lagen.nu
Foresight 2030 Threats

Foresight 2030 Threats

Utgivare
Europeiska unionens cybersäkerhetsbyrå
Antagen
2023-09-13
Språk
engelska
Ämnesord
Cyber Threats
Källa
www.enisa.europa.eu
Endast på engelskaEuropeiska unionens cybersäkerhetsbyrå har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska unionens cybersäkerhetsbyrå.
FORESIGHT 2030 THREATS EXECUTIVE DIRECTOR FOREWORD

The cybersecurity threat landscape is a complex ecosystem of threats, threats actors and attack techniques that are also subject to the influence of world events such as pandemics and geopolitics. The best knowledge, and tools we have at hand today to reduce the impact of cyber threats might not fit tomorrow’s threat landscape.

Can we foresee the full extent of the potential use or abuse of our current technological developments?

Even if we still cannot predict the future, we have the duty to anticipate emerging trends and patterns.

In 2021, ENISA developed a cybersecurity foresight methodological framework grounded in foresight research and future studies. The framework was first used in 2022 to devise future scenarios and identify threats and challenges likely to emerge by 2030. This methodology was produced in cooperation with the wider cybersecurity community.

This booklet summarises upcoming challenges and provides for an assessment of the risks. We are now ready to design the cyber secure future ahead of us.

Juhan Lepassaar

Executive Director

SUPPLY CHAIN COMPROMISE OF SOFTWARE

1

DEPENDENCIES

WHAT IF… State-sponsored actors insert a backdoor in a well-known and popular open-source library on online code repository. They use this to infiltrate information from most major European corporations and

?

use the information to blackmail leaders, espionage, or otherwise initiate disruptions across the EU.

More integrated components and services from third party suppliers and partners could lead to novel and unforeseen vulnerabilities with compromises on the supplier and customer side.

POTENTIAL THREAT ACTORS

State-sponsored groups, criminal organisations

POTENTIAL METHODS

Sabotage, theft, network reconnaissance, malicious code, abuse of information leakage

POTENTIAL IMPACTS

Disruption, malfunction, data loss, data leakage

FORESIGHT 2030 THREATS ADVANCED DISINFORMATION CAMPAIGNS

2

WHAT IF… A state-sponsored actor may impersonate a political rival by using deepfakes and spoofing the candidate’s digital identity, significantly

?

impacting election results.

Deepfake attacks can manipulate communities for (geo) political reasons and for monetary gain.

POTENTIAL THREAT ACTORS

State-sponsored groups, criminal organisations, hackitvists

POTENTIAL METHODS

Fraud, unauthorised access, session hijacking, identity theft, abuse of personal data

POTENTIAL IMPACTS

Distrust, disinformation, financial damage, foreign information manipulation and interference (FIMI)

RISE OF DIGITAL SURVEILLANCE AUTHORITARIANISM /

3

LOSS OF PRIVACY

WHAT IF… An authoritarian regime uses their power to retrieve databases of information about individuals who have visited their country, from both public and private entities. They track all those who participated in anti-government protests, put them on a watch list,

?

and subsequently are able to manipulate those individuals’ access to national services like voting, visits to their healthcare providers, or access to other online services.

Facial recognition, digital surveillance on internet platforms or digital identities data stores may become a target for criminal groups.

POTENTIAL THREAT ACTORS

State-sponsored groups, criminal organisations

POTENTIAL METHODS

Man in the middle, malicious software, use of rogue certificates, abuse of personal data

POTENTIAL IMPACTS

Privacy breaches, human rights abuses

FORESIGHT 2030 THREATS HUMAN ERROR AND EXPLOITED LEGACY SYSTEMS WITHIN CYBER-

4

PHYSICAL ECOSYSTEMS

WHAT IF… Manuals for all legacy OT equipment are available online and studied primarily by state-sponsored groups. Once a vulnerability is found, they target user devices or other IoT products used at the plant.

