Russia and China behind most serious cyberattacks, expert says
Tuesday 25th August 2026 on 17:15 in
Iceland
Most serious cyberattacks are state-sponsored and originate largely from Russia and China, Siggi Pétursson, product development manager at cybersecurity company Varist, told mbl.is.
Varist and fellow cybersecurity company Keystrike will host a briefing at the Grand Hotel on Wednesday morning covering state-sponsored cyber threats, the impact of artificial intelligence on cyberattacks and ways to defend against them.
Experts will discuss how state-backed cybercrime groups choose targets, the methods they use, how they are organised and how companies can protect themselves in the age of artificial intelligence. The session will draw on speakers’ experience dealing with such groups at CERT-IS, Íslandsbanki, SentinelOne, Gen Digital, Varist and Keystrike.
Four speakers will give presentations before taking part in a panel discussion moderated by Jóhanna Guðmundsdóttir of Keystrike. The speakers are Valdimar Óskarsson, Keystrike’s managing director; Magnús Sigurðsson, head of the cybersecurity team CERT-IS; Sigurður Stefnisson, Íslandsbanki’s executive director of digital development and data; and Pétursson.
Pétursson, who recently returned to Iceland after working for the US cybersecurity company SentinelOne, said the Russian authorities allow cybercrime gangs to attack companies in Western countries.
“There is a lot of ransomware, where companies’ data is locked and money is demanded to unlock it again,” he said. The briefing will examine how these groups operate and the methods they use.
Icelandic companies can be used in attacks
Pétursson said Icelanders face two particular concerns. Icelandic companies can themselves become targets, but their computers can also be used to attack companies elsewhere.
He described a recent case in which a US company executive told him that his company was being attacked from a computer in Iceland. Attackers had breached a computer in Iceland and used it to target computers in the United States. Pétursson contacted CERT-IS to identify the Icelandic company involved and asked the organisation to take control of the machine.
“Icelandic companies can be used as attack platforms, with their computers,” he said.
The second concern is the theft of personal data and its use against individuals, including threats to publish sensitive information. Artificial intelligence is often used to create material designed to deceive targets into clicking a link that gives attackers access to their computers, Pétursson said.
The briefing will take place from 9am to 11am on Wednesday. Registration remains open, with places still available when the article was published.