Foresight Cybersecurity Threats For 2030 - Update 2024
FORESIGHT 2030 THREATS
THREATS 2030 7 MARCH 2024 FORESIGHT 2030 THREATS EXECUTIVE DIRECTOR FOREWORD
In today’s world, the growing reliance on digital technologies, such as AI, across all sectors has introduced both opportunities and threats in the cybersecurity ecosystem. Amidst worldwide geopolitics and natural disasters, cyberattacks have become more sophisticated and hybrid threats have gained prominence.
We are currently faced with a rapidly changing cyber threat landscape. To successfully address what the future might bring, we have to continuously adapt our posture, tools and strategies.
The EU Agency for Cybersecurity remains committed to its mission to increase the common level of cybersecurity across the EU, by building resilience against the emerging cybersecurity risks and threats. In order to be able to remodel our approach and shield our critical infrastructure, we need to be vigilant to the upcoming cybersecurity trends.
The second edition of the Foresight Cybersecurity Threats for 2030 is a result of the applied foresight methodology along with the valuable contributions from cybersecurity experts. This booklet provides a comprehensive overview of the top emerging cybersecurity threats and identified trends that lie ahead and eventually aims to improve preparedness and enable better informed actions
Juhan Lepassaar
Executive Director
SUPPLY CHAIN COMPROMISE OF SOFTWARE
1
DEPENDENCIES
WHAT IF… State-sponsored actors insert a backdoor in a well-known and popular open-source library on online code repository. They use this to infiltrate information from most major European corporations and
?
use the information to blackmail leaders, espionage, or otherwise initiate disruptions across the EU.
More integrated components and services from third party suppliers and partners could lead to novel and unforeseen vulnerabilities with compromises on the supplier and customer side.
POTENTIAL THREAT ACTORS
State-sponsored groups, criminal organisations
POTENTIAL METHODS
Sabotage, theft, network reconnaissance, malicious code, abuse of information leakage
POTENTIAL IMPACTS
Disruption, malfunction, data loss, data leakage
FORESIGHT 2030 THREATS SKILL SHORTAGES
2
WHAT IF… The skill shortage leads to an increase of online job advertisements that tell attackers the technologies that each organisation is using and the approximate number of empty positions. A state-sponsored
?
actor may use this to their advantage as a part of a larger campaign to tamper with critical infrastructure in another country.
Lack of capacities and competencies could see cybercriminal groups target organisations with the largest skills gap and the least maturity.
POTENTIAL THREAT ACTORS
Cybercrime actors, hackers-for-hire, state-sponsored actors
POTENTIAL METHODS
Spear phishing attacks, social engineering
POTENTIAL IMPACTS
Financial damage, outages
HUMAN ERROR AND EXPLOITED LEGACY SYSTEMS WITHIN CYBER-
3
PHYSICAL ECOSYSTEMS
WHAT IF… Manuals for all legacy OT equipment are available online and studied primarily by state-sponsored groups. Once a vulnerability is found, they target user devices or other IoT products used at the plant.
Cyber criminals begin a new form of ransomware in which they bring ?
down important infrastructure and demand payment, given that the operator likely lacks the resources to solve the issue themselves.
The fast adoption of IoT, the need to retrofit legacy systems and the ongoing skill shortage could lead to a lack of knowledge, training and understanding of the cyberphysical ecosystem, which can lead to security issues.
POTENTIAL THREAT ACTORS
State-sponsored groups, cyber criminals, hacktivists
POTENTIAL METHODS
Tampering, failure of communication links, denial of service, malicious activity, manipulation of information, targeted attacks, brute force, unauthorised physical access
POTENTIAL IMPACTS
Malfunction, failures and outages, physical damage
FORESIGHT 2030 THREATS EXPLOITATION OF UNPATCHED AND OUT-OF-DATE SYSTEMS
4
WHAT IF… Criminals exploit a vulnerability in an unpatched component of critical infrastructure owned by a private company currently going bankrupt which cannot afford the few subject matter experts or the support contract that can respond to the attack. On the other side attackers launch
?
a ransomware attack towards out of date hospital systems that cannot be patched because the manufacturer doesn't provide updates anymore.