Cyber criminals begin a new form of ransomware in which they bring ?

down important infrastructure and demand payment, given that the operator likely lacks the resources to solve the issue themselves.

The fast adoption of IoT, the need to retrofit legacy systems and the ongoing skill shortage could lead to a lack of knowledge, training and understanding of the cyberphysical ecosystem, which can lead to security issues.

POTENTIAL THREAT ACTORS

State-sponsored groups, cyber criminals, hacktivists

POTENTIAL METHODS

Tampering, failure of communication links, denial of service, malicious activity, manipulation of information, targeted attacks, brute force, unauthorised physical access

POTENTIAL IMPACTS

Malfunction, failures and outages, physical damage 5

TARGETED ATTACKS (E.G. RANSOMWARE) ENHANCED BY SMART

5

DEVICE DATA

WHAT IF… Cybercriminals may use the increased amount of available data from smart devices and analyse it with AI to create behavioral models of

?

their victims for spear phishing campaigns or stalking.

Through data obtained from internet-connected smart devices, attackers can access information for tailored and more sophisticated attacks.

POTENTIAL THREAT ACTORS

Cybercrime actors, hackers-for-hire

POTENTIAL METHODS

Denial of service, interception of information, social engineering, unauthorised activities, data breach

POTENTIAL IMPACTS

Financial damage, privacy breaches

FORESIGHT 2030 THREATS LACK OF ANALYSIS AND CONTROL OF SPACE- BASED INFRASTRUCTURE

6

AND OBJECTS

WHAT IF… State-sponsored attackers access space infrastructure, build up their capabilities and knowledge of the technology, and secure their presence to execute attacks. Their aim may be to create infrastructure

?

malfunctions as a statecraft tool to sabotage other governments or commercial space operations and systems during geopolitical conflicts.

Due to the intersections between private and public infrastructure in space, the security of these new infrastructures and technologies need to be investigated as a lack of understanding, analysis and control of space-based infrastructure can make it vulnerable to attacks and outages.

POTENTIAL THREAT ACTORS

State-sponsored actors, cybercrime actors, hackers-for-hire

POTENTIAL METHODS

Unauthorised use of IPR protected resources, targeted attacks, fraud, sabotage, information leakage, session hijacking, malicious software

POTENTIAL IMPACTS

Damage, outages, malfunctions

RISE OF ADVANCED HYBRID THREATS

7

WHAT IF… Hackers are hired by a corporation to investigate the new technology being developed by a competitor. In their quest, they are able to retrieve metadata, view code, and set up a machine learning algorithm that continuously collects changes to the code and then continuously

accesses user account to prevent monitoring systems from recognising ?

that the attacker is in the network. In parallel they obfuscate the activity by spreading fake news about insider trading and industrial espionage from a third competitor by dropping fake evidence of physical intrusion.

Physical or offline attacks are evolving and becoming often combined with cyberattacks due to the increase of smart devices, cloud usage, online identities and social platforms.

POTENTIAL THREAT ACTORS

State-sponsored actors, hackers-for-hire, cyber criminals

POTENTIAL METHODS

Unauthorised access, social engineering, abuse of personal data, remote command execution, malicious activity

POTENTIAL IMPACTS

Privacy breaches, outages, failures/malfunctions

FORESIGHT 2030 THREATS SKILL SHORTAGES

8

WHAT IF… The skill shortage leads to an increase of online job advertisements that tell attackers the technologies that each organisation is using and the approximate number of empty positions. A state-sponsored

?

actor may use this to their advantage as a part of a larger campaign to tamper with critical infrastructure in another country.

Lack of capacities and competencies could see cybercriminal groups target organisations with the largest skills gap and the least maturity.

POTENTIAL THREAT ACTORS

Cybercrime actors, hackers-for-hire, state-sponsored actors

POTENTIAL METHODS

Spear phishing attacks, social engineering

POTENTIAL IMPACTS

Financial damage, outages

CROSS-BORDER ICT SERVICE PROVIDERS AS A SINGLE POINT OF FAILURE

9

WHAT IF… A state-sponsored actor aims to temporarily cripple a region during an active conflict by installing malware that disrupts all critical functions of the ICT

provider. Without operational cities, roadways, and communication channels, ?

the region is essentially crippled without the ability for civilians to go about their daily lives and the responsible parties limited in their ability to maintain defense monitoring systems and to collaborate to develop response options and methods for bringing the necessary systems back online.

ICT sector connecting critical services such as transport, electric grids and industry that provide services across borders are likely be to targeted by techniques such as backdoors, physical manipulation, and denials of service and weaponised during a future potential conflict.

POTENTIAL THREAT ACTORS

State-sponsored actors, hackers-for-hire

POTENTIAL METHODS

Fraud, theft, corruption, terrorist attack, network traffic manipulation, manipulation of hardware or software, abuse of authorisations

POTENTIAL IMPACTS

Outages, damage/loss, unavailable critical infrastructure

FORESIGHT 2030 THREATS ARTIFICIAL INTELLIGENCE ABUSE

10

WHAT IF… A state-sponsored actor wants to sow discord in a population before an election and manipulates the learning data of a law enforcement algorithm to target specific populations, causing widespread protests and violence. They are also able to deduct information about the political opponents themselves by using an AI analysis of the individuals’

?

whereabouts, health history, and voting history – the correlation of such personal data will likely only be feasible with the use of AI tools.

Manipulation of AI algorithms and training data can be used to enhance nefarious activities such as the creation of disinformation and fake content, bias exploitation, collecting biometrics and other sensitive data, military robots and data poisoning.

POTENTIAL THREAT ACTORS

State-sponsored actors, cyber criminals, hackers-for-hire

POTENTIAL METHODS

Spoofing, denial of service, malicious code, unauthorised access, targeted attacks, misuse of information, man in the middle attack

POTENTIAL IMPACTS

Biased decision-making, privacy violations, foreign information manipulation and interference (FIMI) 11

2030 TOP THREATS CONTINUED

11 12

INCREASED DIGITAL EXPLOITATION OF E-HEALTH CURRENCY-ENABLED (AND GENETIC) DATA CYBERCRIME

The amount of genetic and health data By 2030, digital currency-enabled cybercrime increases tremendously by 2030 and is in will increase rapidly. Cryptocurrencies, and the the hands of many stakeholders in the public broad market adoption of them, already have and private sectors. Vulnerabilities in e-health enabled organised crime to expand their reach. devices and databases containing very sensitive Because digital currencies will be very commonly and/or genetic information may be exploited used as an investment asset and means of or used by criminals to target individuals or by payment in European markets, organised crime governments to control populations, e.g., using may be able to expand their targets. This means diseases and genetic diversity as a reason for that cybercrime groups offering professional discriminating against individuals. Genetic data services (cyber-attacks) will be better funded may further be abused to aid law enforcement because of an increase in the efficiency and activities like predictive policing or to support effectiveness of their efforts. a more regimented social credit system.

FORESIGHT 2030 THREATS

13 14

TAMPERING WITH DEEPFAKE ATTACKS USING QUANTUM VERIFICATION SOFTWARE COMPUTING SUPPLY CHAIN

In 2030 quantum computing resources will be By 2030, deepfake technology will be widely made more widely available, allowing threat used. It may be used as a form of harassment, actors to use quantum computing to attack evidence tampering, and provoking social existing deployments of public key cryptography. unrest. Although there will likely be a rapid influx Likewise, there is a risk that threat actors collect of verification software that analyses videos and sensitive encrypted data now, aiming to decrypt voice to verify the identity of individuals , the it once quantum computing is accessible. This is urgent market demand leads to programmers especially relevant for current digital IDs that use cutting corners. This software will be highly asymmetric cryptography to authenticate. targeted by anyone wishing to use deepfakes for illegal or unethical purposes.

15 16

EXPLOITATION OF AI DISRUPTING / ENHANCING UNPATCHED AND OUT-OF- CYBER ATTACKS DATE SYSTEMS WITHIN THE

Escalation as a result of AI-based tools. Attackers OVERWHELMED CROSS- will use AI-based technologies to launch attacks. SECTOR TECH ECOSYSTEM In order to defend against those attacks and

even to launch counter measures, there must Everything-as-a-service leads to a multitude also be defensive AI-based weapons. Behaviour of tools and services that require frequent of the AI in these cases is difficult to test, updates and maintenance by both consumers measure and control – if speed of response is and providers. This combined with the skill valued. shortage presents a difficult to manage surface of vulnerabilities that can be exploited by threat actors. Furthermore, the complexity of the supply chain fosters confusion on where responsibilities for security lie. For governments, this creates more backdoors for espionage while cyber-criminals can exploit the unpatched and outdated services for financial gains. This is especially true when critical infrastructure is in the hands of the private sector or when national security data is reliant on singular private entities.

FORESIGHT 2030 THREATS

17 18

MALWARE INSERTION TO TECHNOLOGICAL DISRUPT FOOD PRODUCTION INCOMPATIBILITY OF SUPPLY CHAINE BLOCKCHAIN TECHNOLOGIES

Due to increased automatisation and Until 2030, several regionally based blockchain digitalization of food production, food supply technologies are created by different groups of chains can be disrupted by a range of threat governments to create an international "gold actors with medium-high resources. Denial of standard". This is driven by a societal lack of service attacks on packaging plants, for example, trust in blockchain that has accumulated over can prevent continued food operations; the last years. Each technology group aims to processed food manufacturing tools may be gain a competitive advantage. This gives rise manipulated to change the compounds in the to a period of technological incompatibility of food itself. Attacks like these can lead to a food blockchain technology which leads to failures, shortage, economic disruptions, and in the malfunctions, data loss and the exploitation of worst case, poisoning. vulnerabilities at the interfaces of the different blockchains. This creates challenges for ecosystem management and data protection, furthers distrust, and negatively affects trade and GDP growth.

19 20 21

DISRUPTIONS PHYSICAL IMPACT MANIPULATION IN PUBLIC OF NATURAL / OF SYSTEMS BLOCKCHAINS ENVIRONMENTAL NECESSARY FOR DISRUPTIONS ON EMERGENCY

Blockchain has been implemented in nearly all CRITICAL DIGITAL RESPONSE aspects of society in 2030. INFRASTRUCTURE Manipulation of sensors with Unfortunately, security The increased severity and connections to emergency expertise in the area of frequency of environmental services may overload blockchain did not advance disasters causes several services like ambulances, significantly, creating a slew regional outages. Redundant police, firefighters, etc. For of vulnerabilities that may back-up sites that maintain example, call centres may be be exploited in the future. the availability of critical overloaded with inauthentic Locally unavailable blockchain infrastructure will also be calls or fire alarms may be technology will, for example, affected. manipulated to injure specific prevent access to voting, individuals or to obscure legal transactions, and even emergency response teams' security systems. Another ability to locate the issue. possible attack vector is Similarly, mass panics that exploited by partitioning the overload emergency systems bitcoin network by hijacking may also be provoked through IP address prefixes. This the use of social media. can cause, for example, duplicated spending and thus economic damage.

ABOUT ENISA

The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certifi cation schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure and, ultimately, to keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu.

ENISA

European Union Agency for Cybersecurity

Athens Offi ce

Agamemnonos 14 Chalandri 15231, Attiki, Greece

Heraklion Offi ce

95 Nikolaou Plastira 700 13 Vassilika Vouton, Heraklion, Greece

Brussels Offi ce

Rue de la Loi 107 1049 Brussels, Belgium

enisa.europa.eu https://www.enisa.europa.eu/topics/foresight

Fotnoter

  1. Reference to the report page: