All news
cybersecurityregulation

Google Revamps Hacker Group Naming System: What It Means

08 Aug 2026

Google Overhauls How It Names Hacking Groups

For more than a decade, the cybersecurity industry has assigned names to hacking groups to help researchers track and discuss threats. Last month, Google became the latest company to revamp its own naming system—a move its threat intelligence chief says was overdue.

Shane Huntley, chief technology officer of Google Threat Intelligence Group, said the update was necessary "to bring clarity to security researchers both inside the company and externally." Google's new system assigns hacking groups a first name that is memorable and random, paired with a second word whose initial indicates the group's country of origin.

Why the Change Now

Huntley explained that when companies first began publishing reports on cyberattacks in the early 2010s, they weren't anticipating the scale of threat groups that would eventually emerge. That scale is now significant: Google tracks more than 5,000 activity clusters across several countries.

Huntley also noted that "there are very few developed nations that don't have their own cyber capabilities and hacking groups"—a comment that underscores just how widespread state-linked cyber activity has become.

Notably, Mandiant—once an independent security firm known for its own threat-naming conventions—is now part of Google, adding weight to the company's push for a more unified system.

Open Questions

The report does not specify the exact date of Google's announcement, nor does it detail how the country-of-origin initial is determined or verified. It's also unclear how Google's new system compares to those used by other vendors or to Mandiant's prior naming conventions, and whether external researchers have adopted or endorsed the new convention. The full list of countries with tracked activity clusters likewise isn't specified.

The Risks of Naming Threats

Standardizing threat names isn't without pitfalls. Sources in the report flag two key risks: ambiguity or inconsistency in naming conventions across the industry could hinder threat intelligence sharing, and attribution errors in country-of-origin naming could lead to diplomatic or reputational complications.

Why Founders Should Care

  • The sheer volume of tracked clusters—5,000+—suggests that cyber threats are likely more fragmented and numerous than many founders assume, meaning startups should probably not underestimate the diversity of actors that could target them.
  • Google's move may signal a broader industry shift toward standardized threat intelligence, which could eventually make it easier for startups to compare and evaluate security vendors.
  • Mandiant's integration into Google's threat intelligence operations may reflect ongoing consolidation in the cybersecurity industry—a trend worth monitoring when choosing security partners.
  • Huntley's observation that nearly all developed nations have cyber capabilities implies that startups operating internationally could plausibly face state-linked threats, regardless of their industry.

The Bigger Picture

While the naming system itself may seem like an internal industry matter, it points to a larger truth: the threat landscape is expanding faster than most naming conventions—or founders—can keep up with. For early-stage companies, that's a reminder that cybersecurity readiness shouldn't wait until a company reaches a certain size or visibility.

Sources