On the morning of 24 November 2015 an F-16 operated by the Turkish Air Force dropped into position behind a Russian Su-24 Fencer and dispatched an air-to-air Sidewinder missile that sliced into the Russian aircraft, sending it smoking toward the ground. The pilot and weapons officer ejected from the aircraft as it plummeted toward the Syrian desert. The pilot was killed by small arms fire from rebel forces on the ground in direct contravention of the Geneva Convention. The weapons officer was rescued by Russian forces, while the pilot's body was recovered by Turkey, and later returned to Russia. As the Sukhoi came crashing down, the political and diplomatic engines of both countries kicked into full swing. Russia proclaimed the attack a “stab in the back”; Turkey protested that the Russian aircraft had violated its airspace, and had issued numerous warnings that the aircraft change course. As images of the smoking aircraft streaked across news outlets and the fallout percolated across the international community, cyber operations began.
Both Turkey and Russia appear to have leveraged hacktivist-style attacks against the opposing side; while grassroots hacktivist activity potentially could have been a factor, the targeting and impact of cyber attacks following this escalation in physical conflict are closely aligned to the interests of both states. In particular, the activity observed targeting Turkey conforms with the ideas conveyed by General Valery Gerasimov in 2013 in Voyenno-Promyshlennyy Kurier (VPK). These ideas, which can be the subject of a lengthy tome on modern Russian military doctrine, effectively encapsulate the concept of hybrid action in order to accomplish the objectives of the Russian Federation. His writings describe how modern conflict may be instigated by any number of directed capabilities such as roving gangs of “little green men,” pro-Russian rebel forces, or gangsters/unions/motorcycle gangs/disgruntled workers—perhaps even hacktivist actors deliberately inciting some domestic complications?
The conflict between Russia and Turkey began well before the pilot of the F-16 armed the AIM-9 Sidewinder; the Russians had been attacking ethnic Turkish rebels known as the Turkmen, who opposed Bashar al-Assad, for some time. Syrian aircraft had reportedly violated Turkish airspace numerous times, and the rhetoric of Recep Tayyip Erdogan had done nothing to pacify the situation. Shortly after the incident, Russian Federal Security Service (FSB) had raided and shut down numerous Turkish bank branches in the Russian Federation, detained Turkish travelers, stopped Turkish vehicles from crossing into Russia, and denied Turkish trade ships from entering Russian ports. Turkey followed suit by blocking Russian ships from sailing toward the Mediterranean Sea and the Black Sea for failing to meet the necessary “sailing criteria”. Around this time, CrowdStrike observed Distributed Denial of Service (DDoS) attacks targeting Turkish state-owned banks, government sites, and hacking forums. Soon hacktivists operating under Anonymous-style monikers began targeting the Turkish root DNS and threatening to destroy the banking infrastructure claiming that they buy oil from ISIS, amongst other rhetoric.
In January 2016, attacks targeting Russian banking infrastructure and the FSB were observed. This back and forth of hacktivist-style attacks continues today. CrowdStrike has observed the apparent targeting of Turkish critical infrastructure by Russia-associated intrusion actors. Most recently, personally identifiable information for nearly 50 million Turkish citizens was leaked to the Internet with a telling message:
“Who would have imagined that backwards ideologies, cronyism and rising religious extremism in Turkey would lead to a crumbling and vulnerable technical infrastructure?” and “Do something about Erdogan! He is destroying your country beyond recognition.”
These attacks occurring under the guise of hacktivism demonstrate the increasing role that the interconnected world plays in the affairs of nation-states. While these attacks may be a subtle way for opposing countries with tightly linked economies to draw blood against each other without escalating to full-scale combat, hacktivist actors inciting fear, confusion, and unrest in a rival state align well with the concepts described by General Gerasimov as the pretext for direct engagement. This engagement might range from economic sanctions to armed combat. Whatever the eventual outcome, it is clear that the asymmetric use of cyber attacks by nation-states may occur in the shadows of targeted intrusion actors, or in open conflict by purported hacktivist groups acting on nationalistic agendas.
