Cybersecurity teams have long wrestled with a simple yet vexing problem: how do you keep track of thousands of hacking groups when every company calls them something different? Google's top threat hunter, Shane Huntley, recently explained to TechCrunch why the industry's naming conventions are so messy—and why his company just overhauled its own system. The move aims to cut through the confusion that has plagued security researchers, government officials, and journalists for over a decade. Main Developments Google announced last month that it is replacing its old alphanumeric system—the one that produced names like APT1 and APT41, inherited from Mandiant—with something far more intuitive. Each hacking group will now get a memorable first name paired with a second word whose initial signals the country of origin: Castle for China, Ion for Iran, Neptune for North Korea, and Relic for Russia. The change consolidates naming across Google's Threat Analysis Group and Mandiant, which Google acquired in 2022. Huntley, who now serves as CTO of Google Threat Intelligence Group, said the update brings clarity to internal researchers and external partners alike. He recalled that when companies first started publishing reports on cyberattacks in the early 2010s, "we were not expecting to have as many threat groups as we do today." Read also: OpenAI Halts Astra Development Over Cyberattack Fears Google now tracks more than 5,000 activity clusters across several countries, according to John Hultquist, chief analyst at Google Threat Intelligence Group. Huntley noted that very few developed nations lack their own cyber capabilities or hacking groups, making the naming challenge even more acute. For Huntley, naming is not an academic exercise. The goal is to build a baseline understanding of who attacks whom and how, so organizations can recognize threats faster, prepare defenses, and respond to incidents more efficiently. "If you actually get hacked by them or you're dealing with some incident, knowing how that actor behaves, what they do, what they've done in the past, all of these details become critically important," he said. Background The practice of naming hacking groups took off in the early 2010s, when cybersecurity firms began publishing detailed reports on cyberattacks and attributing them to specific actors. Mandiant was the first company to adopt a systematic naming scheme, using the APT (Advanced Persistent Threat) designation followed by numbers. That approach became industry shorthand, but it soon proved unwieldy. As the number of identified groups exploded, so did the confusion. Different companies assigned different names to the same groups, and even industry insiders struggled to keep track. Resources like the one maintained by the cybersecurity community—a sprawling list that attempts to map every alias to a single group—emerged as a stopgap solution. Some names, like Fancy Bear, broke into the mainstream because of the group's high-profile hacks and memorable moniker. Others remained obscure, known only to a small circle of researchers. The fragmentation made it harder for defenders to share intelligence and for policymakers to understand the threat landscape. Why It Matters The naming system is more than a bureaucratic exercise; it directly affects how quickly organizations can respond to cyber threats. When a company is breached, knowing the attacker's identity gives defenders a head start—they can anticipate the group's tactics, objectives, and typical targets. For instance, understanding that North Korea's Lazarus Group usually pursues financial theft helps organizations prioritize their defenses. Tracking state-sponsored hackers is relatively straightforward because they tend to have consistent targets and activities, Huntley explained. Cybercriminal groups and hackers-for-hire are harder to pin down: their members come and go, splinter into factions, and operate across borders. Spyware makers serve customers in multiple regions, making their behavior even less predictable. A common criticism of any new naming system is why companies don't just adopt a single, unified set of codenames. Huntley said that's impossible in practice. Every firm has a different view of each group, based on its own data and telemetry. "No one has perfect visibility," he said. "We are building our model and our best understanding, but we will never know everything about what's going on." By merging Google and Mandiant's schemes, the company has removed one of the many naming systems that researchers had to memorize. But the broader fragmentation remains, and the industry still relies on community-maintained lists to bridge the gaps. What's Next Google's new naming convention is already in effect, with the company's threat intelligence reports now using the updated monikers. Security teams worldwide will need to adjust their internal tracking systems and cross-reference old names with the new ones. The move may pressure othe