Home
Home

Financial

Financial and insurance activities

356
cyberattacks and operations

In the Russian-Ukraine war, why do cyberattacks on the Financial sector matter?

The financial services sector is vital for the functioning of society. A number of factors are contributing to the heightened risk of cyberattacks against the financial sector as a result of the conflict. Banks and financial institutions have been on high alert relating to a fear of an increase in cyberattacks following the sanctions imposed on Russia by Western nations. The sanctions have resulted in a number of Russian and Belarusian organizations being banned from the global payments messaging system Swift used by financial institutions, a system pivotal for the banking network, the transfer of money across borders and to access to funds. This disconnects Russian and Belarusian companies ability to operate globally, adds delays and costs, and cuts off revenues.

DDoS attacks against financial institutions in Ukraine have been reported during the invasion. There have also been a number of hack and leak attacks on banks from Russian which have raised concerns relating to data protection issues as gigabytes (GB) of data are published online often containing the personal information of individuals.

What types of attacks have been documented against the sector?

Which countries have seen attacks on the sector in the context of the war?

+
-

What impact do these attacks have on people?

Disruptive cyberattacks on banks can impact customers directly with issues to access services such as online payments, banking apps and access to ATMs. Limiting the civilian population's access to money during the invasion and in the ongoing conflict is particularly distressing for individuals who seek to retrieve their financial assets in order to buy provisions, make logistical arrangements and to protect themselves and their communities from harm.

On the other hand, hack and leak attacks leading to large volumes of data published online can have repercussions on individuals whose personal information is exposed putting them at risk from digital or physical attacks by actors seeking to exploit this information.

You've been the target of a cyberattack?Share details

What are the primary digital impacts observed on the sector by country?

Can history shed light on the impact of attacks on this sector?

23 March 2022 - Central Bank of Russia, the Russian Federation

A threat actor claims to have breached the Central Bark of Russia and leaked 28GB worth of data which it made available for public download. These roughly 35,000 files contain some of the regulator’s “secret agreements” and may contain hundreds of audit reports and information on bank owners.

Societal harm/impact:

  • Theft of 35,000 files and leak of 28GB worth of data which is now available for public download.
  • This information is likely to contain personal and sensitive information.

Which threat actors have been linked to attacks on the sector during the conflict?

Name
Type
Origin
Number of attacks
NoName057(16)Collective
RU
185
People's CyberArmyCollective
RU
22
IT Army of UkraineNation State
UA
19
Anonymous RussiaCollective
RU
17
KillNetCollective
RU
13
Anonymous ItaliaCollective
Unknown
11
MiraiCollective
RU
10
AnonymousCollective
Unknown
8
Netside GroupCollective
Unknown
6
Russian Hackers CommunityCollective
Unknown
5
Kvazar DDoSCollective
Unknown
5
Net Worker AllianceCollective
Unknown
5
Zulik GroupUnknown
Unknown
5
PhoenixCollective
UA
4
Anonymous SudanCollective
unknown
3
National Hackers of Russia (HXP)Collective
Unknown
3
BloodnetCollective
Unknown
3
Nation State - Russian FederationNation State
RU
2
NB65Collective
Unknown
2
Legion Cyber SpetsnazCollective
RU
2
Ukrainian Cyber AllianceUnknown
Unknown
2
SandwormNation State
RU
1
The Black Rabbit WorldCollective
Unknown
1
Russian ClayCollective
Unknown
1
ChaosSecCollective
Unknown
1
UserSecCollective
Unknown
1
Web InvadersUnknown
Unknown
1
SpyeEye BotnetUnknown
Unknown
1
UAC-0006Unknown
Unknown
1
NLBUnknown
Unknown
1
KiborgUnknown
Unknown
0
Explore and filter attacks on a mapGeopolitical map

Explore the data

Search anything
Browse the table
1 / 36
Event Name
Event Country
Event Date
Event Type
Impact Category
Impact Description
Threat Actor Name
Campaign: DDoS attack against a credit insurance company
Czech Republic
2023-12-31
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
Campaign: DDoS attack against the website of a money and pension service
United Kingdom
2023-12-31
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
DDoS attack against the subdomain of a Ukrainian bank
Ukraine
2023-12-29
DDoSDisruptionDisrupted connectivity to the website. People's CyberArmy
Campaign: DDoS attacks against the websites of two Finnish banks
Finland
2023-12-29
DDoSDisruptionDisrupted connectivity to websites. Websites unavailable to foreign IP addresses.NoName057(16)
DDoS attack against the website of a Ukrainian state property fund
Ukraine
2023-12-28
DDoSDisruptionDisrupted connectivity to the website. People's CyberArmy
Campaign: DDoS attack against the website of a money and pension service
United Kingdom
2023-12-28
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
Campaign: DDoS attacks against a credit insurance company and a commodity exchange
Czech Republic
2023-12-27
DDoSDisruptionDisrupted connectivity to websites.NoName057(16)
Campaign: DDoS attack against the website of a Dutch bank
Netherlands
2023-12-25
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
DDoS attack against the website of a Ukrainian bank
Ukraine
2023-12-24
DDoSDisruptionDisrupted connectivity to the website. People's CyberArmy
Campaign: DDoS attack against the website of an Austrian holding company
Austria
2023-12-23
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
Donate