-
Featured
-
Request, Aggregate, Bypass: How Attackers Can Evade LLM Safety ClassifiersOct 06, 2026
-
Falcon Data Security for SaaS Secures Sensitive Data in Microsoft 365Oct 05, 2026
-
New in Falcon Cloud Security: Third-Party App Insights and AI-Enhanced RemediationOct 05, 2026
-
CrowdStrike Expands Federal SOC Modernization Through CISA-Funded SIEMaaSOct 01, 2026
-
-
Recent
-
Request, Aggregate, Bypass: How Attackers Can Evade LLM Safety ClassifiersOct 06, 2026
-
Falcon Data Security for SaaS Secures Sensitive Data in Microsoft 365Oct 05, 2026
-
New in Falcon Cloud Security: Third-Party App Insights and AI-Enhanced RemediationOct 05, 2026
-
CrowdStrike Expands Federal SOC Modernization Through CISA-Funded SIEMaaSOct 01, 2026
-
-
Video
-
Video Highlights the 4 Key Steps to Successful Incident ResponseDec 02, 2019
-
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VIDEO]Feb 21, 2019
-
Analyzing Targeted Intrusions Through the ATT&CK Framework Lens [VIDEO]Jan 22, 2019
-
Qatar’s Commercial Bank Chooses CrowdStrike Falcon®: A Partnership Based on Trust [VIDEO]Aug 20, 2018
-
-
Category
-
Agentic SOC
-
Cloud & Application Security
- Cloud & Application Security
-
New in Falcon Cloud Security: Third-Party App Insights and AI-Enhanced Remediation10/05/26
-
CrowdStrike Named Strongest Overall Leader in 2026 Frost Radar™: Cloud Workload Protection Platforms08/20/26
-
Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud07/29/26
-
Falcon Cloud Security June 2026 Release: Updates for Azure and Google Cloud06/29/26
-
Threat Hunting & Intel
- Threat Hunting & Intel
-
Copy, Paste, Compromised: How ClickFix Attacks Work and How CrowdStrike Stops Them09/29/26
-
CrowdStrike Named a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 202609/17/26
-
PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting09/15/26
-
Peer Pressure: Inside the Sality Botnet Disruption Operation09/01/26
-
Endpoint Security & XDR
- Endpoint Security & XDR
-
CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks09/02/26
-
Browser Security: Zero-Days Are Only Part of the Problem06/30/26
-
New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever06/18/26
-
New Abuse of the ClickOnce Technology, Part 1: The Inner Workings of ClickOnce Application Deployment06/18/26
-
Engineering & Tech
- Engineering & Tech
-
EMBER2024: Advancing the Training of Cybersecurity ML Models Against Evasive Malware09/03/25
-
Falcon Platform Prevents COOKIE SPIDER’s SHAMOS Delivery on macOS08/20/25
-
CrowdStrike’s Approach to Better Machine Learning Evaluation Using Strategic Data Splitting08/11/25
-
CrowdStrike Researchers Develop Custom XGBoost Objective to Improve ML Model Release Stability03/20/25
-
Executive Viewpoint
- Executive Viewpoint
-
Beyond the Model: Harnessing Frontier AI for Stronger Cyber Defense07/20/26
-
Frontier AI Is Collapsing the Exploit Window. Here’s How Defenders Must Respond.04/20/26
-
Frontier AI for Defenders: CrowdStrike and OpenAI TAC04/16/26
-
Anthropic Claude Mythos Preview: The More Capable AI Becomes, the More Security It Needs04/06/26
-
From The Front Lines
- From The Front Lines
-
CrowdStrike Technical Risk Assessments Reveal Common Exposure Patterns05/04/26
-
Introducing the CrowdStrike Shadow AI Visibility Service04/21/26
-
CrowdStrike Flex for Services Expands Access to Elite Security Expertise03/24/26
-
From Scanner to Stealer: Inside the trivy-action Supply Chain Compromise03/20/26
-
Next-Gen Identity Security
- Next-Gen Identity Security
-
CrowdStrike Announces Agentic Identity Provider09/02/26
-
The Identity Problem Hiding in AI Agent Deployments06/24/26
-
CrowdStrike Announces Continuous Identity for AI Agents06/15/26
-
CrowdStrike Expands Identity Leadership with OpenID and IDPro06/10/26
-
Next-Gen SIEM & Log Management
- Next-Gen SIEM & Log Management
-
CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX08/07/26
-
Falcon Platform IOAs Arrive in Falcon Next-Gen SIEM to Identify New Threats07/29/26
-
5 High-Impact Use Cases for Falcon Onum07/27/26
-
Falcon Next-Gen SIEM Supports Third-Party EDR Tools, Starting with Microsoft Defender03/23/26
-
Public Sector
- Public Sector
-
CrowdStrike Expands Federal SOC Modernization Through CISA-Funded SIEMaaS10/01/26
-
CrowdStrike Falcon Platform Helps Meet U.S. Government Mandates for CISA BOD-26-0407/22/26
-
Falcon Platform for Government Now Offers Falcon for XIoT to Secure Connected Assets03/18/26
-
CrowdStrike Innovates to Modernize National Security and Protect Critical Systems03/18/26
-
Exposure Management
- Exposure Management
-
CrowdStrike Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 202609/24/26
-
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs09/08/26
-
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs08/11/26
-
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days07/14/26
-
Securing AI
- Securing AI
-
Request, Aggregate, Bypass: How Attackers Can Evade LLM Safety Classifiers10/06/26
-
A Win for Defenders: CrowdStrike and NVIDIA Extend Security Across the AI Stack09/28/26
-
CrowdStrike SafeMind: When the Best Offense Builds the Best Defense09/17/26
-
CrowdStrike Falcon Guardian Defines the Next Generation of AI Security09/01/26
-
Data Security
- Data Security
-
Falcon Data Security for SaaS Secures Sensitive Data in Microsoft 36510/05/26
-
CrowdStrike Accelerates Real-Time Data Classification with On-Device AI09/16/26
-
ISO 42001:2023 and the New Reality of Cloud AI Data Risk06/04/26
-
Falcon Data Security Secures Data Wherever It Lives and Moves03/24/26
-
- Start Free Trial
Categories
-
Agentic SOC55
-
Cloud & Application Security150
-
Data Security27
-
Endpoint Security & XDR361
-
Engineering & Tech87
-
Executive Viewpoint181
-
Exposure Management126
-
From The Front Lines205
-
Next-Gen Identity Security75
-
Next-Gen SIEM & Log Management116
-
Public Sector44 -
Securing AI54
-
Threat Hunting & Intel225
CrowdStrike Falcon Platform
Ready to protect your business?
Try CrowdStrike free today
Subscribe
Sign up now to receive the latest notifications and updates from CrowdStrike
See CrowdStrike Falcon in action
- Copyright © 2026 CrowdStrike
- Privacy
- Request Info
- Blog
- Contact Us
- 1.888.512.8906
- Accessibility