Free tools Windows power users keep installed
One-click scans. No signup required.
A 2017 Cybereason analysis described destructive cyber-attacks as increasing, often state-sponsored and frequently carried out with relatively basic tools. Its central warning for private organizations was that attacks aimed at governments or critical infrastructure could cause collateral damage beyond their intended targets. These are historical findings reported by SecurityWeek—not a measurement of attack trends in 2026.
What trends did the 2017 analysis identify?
In a July 24, 2017 article, Kevin Townsend summarized Cybereason’s analysis of destructive attacks stretching from the 1982 software-instigated Siberian pipeline explosion to the then-recent NotPetya incident. The analysis characterized destructive attacks as increasing, usually state-sponsored and, with some exceptions, reliant on relatively basic tools. It also emphasized that attackers appeared to show little concern for damage to private industry.
These were qualitative conclusions. Townsend’s article gives no defined dataset, count, percentage or statistical series that would support a numerical estimate of how quickly attacks increased—or whether the pattern continued after 2017. The findings should be read as Cybereason’s assessment at that time, not as a current global trend statistic.
Which attacks did it single out as sophisticated?
The analysis called three examples especially sophisticated. It described them as attacks thought to be nation-state operations against military or critical infrastructure; that attribution is cautious, not proof of responsibility.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errors| Attack | Target as described in the article | How the analysis characterized it |
|---|---|---|
| 1998 attack against Serbian air-defense systems | Military air-defense systems | One of three especially sophisticated examples; attributed cautiously as thought to be a nation-state attack. |
| Stuxnet, 2010 | Iran’s nuclear program | One of three especially sophisticated examples; attributed cautiously as thought to be a nation-state attack. |
| CrashOverride/Industroyer, 2016 | Ukrainian power grid | One of three especially sophisticated examples; attributed cautiously as thought to be a nation-state attack. |
The article did not present these labels as a standardized sophistication score. They are examples selected in the context of the 2017 analysis.
What other incidents illustrated the concern?
Townsend’s article also discussed incidents whose attribution or motive was qualified rather than certain. It said the 2015 attack on French broadcaster TV5Monde was thought by some to have been a possible test of cyber-weapons. It referred to political attacks by Iranian hackers against Saudi oil production, and to North Korea-associated attacks described as Dark Seoul against South Korean television and banking in 2013 and against Sony Pictures in 2014. NotPetya was among the destructive incidents in the analysis.
#1 Best Overall
These examples help explain the concern about spillover: a campaign directed at a government, military or strategic target can affect private organizations and services. They do not establish that every destructive incident was state-sponsored, that attribution is settled in every case, or that private-sector damage was always deliberate.
Why did the analysis warn private organizations?
The risk was not limited to organizations that considered themselves direct political or military targets. The analysis highlighted the possibility of collateral damage to private industry and argued that organizations should assess where they might be exposed. In its quoted conclusion, Cybereason put the deterrence problem this way: “There is no incentive for nations to stop this behavior.” It also warned that “With no ability, or even intent to dissuade destructive attacks from nation states, the private sector is paying the ultimate price.” Both statements are Cybereason’s wording as quoted in Townsend’s 2017 SecurityWeek article, not independently established measurements.
What defensive steps did Cybereason recommend?
The recommendations below were made in 2017. They are practical considerations, not guarantees of prevention or a claim about a universal current standard.
Assess whether the organization could be affected
Consider whether the organization operates, supplies or depends on services connected to critical infrastructure, government, military or politically sensitive activity. Also consider how an attack intended for another target could disrupt shared systems, business partners or essential operations.
Make disaster recovery effective
Cybereason advised private-sector defenders to treat effective disaster recovery as necessary. A recovery plan matters only insofar as the organization can restore important operations after destructive damage; the article does not specify a particular technology, recovery time or configuration.
Rank #3
Hunt proactively rather than only reacting
The analysis urged defenders to move from reactive defense toward proactive threat hunting, with the aim of finding signs of a destructive attack before it can be triggered. The article does not provide a specific hunt procedure or promise that hunting will detect every attack.
Do not rely on retaliation or hacking back
Townsend’s account cautioned against assuming that deterrence by retaliation would stop state-linked destructive attacks. It also rejected private-sector “hacking back” as a dependable answer. The suggested emphasis was preparedness and earlier detection, not counterattacks.
Rank #4
What the article can—and cannot—tell readers now
The SecurityWeek article is a useful record of how Cybereason framed destructive cyber-attacks in 2017, including the risk that campaigns against strategic targets could harm private organizations. It does not establish the frequency, sponsorship patterns or typical sophistication of attacks in 2026. Its recommendations can inform a discussion of resilience and detection, but organizations need current threat intelligence and their own risk assessments to make present-day decisions.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →

