REVIEW 3 major objections 6 minor 32 references
Yet Another Diminishing Spark: Low-level Cyberattacks in the Israel-Gaza Conflict
T0 review · 3 major / 6 minor · reviewed 2026-08-16 · deepseek-v4-flash
Pith's one-line read Low-level cyberattacks in the Israel-Gaza conflict surged right after the October 7 assault but faded within weeks, and were an order of magnitude smaller and more one-sided than those seen during the Russia-Ukraine war.
desk verdict Solid, honest measurement of low-level cyberattacks in Israel-Gaza, but the headline 'lower than Ukraine' rests on an unnormalized DDoS comparison across years. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing mechanism is a multi-source measurement design combining four observational streams: self-reported defacement archives (over 105,000 records), a global UDP-amplification DDoS honeypot, a large English-language hacking forum, and two public Telegram channels of the Cyber Army of Palestine. Against these, the paper applies a three-era statistical comparison (before the war, the first month, and the following three months) using Kruskal-Wallis tests, a rank-based test for whether the three time periods differ, with Dunn's post-hoc comparisons and eta-squared effect sizes. This era-based design lets the authors attribute the observed spikes to the conflict and quantify both their size and their short duration.
What would settle it
A researcher could test the claims by obtaining TCP-based DDoS logs, non-English hacking forums, or pro-Israeli Telegram channels for the same period; substantial pro-Israeli attacks or volumes comparable to the Russia-Ukraine conflict would falsify the paper's one-sidedness and scale conclusions. A cheaper check is counting defacements of Palestinian (.ps) sites in the same archives after the same de-duplication; a number far above 25 would undermine the asymmetry claim.
Extended reading notes
Core claim
The central discovery is that low-level cyberattacks in the Israel-Gaza conflict followed the same 'diminishing spark' pattern the authors previously documented for Russia-Ukraine: a sudden, statistically significant surge in web defacements and DDoS attacks immediately after the war began, followed by a rapid decline to near-baseline within about a month. The scale was an order of magnitude smaller than in the Russia-Ukraine case, with 1,791 defacements on Israeli sites versus 25 on Palestinian sites and over 3,000 UDP-amplification DDoS hits on Israel versus about 600 on Palestine, and the attack direction was heavily one-sided: 559 defacements explicitly supported Palestine while only one supported Israel. Debate on hacking forums also spiked then collapsed, and the pro-Palestinian Cyber Army of Palestine's Telegram channel lost engagement within weeks. The paper interprets this as evidence that armed conflict reliably produces a brief burst of low-level hacking that fades as interest wanes, and that in this conflict the 'cyber front' was largely a pro-Palestinian phenomenon.
Load-bearing premise
The findings assume that defacement archives, a UDP-only DDoS honeypot, one English-language hacking forum, and one pro-Palestinian Telegram channel together represent the full landscape of low-level cyberattacks in this conflict.
Editorial extensions
If this is right
- Future large armed conflicts can be expected to produce a brief, front-loaded burst of low-level cyberattacks and hacktivist chatter, followed by a rapid return toward baseline within weeks.
- The Israel-Gaza conflict shows that low-level cyberwar can be strongly one-sided, so asymmetry in attack volume is not always a proxy for state capability.
- The order-of-magnitude gap with the Russia-Ukraine conflict suggests that a country's cybercrime ecosystem and history of information operations shape how much volunteer hacking a war attracts.
- Hacktivist groups such as the Cyber Army of Palestine can be created quickly but have short operational lifespans, with their coordination channels losing engagement within about a month.
Reading between the lines
- Editorial inference: the one-sidedness measured here likely understates pro-Israeli activity, because the data sources are asymmetric — the Telegram channel is pro-Palestinian, the forum is English-language, and the honeypot excludes TCP-based DDoS; the paper itself flags the infrastructure asymmetry but does not quantify this bias.
