The digital landscape has shifted from a playground for amateur hackers into a geopolitical battlefield. The largest cyberattacks are evaluated by three criteria: the scale of compromised data, quantifiable economic cost, and strategic impact on critical infrastructure.
Threats have evolved from simple malware in the 1980s, such as the Morris Worm (1988), which caused millions in damages, to sophisticated nation-state espionage. The global average cost of a data breach rose to $4.88 million in 2024; for U.S. organizations, the average jumps to $10.22 million.
Acts of sabotage with the highest economic cost are not defined by victim count, but by the damage caused when operations halt.
1. NotPetya (2017): the $10 billion Maskirovka attack. It is considered the costliest global cyberattack, with ~$10 billion in damages. Attributed to Russia’s GRU, it posed as ransomware ($300 ransom) while aiming to destabilize Ukraine’s economy. It spread via compromised MeDoc software and EternalBlue (from the NSA arsenal), crippling firms like Merck with over $1.4 billion in losses.
2. WannaCry (2017): the global ransomware pandemic. The first major incident to weaponize EternalBlue at scale. It hit hundreds of thousands of computers in 150+ countries, with losses estimated at $4–8 billion. Healthcare was hit hard — the UK NHS cancelled urgent appointments. Attributed to North Korea’s Lazarus Group, with a financial motive for the regime.
Strategic sabotage and the supply-chain weapon: the most impactful attacks hit critical infrastructure or abuse third-party vendors to infect many networks at once.
3. Stuxnet (2010): the birth of physical sabotage. The first widely recognized cyberweapon built for real-world destruction. It targeted SCADA and Siemens PLCs, exploiting four zero-days, and hit configurations such as centrifuges in Iran’s nuclear program while feeding operators fake “normal” readings.
4. SolarWinds Orion (2020): an unprecedented supply-chain compromise. Attributed to Russia’s SVR, it injected SUNBURST into legitimate Orion updates. Nearly 18,000 customers installed the tainted update — access to governments, critical infrastructure, and private firms. Later attacks (Kaseya VSA 2021, MOVEit 2023 / CL0P–LEMURLOOT) confirm third-party vendors remain the weak link.
The future of threats: GenAI and deepfakes accelerate phishing and vishing — about 47% of organizations see adversarial GenAI as an urgent concern. Regulation responds: U.S. EO 14028 accelerated Zero Trust; in Europe, NIS2 (2024) requires major incidents to be reported within 24 hours, under penalty. Risk control starts with cybersecurity designed into the architecture — not bolted on at the end.
The lesson is clear: defense can no longer be static. Priority must shift from mere prevention to resilience, continuous verification of every access point, and rapid management of correlated risks — including on cloud infrastructure. At UNICORE, cybersecurity is part of the architecture — not an afterthought. Contact us for a risk review of your systems.