Everything-as-a-service leads to a multitude of tools and services that require frequent and synchronised updates as well as orchestrated maintenance. This fact along with the skill shortage, results in an extended and unmanageable surface of vulnerabilities that threat actors can exploit.
POTENTIAL THREAT ACTORS
State-sponsored groups, criminal organisations, hacktivists
POTENTIAL METHODS
Tampering, failure of communication links, denial of service, malicious activity, manipulation of information, targeted attacks, brute force, malicious code
POTENTIAL IMPACTS
Malfunction, failures and outages, physical damage, damage/loss, unavailable critical infrastructure 5
RISE OF DIGITAL SURVEILLANCE AUTHORITARIANISM /
5
LOSS OF PRIVACY
WHAT IF… An authoritarian regime uses their power to retrieve databases of information about individuals who have visited their country, from both public and private entities. They track all those who participated in anti-government protests, put them on a watch list,
?
and subsequently are able to manipulate those individuals’ access to national services like voting, visits to their healthcare providers, or access to other online services.
Facial recognition, digital surveillance on internet platforms or digital identities data stores may become a target for criminal groups.
POTENTIAL THREAT ACTORS
State-sponsored groups, criminal organisations
POTENTIAL METHODS
Man in the middle, malicious software, use of rogue certificates, abuse of personal data
POTENTIAL IMPACTS
Privacy breaches, human rights abuses
FORESIGHT 2030 THREATS CROSS-BORDER ICT SERVICE PROVIDERS AS A SINGLE POINT OF FAILURE
6
WHAT IF… A state-sponsored actor aims to temporarily cripple a region during an active conflict by installing malware that disrupts all critical functions of the ICT
provider. Without operational cities, roadways, and communication channels, ?
the region is essentially crippled without the ability for civilians to go about their daily lives and the responsible parties limited in their ability to maintain defense monitoring systems and to collaborate to develop response options and methods for bringing the necessary systems back online.
ICT sector connecting critical services such as transport, electric grids and industry that provide services across borders are likely be to targeted by techniques such as backdoors, physical manipulation, and denials of service and weaponised during a future potential conflict.
POTENTIAL THREAT ACTORS
State-sponsored actors, hackers-for-hire
POTENTIAL METHODS
Fraud, theft, corruption, terrorist attack, network traffic manipulation, manipulation of hardware or software, abuse of authorisations
POTENTIAL IMPACTS
Outages, damage/loss, unavailable critical infrastructure
ADVANCED DISINFORMATION CAMPAIGNS
7
WHAT IF… A state-sponsored actor may impersonate a political rival by using deepfakes and spoofing the candidate’s digital identity, significantly
?
impacting election results.
Deepfake attacks can manipulate communities for (geo) political reasons and for monetary gain.
POTENTIAL THREAT ACTORS
State-sponsored groups, criminal organisations, hacktivists
POTENTIAL METHODS
Fraud, unauthorised access, session hijacking, identity theft, abuse of personal data
POTENTIAL IMPACTS
Distrust, disinformation, financial damage, foreign information manipulation and interference (FIMI)
FORESIGHT 2030 THREATS RISE OF ADVANCED HYBRID THREATS
8
WHAT IF… Hackers are hired by a corporation to investigate the new technology being developed by a competitor. In their quest, they are able to retrieve metadata, view code, and set up a machine learning algorithm that continuously collects changes to the code and then continuously
accesses user account to prevent monitoring systems from recognising ?
that the attacker is in the network. In parallel they obfuscate the activity by spreading fake news about insider trading and industrial espionage from a third competitor by dropping fake evidence of physical intrusion.
Physical or offline attacks are evolving and becoming often combined with cyberattacks due to the increase of smart devices, cloud usage, online identities and social platforms.
