Home
Home

ICT

Information & communication

219
cyberattacks and operations

In the Russian-Ukraine war, why do cyberattacks on the ICT sector matter?

Information and Communication Technology is a key enabler across all sectors, for the digital economy, for media platforms and potentially a path to attack organizations and other sectors. The deliberate destruction of TV and radio broadcasting infrastructure in Ukraine have been documented as a result of physical attacks on infrastructure; cyberattacks on telecommunication providers have also been documented. These attacks are being used as a means to disrupt access to reliable information relating to developments in the war and the situation in Ukraine.

What types of attacks have been documented against the sector?

Which countries have seen attacks on the sector in the context of the war?

+
-

What impact do these attacks have on people?

Cyberattacks on telecommunications and internet service providers have a direct impact on people. Targeting these services on the day of the invasion and in the ongoing conflict has an impact on civilians who depend on their services in order to stay informed, contact loved ones, seek medical support, access online services, coordinate rescue efforts and much more. Targeting telecommunications networks adds to the confusion and fog of war and the impact for civilians is accentuated during hostilities.

You've been the target of a cyberattack?Share details

What are the primary digital impacts observed on the sector by country?

Can history shed light on the impact of attacks on this sector?

24 February 2022 – Viasat, Ukraine (impact felt in other European countries)

On the day of the invasion a cyberattack disrupted broadband satellite internet access. It disabled modems that communicate with Viasat Inc's KA-SAT satellite network, which supplies internet access to tens of thousands of people in Ukraine and Europe. More than two weeks later some remained offline.

Viasat in a later statement said they believed the purpose of the attack was to interrupt services rather than to access data or systems.

Societal harm/impact:

  • Internet access offline for more than 2 weeks.
  • Nearly 9,000 subscribers of a satellite internet service provider were deprived of the internet in France.
  • Around a third of 40,000 subscribers of another satellite internet service provider in Europe (Germany, France, Hungary, Greece, Italy, Poland) were affected.
  • A major German energy company lost the remote monitoring access to over 5,800 wind turbines which was deactivated during the attack.
  • Affected several thousand customers located in Ukraine and tens of thousands of other fixed broadband customers across Europe.
To find out more about the cyberattack on Viasatsee the Case Study

Which threat actors have been linked to attacks on the sector during the conflict?

Name
Type
Origin
Number of attacks
NoName057(16)Collective
RU
50
People's CyberArmyCollective
RU
38
IT Army of UkraineNation State
UA
21
Anonymous RussiaCollective
RU
14
MiraiCollective
RU
9
Netside GroupCollective
Unknown
7
KillNetCollective
RU
6
BloodnetCollective
Unknown
6
AnonymousCollective
Unknown
5
Anonymous SudanCollective
unknown
4
Anonymous ItaliaCollective
Unknown
3
Cyber CatCollective
Unknown
3
SandwormNation State
RU
3
NLBUnknown
Unknown
2
APT28Nation State
RU
2
GURMONation State
UA
2
DEV-0586Nation State
RU
1
UNC1151Nation State
BY
1
Nation State - Russian FederationNation State
RU
1
StudentCyberArmyCollective
UA
1
GhostSecCollective
US
1
NB65Collective
Unknown
1
TurlaNation State
RU
1
ZaryaCollective
RU
1
HaydamakiCollective
UA
1
2402teamCollective
Unknown
1
National Republican ArmyCollective
RU
1
XakNetCollective
RU
1
Russian Hackers TeamCollective
Unknown
1
National Hackers of Russia (HXP)Collective
Unknown
1
Bear IT ArmyCollective
RU
1
PhoenixCollective
UA
1
Russian ClayCollective
Unknown
1
Cyber Anarchy SquadCollective
Unknown
1
UAC-0102Unknown
Unknown
1
BlueNet RussiaUnknown
Unknown
1
Net Worker AllianceCollective
Unknown
1
Hdr0Unknown
Unknown
1
UAC-0165Unknown
Unknown
1
Glory to Russia 666Unknown
Unknown
1
Zulik GroupUnknown
Unknown
1
Hustle BrosUnknown
Unknown
1
SolntsepekCollective
Unknown
0
Explore and filter attacks on a mapGeopolitical map

Explore the data

Search anything
Browse the table
1 / 22
Event Name
Event Country
Event Date
Event Type
Impact Category
Impact Description
Threat Actor Name
Campaign: DDoS attacks against the websites of two Lithuanian ISPs
Lithuania
2023-12-30
DDoSDisruptionDisrupted connectivity to websites.NoName057(16)
Campaign: DDoS attacks against the website of a Lithuanian ISP and the website and subdomain of another ISP
Lithuania
2023-12-26
DDoSDisruptionDisrupted connectivity to websites.NoName057(16)
DDoS attack against an Italian software developing company
Italy
2023-12-24
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
Campaign: DDoS attack against an Italian software developing company
Italy
2023-12-21
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
DDoS attack against the Internet resources and server infrastructure of a Russian ISP
Russian Federation
2023-12-16
DDoSDisruptionDisrupted Internet access services.IT Army of Ukraine
DDoS attack against the website of a Czech telecommunications company
Czech Republic
2023-12-16
DDoSDisruptionDisrupted connectivity to website.Anonymous Russia
DDoS attacks against the website and subdomain of a Ukrainian ISP
Ukraine
2023-12-15
DDoSDisruptionDisrupted connectivity to the website. People's CyberArmy
Campaign: DDoS attack against the subdomain of a Ukrainian online authorization system
Ukraine
2023-12-12
DDoSDisruptionDisrupted connectivity to the website. NoName057(16)
Malware cyberattack against a Russian IT company
Russian Federation
2023-12-12
WiperDestructionAll servers were infected with malware resulting in the deletion of the entire system database, back ups and configuration files ensuring the functioning of the system.GURMO
Cyberattack against a Ukrainian telecommunications company
Ukraine
2023-12-12
UnknownDestructionThe cyberattack against the target's core network began around 5 a.m. The threat actor was successful in destroying some of the core network's functions leading to the disruption of internet and mobile services, lasting two days. 24 million users affected by the cyberattack, along with the disruption of air raid sirens, banks, ATMs and point-of-sale terminals.Sandworm
Donate