---
title: "Key Cyber Moments Of 2022: What Happened And What Have We Learned?"
description: Whether it’s governments, big corporations, or individuals, any organization with an internet connection is a possible target for hackers. As a result, cybercrime has unfortunately become big business and numerous high-profile attacks hit the headlines over the last year.
image: https://csacyber.com/hubfs/2022.jpg
---

[Skip to content](https://csacyber.com/blog/key-cyber-moments-of-2022-what-happened-and-what-have-we-learned#main-content)

[![CSA Cyber - Cyber Security Solutions to Protect your People](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=300&height=108&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber - Cyber Security Solutions to Protect your People")](https://csacyber.com/)

- Services 
    - [Offensive Security Services](https://csacyber.com/offensive-security-services) 
          - [Penetration Testing](https://csacyber.com/penetration-testing)
          - [Red Teaming and attack simulations](https://csacyber.com/offensive-security-services#red-teaming)
          - [Continuous testing](https://csacyber.com/offensive-security-services#continuous-assurance)
          - [Managed offensive security](https://csacyber.com/offensive-security-services#managed-offensive)
    - [Consultancy Services](https://csacyber.com/cyber-consultancy-services) 
          - [Frameworks & assessments](https://csacyber.com/cyber-consultancy-services/frameworks-and-assessments)
          - [Data protection](https://csacyber.com/cyber-consultancy-services#data-protection)
          - [Virtual leadership](https://csacyber.com/cyber-consultancy-services#virtual-leadership)
          - [Technical security consulting](https://csacyber.com/cyber-consultancy-services#technical-consultancy)
          - [Governance, Risk & Compliance (GRC)](https://csacyber.com/cyber-consultancy-services/governance-risk-and-compliance-services)
    - [Extended Managed Security Services](https://csacyber.com/extended-managed-security-services) 
          - [Microsoft Sentinel SIEM](https://csacyber.com/extended-managed-security-services#microsoft-sentinel)
          - [SOC services](https://csacyber.com/extended-managed-security-services#soc-services)
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/extended-managed-security-services#cyber-helpdesk)
    - [Incident Response Services](https://csacyber.com/incident-response-services) 
          - [Emergency Incident Response](https://csacyber.com/urgent/emergency-incident-response)
          - [Incident Response Retainer](https://csacyber.com/incident-response-services)
          - [Cyber Incident Readiness & Response Planning](https://csacyber.com/incident-response-services)
          - [Tabletop Exercises & Live-Range Engagements](https://csacyber.com/incident-response-services)
    - [Specialist Security Services](https://csacyber.com/specialist-services) 
          - [AI Security](https://csacyber.com/cyber-services-for-ai)
          - [Operational Technology (OT)](https://csacyber.com/specialist-services#operational-technology)
          - [Cyber security for Private Equity](https://csacyber.com/specialist-services#mergers-and-acquisitions)
          - [Cyber training and education](https://csacyber.com/specialist-services#training-and-education)
          - [Virtual leadership](https://csacyber.com/specialist-services#leadership)
    - [Cyber Technologies](https://csacyber.com/cyber-technologies) 
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/cyber-technologies#sentinelone)
          - [AppGuard Endpoint & Server Zero Trust Protection](https://csacyber.com/cyber-technologies#appguard)
          - [Qualys Vulnerability Management as a Service (VMaaS)](https://csacyber.com/cyber-technologies#qualys-vmaas)
          - [Lookout Mobile Device Protection](https://csacyber.com/cyber-technologies#lookout)
          - [ThreatER DNS Protection](https://csacyber.com/cyber-technologies#threater-dns)
          - [Cyber Security Awareness & Training platform](https://csacyber.com/cyber-technologies#boxphish)
- [About](https://csacyber.com/about-us) 
    - [Careers](https://csacyber.com/careers)
    - [Certifications](https://csacyber.com/certifications-and-awards)
- [Blog](https://csacyber.com/blog)
- [Support Centre](https://csacyber.com/support)
- Resources 
    - [Case Studies](https://csacyber.com/case-studies)
    - [Downloads & Reports](https://csacyber.com/downloads-and-reports)
    - [Webinars](https://csacyber.com/webinars)
    - [Partners](https://csacyber.com/partners)
    - [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)
- [Contact](https://csacyber.com/contact-us)

