OT environments should be protected. Yet official advisories continue to describe exposed control systems, weak authentication, insufficient segmentation, and remote-access services directly reachable from the Internet.

A joint advisory issued in December 2025 and supported by the FBI and several international agencies specifically warned that pro-Russian hacktivist groups were targeting minimally secured, Internet-facing VNC connections to reach HMIs and other OT control devices. The recommended measures — reducing Internet exposure, segmenting IT and OT, maintaining accurate asset inventories, strengthening authentication, and monitoring control networks — are hardly novel defensive concepts.

The problem visible in material published by NoName057(16) reflects the same uncomfortable gap. In one claimed access involving a water system in France, the actor explicitly attributed entry to a weakness in the authentication mechanism. In another case involving a German hydroelectric facility, the published material described the compromised HMI as running Windows CE.

This does not establish a single exploitation method across all 53 cases. But it does expose a broader governance problem: OT security cannot continue to be treated as an accessory added to a service after deployment. Security must be part of the raw material from which that service is designed, procured, maintained, and operated.

Asset owners matter, but so do integrators, equipment manufacturers, managed-service providers, and every third party whose software or remote-access layer becomes part of the operational chain.

The SCADA application may be the visible interface, while the actual weakness may reside in the operating system beneath it, an exposed remote-management service, an authentication layer, a gateway, a VPN appliance, or another component required to keep the environment operational.

That distinction will become increasingly important as attackers learn to focus not only on the industrial application itself, but also on the technology that inevitably allows that application to exist and operate.

 

Target selection does not appear to be random

In its interview with iQBlack, the group said it devotes considerable time to intelligence gathering and analysis. According to the actor, country selection is influenced by geopolitical developments and government decisions, while specific targets are chosen according to an overall attack strategy and the expected economic, reputational, and social impact.

A previous iQBlack analysis identified a functional division consistent with that description: intelligence collection and analysis, technical execution, and information activity. Target selection was not described simply as a search for something vulnerable, but as the identification of places where technical action could produce a broader political or public effect.

The observed OT sequence is consistent with that model. Repeated access across multiple countries, industrial technologies, and operational sectors is difficult to explain solely as a succession of fortuitous discoveries. The pattern is more consistent with a workflow involving the identification of exposed surfaces, technical assessment, target selection, access, and subsequent publication.

It is also during this earlier phase that alliances with teams specializing in OSINT and private intelligence acquire operational value. iQBlack has documented, for example, the relationship between NoName057(16) and Meta Yadro Legion — initially known as AlfaNet — an association that illustrates how different capabilities can coexist within the same ecosystem: target research and contextualization on one side, technical intervention capabilities on the other.

Not all of those capabilities need to reside within a single organization. The evolution of hacktivism is also taking place through specialization and cooperation between actors.

This does not mean that every operation requires the same level of sophistication or follows an identical operational chain. It does mean that moving from discovering a vulnerable interface to understanding what it controls, which variable it changes, and what consequence that change could produce requires specialized knowledge. That knowledge may reside with the actor conducting the access or form part of a distributed capability shared across allies, researchers, OSINT teams, and other components of the ecosystem.

 

What happens after access matters too

For NoName057(16), technical access represents only one layer of the operation. The group has repeatedly described success in terms that include economic impact, reputational cost, institutional reaction, media coverage, and longer-term political effects. iQBlack previously assessed this model as an economy of reaction: the initial cyber event generates a response, and that response then becomes material for producing additional pressure.

OT is particularly useful within that strategy because its potential consequences are immediately understandable even outside the cybersecurity community. A temporarily unavailable website requires explanation. A drinking-water system does not.

Neither does a power-generation facility, a heating system, or infrastructure controlling chemicals, pumps, or food-production processes. The possibility of physical consequences introduces an additional layer of psychological and political pressure even when the actual technical impact remains limited.

 

The next target does not have to be water

NoName057(16) does not operate in isolation. It forms part of a broader pro-Russian ecosystem in which actors such as Z-Pentest, PalachPro, Beregini, Morningstar, and others have progressively expanded the boundaries traditionally associated with hacktivist activity.

U.S. authorities have also shifted their assessment in that direction. A joint advisory issued by the FBI, CISA, NSA, and other agencies warned about pro-Russian hacktivist groups attempting to access OT control devices belonging to critical infrastructure and noted that potential consequences could include physical damage.

The 53 cases tracked by iQBlack should not be read as a catalogue of spectacular intrusions. Their significance lies in what the sequence indicates about the direction of the threat.

The transition from DDoS toward OT does not require abandoning DDoS. Both capabilities can coexist. And they do. But one provides scalable disruption and visibility; the other introduces the possibility of influencing the physical process that sustains the service.

For security professionals, operators, and governments, this changes what must be protected and how consequences need to be understood. For the actors, it changes what an attack can mean.

The next system does not have to control drinking water. And the next consequence does not have to remain in the digital world.

 

Explore 3C-INT

Expand actor, campaign and operational-link tracking through a structured intelligence layer.

View module More articles

Get new publications

Subscribe to receive new articles and public updates from iQBlack without unnecessary noise.

iQBlack | Threat Intelligence & Threat Research . © Copyright 2026. All Rights Reserved