What the Study Found
- NoName057(16) has launched more than 1,500 DDoS attacks on NATO and allied states since March 2022.
- The group pairs hacktivist ideology with hacker-for-hire economics, paying volunteers up to $1,200 per successful attack.
- Since January 2025, 23 rounds of attacks have hit 129 Finnish public and private organizations.
- Public trust, not the servers, is the real target, which makes a fast, transparent response the best defense.
A government website goes dark for a few hours. Staff scramble, a help desk fields angry calls, and by evening the service is back up. Nothing was stolen, nothing was altered, and on paper the damage looks minor. That is exactly the read a new case study wants readers to reject.
According to the analysis, the outage was never really the objective for NoName057(16), a pro-Russian hacktivist collective that has repeatedly targeted Finland and other members of the North Atlantic Treaty Organization (NATO), plus assorted European states. The disruption is the opening act of a longer campaign meant to chip away at public confidence in the governments and institutions it hits.
NoName appeared within days of Russia’s full-scale invasion of Ukraine in 2022, and it has been busy since. The case study, drawing on more than 20 documents, including government advisories, industry threat reports and prior research, plus direct review of the group’s own Telegram and Teletype channels, counts more than 1,500 distributed denial of service attacks by June 2025, most aimed at countries seen as hostile to Russian interests. Since Finland joined NATO, the tempo there has climbed sharply: 23 rounds of attacks since the start of 2025 alone hit 129 public and private organizations, from the national parliament to municipal offices and banks. A distributed denial of service attack works by flooding a target’s servers with junk traffic from many machines at once, until legitimate visitors cannot get through.
Hacktivism is usually filed under nuisance rather than serious threat. The researchers push back on that instinct.
Their argument rests on how the group is built, not just on what it breaks. NoName recruits through Telegram and Teletype, distributing a custom denial-of-service tool called DDoSia through a bot that handles sign-ups, and it instructs new members on installing the software, sometimes advising them to disable their own antivirus protection to avoid conflicts, a step the authors flag as a classic defence-evasion tactic. What makes the operation unusual is what happens after someone joins: active participants can earn cryptocurrency payouts of up to $1,200 for a successful run.
“They claim to be hacktivists but they have an incentive system more common for cyber criminals,” says Hadi Ghanbari, an assistant professor at Aalto University School of Business who led the study.
That payment structure is what pulls NoName out of the tidy categories cybersecurity teams tend to use. The paper sorts attackers into four familiar buckets: cybercriminals chasing money, state-sponsored hackers chasing geopolitical advantage, hackers-for-hire selling their skills to clients, and hacktivists chasing a cause. NoName, the authors argue, borrows from three of the four at once: the ideology and propaganda instincts of a hacktivist group, the piecework payments of a hacker-for-hire operation, and alliances with at least one collective German investigators have linked to the Russian cyber army. The group has also formed a joint offshoot, Z-Pentest, with one of those allies, and it has struck well beyond Europe, hitting more than 50 Taiwanese organizations in a single 2024 campaign and, more recently, Israeli targets in solidarity with Iran.
“It’s easy to focus on the financial costs, but the more hidden risk is if people lose confidence in large organisations or government services, then the next step is for them to ask what’s the point of having them,” Ghanbari says.
A Manifesto Written for Volunteers, Not Just Enemies
Most of what is known about NoName’s inner workings comes from the group itself, and the authors treat that fact carefully throughout the case. Its manifesto, posted on the minimalist publishing platform Telegraph, casts the group as defending Russian values on what it calls an information front, and its recruitment materials read less like propaganda than a product pitch: install instructions in six languages, a rewards program paid out in a proprietary token called dCoin, and a target list published in advance on a channel the authors call the DDoSia Target Monitor. One recruiting post goes so far as to reassure Russia-based volunteers that the software is framed, legally, as a stress-testing tool and that legal risk there is minimal, a claim the authors read as a deliberate hint at tolerance, if not protection, from Russian authorities. Whether the group receives state funding, or any funding beyond its own uncertain revenue, is left unresolved. A separate claim that NoName ran a phishing scheme impersonating the Polish government to harvest payment details could not be verified by the authors.
The uncertainty around funding does not blunt the concern the authors raise about response. Because NoName is waging what it frames as psychological warfare, the case argues that a purely technical fix, restoring the server and moving on, hands the group exactly the silence it wants. That framing echoes a 2025 assessment from the EU’s own cybersecurity agency, which found that hacktivist DDoS campaigns against European public administrations aim at undermining confidence in institutions as much as at the outage itself.