POTENTIAL THREAT ACTORS
State-sponsored actors, hackers-for-hire, cyber criminals
POTENTIAL METHODS
Unauthorised access, social engineering, abuse of personal data, remote command execution, malicious activity
POTENTIAL IMPACTS
Privacy breaches, outages, failures/malfunctions
ARTIFICIAL INTELLIGENCE ABUSE
9
WHAT IF… A state-sponsored actor wants to sow discord in a population before an election and manipulates the learning data of a law enforcement algorithm to target specific populations, causing widespread protests and violence. They are also able to deduct information about the political opponents themselves by using an AI analysis of the individuals’
?
whereabouts, health history, and voting history – the correlation of such personal data will likely only be feasible with the use of AI tools.
Manipulation of AI algorithms and training data can be used to enhance nefarious activities such as the creation of disinformation and fake content, bias exploitation, collecting biometrics and other sensitive data, military robots and data poisoning.
POTENTIAL THREAT ACTORS
State-sponsored actors, cyber criminals, hackers-for-hire
POTENTIAL METHODS
Spoofing, denial of service, malicious code, unauthorised access, targeted attacks, misuse of information, man in the middle attack
POTENTIAL IMPACTS
Biased decision-making, privacy violations, foreign information manipulation and interference (FIMI)
FORESIGHT 2030 THREATS PHYSICAL IMPACT OF NATURAL/ ENVIRONMENTAL
10
DISRUPTIONS ON CRITICAL DIGITAL INFRASTRUCTURE
WHAT IF… The increasingly common occurrences of fires and flooding result in more frequent power outages, leading to disruptions in connectivity services.
?
Techno luddites weaponise this and perform physical attacks to back up sites.
The increased severity and frequency of environmental disasters following climate change may cause several unforeseen regional outages. Redundant back-up sites that maintain the availability of critical infrastructure are also impacted by the massive and extreme weather phenomena
POTENTIAL THREAT ACTORS
State-sponsored actors, hacktivists
POTENTIAL METHODS
Tampering, terrorist attack, sabotage, theft, manipulation of hardware
POTENTIAL IMPACTS
Outages, damage/loss, unavailable critical infrastructure, disruption, malfunction, data loss 11
2030 TOP THREATS CONTINUED
11 12
LACK OF ANALYSIS AND TARGETED ATTACKS (E.G. CONTROL OF SPACE-BASED RANSOMWARE) ENHANCED INFRASTRUCTURE AND BY SMART DEVICE DATA OBJECTS
Cybercriminals may use the increased amount State-sponsored attackers access space of available data from smart devices and analyse infrastructure, build up their capabilities and it with AI to create behavioral models of their knowledge of the technology, and secure their victims for spear phishing campaigns or stalking. presence to execute attacks. Their aim may Through data obtained from internet-connected be to create infrastructure malfunctions as smart devices, attackers can access information a statecraft tool to sabotage other governments for tailored and more sophisticated attacks. or commercial space operations and systems during geopolitical conflicts. Due to the intersections between private and public infrastructure in space, the security of these new infrastructures and technologies need to be investigated as a lack of understanding, analysis and control of space-based infrastructure can make it vulnerable to attacks and outages.
FORESIGHT 2030 THREATS
13 14
INCREASED DIGITAL MANIPULATION OF SYSTEMS CURRENCY-ENABLED NECESSARY FOR EMERGENCY CYBERCRIME RESPONSE
By 2030, digital currency-enabled cybercrime Manipulation of sensors with connections to will increase rapidly. Cryptocurrencies, and the emergency services may overload services like broad market adoption of them, already have ambulances, police, firefighters, etc. For example, enabled organised crime to expand their reach. call centres may be overloaded with inauthentic Because digital currencies will be very commonly calls or fire alarms may be manipulated to injure used as an investment asset and means of specific individuals or to obscure emergency payment in European markets, organised crime response teams' ability to locate the issue. may be able to expand their targets. This means Similarly, mass panics that overload emergency that cybercrime groups offering professional systems may also be provoked through the use services (cyber-attacks) will be better funded of social media. because of an increase in the efficiency and effectiveness of their efforts.
