lagen.nu
Foresight Cybersecurity Threats For 2030 - Update 2024

Foresight Cybersecurity Threats For 2030 - Update 2024

Utgivare
Europeiska unionens cybersäkerhetsbyrå
Antagen
2024-03-27
Språk
engelska
Ämnesord
Cyber Threats
Källa
www.enisa.europa.eu
Endast på engelskaEuropeiska unionens cybersäkerhetsbyrå har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska unionens cybersäkerhetsbyrå.

FORESIGHT 2030 THREATS

THREATS 2030 7 MARCH 2024 FORESIGHT 2030 THREATS EXECUTIVE DIRECTOR FOREWORD

In today’s world, the growing reliance on digital technologies, such as AI, across all sectors has introduced both opportunities and threats in the cybersecurity ecosystem. Amidst worldwide geopolitics and natural disasters, cyberattacks have become more sophisticated and hybrid threats have gained prominence.

We are currently faced with a rapidly changing cyber threat landscape. To successfully address what the future might bring, we have to continuously adapt our posture, tools and strategies.

The EU Agency for Cybersecurity remains committed to its mission to increase the common level of cybersecurity across the EU, by building resilience against the emerging cybersecurity risks and threats. In order to be able to remodel our approach and shield our critical infrastructure, we need to be vigilant to the upcoming cybersecurity trends.

The second edition of the Foresight Cybersecurity Threats for 2030 is a result of the applied foresight methodology along with the valuable contributions from cybersecurity experts. This booklet provides a comprehensive overview of the top emerging cybersecurity threats and identified trends that lie ahead and eventually aims to improve preparedness and enable better informed actions

Juhan Lepassaar

Executive Director

SUPPLY CHAIN COMPROMISE OF SOFTWARE

1

DEPENDENCIES

WHAT IF… State-sponsored actors insert a backdoor in a well-known and popular open-source library on online code repository. They use this to infiltrate information from most major European corporations and

?

use the information to blackmail leaders, espionage, or otherwise initiate disruptions across the EU.

More integrated components and services from third party suppliers and partners could lead to novel and unforeseen vulnerabilities with compromises on the supplier and customer side.

POTENTIAL THREAT ACTORS

State-sponsored groups, criminal organisations

POTENTIAL METHODS

Sabotage, theft, network reconnaissance, malicious code, abuse of information leakage

POTENTIAL IMPACTS

Disruption, malfunction, data loss, data leakage

FORESIGHT 2030 THREATS SKILL SHORTAGES

2

WHAT IF… The skill shortage leads to an increase of online job advertisements that tell attackers the technologies that each organisation is using and the approximate number of empty positions. A state-sponsored

?

actor may use this to their advantage as a part of a larger campaign to tamper with critical infrastructure in another country.

Lack of capacities and competencies could see cybercriminal groups target organisations with the largest skills gap and the least maturity.

POTENTIAL THREAT ACTORS

Cybercrime actors, hackers-for-hire, state-sponsored actors

POTENTIAL METHODS

Spear phishing attacks, social engineering

POTENTIAL IMPACTS

Financial damage, outages

HUMAN ERROR AND EXPLOITED LEGACY SYSTEMS WITHIN CYBER-

3

PHYSICAL ECOSYSTEMS

WHAT IF… Manuals for all legacy OT equipment are available online and studied primarily by state-sponsored groups. Once a vulnerability is found, they target user devices or other IoT products used at the plant.

Cyber criminals begin a new form of ransomware in which they bring ?

down important infrastructure and demand payment, given that the operator likely lacks the resources to solve the issue themselves.

The fast adoption of IoT, the need to retrofit legacy systems and the ongoing skill shortage could lead to a lack of knowledge, training and understanding of the cyberphysical ecosystem, which can lead to security issues.

