Skip to main content
Fingers seen in silhouette touch a computer screen filled with ones and zeros.
Analyst Insights

Subtle Sabotage: The Rise of Data Tampering, the Next Cyber Battleground

This stealthy, often underestimated tactic in a hacker’s toolkit can distort audits, mislead regulators, and erode customer trust. To fight back, arm your teams with these five expert-backed strategies.

A recent crypto heist – one of the most lucrative in history – reflects a chilling new trend in cybercrime: data tampering.

Last February, employees at Bybit, one of the world’s largest cryptocurrency exchanges, noticed something odd: More than 400,000 Ethereum tokens, worth around $1.5 billion, had quietly vanished. There were no ransomware notes, no signs of brute-force hacking, no obvious alerts tripped.

The telltale clue lay deep in the code of a third-party service the company used for multi-signature transactions. One line had changed: a destination wallet address.

That subtle edit is believed to have allowed nearly $300 million to be diverted to accounts tied to the Lazarus Group, a North Korean hacking gang. (While the exposed infrastructure put about $1.5 billion of cryptocurrency at risk, only a portion was successfully cashed out).

This wasn’t just a smash-and-grab. It was precision sabotage, a clear illustration of data tampering and how it can quietly subvert even the most secure digital systems. And it’s not just a problem for crypto exchanges. Data tampering can hurt any business in any industry in unimaginable ways. Banks, which are cautiously testing cryptocurrency and blockchain services, are particularly vulnerable to these attacks. And chief information security officers would be wise to not underestimate the threat, experts note.

“CISOs should pay close attention to data tampering primarily as these threats often have visible, immediate impacts, such as financial losses or reputational damage,” warned Kevin Curran, a cybersecurity professor at Ulster University in Northern Ireland.

What is data tampering?

What makes data tampering so problematic is how quietly and pervasively it can be deployed.

By subtly altering data instead of stealing or destroying it, attackers can manipulate decisions, sow distrust, or mask their presence – all while remaining under the radar.
Kevin Curran, cybersecurity professor, Ulster University

By definition, it is the intentional and unauthorized modification of data to mislead systems, operators, or downstream decisions. The goal isn’t necessarily to steal or break things, as with most cyberattacks; instead, it’s often about stealthily manipulating records like logs, sensor readings, or transactional information for financial, espionage, or sabotage purposes.

[Read also: What is threat detection and response? An actionable guide]

“Data tampering is a powerful and often underestimated method in the hacker’s toolkit because it targets the integrity of information rather than its availability or confidentiality,” said Curran. “By subtly altering data instead of stealing or destroying it, attackers can manipulate decisions, sow distrust, or mask their presence – all while remaining under the radar.”

Data tampering is not data poisoning – though both erode trust

Though sometimes confused with data poisoning, which involves injecting malicious or corrupted data into a model during its creation or training, tampering targets existing information. It alters the data that systems and solutions, including AI agents, rely on to drive decisions and take action. Both types of attacks ultimately lead to erosion of trust in the integrity of data. When organizations can no longer trust that their data reflects reality, every decision, action, or audit based on that data becomes suspect.

A 2024 Protiviti and the Institute of Internal Auditors survey ranked data governance and integrity among the top technology risks, reinforcing the growing recognition that tampering directly threatens the trustworthiness of systems. And as organizations move toward more automated decision-making, the consequences of acting on tampered data multiply.

Gartner predicts that by 2028, 33% of enterprise software applications will include agentic AI, up from just 1% in 2024, and 80% of common customer service issues could be handled by agents instead of humans by 2029. But what happens if hackers manipulate the operational data used by agents to make decisions?

What then?

According to Jennifer Glenn, research director for data and information security at IDC, the global IT market intelligence firm, companies using customer-facing AI agents should be especially concerned about corrupted data that affects brand experience. If a saboteur, hacktivist, corporate spy, or nation-state changes data in a way that causes agents to respond poorly to customers, it could have long-term repercussions for the business, she said.

“Since GenAI came on the scene and became mainstream, the data information security area has just gone bananas,” Glenn said. “You need so much protection now around that AI data. A single disruption is enough to make a company lose significant money and reputation.”

[Read also: The good news – here’s how AI can redefine data loss prevention and protect your assets]

But GenAI isn’t just vulnerable to tampered data. It can also serve as a powerful data tampering tool. That’s what worries Curran.

