Cyber espionage represents a silent but prolific threat for mining operators. In an era of increasing digitalisation, the mining industry has more attack surfaces than ever before. As the race for transition minerals heats up, the sector also has more security-critical information including geological surveys and merger and acquisition planning.  

As a result, cyber espionage is rife – most states are both perpetrators and victims. Yet, the clandestine nature of the threat makes it near-impossible to quantify.  

Discover B2B Marketing That Performs

Combine business intelligence and editorial excellence to reach engaged professionals across 36 leading media platforms.

Find out more

In this episode, we speak to William Akoto, professor of foreign policy and global security at American University, and Nilesh Raghoo, associate analyst at GlobalData, to understand the scale and shape of the threat, the technologies that make operators vulnerable and those being used in cyber defence. 

What is cyber espionage and why are mining companies vulnerable?

The most effective cyber espionage is invisible; the victim will be ignorant of the data breach and the perpetrator will never reveal themselves.

“It is very different from ordinary cyberattacks that we would hear about in the news: ransomware, hacktivism, website defacements,” says Akoto. “Those are louder.”

Instead, cyber espionage is silent and “the main objective is really to extract information that is potentially economically or strategically useful”, says Akoto. This puts mining operators in particular at risk. High-value datasets on mineral endowment, or sensitive strategic data such as bidding plans or economic assessments, make operators high-value targets, particularly for state-sponsored actors.

Akoto points to the potential leverage operational data would offer a rival mine, which could use confidential information to “tailor and shape its own investment strategies”.

“They can use that information […] They know how to structure their deal to win and that is why espionage is different”.

Digitalisation means more attack surfaces

The cyber espionage risk in mining is ever-growing too. “Mining sites are beginning to rely on increased levels of operational technology as the sector undergoes digitalisation,” comments Raghoo.

“With this comes an increased risk of systems being breached and exposed if not properly protected. For example, technology that employs the Internet of Things (IoT) can give attackers access to the wider network that they operate on.”

IoT technologies are used across mining for predictive maintenance, collision avoidance for autonomous vehicles, wearable technology and drones. According to a recent report by Mining Technology’s parent company, GlobalData, the global IoT market will reach $1.8tn in revenue by 2028.

It noted: “IoT-enabled sensors and actuators allow for automation of the mining value chain, enhancing safety, productivity, cost-effectiveness, and environmental, social and governance compliance,” before caveating that “cybersecurity remains a significant concern”.

With increased technology comes increased cybersecurity risk, but Raghoo notes that the mining sector has taken steps to secure itself. “I have noticed the improvement or introduction of cybersecurity response teams, and the introduction of security operation centres, which help companies to monitor and respond to threats,” he says.

He adds that third-party cybersecurity solutions are particularly important for mining operators, offering security across the value chain.

Akoto says that the majority of cyberattacks come from five main countries: China, Russia, Iran, North Korea and Syria.

However, he adds that “there are minor actors who every now and then pop up as well”. In 2025, Recorded Future identified at least 20 actors across 13 countries, excluding China, Russia, Iran and North Korea (known as cybersecurity’s ‘Big Four’). These smaller actors were primarily linked to regional conflicts, domestic surveillance or foreign espionage.

Saudi Arabia is one example of a smaller player, but Akoto says state-sponsored cyber operations are frequently perpetrated by Western nations too. “France, for example, is sometimes active in the cyberspace. Canada has also been active,” he notes.

Crucially, says Akoto, cyber espionage is not illegal. In fact, it is assumed. “It is widely understood that nation states would spy on each other. That is just routine.”

While using cyberattacks to disrupt or damage critical infrastructure is unlawful, simply watching and gathering data is not. “If I can get into your systems, I can spy and try and get information that benefits me. There is nothing actually wrong with that. There are no legal restrictions in place,” Akoto says.

Can the threat be quantified?

“We can never really measure the scale of it,” says Akoto. “In fact, whatever we think we know about how much cyber espionage there is, we know for sure that it is an underestimate.”

Most victims will never know that their data has been stolen, but there are significant incentives for both victims and perpetrators to keep cyber espionage campaigns quiet.

“It is very costly to be on the receiving end of a cyber espionage attack, and so most companies that are targeted don’t disclose it,” says Akoto. Compromised companies face reputational damage, financial loss, competitive disadvantages and liability risks, all of which can cause lasting harm.

Simultaneously, attackers are unlikely to disclose a successful case of cyber espionage. Any strategic advantage could be lost and future covert activities would be harder to conduct. “They try to be as quiet as they can, but even if you find out, they are not the type to go and brag about it,” explains Akoto.

As a result, cyber espionage is not only a significant threat for mining operators, it is an unquantifiable one.

The next frontier for cyberattacks and cybersecurity

As AI capabilities develop and grow, so do both the attack surfaces of mining technology and the sophistication of the attacks.

“AI has completely changed the game, acting as a double-edged sword,” explains Raghoo. “It can enable attackers to create malware or code that maliciously attacks a computer system. Additionally, AI can help with more humanistic approaches, such as phishing, by creating more convincing examples that can deceive someone uneducated on the matter.

“On the flip side, AI can be used in cybersecurity solutions; for example, monitoring and threat detection, working autonomously to keep systems safe.”

He notes that hacking is more efficient than ever before, “with attackers needing only hours or minutes to breach a system, compared to a decade ago where weeks or months may have been required”.

Yet AI is not the only looming threat. Quantum computing is set to be the next technological frontier, offering a plethora of both risks and potential capabilities, as yet unseen by the mining sector.

“Quantum computers will soon be able to hack digital infrastructure,” says Raghoo. He warns of ‘Q Day’, “the future date when cryptographically relevant computers (CRQCs) will be able to break public key encryption.

“Even the latest asymmetric public key encryption technologies are at risk from CRQCs.”