- Editorial inference: the 'diminishing spark' pattern could be tested prospectively in the next major conflict; if it recurs with similar timing (peak within days, decay within weeks), it would support a general regularity of low-level cyber-conflict engagement.
- Editorial inference: the paper's ratio of about 559 pro-Palestinian to 1 pro-Israeli defacement messages suggests that defacement archives may serve as a rough, real-time barometer of online political sympathy in a conflict, worth comparing with social-media hashtag data.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper empirically studies low-level, non-state cyberattacks (web defacement and UDP-amplification DDoS) and hacking-community discussions during the Israel-Gaza conflict from August 2023 to January 2024, comparing these with the authors' prior findings for the Russia-Ukraine war. It uses four datasets: self-reported defacement archives, a UDP-amplification DDoS honeypot, the English-language HACK FORUMS, and two Telegram channels of the Cyber Army of Palestine. The authors report immediate but short-lived surges in defacements and DDoS attacks after the Hamas-led assault, a largely one-sided pattern with far more attacks on Israeli than Palestinian targets, and a rapid decline in both attacks and discussions within weeks. Statistical significance is assessed with Kruskal-Wallis tests, Dunn post-hoc tests, and effect sizes.
Significance. If the findings hold, the paper provides a useful, systematic, comparative look at how low-level cybercrime actors respond to a major armed conflict, extending the authors' earlier Russia-Ukraine study. The analysis is transparent about its statistical methods and makes all datasets and scripts available through a data-sharing agreement, which is a strength for reproducibility. The paper also highlights the rapid decay of engagement, a pattern consistent with prior work. However, the central comparative claims—that attack and discussion scale was 'significantly lower' than in the Russia-Ukraine war, and that the conflict was 'prominently one-sided'—rest on data sources with notable selection biases and on an absolute-count comparison that does not control for global baseline changes; these issues need to be addressed before the headline conclusions can be considered fully supported.
major comments (3)
- [Section 4.2, 'UDP Amplification DDoS Attacks'] The claim that Israel-Gaza DDoS activity was 'an order of magnitude less (15–20 times)' than in the Russia-Ukraine conflict compares absolute honeypot counts from late 2023 with roughly 600 attacks/day from early 2022, without accounting for changes in the global UDP-amplification baseline between those periods. This is a load-bearing comparison for the abstract's statement that the scale of attacks was 'significantly lower' than in the Russia-Ukraine war. The same honeypot dataset was used in Ref. [24] to measure the effects of a global takedown of DDoS-for-hire services in 2022–2023, which implies that global UDP-amplification attack volumes may have fallen substantially for reasons unrelated to this conflict. Without a difference-in-differences design using a control group of non-conflict countries, a ratio-to-baseline normalization, or at least a demonstration that the honeypot sensor set and global attack mix were stable over the comparison period, the 15–20x gap could be an artifact of market trends rather than a conflict-specific difference. I recommend the authors either provide such a normalization or substantially soften the cross-conflict scale claim.
- [Section 5, 'Discussions on HACK FORUMS'] There is an internal inconsistency between the abstract and the reported forum data. The abstract states that 'The scale of attacks and discussions within the hacking community this time was both significantly lower than those during the early days of the Russia-Ukraine war,' but Section 5 reports that the Israel-Gaza surge 'peaked at a higher level but tailed off much faster than those previously seen in the Russia-Ukraine conflict (which peaked at around 140 but lasted for a few weeks [5])'. Concretely, the paper reports about 270 posts per day for Israel-Gaza versus about 140 for Russia-Ukraine. If 'scale' is meant to refer to cumulative volume over the entire conflict window, the paper must compute and present those totals; if it refers to peak intensity, the current statement is contradicted by the paper's own numbers. This needs to be resolved by either adding a proper cumulative comparison or revising the abstract and conclusion.