Law enforcement has already tried the purely technical route. In July 2025, a Europol-coordinated operation called Eastwood disrupted more than 100 of the group’s servers and led to arrest warrants for six people in Russia, according to Europol’s own statement. NoName’s Telegram channel dismissed the operation days later and kept publishing target lists, which is exactly the resilience the case study would predict from a network built to survive the loss of any single node.
Why the Silence After an Attack Is Costly
“The point is to escalate the psychological cost of their actions. It’s a complex game. Companies and governments can play into the hackers’ hands if they’re not transparent,” Ghanbari says. The case study recommends that technical and communications teams coordinate from the first hour of an incident, so that a factual account of what happened reaches the public before the group’s own channels get to frame it first.
The authors are careful not to inflate a website outage into an act of war. Their point is narrower: an outage becomes something larger the moment an attacker treats it as a stage rather than a goal, and Finland’s Parliament, its banks and its municipalities have been standing on that stage since 2023. “Not only does it undermine their basic rights, it also undermines the ideological system that underpins them,” Ghanbari says of the citizens caught in the middle. The next country to notice the pattern, the case suggests, is likely to be whichever one Moscow decides, next, counts as an enemy.
Reference
Ghanbari, H., & Abbasi, R. (2026). The blurring lines of hacktivism and crowdsourced cyber warfare: How NoName057(16) weaponises distributed denial of service attacks. Journal of Information Technology Teaching Cases. https://doi.org/10.1177/20438869261462968
- Study type: Qualitative case study; peer-reviewed teaching case, Journal of Information Technology Teaching Cases (SAGE), open access, published online 22 June 2026.
- Corpus: More than 20 cited sources, government advisories, industry threat reports and prior research, plus direct review of the group’s Telegram, Teletype and Onion-site channels.
- Method: Document and open-source analysis of the group’s public statements, recruitment materials and documented attack activity.
- Analytic approach: Comparison against a four-category threat-actor framework: cybercriminals, state-sponsored hackers, hackers-for-hire and hacktivists.
- Time horizon: Attack activity from March 2022 to June 2025; analysis published 2026.
- Funding / conflicts of interest: Authors declared no funding and no competing interests; corresponding author used Grammarly for proofreading.
- Data availability: Not reported; the case draws on cited public sources rather than a released dataset.
- Main limitation: Single-case study of one group; the authors describe its leadership, revenue sources and any state ties as unverified.
FAQ
Is NoName057(16) directed by the Russian government?
Is NoName057(16) directed by the Russian government? The case study cannot say for certain. German investigators have linked five individuals to the group and traced alliances with at least one collective tied to the Russian cyber army, and the group’s own materials hint at confidence that Russian authorities will look the other way. But the authors found no evidence of direct state funding or command, and they explicitly flag the group’s leadership and financing as unresolved.
Why would volunteers get paid to join a cause-driven hacking group?
Why would volunteers get paid to join a cause-driven hacking group? Payment lowers the barrier to participation and keeps the botnet supplied with fresh machines, which is exactly what a crowdsourced attack tool needs. The researchers argue this financial layer, cryptocurrency rewards of up to $1,200 per successful attack, is what pulls NoName out of the traditional hacktivist mold and closer to a hacker-for-hire operation, even though its stated motives stay ideological.
Could a company get targeted just for being based in a NATO country?
Could a company get targeted just for being based in a NATO country? According to the case, yes, particularly if it sits in critical infrastructure, finance or government services. NoName’s targeting has tracked geopolitical alignment rather than any specific vulnerability or grievance, hitting Finnish banks and municipalities, Taiwanese organizations and, most recently, Israeli entities, wherever a country is seen as opposing Russian interests.
How is a DDoS attack different from a data breach?
How is a DDoS attack different from a data breach? A distributed denial of service attack floods a target’s servers with traffic until legitimate users cannot get through, but it does not, on its own, expose or steal data the way a breach does. The case study argues that this distinction is exactly why DDoS attacks get underrated: no headline about stolen records, just an outage that looks temporary and contained.
What should an organization change once it understands this hybrid threat model?
What should an organization change once it understands this hybrid threat model? The authors recommend folding communications planning into incident response from the first hour, rather than treating an attack as a purely technical problem to fix quietly. If the attacker’s goal is public doubt, a fast and transparent account of what happened denies it the silence it is counting on.
Cite This Page

