Home
Home

Transportation

Transportation and storage

525
cyberattacks and operations

In the Russian-Ukraine war, why do cyberattacks on the Transportation sector matter?

Cyberattacks on the transportation sector may disrupt or shut down entire systems and/or services, including transport booking systems (e.g. airlines and railways), expose or block access to sensitive data, compromise safety of staff and passengers, and impact supply chains across all sectors (e.g. medical, agriculture, mining, trade). Disruptive attacks such as DDoS on transportation service providers such as railways or airports in different countries have been documented during the conflict. In addition to this, so called hacktivist collectives, acting in the name of activism, are also targeting transportation providers linked to the mining/oil industry by compromising their systems, exfiltrating data and publishing it online.

What types of attacks have been documented against the sector?

Which countries have seen attacks on the sector in the context of the war?

+
-

What impact do these attacks have on people?

Cyberattacks on transportation and storage providers can compromise people’s safety, disrupt their access to emergency and passenger services, ( and expose highly sensitive data on individuals or organizations. Such attacks have the potential for accidents, mass chaos, and injuries or loss of life.

You've been the target of a cyberattack?Share details

What are the primary digital impacts observed on the sector by country?

Can history shed light on the impact of attacks on this sector?

19-20 April 2022 - National railways and airports, Czechia

Czech websites came under DDoS attack, including České dráhy (Czech railways) and some regional and international airports.

Societal harm/impact:

  • Czech Railways tackled an outage on the Můj vlak (My train) mobile application for over 24 hours. Buying tickets online did not work and there were also problems finding connections.
  • The attack on Pardubice Airport caused failure of the entire web system and the website no longer worked.

An unrelated ransomware attack on 23 March 2022 on IT systems belonging to Italian State Railways demonstrates, although in this case unrelated to the war against Ukraine, the impacts on people as a result of cyberattacks:

  • the disruption of ticket sales at stations,
  • the malfunction of passenger information screens,
  • the disruption of applications used by railway staff through tablets,
  • the suspension of all rail freight thus impacting shipments.

Which threat actors have been linked to attacks on the sector during the conflict?

Name
Type
Origin
Number of attacks
NoName057(16)Collective
RU
355
KillNetCollective
RU
22
Anonymous RussiaCollective
RU
21
People's CyberArmyCollective
RU
17
Anonymous ItaliaCollective
Unknown
15
Net Worker AllianceCollective
Unknown
11
BlueNet RussiaUnknown
Unknown
9
Netside GroupCollective
Unknown
8
BloodnetCollective
Unknown
8
UserSecCollective
Unknown
7
Kvazar DDoSCollective
Unknown
6
Russian Hackers TeamCollective
Unknown
5
Russian Hackers CommunityCollective
Unknown
4
SandwormNation State
RU
3
Anonymous SudanCollective
unknown
3
National Hackers of Russia (HXP)Collective
Unknown
3
Cyber CatCollective
Unknown
2
IT Army of UkraineNation State
UA
2
Legion Cyber SpetsnazCollective
RU
2
Cyber PartisansCollective
BY
1
GhostSecCollective
US
1
AnonymousCollective
Unknown
1
Red StingerUnknown
Unknown
1
AlTahreaCollective
IQ
1
MiraiCollective
RU
1
StudentCyberArmyCollective
UA
1
Furious Russian HackersUnknown
Unknown
1
ChaosSecCollective
Unknown
1
KillMilkIndividual
RU
1
Cyber DDoSCollective
Unknown
1
RuBitUnknown
Unknown
1
Zulik GroupUnknown
Unknown
1
Explore and filter attacks on a mapGeopolitical map

Explore the data

Search anything
Browse the table
1 / 53
Event Name
Event Country
Event Date
Event Type
Impact Category
Impact Description
Threat Actor Name
Campaign: DDoS attack against the subdomain of a British local public transportation operator
United Kingdom
2023-12-31
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
Campaign: DDoS attack against the website of a Dutch bike rental agency and a local public transportation operator
Netherlands
2023-12-30
DDoSDisruptionDisrupted connectivity to websites.NoName057(16)
Campaign: DDoS attacks against the website of a British local public transportation operator and the subdomain of another local public transportation operator
United Kingdom
2023-12-28
DDoSDisruptionDisrupted connectivity to websites.NoName057(16)
Campaign: DDoS attack against the website of a Dutch bike rental agency and a local public transportation operator
Netherlands
2023-12-25
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
Campaign: DDoS attacks against the website of a Swedish local public transportation operator and the website and subdomain of another local public transportation operator
Sweden
2023-12-24
DDoSDisruptionDisrupted connectivity to websites.NoName057(16)
Campaign: DDoS attack against the website of a British local public transportation operator
United Kingdom
2023-12-23
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
DDoS attack against the website of a Swiss railway company
Switzerland
2023-12-22
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
Campaign: DDoS attack against the website of a Finnish cruise company
Finland
2023-12-22
DDoSDisruptionDisrupted connectivity to website.NoName057(16)
Campaign: DDoS attacks against the websites of two Italian public transportation operators
Italy
2023-12-21
DDoSDisruptionDisrupted connectivity to websites.NoName057(16)
Campaign: DDoS attacks against the website of a Swedish local public transportation operator and the website and subdomain of another local public transportation operator
Sweden
2023-12-20
DDoSDisruptionDisrupted connectivity to websites.NoName057(16)
Donate