- [Sections 3.1 and 5 ('Web Defacements', 'UDP Amplification DDoS Attacks', 'Underground Forum Posts', 'Telegram Chats')] The conclusion that the conflict was 'prominently one-sided' rests on four data sources: self-reported defacement archives, a UDP-only DDoS honeypot, a single English-language forum, and a pro-Palestinian Telegram channel. The paper acknowledges these limitations in a general way, but does not quantify how much bias they could introduce. For instance, pro-Israeli attackers could be using TCP-based DDoS, private defacement methods, or non-English channels, all of which would be invisible to this data collection. The one-sidedness finding is within-period and therefore less affected by the baseline-trend confound, but it is still susceptible to source-selection bias. I recommend either triangulating with additional independent data (e.g., Cloudflare's HTTP DDoS observations, Arabic-language sources, or pro-Israeli channels) or explicitly restricting the conclusion to the studied data sources rather than presenting it as a general characterization of the conflict's cyber dimension.
minor comments (6)
- [Section 3.2, 'Statistical Tests'] The text reads 'from 7 October to 31 October 2024' when it should be '2023' for the E2 era; please correct the typo.
- [Section 4.1, 'Website Defacement Attacks'] The phrase 'significantly less than that against Russia' uses the word 'significantly' in a non-statistical sense; since no significance test across conflicts is reported, consider replacing it with 'substantially less' to avoid ambiguity.
- [Section 4.1, 'Website Defacement Attacks'] The sentence 'suggesting that the conflict is highly associated with the outbreak of attacks on Israel' uses causal-sounding language; I recommend 'associated with' to match the observational nature of the data.
- [Section 3.1, 'Web Defacements'] It would be helpful to state explicitly whether the same victim-country identification procedure (ccTLD, IP geolocation, AS geolocation excluding CDNs) was used in the earlier Russia-Ukraine study [5], to confirm the cross-conflict comparability of the defacement counts.
- [Figure 1 and Table 1] The annotations in Figure 1 (e.g., the red star marking the Hamas strike and the textual comments) are useful, but the font is small; please ensure legibility and that the era boundaries E1/E2/E3 are clearly aligned with the time axis.
- [Section 5, 'The Cyber Army of Palestine'] The statement '10–15 times less than the IT Army of Ukraine' is awkward; consider '10–15 times fewer subscribers'.
Circularity Check
No circularity found; the paper reports direct measurements and external comparisons without fitting or definitional reductions.
full rationale
This paper is an empirical measurement study with no fitted parameters, no derived quantity that is defined in terms of another measured quantity, and no predictive claim that reduces to its inputs by construction. The central claims—immediate but short-lived surges in defacements, DDoS attacks, and forum/Telegram activity after 7 October 2023, and the one-sidedness of attacks—are supported by direct counts from four described datasets and standard non-parametric statistical tests. The comparison to the Russia-Ukraine conflict uses the same honeypot and defacement datasets as prior work [5], but that prior result is used as an external empirical benchmark, not as a theorem or a fitted input; the authors explicitly quote the earlier figure of roughly 600 attacks per day and compare their own contemporaneous counts. The potential baseline-shift confound in the DDoS comparison is a validity limitation, not a circularity, because the conclusion does not presuppose the data that is being measured. Self-citations appear for dataset provenance, method reuse, and comparison baselines, but none of these citations is load-bearing in the sense of smuggling in the paper's conclusions; the datasets are public and the analyses are reproducible under the Cambridge Cybercrime Centre sharing agreement. The one-sidedness and activity-decay conclusions are within-period observations that do not depend on any prior conclusion. No circular step can be exhibited from the paper's text, so the appropriate score is 0.
Assumptions & free parameters
assumptions (6)
- domain assumption Victim country identification via ccTLD, IP geolocation, and AS geolocation excluding CDNs accurately reflects the target nationality.
- domain assumption Self-reported web defacement archives are a representative sample of low-level defacement activity.
- domain assumption The UDP amplification DDoS honeypot captures a representative sample of low-level DDoS attacks.
