Russia

Country

Large Scale DDoS Attack at Large Russian Telecoms MegaFon

January 24, 2025

A significant cyberattack hit MegaFon, one of Russia’s largest mobile and internet operators. The failure in Megafon’s operation occurred on the morning of January 24. The cause was a carpet DDoS attack on the mobile operator. Forbes reports the attack was carried out by one of the groups of “politically motivated hackers” (the IT army of Ukraine). The attack “was effective, and degradation of services was observed at the international level.”

Later the Russian media revealed the true cause of the disruptions – a highly effective “carpet-bombing DDoS attack” targeting MegaFon. While the company claimed its network was operating “smoothly,” it admitted to “possible access issues” caused by factors beyond its control.

read more

DDoS Attack at Russian Telecom Beeline

February 26, 2025

Beeline experienced a failure due to a DDoS attack. About 6,000 users complained about the problems on Downdetector. “Specialists are taking all necessary measures to minimize possible consequences and maintain stable operation of services,” the operator’s press service said.

read more

Rostelecom Investigates Data Leak

January 21, 2025

Rostelecom, a major Russian telecommunications provider, says it’s investigating a cyberattack on one of its contractors. A hacker group calling itself Silent Crow, earlier released a batch of allegedly stolen company data. The company admitted it had previously detected “information security incidents” at one of its contractors. According to Rostelecom, the unnamed contractor is responsible for maintaining its corporate website and procurement portal. Both were reportedly targeted by hackers.

read more

DDoS Attack on Russian Telecom Beeline Causes Outages

March 3, 2025

Some Russians had their internet disrupted on Monday due to a targeted distributed denial-of-service (DDoS) attack on the telecom Beeline — the second major attack on the Moscow-based company in recent weeks. Beeline confirmed the attack to local media following reports from several outage-tracking services and user complaints. The provider has more than 44 million subscribers.

Data from the internet monitoring service Downdetector indicates that most Beeline users in Russia faced difficulties accessing the company’s mobile app, while some also reported website outages, notification failures and internet disruptions.

Russia’s communications watchdog, Roskomnadzor, reported that subscribers in Moscow and surrounding regions had filed mass complaints over connectivity issues following Monday’s incident.

read more

Free Parking for Russian City Residents after Alleged Cyberattack

October 31, 2024

Residents of the northwestern Russian city of Tver were able to park for free for nearly two days due to what local authorities referred to as a “technical failure” in the digital parking payment system. Ukrainian Cyber Alliance claims the cyberattack on the city’s administrative network.

read more

Cyberattack Destroys Infrastructure of Russian Internet Provider Nodex

January 7, 2025

Russian internet provider Nodex’s network was destroyed in a cyberattack claimed by the Ukrainian Cyber Alliance. The attack resulted in significant service disruptions and data theft. Nodex confirmed the attack and began working on restoring services. The Ukrainian Cyber Alliance shared screenshots of hacked systems and data they allegedly stole.

read more

ICS Malware Fuxnet Disrupts Russian Infrastructure

April 9, 2024

ICS malware Fuxnet allegedly used by Ukrainian Blackjack group to disrupt industrial sensors and other systems belonging to a Moscow infrastructure firm.

BlackJack claimed to have significantly impacted Moscollector’s IOT sensor gateway network deployed throughout underground utility corridors, providing telecommunications, district heating, water, and sewage services throughout Moscow. Claroty analyzed a Fuxnet malware sample from the attack adding credibility to BlackJack’s claims. Fuxnet has the capability of sending spurious commands over RS-485/MBus protocols and bricking sensor gateways by destroying their flash memory chips.

read more

Cyberattack Disrupts Operations at Russian State Media Company VGTRK

October 7, 2024

Russian state television and radio broadcasting company VGTRK was hit by a cyberattack on Monday. The company confirmed in a statement to local news agencies that its operations were disrupted due to the attack.

Local media reported that the broadcast of several television channels owned by VGTRK, including Russia 1 and Russia 24, was cut off mid-program and resumed nearly an hour later. An anonymous source at the company told the Russian media outlet Gazeta.ru that the hackers erased data from the company’s servers, including backups. This was not independently verified.

read more

DDoS Attack on Gazprombank Affects Customers

December 6, 2024

Russian users have reported difficulties accessing services at Gazprombank, one of the country’s largest privately owned banks, following an alleged cyberattack by Ukraine’s military intelligence agency.

Data from several website outage tracking services indicates that Gazprombank customers have complained about being unable to make transactions or pay bills through the bank’s app or website. Earlier this week, Ukraine’s military intelligence agency (HUR) claimed responsibility for launching a powerful distributed denial-of-service (DDoS) attack on Gazprombank, disrupting its online and mobile banking services.

read more

End of Year Cyberattack at Russian Oil Company Lukoil

December 30, 2024

Cyber specialists of Ukraine’s Main Intelligence Directorate (HUR) carried out a cyberattack on Russian oil company Lukoil. The attack compromised the company’s digital resources. Customers were unable to make payments at gas stations via the mobile app. In addition the DDOS attack caused disruptions and financial losses across the retail sector due to payment system failures.

read more