Attribution Is Fascinating; Ask What It Changes
Attribution · June 20, 2026 · 9 min read
Every incident produces the same question from someone senior, usually within the first hour: who is doing this?
The question is natural and the pull behind it is not frivolous. Naming an adversary converts an unbounded situation into a bounded one. A named group has a history, a documented set of behaviours, an implied ceiling on what it will attempt. Uncertainty is exhausting, and a name relieves it.
The problem is that relief is not the same as information, and the effort spent producing a name is usually large while the number of decisions it alters is usually small. It is worth being precise about which decisions those are.
Four different claims wearing one word
“Attribution” is used to mean at least four assertions that require entirely different evidence and carry entirely different confidence.
This is the same activity we saw before. A claim about clustering: shared tooling, shared infrastructure, shared sequencing. It rests on technical observables and can often be made well, sometimes even from internal data alone.
This is a known toolset. A claim about implementation. Useful, and weaker than it sounds — tooling is shared, sold, leaked and reimplemented, and the inference from tool to operator is a step that frequently does not hold.
This is a specific organisation. A claim about people and structure. It generally requires access no defender has: legal process, human sources, signals collection, the sustained work of an agency or a vendor with unusual telemetry breadth. Almost nobody can make it from an incident.
This is a state, acting deliberately. A claim about policy and intent, which requires everything above plus an argument about tasking. It is a political judgement wearing technical clothing, and it belongs to governments.
Most conversations that begin “who is this?” slide between the first claim and the fourth without anyone noticing the transition. The single most useful intervention an analyst can make in an incident room is to ask which of the four is being asserted.
The actions that do not change
Consider what a defender actually does during an intrusion: identify affected systems, work out how access was obtained, contain, evict, restore, close the route in.
Now ask which step is performed differently depending on who the adversary is.
Containment is not. The compromised host is isolated regardless. Eviction is not — credentials are rotated and persistence removed whichever flag flies over the operator. Root-cause remediation is not: the unpatched service, the over-privileged role, the exposed management interface are equally wrong whoever walked through them.
This is the uncomfortable core of the argument. The overwhelming majority of incident response is attribution-independent, and hours spent debating a name during the response window are hours not spent on scope, which is the variable that genuinely determines the outcome.
Where it genuinely matters
There are real exceptions, and they cluster in a few places.
Expected persistence. Some adversaries treat a lost foothold as the end of a job; others treat it as a setback and return. That expectation should change how long you watch after closing an incident, how much you invest in detecting re-entry, and whether you treat eviction as a single event or a campaign. This is the exception that most often justifies the effort, and note that it does not require a name — it requires an assessment of intent and resourcing.
Legal and regulatory position. Notification obligations, sanctions exposure where a ransom payment is contemplated, insurance terms with state-action language, evidence handling if a prosecution is conceivable. These are questions where the identity of the party has direct consequences, and where the standard of evidence is legal rather than analytic.
Anticipating the next move. If you can genuinely establish what an adversary has done elsewhere, you can prioritise what to check and what to harden. This is the most-claimed benefit and the most frequently overstated, because it depends on a behavioural profile stable enough to predict from — and operators change tooling far faster than reports get updated.
Strategic posture. At a programme level, understanding which categories of adversary plausibly target your sector should shape investment. This is a planning input, on a timescale of quarters, and it does not need to resolve to individual groups.
The precision trap
A name creates a false impression of resolution. Once a group label is in the incident channel, statements start attaching themselves to it that the evidence never supported. They always use that persistence technique. They don’t usually destroy data. They tend to go quiet after detection. Each may be true of some past activity attributed to some cluster under that label, and none of it is a property of the person currently in your environment.
Public actor profiles are also survivorship-biased in a way that is rarely stated. They describe the operations that were discovered, analysed and published. Operations that succeeded quietly are, by construction, absent. A profile is a description of an adversary’s failures, and planning against it assumes the adversary will fail the same way again.
Say what you saw
The substitute for a name is a description, and it is usually more actionable.
“Whoever this was arrived with valid credentials, moved within twenty minutes, knew which host was the jump box without scanning for it, and used only tooling already present on the systems” is a far better basis for decisions than a label. It tells you the initial access route to close, the detection gap to fill, the possibility of prior reconnaissance or insider knowledge to investigate, and the capability level to plan against. It does all of that without asserting anything unsupported.
Where a judgement has to be made, make it in explicit confidence language and say what would change it. We assess with moderate confidence that this is the same activity as the March event, based on reuse of the same certificate and the same staging directory layout; discovery that the certificate is shared across unrelated operations would substantially weaken this. That sentence is honest, decision-relevant, and revisable — three properties a group name does not have.
The question to ask instead
When attribution comes up, the productive response is not to refuse it. It is to convert it into a decision.
If we knew it was A rather than B, what would we do differently? If the answer is a specific action — extend monitoring by three months, involve counsel, withhold a payment, notify a regulator — then the analysis is worth funding to whatever standard that decision requires. If the answer is that the response would be identical, the question is curiosity, and curiosity can wait until the environment is clean.