OUTLOOK: CYBERSECURITY TRENDS IN THE
CZECH REPUBLIC FOR 2023 AND 2024
Threats for Energy Industry and Transportation
One of the last year’s prominent trends was the growing interest of malicious attackers in the
energy and transportation sectors. Importance of such threats significantly increased with the
beginning of the Russian invasion of Ukraine and related events, which was soon exploited by
state or state-sponsored actors, as well as cybercriminal and hacktivist groups. It is probable
(55-70%) that more or less serious attacks on entities in the energy and transport sectors in
the forthcoming period will take place. The risk of such attacks will be highly likely (75-85%)
growing as a result of political decisions and other developments associated with the RussianUkrainian war.
Persistence of Campaigns
In 2022, the Czech Republic faced several persistent campaigns. The first case involved vishing,
which was used to make users install remote administration software on their computers. The
second persistent campaign was phishing distributed via text messages targeting bank identity
and subsequent theft of funds. Both campaigns were notable due to persistence of the attackers,
who continued their attacks despite active interventions by various institutions. This shows
a trend where attackers are deploying more automated methods of infrastructure creation to
keep their campaign running even in case of proactive interventions. We are also observing
and expecting to continue the trend of growing sophistication of attackers, especially with
regard to credibility of fraudulent emails or websites used in attacks.
Ransomware
The NÚKIB records ransomware incidents almost every month, and this trend will almost
certainly (90-100%) continue in the coming years. Ransomware offered as a service
(ransomware-as-a-service), which usually operates on the basis of multiple extortion (including
data exfiltration, the possibility of data publication/sale or other activities aimed at increasing
the pressure to pay the ransom), has become the predominant form. Although ransomware is
primarily the domain of cybercriminal groups, it cannot be ruled out (25-50%) that selected
countries under sanction mechanisms will resort to using it as well, either for financial gain or
to cover up their true destructive or cyberespionage goals. There is also a real possibility (2550%) of cooperation between non-state and state actors, with non-state actors gaining funding
through this activity and state actors gaining access to exfiltrated information along with a higher
level of plausible deniability.
42