- domain assumption Keyword-filtered posts on Hack Forums and the two Telegram channels represent the war-related discussion among low-level hacking actors.
- ad hoc to paper The era boundaries E1 (before Oct 7), E2 (Oct 7-31), E3 (Nov 1-Jan 31) are the correct segmentation for detecting conflict-driven activity changes.
- standard math Daily attack counts are independent observations for Kruskal-Wallis testing.
Cite this review
Pith. "Pith review of Yet Another Diminishing Spark: Low-level Cyberattacks in the Israel-Gaza Conflict." pith.science (2026). https://pith.science/paper/TU3TZTWV
@misc{pith2026250415592,
author = {Pith},
title = {Pith review of: Yet Another Diminishing Spark: Low-level Cyberattacks in the Israel-Gaza Conflict},
year = {2026},
howpublished = {\url{https://pith.science/paper/TU3TZTWV}},
note = {Machine review of arXiv:2504.15592}
}
read the original abstract
We report empirical evidence of web defacement and DDoS attacks carried out by low-level cybercrime actors in the Israel-Gaza conflict. Our quantitative measurements indicate an immediate increase in such cyberattacks following the Hamas-led assault and the subsequent declaration of war. However, the surges waned quickly after a few weeks, with patterns resembling those observed in the aftermath of the Russian invasion of Ukraine. The scale of attacks and discussions within the hacking community this time was both significantly lower than those during the early days of the Russia-Ukraine war, and attacks have been prominently one-sided: many pro-Palestinian supporters have targeted Israel, while attacks on Palestine have been much less significant. Beyond targeting these two, attackers also defaced sites of other countries to express their war support. Their broader opinions are also largely disparate, with far more support for Palestine and many objections expressed toward Israel.
Figures
Reference graph
Works this paper leans on
-
[24]
Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services,
A. V . Vu, B. Collier, D. R. Thomas, J. Kristoff, R. Clayton, and A. Hutchings, “Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services,” in Proceedings of the USENIX Security Symposium (USENIX Security) , 2025, https: //rb.gy/4nkvvv
work page 2025
-
[5]
A. V . Vu, D. R. Thomas, B. Collier, A. Hutchings, R. Clayton, and R. Anderson, “Getting Bored of Cyberwar: Exploring the Role of Low-Level Cybercrime Actors in the Russia-Ukraine Conflict,” in Proceedings of the ACM World Wide Web Conference (WWW) , 2024, DOI:10.1145/3589334.3645401
arXiv 2024
-
[1]
F. G. Hoffman, Conflict in the 21st Century: The Rise of Hybrid Wars. Potomac Institute for Policy Studies, 2007, https:// rb.gy/2u7fpo
work page 2007
-
[2]
Hackers Hit United Hatzalah, Aid Group Treating Wounded Israelis,
The Jerusalem Post, “Hackers Hit United Hatzalah, Aid Group Treating Wounded Israelis,” https://rb.gy/dtl7w1, 2023
work page 2023
-
[3]
Cyberattacks on the Middle East Will Continue to Rise,
Oxford Analytica, “Cyberattacks on the Middle East Will Continue to Rise,” Emerald Expert Briefings, 2024, DOI:10.1108/OXAN- DB291422
-
[4]
Journalist Casualties in the Israel-Gaza War,
Committee to Protect Journalists, “Journalist Casualties in the Israel-Gaza War,” https://rb.gy/hjzftg, 2025
work page 2025
