Hacktivist Groups Exploit Zero-Day Vulnerabilities in North America
Hacktivist groups are increasingly exploiting zero-day vulnerabilities in North America, targeting unpatched systems to advance their agendas. This trend poses a medium-level threat to organizations.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Medium
- Actor Type:
- Hacktivist
- Geography:
- North America
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
Zero-day vulnerabilities—flaws in software or hardware unknown to the vendor—pose significant cybersecurity risks. Hacktivist groups, motivated by ideological or political objectives, have been increasingly exploiting these vulnerabilities in North America. This briefing examines recent trends, notable incidents, and the implications of such activities.
Rise in Zero-Day Exploitation by Hacktivists
In the first half of 2025, Forescout Technologies reported a 46% increase in zero-day exploits compared to the previous year. Hacktivist groups have been identified among the perpetrators of these attacks, leveraging zero-day vulnerabilities to disrupt services and draw attention to their causes. (silicon.co.uk)
Notable Incidents
-
Healthcare Sector Attacks: In June 2023, the Health Sector Cybersecurity Coordination Center (HC3) highlighted the activities of FIN11, a cybercriminal collective associated with extensive phishing campaigns and the exploitation of zero-day vulnerabilities. The group has targeted healthcare organizations, including pharmaceutical companies, using Clop ransomware to steal data. (techtarget.com)
-
U.S. Defense Contractor Breach: In February 2026, a former executive at L3Harris, a U.S. defense contractor, was sentenced to 87 months in prison for stealing and selling zero-day exploits to a Russian exploit broker. This incident underscores the risks associated with insider threats and the illicit trade of zero-day vulnerabilities. (ubos.tech)
Exploit Broker Transactions
The trade of zero-day exploits has become a significant concern. In February 2026, the U.S. Treasury sanctioned "Operation Zero," a Russian exploit broker, and its affiliates for acquiring and reselling U.S. defense contractor exploits. This action highlights the global nature of the zero-day exploit market and its implications for national security. (ubos.tech)
Implications for North American Organizations
Hacktivist exploitation of zero-day vulnerabilities presents a medium-level threat to North American organizations. While these groups may lack the resources of nation-state actors, their attacks can still cause significant disruption. Organizations should prioritize timely patching of known vulnerabilities, conduct regular security assessments, and monitor for signs of exploitation.
Conclusion
The exploitation of zero-day vulnerabilities by hacktivist groups in North America is a growing concern. Staying informed about emerging threats and implementing robust cybersecurity measures are essential to mitigate potential risks.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