15 16
TAMPERING WITH DEEPFAKE AI DISRUPTING / ENHANCING VERIFICATION SOFTWARE CYBER ATTACKS SUPPLY CHAIN
Escalation as a result of AI-based tools. Attackers By 2030, deepfake technology will be widely will use AI-based technologies to launch attacks. used. It may be used as a form of harassment, In order to defend against those attacks and evidence tampering, and provoking social even to launch counter measures, there must unrest. Although there will likely be a rapid influx also be defensive AI-based weapons. Behaviour of verification software that analyses videos and of the AI in these cases is difficult to test, voice to verify the identity of individuals , the measure and control – if speed of response is urgent market demand leads to programmers valued. cutting corners. This software will be highly targeted by anyone wishing to use deepfakes for illegal or unethical purposes.
FORESIGHT 2030 THREATS
17 18
MALWARE INSERTION TO EXPLOITATION OF E-HEALTH DISRUPT FOOD PRODUCTION (AND GENETIC) DATA SUPPLY CHAINE
The amount of genetic and health data Due to increased automatisation and increases tremendously by 2030 and is in digitalization of food production, food supply the hands of many stakeholders in the public chains can be disrupted by a range of threat and private sectors. Vulnerabilities in e-health actors with medium-high resources. Denial of devices and databases containing very sensitive service attacks on packaging plants, for example, and/or genetic information may be exploited can prevent continued food operations; or used by criminals to target individuals or by processed food manufacturing tools may be governments to control populations, e.g., using manipulated to change the compounds in the diseases and genetic diversity as a reason for food itself. Attacks like these can lead to a food discriminating against individuals. Genetic data shortage, economic disruptions, and in the may further be abused to aid law enforcement worst case, poisoning. activities like predictive policing or to support a more regimented social credit system.
19 19 21
ATTACKS USING DISRUPTIONS TECHNOLOGICAL QUANTUM IN PUBLIC INCOMPATIBILITY COMPUTING BLOCKCHAINS OF BLOCKCHAIN TECHNOLOGIES
In 2030 quantum computing Blockchain has been resources will be made more implemented in nearly all Until 2030, several regionally based widely available, allowing aspects of society in 2030. blockchain technologies are created threat actors to use quantum Unfortunately, security by different groups of governments computing to attack existing expertise in the area of to create an international "gold deployments of public key blockchain did not advance standard". This is driven by a cryptography. Likewise, there significantly, creating a slew societal lack of trust in blockchain is a risk that threat actors of vulnerabilities that may that has accumulated over the last collect sensitive encrypted be exploited in the future. years. Each technology group aims data now, aiming to decrypt it Locally unavailable blockchain to gain a competitive advantage. once quantum computing is technology will, for example, This gives rise to a period of accessible. This is especially prevent access to voting, technological incompatibility of relevant for current digital legal transactions, and even blockchain technology which IDs that use asymmetric security systems. Another leads to failures, malfunctions, cryptography to authenticate. possible attack vector is data loss and the exploitation of exploited by partitioning the vulnerabilities at the interfaces bitcoin network by hijacking of the different blockchains. This IP address prefixes. This creates challenges for ecosystem can cause, for example, management and data protection, duplicated spending and thus furthers distrust, and negatively economic damage. affects trade and GDP growth.
ABOUT ENISA
The European Union Agency for Cybersecurity, ENISA, is the Union’s agency dedicated to achieving a high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy, enhances the trustworthiness of ICT products, services and processes with cybersecurity certifi cation schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the Agency works together with its key stakeholders to strengthen trust in the connected economy, to boost resilience of the Union’s infrastructure and, ultimately, to keep Europe’s society and citizens digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu.
ENISA
European Union Agency for Cybersecurity
Athens Offi ce
Agamemnonos 14 Chalandri 15231, Attiki, Greece
Heraklion Offi ce
95 Nikolaou Plastira 700 13 Vassilika Vouton, Heraklion, Greece
Brussels Offi ce
Rue de la Loi 107 1049 Brussels, Belgium
enisa.europa.eu https://www.enisa.europa.eu/topics/foresight
Fotnoter
- Reference to the report page: