Cybercriminals Target Critical Infrastructure in Central Asia Amid Rising Threats
Cybercriminals are increasingly targeting critical infrastructure in Central Asia, including power grids, water systems, and healthcare facilities, posing significant risks to national security and economic stability.
Executive Takeaway — TL;DR
- Category:
- Critical Infrastructure
- Severity:
- Medium
- Actor Type:
- Cybercriminal
- Geography:
- Central Asia
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Executive Summary
As of April 2026, cybercriminal activities targeting critical infrastructure in Central Asia have escalated, posing medium-level threats to sectors such as power grids, water systems, industrial control systems (ICS), healthcare, and the financial sector. These attacks are characterized by their sophistication and potential for widespread disruption.
Current Threat Landscape
Recent reports indicate a surge in cybercriminal activities targeting critical infrastructure in Central Asia. Notably, in the third quarter of 2025, hacktivist attacks on industrial control systems (ICS) nearly doubled compared to the previous quarter, accounting for 25% of all hacktivist activities by September 2025. (cyble.com) This trend underscores the growing focus on critical infrastructure by cybercriminals in the region.
Targeted Sectors
-
Power Grids and Water Systems: Cybercriminals have exploited vulnerabilities in Supervisory Control and Data Acquisition (SCADA) systems to gain unauthorized access to power grids and water facilities. For instance, in 2025, Canadian authorities reported incidents where attackers manipulated water pressure valves and triggered false alarms in oil and gas facilities, highlighting the potential for significant operational disruptions. (techradar.com)
-
Industrial Control Systems (ICS): Hacktivist groups have increasingly targeted ICS environments, including Human Machine Interface (HMI) devices and Virtual Network Computing (VNC) systems. These attacks often involve exploiting weak or default credentials to gain remote access, leading to operational disruptions and potential safety hazards. (ics-cert.kaspersky.com)
-
Healthcare Sector: The healthcare sector remains a prime target for cybercriminals due to the sensitive nature of medical data. Attacks on healthcare facilities can result in data breaches, operational disruptions, and compromised patient care.
-
Financial Sector: Financial institutions in Central Asia have been targeted by cybercriminals aiming to steal sensitive financial data and disrupt services. Such attacks can lead to significant financial losses and undermine public trust in financial systems.
Notable Threat Actors
While specific threat actor groups targeting Central Asia's critical infrastructure remain unidentified, the region has experienced activities from various cybercriminal groups. For example, in 2025, Russian state-sponsored hackers were reported to have engaged in a prolonged cyber campaign targeting Western critical infrastructure, particularly the energy sector. (techradar.com) Although this campaign was focused on Western targets, it highlights the capabilities and intentions of cybercriminal groups that could potentially extend their operations to Central Asia.
Mitigation Strategies
To address the escalating threat to critical infrastructure in Central Asia, the following measures are recommended:
-
Enhanced Security Protocols: Implement robust security measures, including multi-factor authentication, regular system updates, and intrusion detection systems to safeguard critical infrastructure.
-
Employee Training: Conduct regular cybersecurity training for personnel to recognize and respond to potential cyber threats effectively.
-
Incident Response Planning: Develop and regularly update incident response plans to ensure a swift and coordinated response to cyber incidents.
-
International Collaboration: Engage in information sharing and collaboration with international cybersecurity organizations to stay informed about emerging threats and best practices.
Conclusion
The medium-level threat posed by cybercriminals to critical infrastructure in Central Asia necessitates immediate and sustained attention. By implementing comprehensive security measures and fostering international cooperation, stakeholders can enhance the resilience of critical infrastructure against cyber threats.
Highlights:
- Canadian government claims hacktivists are attacking water and energy facilities, Published on Friday, October 31
- Amazon says Russian hackers behind major cyber campaign to target Western energy sector, Published on Tuesday, December 16
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Qilin Ransomware Surge Targets Industrial Sector as Global Critical Infrastructure Threats Escalate

Industrial Sector Faces Record Ransomware Surge as Qilin Group Targets Critical Infrastructure

