The Illusion of Attribution in Cyber Threat Intelligence

Cyber Threat Intelligence (CTI) professionals often carry an air of mystique—like they possess secret knowledge or operate as elite hackers beyond the reach of ordinary teams. In reality, many are more style than substance. Of course, there are genuine threat researchers—experts who quietly deliver meaningful insights without public recognition. You’ll likely never meet them because they’re too busy doing real threat research.

This article illustrates how some cybersecurity vendors misuse threat attribution—often defaulting to blaming Russia, China, or another nation-state. While nation-state actors absolutely exist, attribution in cybersecurity is an inherently flawed process. In too many meetings, I’ve seen attribution used as a shortcut to impress or appear informed, rather than being grounded in verifiable evidence.

I’ve been in those meetings. I always try to focus on facts, remain transparent, and explain the limitations of the data. Unless someone has been convicted after a thorough legal investigation, attributing an attack to a nation-state should be treated with extreme caution.

Case Study 1: NotPetya – Attribution Without Accountability

In 2017, the NotPetya malware outbreak crippled global businesses. Though it initially resembled ransomware, the malware was in fact designed to destroy data. It caused an estimated $10 billion in damage, affecting companies like Maersk, Merck, and FedEx.

Cybersecurity vendors and intelligence agencies swiftly attributed the attack to Russian military intelligence (GRU). This conclusion was based on circumstantial evidence—code similarities, infrastructure overlaps, and geopolitical assumptions. Yet no definitive proof was made public, and no individuals were brought to justice.

Despite the scale of the impact, few questioned the vendors that pushed the attribution narrative. This event marked a shift where attribution became more about headlines and brand positioning than about disciplined analysis.

Case Study 2: Sony Pictures – Political Narratives Over Technical Evidence

In 2014, Sony Pictures suffered a devastating breach. Confidential employee data, unreleased films, and internal emails were leaked online. The U.S. government quickly attributed the attack to North Korea, citing geopolitical motives tied to the movie The Interview.

However, several independent researchers raised doubts. Alternate theories pointed to disgruntled insiders or different hacker groups. Despite the uncertainty, the North Korea attribution stood—supported more by geopolitical narrative than technical validation.

There is allot of evidence to point to North Korea for this, mainly due to warnings from North Korea to Sony not to release ‘The Interview’ film in 2014, which made fun of the Dictator. Based on Balance of Probability, it was most likely North Korean funded group. But, once again, not proven.

This case highlighted how attribution can be influenced by political agendas and public pressure, rather than objective analysis.

Case Study 3: SolarWinds – A Rush to Confirm Bias

The 2020 SolarWinds breach compromised U.S. federal agencies and numerous private firms through a tampered software update. Within days, cybersecurity companies and officials attributed the campaign to Russian intelligence services (APT29, aka Cozy Bear).

Though the attack was sophisticated and long-running, concrete evidence linking it to a specific government was not made public early on. Nevertheless, the Russia narrative quickly dominated media and industry discussions.

The pattern repeated: technical complexity was overshadowed by attribution certainty. This created an environment where critical questions about supply chain security and software integrity were sidelined by geopolitical finger-pointing.

Case Study 3: CrowdStrike, the DNC Hack, and the Assumption of Attribution

Before gaining widespread recognition in the industry, CrowdStrike became a household name for its role in investigating the 2016 breach of the Democratic National Committee (DNC) servers. The company publicly attributed the attack to Russian state-sponsored actors—claims that were amplified by major media outlets and became foundational to the broader “Russiagate” narrative.

However, key details emerged years later that challenged the integrity of this attribution.

In sworn testimony before the U.S. House Permanent Select Committee on Intelligence in 2017, CrowdStrike’s President of Services and Chief Security Officer, Shawn Henry, admitted under oath that:

“Crowdstrike President Shawn Henry: “We just don’t have the evidence …”

“We just don’t have the evidence that says [the data] actually left.”
“There’s no evidence that [the emails] were actually exfiltrated.”
“We said that the data left based on the circumstantial evidence. That was the conclusion that we made.”
“I can’t say based on that [data]” when asked directly if the emails were exfiltrated out of the DNC.

These statements were not made public until 2020 when the transcripts were declassified. By then, the narrative had already taken hold in both public discourse and policy. CrowdStrike’s initial attribution was based on inference, not definitive forensics, and yet it became a central claim in one of the most consequential political narratives in recent memory.

Adam Meyers from the one who made the statement around Russiagate – https://www.crowdstrike.com/en-au/about-us/executive-team/adam-meyers/

Shawn Henry – you might want to lawyer up – https://www.crowdstrike.com/en-au/about-us/executive-team/shawn-henry/

This case highlights a broader concern in cybersecurity: when attribution is driven by assumptions and amplified without transparent evidence, it undermines trust in the industry as a whole. CrowdStrike’s high-profile role in the DNC case raises important questions about accountability and the responsibility vendors hold when making public claims with geopolitical consequences.

There is potential for these people to be indicted by the current administration, and I am positive that ball is already rolling.


Update 07/08/2025

US DOJ to open grand jury investigation into political opponents over Trump-Russia probe

Sources

In conclusion, the Cyber Threat Intelligence industry is highly profitable and its attribution isn’t legislated by something like the Evidence Act.