Mandiant-2023 Forecast Report-01
Mandiant-2023 Forecast Report-01
Introduction
Our insights on the year ahead have previously been referred to as “predictions.”
However, our thoughts about the cyber security landscape in the coming year are
always based on the trends we are already seeing. “Forecast” captures our intent
more precisely. And so, we present the Mandiant Cyber Security Forecast 2023. This
report is filled with forward-looking thoughts from several of Mandiant’s brightest
minds, including Sandra Joyce, Head of Global Intelligence, and Charles Carmakal,
Consulting CTO, as well as Phil Venables, CISO for Google Cloud.
Threats evolve, attackers constantly change their tactics, techniques and
procedures, and defenders must adapt and stay relentless if they want to keep
up. This Forecast aims to help the cyber security industry frame its fight against
cyber adversaries in 2023.
2
MANDIANT CYBER SECURITY FORECAST 2023
Global Forecasts
More Attacks by Non-Organized Attackers and Non-Nation
State Attackers
In 2023 we expect to see more intrusions conducted by non-organized attackers
and non-nation state attackers. More of the threat actors operating out of North
America and Europe will likely be younger, and conducting intrusion operations not
because they're interested in making money specifically, or because governments
have tasked them with doing it, but because they want to be able to brag to their
friends or boast online that they've hacked into and brought embarrassment to
prominent organizations. While they will be happy to achieve financial gain, that
may not necessarily be their lead motivation.
1. FCW (September 27, 2022). The U.S. is the top target of ransomware attacks, report says.
2. Washington Post (August 17, 2022). Is the drop in ransomware numbers an illusion?.
3
MANDIANT CYBER SECURITY FORECAST 2023
Iranian Escalation
Mandiant expects that Iranian cyber espionage groups will continue to conduct
widespread intelligence collection activity, particularly against government and
Middle Eastern targets, as well as telecommunications, transportation and other
entities. We anticipate Iranian threat actors’ continued willingness to use disruptive
and destructive cyber attacks to remain elevated, absent a significant change to
Iran’s current international isolation.
3. Mandiant (June 28, 2022). Pro-PRC DRAGONBRIDGE Influence Campaign Targets Rare Earths Mining Companies in Attempt to Thwart Rivalry to PRC Market Dominance.
4
MANDIANT CYBER SECURITY FORECAST 2023
4. U.S. Department of Justice (March 2019). Report On The Investigation Into Russian Interference In The 2016 Presidential Election.
5. Australian Strategic Policy Institute (October 15, 2019). Joint BBC-ASPI investigation into West Papua information operations.
6. ZDNET (July 29, 2021). Disinformation for hire: PR firms are the new battleground for Facebook.
7. Apple (May 5, 2022). Apple, Google, and Microsoft commit to expanded support for FIDO standard to accelerate availability of passwordless sign‑ins.
5
MANDIANT CYBER SECURITY FORECAST 2023
6
MANDIANT CYBER SECURITY FORECAST 2023
8. The White House (May 12, 2021). Executive Order on Improving the Nation’s Cybersecurity.
9. The White House (January 19, 2022). FACT SHEET: President Biden Signs National Security Memorandum to Improve the Cybersecurity of National Security, Department
of Defense, and Intelligence Community Systems.
7
MANDIANT CYBER SECURITY FORECAST 2023
APJ Forecasts
Cyber Activity Around Southeast Asia Elections in 2023
Several Southeast Asian countries have general elections scheduled for or
expected in 2023. We are preparing for the Cambodian general election, Malaysian
general election, Myanmar general election and Thailand general election. Cyber
espionage groups have had interest in previous Southeast Asian elections and
the 2023 elections may prove to be compelling targets. We also expect to see
these elections being used as lures for phishing and social engineering. Philippine
elections were held in 2022 and the government cited 20,000 attempts to attack
the automated election systems.10
10. CNN Philippines (May 11, 2022). Govt blocks over 20K attempts to hack elections, says Esperon.
11. Recorded Future (September 29, 2022). Semiconductor Companies Targeted by Ransomware.
8
MANDIANT CYBER SECURITY FORECAST 2023
EMEA Forecasts
Russia to Expand Targets Across Europe
A significant portion of Russian cyber activity has been focused on Ukraine since the
onset of the conflict, but 2023 could see Russia further expand its cyber operations
across Europe. The winter months will likely slow the pace of physical conflict, which
could provide Russian cyber threat actors with more threat capacity. During the
past year, Russia has typically conducted information-gathering campaigns against
European organizations outside Ukraine while most of its disruptive and destructive
attacks have been focused within Ukraine. This may change in 2023, with Russia
using more of its (potentially increased) disruptive cyber capabilities against
European organizations. This could impact a range of organizations, including energy
and military suppliers, logistics companies involved in the supply of goods to Ukraine
and organizations involved in the introduction and implantation of sanction regimes.
12. The Verge (August 19, 2021). The pandemic revealed the health risks of hospital ransomware attacks.
9
MANDIANT CYBER SECURITY FORECAST 2023
Conclusion
Ransomware has been a staple of Mandiant reports for several years, and for good
reason. While it is well-established as part of many threat actors’ toolkits, data
shows more of drop in the U.S. ransomware incidents and a rise in European
ransomware incidents. While entities in European regions need to stay especially
vigilant, organizations around the world need to be ready for increased attempts at
extortion. Extortion actors will stop at nothing to achieve their goals, even using
physical devices and less common types of social engineering.
Next year is also expected to bring an increase in the number of attackers motivated
simply by bragging rights. These actors are often younger and not tied to a nation
state or organized group. However, that doesn’t mean we won’t see nation-state
activity. The Big Four—Russia, China, Iran and North Korea—will be highly active in
2023, using destructive attacks, information operations, financial threats and more.
The road to stronger cyber defenses has never been simple, especially for security
professionals. Organizations have a lot to keep in mind for 2023. As always,
Mandiant’s relentless work on the frontlines gathers insights and develops best
practices we regularly share with security leaders, so they can take the steps
needed to prevent these threats—and respond quickly and effectively to the
attacks that invariably get through.
10
MANDIANT CYBER SECURITY FORECAST 2023
Contributors
In the past few years of publishing Mandiant Cyber Security Forecast (formerly
Security Predictions), Sandra Joyce, Head of Global Intelligence, and Charles
Carmakal, Consulting CTO, have spearheaded the report. This year we added insights
from Phil Venables, CISO for Google Cloud. Many other experts at Mandiant also
contributed to this report, including:
©2022 Mandiant, Inc. All rights reserved. Mandiant and M-Trends are registered trademarks of
Mandiant, Inc. All other brands, products, or service names are or may be trademarks or service marks
of their respective owners. EXT-RT-EN-US-000475-01