- Search Search
  
  Search

 December 1, 2022

 5 min read time

# Key Cyber Moments Of 2022: What Happened And What Have We Learned?

![Cyber Security Associates](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e) [Written by: Cyber Security Associates -](https://csacyber.com/blog/author/cyber-security-associates)

[Article](https://csacyber.com/blog/tag/article) 

![](https://csacyber.com/hubfs/2022.jpg)

Whether it’s governments, big corporations, or individuals, any organization with an internet connection is a possible target for hackers. As a result, cybercrime has unfortunately become big business and numerous high-profile attacks hit the headlines over the last year.

Organizations of every size are reaching for more effective cybersecurity risk management software, services, and solutions to protect their assets and data.

As we enter a new year, the frequency and sophistication of these attacks show no sign of slowing down. Throughout 2022, we shared regular updates on the current cybersecurity landscape via our monthly cyber threat briefings – you can still catch up on any episodes you missed.

In the meantime, we asked our team of experts to pick out some of the biggest incidents that took place over the past 12 months, as well as their key learnings for 2023.

Here’s what they said.

### Hugh Raynor: Russian Ukraine conflict – the digital battleground

State-sponsored cyberattacks are becoming increasingly common and the battleground for geopolitical conflicts is no longer restricted to physical borders. This was demonstrated in February 2022 when Russia invaded Ukraine. Leading up to the invasion there was an 1,885% increase in cyberattacks on government targets and 89% of worldwide attacks targeted Russian or Ukrainian organizations.

As a result of the conflict, governments and organizations across the globe have been quick to pledge support for Ukraine’s cyber defenses. US Cyber Command has provided remote analytic support and conducted network defense activities, the UK is investing over £6 million to boost Ukraine’s current cyber defenses, and the EU has mobilized its Cyber Rapid Response Team to help defend Ukraine and its critical infrastructure from the threat of malicious attacks.

In addition to this international support, there is also a group of almost 400,000 volunteers, known as Ukraine’s IT army, who are actively launching cyberattacks against Russian targets.

##### Key Takeaway:

##### For your security strategy to be successful it’s vital to take a global view of the current threat landscape.

### Chris Burton: Log4j – Iranian cyberspies hack US government network

Further evidence of state-sponsored attacks came in November 2022 when it emerged Iranian cyberspies had exploited an unpatched flaw in Log4j to gain access to the US government network.

As a result, they were able to illegally mine for cryptocurrency, steal credentials and change user passwords. Their activity went undetected for several months, having initially gained access via Log4Shell in February 2022.

The Cybersecurity & Infrastructure Security Agency (CISA) had issued an emergency directive in November 2021 that required federal agencies to patch the flaw by December 23rd that year. This would have prevented the incident, but the patch was not installed.

You can spend thousands, if not hundreds of thousands of dollars on the latest security software, but if the individuals responsible for using it don’t spot the flagged issues, your network could be susceptible to multiple breaches.

##### Key Takeaway:

##### The human element is always the weakest link when it comes to implementing cybersecurity defenses .

### Nick Rafferty: Rockstar Games – hacker threatens brand reputation

In September 2022 a hacker leaked 90 unseen clips of the yet-to-be-released video game, Grand Theft Auto 6. The individual responsible targeted Rockstar Games Slack servers and used social engineering to obtain the footage. They also claimed to have stolen the games source code; however, this was later denied by Rockstar Games.

The impact of such a breach is highly significant. Grand Theft Auto 6 is predicted to be the biggest selling video game of all time, so the reputational damage could be huge, not to mention the impact on the share price of Rockstar Games’ parent company, Take Two.

##### Key Takeaway:

##### A lack of communication and transparency following a breach can have a significant impact on your organization’s reputation and value.

### Hugh Raynor: Uber – Multiple attacks in a matter of months

Ride-hailing giant Uber fell victim to a hacker who gained access by phishing an Uber employee via text message. The attacker claimed to be a member of Uber’s corporate IT team and secured the individual’s personal login details.

In yet another example of social engineering, the hacker caused a near total compromise of Uber’s network and was able to access the vast majority of the company’s internal resources including its VPN, Intranet and Slack servers.

This wasn’t the first time Uber has fallen victim to a data breach, nor was it the last. In December 2022, they suffered another attack after information was stolen via a third party and published on the dark web. These events follow on from 2017 when they were also fined $148 million for attempting to cover up a breach that impacted 57 million user accounts.

##### Key Takeaway:

##### The versatility of social engineering means it’s almost impossible to completely eliminate it as a threat.

### Chris Cohen: ADCS – a vulnerability few saw coming

A vulnerability that had flown under the radar for around 50% of the organizations that we consulted in 2022 came from misconfigurations in Active Directory Certificate Services (ADCS). Tools to exploit these vulnerabilities have existed for a couple of years, but in the last twelve months, the tooling has improved, and additional escalation paths have also been found.

This significantly increases the risk of a threat actor being able to take over a domain. In fact, in most cases where this was found, our consultants were able to become domain admins from a standard user within a very short amount of time. It can easily be fixed with a reconfiguration, so engage with your cybersecurity consultant to ensure they have this covered.

##### Key Takeaway:

##### One misconfiguration in ADCS can lead to a multitude of vulnerabilities which puts your organization at risk of an attack.

### Key learnings for 2023

The above examples are just a snapshot of the cybersecurity landscape in 2022. The reality is, however, that attacks are becoming more frequent, and the individuals who launch them are becoming more sophisticated.

Having a robust cybersecurity strategy in place — combining cybersecurity risk management software with expert services and consulting — should be top of your to-do list in 2023.

What are some of the learnings we can take from the past 12 months, and what can you do to better protect your organization?

**Patching:** It may seem simple, but ensuring you have the latest software patches in place is paramount. Patches are there to stem the impact and aftereffects of an attack. If you fail to implement them, the repercussions for your organization and partners can be catastrophic.

**Vulnerability Assessments and PEN Testing:** Regular testing and assessments can help protect your organization from a potentially devastating cyber attack. Incorporating monthly vulnerability scanning or continuous PEN testing into your cybersecurity strategy should be a priority for 2023.

**Educate and upskill staff:** The processes you have in place to protect your organization are only as good as the people who implement them. When developing your security strategy, incorporate the ‘human element’ by committing to investment in enhancing the knowledge and skills of employees.

**Seek external advice:** Utilize the skills and expertise of an external provider. Not every organization has the resources available to conduct regular testing, patching, or training, so ease the burden by reaching out to experts who can verify your current security posture and make recommendations for the future.

Related Posts

## You may also like this

[Similar Articles](https://csacyber.com/blog)

[![](https://csacyber.com/hs-fs/hubfs/20230510-N1005919-Edit1.jpg?width=624&height=427&name=20230510-N1005919-Edit1.jpg)](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 August 24, 2026

 2 min read

### [FluidOne Group appoints Charly Davis as Managing Director of CSA Cyber to advance its security-first strategy](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 Experienced industry leader joins FluidOne to strengthen integrated cyber, IT and secure networking...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Untitled%20design.jpg?width=624&height=427&name=Untitled%20design.jpg)](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 August 20, 2026

 2 min read

### [CSA Cyber and FluidOne named as suppliers on G-Cloud 15](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 CSA Cyber (CSA), part of the FluidOne Group, has been named as a supplier on Government Commercial...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Engineered%20to%20Endure%20Campaign%20Assets%20(2).png?width=624&height=427&name=Engineered%20to%20Endure%20Campaign%20Assets%20(2).png)](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 August 20, 2026

 6 min read

### [Why organisations lose security visibility without realising it](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 Before an organisation can understand risk, maintain control or respond effectively to emerging...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![CSA Cyber Logo FNL_Full Logo](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=3463&height=1248&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber Logo FNL_Full Logo")](https://csacyber.com/)

Established in 2013, Cyber Security Associates Limited trading as CSA Cyber provides cyber consultancy and cyber managed services which help to detect, protect and educate against the ever-changing cyber threat. We have built our team from a foundation of Government (ex-Military) and Commercially experienced specialists all holding current and relevant cyber certifications. Today our core services are based around a 24/7 Security Operations Centre (SOC) based in Gloucester.

#### News & Resources

- [Blog](https://csacyber.com/blog)
- [Case Studies](https://csacyber.com/case-studies)
- [Downloads & Reports](https://csacyber.com/downloads-and-reports)
- [Webinars](https://csacyber.com/webinars)
- [Careers](https://csacyber.com/careers)
- [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)

#### Quick Links

- [About Us](https://csacyber.com/about-us)
- [Certifications](https://csacyber.com/certifications-and-awards)
- [Our Parent Company](https://www.fluidone.com)
- [Partners](https://csacyber.com/partners)
- [Contact Us](https://csacyber.com/contact-us)
- [Anti Bribery Policy](https://csacyber.com/hubfs/CSAAnti-BriberyPolicy.pdf)
- [Complaints Policy](https://csacyber.com/hubfs/CSAComplaintsPolicy.pdf)
- [Corporate Social Responsibility Policy](https://csacyber.com/hubfs/CSACorporateSocialResponsibilityPolicy.pdf)
- [Slavery and Human Trafficking Statement](https://csacyber.com/hubfs/CSASlaveryandHumanTraffickingStatement.pdf)
- [NCSC CHECK Status Verification](https://www.ncsc.gov.uk/organisation/csa-cyber/check-penetration-testing)
- [CREST Approved Certification Verification](https://www.crest-approved.org/member_companies/csa-cyber/)

#### Contact Information

**United Kingdom - London**

Cyber Security Associates Ltd

5 Hatfields, London, SE1 9PG

 

**United Kingdom - Gloucester**

Cyber Security Associates Ltd

Unit 11, Wheatstone Court, Waterwells Business Park, GL2 2AQ

 

**Phone:** [+44(0) 300 303 4691](tel:03003034691)

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

**United States of America**

Cyber Security Associates Inc.

6010 W. Spring Creek Pkwy, Plano, Texas, 75024

 

**Phone:** [+1 469 750 1695](tel:14697501695) 

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

[![trust-pilot](https://csacyber.com/hs-fs/hubfs/trust-pilot.png?width=178&height=104&name=trust-pilot.png)](https://uk.trustpilot.com/review/csa.limited)

 

---

- [Website Terms of Use](https://csacyber.com/website-terms-of-use)
- [Website Privacy Policy](https://csacyber.com/privacy-notice)
- [Website Cookie Policy](https://csacyber.com/cookie-policy)

 Copyright 2026. Cyber Security Associates Ltd [Follow us on Facebook](https://www.facebook.com/CSALIMITED/) [Follow us on LinkedIn](https://www.linkedin.com/company/csa-cyber/) [Follow us on Twitter](https://twitter.com/cybersecurityis) [Follow us on Facebook](https://www.youtube.com/@cybersecurityassociateslim) [Follow us on Facebook](https://www.instagram.com/cybersecurityassociates)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Cyber Security Associates",
    "url" : "https://csacyber.com/blog/author/cyber-security-associates"
  },
  "dateModified" : "2024-12-07T14:17:31.232Z",
  "datePublished" : "2022-12-01T05:00:00.000Z",
  "headline" : "Key Cyber Moments Of 2022: What Happened And What Have We Learned?",
  "image" : [ "https://csacyber.com/hubfs/2022.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://csacyber.com/blog/key-cyber-moments-of-2022-what-happened-and-what-have-we-learned",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://csacyber.com/hubfs/csacyber-logo-black-01.svg"
    },
    "name" : "Cyber Security Associates Ltd"
  }
}
```