-
[6]
Identify- ing and Collecting Public Domain Data for Tracking Cyber- crime and Online Extremism,
L. Wilson, A. V . Vu, I. Pete, and Y . T. Chua, “Identify- ing and Collecting Public Domain Data for Tracking Cyber- crime and Online Extremism,” in Open-Source Verification in the Age of Google . World Scientific, 2024, DOI:10.1142/ 9781800614079_0015
work page 2024
-
[7]
British Society of Criminology, “Statement of Ethics,” https:// rb.gy/ldwfkl, 2015. [Online]. Available: http://britsoccrim.org/ ethics/
work page 2015
Show all 32 references
-
[8]
ESET Partner Breached to Send Data Wipers to Israeli Orgs,
Bleeping Computer, “ESET Partner Breached to Send Data Wipers to Israeli Orgs,” https://rb.gy/0zj5zz, 2024
2024
-
[9]
Cyber Attacks in the Israel-Hamas War,
Cloudflare, “Cyber Attacks in the Israel-Hamas War,” https: //rb.gy/czdpjh, 2023
2023
-
[10]
Attacks on Israeli Orgs ‘More Than Doubled’ Since October 7,
The Record, “Attacks on Israeli Orgs ‘More Than Doubled’ Since October 7,” https://rb.gy/wwmwg2, 2024
2024
-
[11]
Tool of First Resort: Israel-Hamas War in Cyber,
Google, “Tool of First Resort: Israel-Hamas War in Cyber,” https://rb.gy/45b4yz, 2024
2024
-
[12]
Iran Surges Cyber-Enabled Influence Operations in Support of Hamas,
Microsoft, “Iran Surges Cyber-Enabled Influence Operations in Support of Hamas,” https://rb.gy/ion04y, 2024
2024
-
[13]
Hackers Infiltrated Israeli Smart Billboards to Post Pro-Hamas Messages,
Business Insider, “Hackers Infiltrated Israeli Smart Billboards to Post Pro-Hamas Messages,” https://rb.gy/dtfyhd, 2023
2023
-
[14]
Disinformation Surge Threatens to Fuel Israel-Hamas Conflict,
Reuters, “Disinformation Surge Threatens to Fuel Israel-Hamas Conflict,” https://rb.gy/oinh39, 2023
2023
-
[15]
Malicious “RedAlert - Rocket Alerts
Cloudflare, “Malicious “RedAlert - Rocket Alerts” Application Targets Israeli Phone Calls, SMS, and User Information,” https: //rb.gy/tu8m25, 2023
2023
-
[16]
US Cyber Agencies in ‘Very Close Contact’ With Israel After Unprecedented Hamas Attacks,
Nextgov/FCW, “US Cyber Agencies in ‘Very Close Contact’ With Israel After Unprecedented Hamas Attacks,” https://rb.gy/ xk22yn, 2023
2023
-
[17]
Gaza Communications Blackout, the Longest of the War, Hits One-Week Mark,
CNN News, “Gaza Communications Blackout, the Longest of the War, Hits One-Week Mark,” https://rb.gy/2axuic, 2024
2024
-
[18]
Internet Connec- tivity for Gaza Strip,
Internet Outage Detection & Analysis (IODA), “Internet Connec- tivity for Gaza Strip,” https://rb.gy/x1un70, 2023
2023
-
[19]
‘Don’t Play With Fire’: Israeli Hack- ers Claim to Have Disabled Tehran Electrical Grid,
Israel National News, “‘Don’t Play With Fire’: Israeli Hack- ers Claim to Have Disabled Tehran Electrical Grid,” https: //rb.gy/ucgprr, 2023
2023
-
[20]
The 7 October Hamas Attack: A Preliminary Assess- ment of the Israeli Intelligence, Military and Policy Failures,
P. Selj ´an, “The 7 October Hamas Attack: A Preliminary Assess- ment of the Israeli Intelligence, Military and Policy Failures,” Aca- demic and Applied Research in Military and Public Management Science, 2024, DOI:10.32565/AARMS.2024.1.5
2024 doi
-
[21]
A Look Inside the Cyberwar Between Is- rael and Hamas Reveals the Civilian Toll,
