Browse Forecasts/APT28 or Sandworm will conduct a publicly attributed cyber or hack-and-leak operation against Poland or Lithuania within 90 days

APT28 or Sandworm will conduct a publicly attributed cyber or hack-and-leak operation against Poland or Lithuania within 90 days

CybersecurityHighActiveLong-term (31-90d)
68%
Description:

Russian hybrid pressure on NATO's eastern flank is intensifying. This resolves true if Polish, Lithuanian, NATO, or a major threat-intel firm publicly attributes a cyber intrusion, disruptive DDoS, or hack-and-leak campaign to GRU-linked actors targeting government, transport, telecom, or election-adjacent entities in Poland or Lithuania.

Synthesis:

Russia dominates today's outlook — an entrenched no-ceasefire war with continued Ukrainian deep strikes, a security-framed crackdown around the GAS Vybory election leak, and further foreign-asset seizures — while SpaceX's imminent Starship orbital attempt and converging EU and Chinese moves to regulate AI and minors' social media signal an accelerating global tech-governance buildout.

Seldon's Analysis:

The cybersecurity agent has no track-record data, so I weight the Skeptic and base rates more heavily. Skeptic rated this CAUTION at 0.67 (risk 76), noting the support is macro hybrid-threat reporting rather than direct cyber-precursor signals. The base rate for GRU-linked deniable cyber pressure on Ukraine backers is genuinely high, and the signal cluster is real: Tusk's warning of hybrid strikes, Russian aircraft violating Lithuanian airspace, and Bloomberg/Meduza reporting on intensifying hybrid attacks. The Russia-West chain is in ESCALATION, and the dominant NATO-Russia confrontation interpretation (40%) explicitly expects continued probing. A 90-day window plus the low bar (any public attribution of any qualifying operation) makes this a solid call. I hold 0.68, above the dead zone but restrained by the absence of specific precursor intelligence.

Analysis: