U.S. federal authorities have issued a renewed warning about ongoing cyber activity by pro-Russian hacktivist groups targeting critical infrastructure, alongside the announcement of new criminal charges tied to those operations.
This week, prosecutors disclosed that Victoria Dubranova1 , 33, pleaded not guilty in federal court in Los Angeles to an additional set of hacking-related charges linked to the group NoName057(16)2 . Dubranova was extradited to the United States earlier in 2025 and had already faced separate charges connected to CyberArmyofRussia_Reborn3 .
At the same time, a joint advisory released by the Cybersecurity and Infrastructure Security Agency4 , the 5, and the National Security Agency6 outlined the tactics used by Russian-aligned hacktivists. While these groups operate with less technical sophistication than state-sponsored cyber units, officials emphasized that their activities still pose a serious risk due to their focus on critical services.
According to the advisory, attackers commonly scan the internet for exposed industrial control systems and operational technology environments with weak or misconfigured security. They often exploit remote access tools, such as virtual network computing services, that are directly connected to equipment controlling physical infrastructure.
Federal officials identified several groups involved in these campaigns, including Cyber Army of Russia Reborn, NoName057(16), Z-Pentest, and Sector16. Over the past several years, these actors have targeted water utilities, energy providers, and government organizations in the United States and abroad, frequently prioritizing ease of access over precise targeting.
Prosecutors allege that CyberArmyofRussia_Reborn operated with funding and direction from Russia’s military intelligence agency, the GRU7 . Investigators linked the group to multiple incidents with real-world consequences, including a January 2024 breach of a water facility in Muleshoe, Texas, that caused large-scale water overflow. Other cases cited include attacks on water infrastructure in Indiana and Pennsylvania during 2024.
The Justice Department also reported a November 2024 cyber incident at a Los Angeles meat processing facility that resulted in spoiled product and an ammonia leak.
In a statement, Craig Pritzlaff8, Acting Assistant Administrator at the Environmental Protection Agency9, said the alleged actions put public safety at risk and threatened the resilience of the nation’s water infrastructure.
Authorities further allege that these hacktivist groups used Russian government-backed funding to purchase distributed denial-of-service capabilities and commercially available hacking tools. While many of the incidents were limited in scope, officials cautioned that poorly segmented networks—where remote access tools connect directly to live control systems—can turn even basic intrusions into events with physical consequences.
The advisory underscores the continued need for infrastructure operators to secure remote access, segment operational networks, and monitor exposed systems to reduce the risk posed by opportunistic but persistent cyber adversaries.
3 CyberArmyofRussia_Reborn: CyberArmyofRussia_Reborn is a pro-Russian hacktivist organization known for coordinating and publicizing cyberattacks against government, corporate, and infrastructure targets in countries supporting Ukraine. Emerging prominently after Russia’s 2022 invasion of Ukraine, it operates as part of a broader ecosystem of politically motivated cyber groups tied to the conflict.
4 Cybersecurity and Infrastructure Security Agency: The Cybersecurity and Infrastructure Security Agency (CISA) is a U.S. federal agency under the Department of Homeland Security (DHS) responsible for safeguarding the nation’s cybersecurity and critical infrastructure. Created in 2018, it serves as the country’s primary civilian cyber defense agency and national coordinator for infrastructure resilience.
5 Federal Bureau of Investigation: The Federal Bureau of Investigation (FBI) is the principal federal law enforcement and domestic intelligence agency of the United States. Operating under the United States Department of Justice, it addresses threats ranging from terrorism and espionage to cybercrime and corruption. The FBI plays a key role in national security and major criminal investigations.
6 National Security Agency: The National Security Agency (NSA) is a United States intelligence organization under the Department of Defense. It is responsible for global signals intelligence (SIGINT) collection and cybersecurity operations, protecting U.S. government communications and information systems while gathering intelligence on foreign targets. Established in 1952, it is one of the most secretive and technologically advanced components of the U.S. Intelligence Community.
7 GRU: The GRU (Main Intelligence Directorate, Russian: Glavnoye Razvedyvatel’noye Upravlenie) is Russia’s military intelligence agency under the General Staff of the Armed Forces. Established after the 1917 Revolution, it remains one of Russia’s most secretive and powerful intelligence organizations, noted for espionage, cyber operations, and special forces support.
8 Craig Pritzlaff: Craig Pritzlaff is an environmental policy professional and senior official with the U.S. Environmental Protection Agency (EPA). He has held key leadership roles focused on water policy, environmental management, and regulatory coordination within the agency. Pritzlaff is recognized for his work in advancing intergovernmental collaboration on environmental protection and sustainability initiatives.
9 Environmental Protection Agency: The Environmental Protection Agency (EPA) is an independent agency of the United States federal government responsible for protecting human health and the environment. Established in 1970, it enforces environmental laws, conducts research, and develops regulations to control pollution in air, water, and land.