The Conversation, “A Look Inside the Cyberwar Between Is- rael and Hamas Reveals the Civilian Toll,” https://rb.gy/ wxzdwv, 2024
2024
-
[22]
1000 Days of UDP Amplification DDoS Attacks,
D. R. Thomas, R. Clayton, and A. R. Beresford, “1000 Days of UDP Amplification DDoS Attacks,” in Proceedings of the APWG Symposium on Electronic Crime Research (eCrime) , 2017, DOI: 10.1109/ECRIME.2017.7945057
2017
-
[23]
Booting the Booters: Evaluating the Effects of Police Interventions in the Market for Denial-of-Service Attacks,
B. Collier, D. R. Thomas, R. Clayton, and A. Hutchings, “Booting the Booters: Evaluating the Effects of Police Interventions in the Market for Denial-of-Service Attacks,” in Proceedings of the ACM Internet Measurement Conference (IMC) , 2019, DOI:10.1145/ 3355369.3355592
2019
-
[25]
CrimeBB: Enabling Cybercrime Research on Underground Fo- rums at Scale,
S. Pastrana, D. R. Thomas, A. Hutchings, and R. Clayton, “CrimeBB: Enabling Cybercrime Research on Underground Fo- rums at Scale,” in Proceedings of the ACM World Wide Web Conference (WWW), 2018, DOI:10.1145/3178876.3186178
2018
-
[26]
Charac- terizing Eve: Analysing Cybercrime Actors in a Large Under- ground Forum,
S. Pastrana, A. Hutchings, A. Caines, and P. Buttery, “Charac- terizing Eve: Analysing Cybercrime Actors in a Large Under- ground Forum,” in Proceedings of the International Symposium on Research in Attacks, Intrusions, and Defenses (RAID) , 2018, DOI:10.1007/978-3-030-00470-5_10
2018 doi
-
[27]
Miles and M
J. Miles and M. Shevlin, Applying Regression and Correlation: A Guide for Students and Researchers . Sage, 2000, https: //rb.gy/1hi361
2000
-
[28]
Repeat Victimization by Website Defacement: An Em- pirical Test of Premises From an Environmental Criminology Per- spective,
A. Moneva, E. R. Leukfeldt, S. G. Van De Weijer, and F. Mir ´o- Llinares, “Repeat Victimization by Website Defacement: An Em- pirical Test of Premises From an Environmental Criminology Per- spective,” Computers in Human Behavior , 2022, DOI:10.1016/ J.CHB.2021.106984
2022
-
[29]
Turning Up the Dial: the Evolution of a Cy- bercrime Market Through Set-Up, Stable, and Covid-19 Eras,
A. V . Vu, J. Hughes, I. Pete, B. Collier, Y . T. Chua, I. Shumailov, and A. Hutchings, “Turning Up the Dial: the Evolution of a Cy- bercrime Market Through Set-Up, Stable, and Covid-19 Eras,” in Proceedings of the ACM Internet Measurement Conference (IMC) , 2020, DOI:10.1145/...
2020
-
[30]
Russian Information Warfare: Lessons From Ukraine,
M. Jaitner, “Russian Information Warfare: Lessons From Ukraine,” in Cyber War in Perspective: Russian Aggression against Ukraine . NATO Cooperative Cyber Defence Centre of Excellence (CCD- COE), 2015, https://rb.gy/ywkisg
2015
-
[31]
Mapping the Geogra- phy of Cybercrime: A Review of Indices of Digital Offending by Country,
J. Lusthaus, M. Bruce, and N. Phair, “Mapping the Geogra- phy of Cybercrime: A Review of Indices of Digital Offending by Country,” in Proceedings of the IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) , 2020, DOI: 10.1109/EuroSPW51379.2020.00066
2020
-
[32]
Does Social Media Favor Palestine Over Israel?
Politico, “Does Social Media Favor Palestine Over Israel?” https://rb.gy/z0nwsu, 2023. 6 Anh V . Vu, Alice Hutchings, and Ross Anderson
2023
Reviewed August 16, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.