POTENTIAL THREAT ACTORS

State-sponsored groups, cyber criminals, hacktivists

POTENTIAL METHODS

Tampering, failure of communication links, denial of service, malicious activity, manipulation of information, targeted attacks, brute force, unauthorised physical access

POTENTIAL IMPACTS

Malfunction, failures and outages, physical damage

FORESIGHT 2030 THREATS EXPLOITATION OF UNPATCHED AND OUT-OF-DATE SYSTEMS

4

WHAT IF… Criminals exploit a vulnerability in an unpatched component of critical infrastructure owned by a private company currently going bankrupt which cannot afford the few subject matter experts or the support contract that can respond to the attack. On the other side attackers launch

?

a ransomware attack towards out of date hospital systems that cannot be patched because the manufacturer doesn't provide updates anymore.

Everything-as-a-service leads to a multitude of tools and services that require frequent and synchronised updates as well as orchestrated maintenance. This fact along with the skill shortage, results in an extended and unmanageable surface of vulnerabilities that threat actors can exploit.

POTENTIAL THREAT ACTORS

State-sponsored groups, criminal organisations, hacktivists

POTENTIAL METHODS

Tampering, failure of communication links, denial of service, malicious activity, manipulation of information, targeted attacks, brute force, malicious code

POTENTIAL IMPACTS

Malfunction, failures and outages, physical damage, damage/loss, unavailable critical infrastructure 5

RISE OF DIGITAL SURVEILLANCE AUTHORITARIANISM /

5

LOSS OF PRIVACY

WHAT IF… An authoritarian regime uses their power to retrieve databases of information about individuals who have visited their country, from both public and private entities. They track all those who participated in anti-government protests, put them on a watch list,

?

and subsequently are able to manipulate those individuals’ access to national services like voting, visits to their healthcare providers, or access to other online services.

Facial recognition, digital surveillance on internet platforms or digital identities data stores may become a target for criminal groups.

POTENTIAL THREAT ACTORS

State-sponsored groups, criminal organisations

POTENTIAL METHODS

Man in the middle, malicious software, use of rogue certificates, abuse of personal data

POTENTIAL IMPACTS

Privacy breaches, human rights abuses

FORESIGHT 2030 THREATS CROSS-BORDER ICT SERVICE PROVIDERS AS A SINGLE POINT OF FAILURE

6

WHAT IF… A state-sponsored actor aims to temporarily cripple a region during an active conflict by installing malware that disrupts all critical functions of the ICT

provider. Without operational cities, roadways, and communication channels, ?

the region is essentially crippled without the ability for civilians to go about their daily lives and the responsible parties limited in their ability to maintain defense monitoring systems and to collaborate to develop response options and methods for bringing the necessary systems back online.

ICT sector connecting critical services such as transport, electric grids and industry that provide services across borders are likely be to targeted by techniques such as backdoors, physical manipulation, and denials of service and weaponised during a future potential conflict.

POTENTIAL THREAT ACTORS

State-sponsored actors, hackers-for-hire

POTENTIAL METHODS

Fraud, theft, corruption, terrorist attack, network traffic manipulation, manipulation of hardware or software, abuse of authorisations

POTENTIAL IMPACTS

Outages, damage/loss, unavailable critical infrastructure

ADVANCED DISINFORMATION CAMPAIGNS

7

WHAT IF… A state-sponsored actor may impersonate a political rival by using deepfakes and spoofing the candidate’s digital identity, significantly

?

impacting election results.

Deepfake attacks can manipulate communities for (geo) political reasons and for monetary gain.

POTENTIAL THREAT ACTORS

State-sponsored groups, criminal organisations, hacktivists

POTENTIAL METHODS

Fraud, unauthorised access, session hijacking, identity theft, abuse of personal data

POTENTIAL IMPACTS

Distrust, disinformation, financial damage, foreign information manipulation and interference (FIMI)

FORESIGHT 2030 THREATS RISE OF ADVANCED HYBRID THREATS

8

WHAT IF… Hackers are hired by a corporation to investigate the new technology being developed by a competitor. In their quest, they are able to retrieve metadata, view code, and set up a machine learning algorithm that continuously collects changes to the code and then continuously

accesses user account to prevent monitoring systems from recognising ?

that the attacker is in the network. In parallel they obfuscate the activity by spreading fake news about insider trading and industrial espionage from a third competitor by dropping fake evidence of physical intrusion.

