Ukraine

Country

Ukrainian Railways IT Services Outage After Cyberattack

March 23, 2025

On March 23 when the ukrainian rail company Ukrzaliznytsia notified passengers about a failure in its IT system. Passengers were advised to buy tickets on site or on trains. Valeriy Tkachev, deputy head of the commercial department of Ukrzaliznytsia, said the company needs “one or two weeks” to restore all services.

For a country at war where commercial aviation is prohibited, disruption on such a vital travel network threatened country-wide chaos. The railway in Ukraine these days transports everything from the military, the wounded, to the evacuation of the civilians, and international diplomats.

read more

Ukraine Claims Attack on Russian Center for Space Hydrometeorology

January 24, 2024

Pro-Ukraine hackers have reportedly breached a Russian scientific research center, Ukraine’s defense intelligence directorate (GUR) said. Ukrainian hacktivists claimed destruction of a critical state-run meterology institute essential to Russia’s aerospace industry and military.

While there is no independent confirmation of the damage to the supercomputers, it is likely the HVAC shutdown plus the destruction of data during war-time would have rendered such destruction permanent as trade embargoes prevent ordering new parts, system repair, and restoration.

According to GUR’s report on Wednesday, the hacker group called “BO Team” attacked the and destroyed its database and valuable equipment.

Planeta is a Russian state enterprise that receives and processes data from 11 domestic and 23 foreign Earth observation satellites, according to its website. This data is then used by other Russian state entities.

Ukraine’s intelligence claimed that hackers attacked the eastern branch of the organization, described as “the largest of the three.” The agency hasn’t responded to a request for a comment to confirm the attack.

read more

Ransomware Attack Causes Disruption To Ukrainian National Post Services

January 25, 2024

Ukrposhta is restoring the operation of IT systems after a significant technical failure. This was announced on the company’s Facebook page. “Our IT systems have experienced a significant technical failure. Our specialists are actively working to resolve the issue and restore full operation, but this may take some time,” the message says.

The attack was mostly mitigated but may have resulted in delivery delays and other issues.

read more

Broadcasting of Ukrainian TV Interrupted

March 28, 2024

One of Ukraine’s main media companies, 1+1 Media, said its satellite TV channels had suffered a cyberattack on Wednesday. It said in a statement that 39 channels, including some of its own, were currently unavailable. Ukraine’s 24 Channel said on its website that its satellite broadcast had also been affected as hackers “launched their propaganda”. “After two hours of the attack, the signal was restored, but the attack started again,” it said.

European provider SES that operates Astra told Reuters a few dozen video distributors in Europe faced outages caused by “external radio frequency interference” on Wednesday. It added that satellites were safe.

read more

Ukrainian Railway Company Ukrzaliznytsia Hit by Cyberattack

December 13, 2016

On December 13, 2016, the Ukrainian railway company, Ukrzaliznytsia, announced it had been targeted by a cyberattack that affected its online ticketing system, causing delays in ticket purchases and train scheduling. The attack not only impacted the railway system but also had broader consequences for the country’s economy, as the rail network plays a vital role in transporting goods and people throughout Ukraine.

The group behind the attack, known as “Sandworm,” was later identified as a state-sponsored hacking group with links to the Russian government.

read more

Malware caused Ukranian Energy Company to Disconnect Heating Services

January 22, 2024

Russian-linked malware was used in a January 2024 cyberattack to cut off the heating of over 600 apartment buildings in Lviv, Ukraine, for two days during sub-zero temperatures. The attack forced district heating company Lvivteploenergo to disconnect heating services on January 23, impacting over 100,000 people across Lviv’s Sykhiv residential area.

An investigation into the January 2024 cyberattack in Lviv showed that the attackers may have entered Lvivteploenergo’s network almost a year earlier, on 17 April 2023, by exploiting an unidentified vulnerability in an Internet-exposed Mikrotik router. Three days later, they deployed a webshell that allowed them to maintain access and helped them connect to the breached network in November and December to steal user credentials from the Security Account Manager (SAM) registry hive. On the day of the attack, the attackers used L2TP (Layer Two Tunnelling Protocol) connections from Moscow-based IP addresses to access the district energy company’s network assets.

FrostyGoop, the Windows malware used in this attack, is designed to target industrial control system (ICS) using the Modbus TCP communications, a standard ICS protocol across all industrial sectors.

read more

Ukranian Oil and Gas Company Naftogaz Hit by Cyberattack

January 25, 2024

State-owned critical infrastructure companies in Ukraine fell victim to cyberattacks on Thursday, with the largest oil and gas company, Naftogaz, being among the targets. The cyber assailants targeted Naftogaz’s data center, leading to the complete inactivity of the company’s website and call centers.

As of the latest update, specialists from Naftogaz are actively working to resolve the incident, promising further comments on the nature of the attack. Naftogaz, a cornerstone of Ukraine’s energy industry employing 100,000 people and supplying gas to over 12 million households, faces a critical situation, and the motive and identity of the attackers remain unclear.

read more

Attack on Kyiv Power Substation Shut Down Remote Terminals

December 17, 2016

The attack on the Pivnichna transmission facility shut down the remote terminal units that control circuit breakers. Oleksii Yasynskyi, head of research for Information Systems Security Partners in Ukraine, said the attackers belonged to several different groups that worked together. Among other things, they gathered passwords for targeted servers and workstations and created custom malware for their targets. Sandworm suspected in deploying Industroyer (also: CrashOverride) malware, by exploiting a vulnerability in Siemens SIPROTEC relays.

The hack was less severe than the one used in the 2015 attack, which rendered the devices inoperable and prevented engineers from remotely restoring power.

read more

Targeted Cyberattack on Ukranian Critical Energy Infrastructure Facility

September 5, 2023

The Computer Emergency Response Team of Ukraine (CERT-UA) recorded on Tuesday a targeted cyber attack against a critical energy infrastructure facility in the country. The advisory added that the described activity is carried out by the Russian state-sponsored APT28 hacker group. The agency confirmed that they were able to prevent any intrusion.

read more