“The rise of generative AI significantly amplifies the importance of addressing data tampering as a cybersecurity threat vector, as it introduces new methods, scale, and complexity for malicious actors to manipulate data,” Curran said. “These manipulations are harder to detect than traditional tampering methods, as AI-generated fakes can bypass basic integrity checks or human scrutiny.”

For example, an AI-altered financial report could mislead auditors or a deepfake video could impersonate a CEO to authorize fraudulent transactions, he added.

Data tampering’s subtle distinction

Tampering can take several forms: It might disable the AI model entirely or cause it to produce inaccurate, biased, or offensive outputs that erode customer trust. In some cases, attackers might use it as a distraction to mislead security teams, similar to a heist movie where one group stages a crisis while another hits the real target.

Since GenAI came on the scene and became mainstream, the data information security area has just gone bananas.
Jennifer Glenn, research director for data and information security, IDC

“Attackers might do something over here to keep you from looking at what's happening over there,” Glenn said. “Maybe they're manipulating your data to create really bad responses that get you in trouble. But while you are fixing that, they're exfiltrating data they shouldn’t have from another location. So, I mean, it could be like a cover.”

Hackers could also use data tampering to mess with code as it develops. For example, someone could change data slightly to slow development lifecycles, introduce software backdoors, or even sideline a project. With so many IT teams understaffed, it might be challenging to address such issues, Glenn said.

Thus far, these types of incidents seem rare. But data tampering has been popping up in attacks on critical infrastructure. For example, in November 2023, a water treatment facility near Pittsburgh discovered that its programmable logic controller (PLC) had been hijacked. Instead of regular readings, operators saw an anti-Israel message scrawled across the touchscreen. The breach didn’t shut down the plant. Still, it forced the utility to switch to manual controls and raised alarms about how easily attackers could manipulate what operators see (a visual form of data tampering).

A few weeks later in Muleshoe, Texas, pro-Russian hackers remotely turned on water pumps and altered alarms, causing a tank to overflow. The data on-screen showed normal operation, even as the tank spilled over. This wasn’t a brute-force attack. It was subtle sabotage through control manipulation.

[Read also: Seeing is believing – how enterprises are using AI to improve cybersecurity]

Other campaigns have gone even deeper. China-linked groups like BlackTech and UNC3886 have reportedly tampered with router firmware and logs – that control device behavior and record network activity – to maintain long-term, undetected access to networks at defense, government, telecommunications, high-tech, and media organizations. In some cases, they disabled logging altogether, blinding network defenders to their presence.

Glenn notes that nation-states often favor data tampering because, when discovered, it can resemble a routine system misconfiguration or coding error rather than the work of a foreign intruder.

What’s more, traditional defenses aren’t built to spot subtle integrity violations. And many organizations lack the tooling to distinguish between a legitimate configuration change and a malicious one made to erase footprints or subvert systems.

5 tactics to tamp down data tampering

Stopping data tampering requires a shift from perimeter defense to deep integrity assurance. Here are five expert-backed strategies:

1. Watch for anomalies

Know what "normal" looks like for key data and configurations. Deploy endpoint tools for sensitive data monitoring, endpoint visibility and control, real-time threat detection, integrity monitoring, and data loss prevention (DLP).

2. Stay vigilant

Tracking where data comes from and how it moves through a system makes it easier to spot signs of tampering and hold the right parties accountable.

3. Use cryptographic integrity checks

Protect critical logs and configuration files using methods that verify their authenticity. These checks ensure that any unauthorized changes are detected right away, helping to stop silent manipulation and maintain trust in system data.

4. Centralize logs on tamper-proof storage

Push logs to secure, append-only systems (like Write-Once-Read-Many, or WORM, storage) where attackers can’t quietly erase their tracks if they compromise a machine.

5. Adopt secure-by-design principals

Secure by design means embedding security considerations into every stage of system development from the initial stages. According to Curran, organizations can prevent data tampering by anticipating threats through modelling, preparing incident-response plans that include data integrity breaches, and securing their supply chain by vetting third-party components and enforcing secure development practices.

[Read also: Drilling down on data privacy – 5 key charts from ISACA’s 2025 report]

The larger risk

Data integrity has always been a business and IT priority, yet 67% of data-driven decision makers don’t fully trust their data, according to Precisely research. As more companies explore AI agents that depend on trusted data to function, CISOs must rethink their data strategies, said Curran.

“Data tampering incidents will rise,” he said. “Ignoring this threat risks operational disruptions, regulatory penalties, and eroded trust.”