Physical or offline attacks are evolving and becoming often combined with cyberattacks due to the increase of smart devices, cloud usage, online identities and social platforms.

POTENTIAL THREAT ACTORS

State-sponsored actors, hackers-for-hire, cyber criminals

POTENTIAL METHODS

Unauthorised access, social engineering, abuse of personal data, remote command execution, malicious activity

POTENTIAL IMPACTS

Privacy breaches, outages, failures/malfunctions

ARTIFICIAL INTELLIGENCE ABUSE

9

WHAT IF… A state-sponsored actor wants to sow discord in a population before an election and manipulates the learning data of a law enforcement algorithm to target specific populations, causing widespread protests and violence. They are also able to deduct information about the political opponents themselves by using an AI analysis of the individuals’

?

whereabouts, health history, and voting history – the correlation of such personal data will likely only be feasible with the use of AI tools.

Manipulation of AI algorithms and training data can be used to enhance nefarious activities such as the creation of disinformation and fake content, bias exploitation, collecting biometrics and other sensitive data, military robots and data poisoning.

POTENTIAL THREAT ACTORS

State-sponsored actors, cyber criminals, hackers-for-hire

POTENTIAL METHODS

Spoofing, denial of service, malicious code, unauthorised access, targeted attacks, misuse of information, man in the middle attack

POTENTIAL IMPACTS

Biased decision-making, privacy violations, foreign information manipulation and interference (FIMI)

FORESIGHT 2030 THREATS PHYSICAL IMPACT OF NATURAL/ ENVIRONMENTAL

10

DISRUPTIONS ON CRITICAL DIGITAL INFRASTRUCTURE

WHAT IF… The increasingly common occurrences of fires and flooding result in more frequent power outages, leading to disruptions in connectivity services.

?

Techno luddites weaponise this and perform physical attacks to back up sites.

The increased severity and frequency of environmental disasters following climate change may cause several unforeseen regional outages. Redundant back-up sites that maintain the availability of critical infrastructure are also impacted by the massive and extreme weather phenomena

POTENTIAL THREAT ACTORS

State-sponsored actors, hacktivists

POTENTIAL METHODS

Tampering, terrorist attack, sabotage, theft, manipulation of hardware

POTENTIAL IMPACTS

Outages, damage/loss, unavailable critical infrastructure, disruption, malfunction, data loss 11

2030 TOP THREATS CONTINUED

11 12

LACK OF ANALYSIS AND TARGETED ATTACKS (E.G. CONTROL OF SPACE-BASED RANSOMWARE) ENHANCED INFRASTRUCTURE AND BY SMART DEVICE DATA OBJECTS

Cybercriminals may use the increased amount State-sponsored attackers access space of available data from smart devices and analyse infrastructure, build up their capabilities and it with AI to create behavioral models of their knowledge of the technology, and secure their victims for spear phishing campaigns or stalking. presence to execute attacks. Their aim may Through data obtained from internet-connected be to create infrastructure malfunctions as smart devices, attackers can access information a statecraft tool to sabotage other governments for tailored and more sophisticated attacks. or commercial space operations and systems during geopolitical conflicts. Due to the intersections between private and public infrastructure in space, the security of these new infrastructures and technologies need to be investigated as a lack of understanding, analysis and control of space-based infrastructure can make it vulnerable to attacks and outages.

FORESIGHT 2030 THREATS

13 14

INCREASED DIGITAL MANIPULATION OF SYSTEMS CURRENCY-ENABLED NECESSARY FOR EMERGENCY CYBERCRIME RESPONSE

By 2030, digital currency-enabled cybercrime Manipulation of sensors with connections to will increase rapidly. Cryptocurrencies, and the emergency services may overload services like broad market adoption of them, already have ambulances, police, firefighters, etc. For example, enabled organised crime to expand their reach. call centres may be overloaded with inauthentic Because digital currencies will be very commonly calls or fire alarms may be manipulated to injure used as an investment asset and means of specific individuals or to obscure emergency payment in European markets, organised crime response teams' ability to locate the issue. may be able to expand their targets. This means Similarly, mass panics that overload emergency that cybercrime groups offering professional systems may also be provoked through the use services (cyber-attacks) will be better funded of social media. because of an increase in the efficiency and effectiveness of their efforts.

