Home
Home

Public administration

Public administration and defence; compulsory social security

875
cyberattacks and operations

In the Russian-Ukraine war, why do cyberattacks on the Public administration sector matter?

Cyberattacks on the public administration sector threaten e-government activities, the protection of sensitive government and personal data, as well as the functioning of services. Public administration in Ukraine, Russia and in other countries has been the target of cyberattacks linked to the conflict. Due to the sector’s direct connection with government entities the sector has been a specific target of disruptive attacks in Ukraine in the lead up to the invasion and in the ongoing conflict. On the other hand, government institutions in Russia have also been subject to various types of attacks. The conflict has also seen disruptive attacks impacting public administration and the government websites of countries who have demonstrated support to Ukraine through the application of sanctions and/or the supply of military aid.

What types of attacks have been documented against the sector?

Which countries have seen attacks on the sector in the context of the war?

+
-

What impact do these attacks have on people?

Attacks on the public administration including national and local government institutions have an impact on the civilian population both through the impact on access to key public services such as health, social services, migration, education, and for timely and reliable information. Cyberattacks during the conflict have played a role in trying to undermine trust and confidence in state institutions and trying to control the information space, through the spread of disinformation and propaganda, based on geopolitical objectives.

You've been the target of a cyberattack?Share details

What are the primary digital impacts observed on the sector by country?

Can history shed light on the impact of attacks on this sector?

21 April 2022 – government websites, Estonia

DDoS cyberattacks temporarily disrupted and blocked access to thirteen Estonian government websites. Targeted websites included the president's (president.ee), Ministry of Foreign Affairs (vm.ee), Police and Border Guard Board (politsei.ee), digital state services portal (eesti.ee) and ID card information page (id.ee).

Societal harm/impact

  • The attacks started around 4 pm on Thursday and lasted for several hours disrupting and blocking access to key websites. The campaign of attacks ended on the following Monday.
  • A total of 13 websites were targeted, though in many cases regular users of the sites would have been unaware at the time of the onslaught, thanks to counter-measures. In a few cases, reconfiguration meant that sites were temporarily down, though these were only isolated and relatively short-lived outages.
  • Over two billion malicious queries were issued to the state sites and those of state agencies and state-owned firms, with up to 11,000 malicious queries per regular, non-hostile query, at the peak of the attack.

Which threat actors have been linked to attacks on the sector during the conflict?

Name
Type
Origin
Number of attacks
NoName057(16)Collective
RU
455
People's CyberArmyCollective
RU
79
KillNetCollective
RU
28
Anonymous RussiaCollective
RU
28
PhoenixCollective
UA
19
Netside GroupCollective
Unknown
16
BloodnetCollective
Unknown
16
Zulik GroupUnknown
Unknown
15
AnonymousCollective
Unknown
12
Russian Hackers TeamCollective
Unknown
11
National Hackers of Russia (HXP)Collective
Unknown
11
IT Army of UkraineNation State
UA
10
TA499Unknown
unknown
7
Net Worker AllianceCollective
Unknown
7
XakNetCollective
RU
6
Anonymous SudanCollective
unknown
6
DEV-0586Nation State
RU
4
Russian Hackers CommunityCollective
Unknown
4
UNC1151Nation State
BY
4
APT28Nation State
RU
4
SandwormNation State
RU
3
GamaredonNation State
RU
3
ChaosSecCollective
Unknown
3
BlueNet RussiaUnknown
Unknown
3
Kvazar DDoSCollective
Unknown
3
Nation State - Russian FederationNation State
RU
2
NB65Collective
Unknown
2
v0g3lSecCollective
Unknown
2
TA416Nation State
CN
2
Legion Cyber SpetsnazCollective
RU
2
APT37Nation State
NK
2
ZaryaCollective
RU
2
KillNet CollectiveCollective
Russian Federation
2
MiraiCollective
RU
2
Russian ClayCollective
Unknown
2
Cyber CatCollective
Unknown
2
APT29Nation State
RU
2
SolntsepekCollective
Unknown
2
Web InvadersUnknown
Unknown
2
SpyeEye BotnetUnknown
Unknown
2
KillMilkIndividual
RU
2
Anonymous ItaliaCollective
Unknown
2
UAC-0050Unknown
Unknown
2
GURMONation State
UA
2
AgainstTheWestCollective
Unknown
1
GhostSecCollective
US
1
VerminCollective
UA
1
InvisiMoleNation State
RU
1
UAC-0094Unknown
Unknown
1
The Black Rabbit WorldCollective
Unknown
1
UAC-0098Unknown
RU
1
Anonymous-DepaixPorteurCollective
Unknown
1
Anonymous-Spid3rCollective
Unknown
1
UAC-0099Unknown
Unknown
1
RaHDItCollective
RU
1
HaydamakiCollective
UA
1
StudentCyberArmyCollective
UA
1
Red StingerUnknown
Unknown
1
UAC-0132Unknown
Unknown
1
Cyber PartisansCollective
BY
1
UNC4166Unknown
Unknown
1
Bear IT ArmyCollective
RU
1
UAC-0063Unknown
Unknown
1
UAC-0165Unknown
Unknown
1
RomComUnknown
Unknown
1
Structura National TechnologiesNation State
Unknown
1
UserSecCollective
Unknown
1
Sudo RM -RFUnknown
Unknown
1
Cyber ResistanceCollective
Unknown
1
NLBUnknown
Unknown
1
BlackjackUnknown
Unknown
1
APT10Nation State
CN
0
Infinity Hackers BYCollective
Belarus
0
Social Digital AgencyNation State
Unknown
0
Explore and filter attacks on a mapGeopolitical map

Explore the data

Search anything
Browse the table
1 / 88
Event Name
Event Country
Event Date
Event Type
Impact Category
Impact Description
Threat Actor Name
DDoS attack against the website of a Ukrainian government ministry
Ukraine
2023-12-31
DDoSDisruptionDisrupted connectivity to the website. Anonymous Russia
Campaign: DDoS attacks against the websites of a Czech ministry and a government chamber
Czech Republic
2023-12-31
DDoSDisruptionDisrupted connectivity to websites. Website unavailable to foreign IP addresses.NoName057(16)
Campaign: DDoS attacks against the websites of a British town council and a city council
United Kingdom
2023-12-31
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
Campaign: DDoS attack against the subdomain of a Dutch government service
Netherlands
2023-12-30
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
Campaign: DDoS attack against the website of a Finnish commerce chamber
Finland
2023-12-29
DDoSDisruptionDisrupted connectivity to website. Website unavailable to foreign IP addresses.NoName057(16)
Campaign: DDoS attacks against the websites of a British town council, a city council and a judicial platform
United Kingdom
2023-12-28
DDoSDisruptionDisrupted connectivity to websites.NoName057(16)
Campaign: DDoS attacks against the websites of a Czech ministry, a government office and a government chamber
Czech Republic
2023-12-27
DDoSDisruptionDisrupted connectivity to websites.NoName057(16)
Campaign: DDoS attack against the subdomain of a Dutch government service
Netherlands
2023-12-25
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
Campaign: DDoS attack against the official website of a Swedish government agency
Sweden
2023-12-24
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
Campaign: DDoS attacks against the websites of a British councils
United Kingdom
2023-12-23
DDoSDisruptionDisrupted connectivity to websites.NoName057(16)
Donate