15 16

TAMPERING WITH DEEPFAKE AI DISRUPTING / ENHANCING VERIFICATION SOFTWARE CYBER ATTACKS SUPPLY CHAIN

Escalation as a result of AI-based tools. Attackers By 2030, deepfake technology will be widely will use AI-based technologies to launch attacks. used. It may be used as a form of harassment, In order to defend against those attacks and evidence tampering, and provoking social even to launch counter measures, there must unrest. Although there will likely be a rapid influx also be defensive AI-based weapons. Behaviour of verification software that analyses videos and of the AI in these cases is difficult to test, voice to verify the identity of individuals , the measure and control – if speed of response is urgent market demand leads to programmers valued. cutting corners. This software will be highly targeted by anyone wishing to use deepfakes for illegal or unethical purposes.

FORESIGHT 2030 THREATS

17 18

MALWARE INSERTION TO EXPLOITATION OF E-HEALTH DISRUPT FOOD PRODUCTION (AND GENETIC) DATA SUPPLY CHAINE

The amount of genetic and health data Due to increased automatisation and increases tremendously by 2030 and is in digitalization of food production, food supply the hands of many stakeholders in the public chains can be disrupted by a range of threat and private sectors. Vulnerabilities in e-health actors with medium-high resources. Denial of devices and databases containing very sensitive service attacks on packaging plants, for example, and/or genetic information may be exploited can prevent continued food operations; or used by criminals to target individuals or by processed food manufacturing tools may be governments to control populations, e.g., using manipulated to change the compounds in the diseases and genetic diversity as a reason for food itself. Attacks like these can lead to a food discriminating against individuals. Genetic data shortage, economic disruptions, and in the may further be abused to aid law enforcement worst case, poisoning. activities like predictive policing or to support a more regimented social credit system.

19 19 21

ATTACKS USING DISRUPTIONS TECHNOLOGICAL QUANTUM IN PUBLIC INCOMPATIBILITY COMPUTING BLOCKCHAINS OF BLOCKCHAIN TECHNOLOGIES

In 2030 quantum computing Blockchain has been resources will be made more implemented in nearly all Until 2030, several regionally based widely available, allowing aspects of society in 2030. blockchain technologies are created threat actors to use quantum Unfortunately, security by different groups of governments computing to attack existing expertise in the area of to create an international "gold deployments of public key blockchain did not advance standard". This is driven by a cryptography. Likewise, there significantly, creating a slew societal lack of trust in blockchain is a risk that threat actors of vulnerabilities that may that has accumulated over the last collect sensitive encrypted be exploited in the future. years. Each technology group aims data now, aiming to decrypt it Locally unavailable blockchain to gain a competitive advantage. once quantum computing is technology will, for example, This gives rise to a period of accessible. This is especially prevent access to voting, technological incompatibility of relevant for current digital legal transactions, and even blockchain technology which IDs that use asymmetric security systems. Another leads to failures, malfunctions, cryptography to authenticate. possible attack vector is data loss and the exploitation of exploited by partitioning the vulnerabilities at the interfaces bitcoin network by hijacking of the different blockchains. This IP address prefixes. This creates challenges for ecosystem can cause, for example, management and data protection, duplicated spending and thus furthers distrust, and negatively economic damage. affects trade and GDP growth.

ABOUT ENISA

The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certifi cation schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure and, ultimately, to keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu.

ENISA

European Union Agency for Cybersecurity

Athens Offi ce

Agamemnonos 14 Chalandri 15231, Attiki, Greece

Heraklion Offi ce

95 Nikolaou Plastira 700 13 Vassilika Vouton, Heraklion, Greece

Brussels Offi ce

Rue de la Loi 107 1049 Brussels, Belgium

enisa.europa.eu https://www.enisa.europa.eu/topics/foresight

Fotnoter

  1. Reference to the report page: