Current:Home > NewsUkraine says government websites and banks were hit with denial of service attack -RiskWatch
Ukraine says government websites and banks were hit with denial of service attack
View
Date:2025-04-15 15:46:15
WASHINGTON — Amid heightened tensions between Russia and Ukraine, multiple Ukrainian government websites and banking systems were temporarily inaccessible to users Tuesday afternoon. But so far it remains unclear who was behind the disruption, and the overall intent.
The outage, which impacted the website of the Ukrainian Defense Ministry and the Armed Services as well as two large Ukrainian banks, Privatbank and Oschadbank, was the result of a digital denial of service attack, according to multiple Ukrainian government agencies.
The reports quickly generated concern, especially given ongoing U.S. government warnings that Russia might launch a massive cyberattack impacting critical infrastructure in Ukraine, such as communications or banking, prior to an invasion.
Digital attackers targeted the organizations' online services to prevent them from functioning properly, but the intrusion fell well short of any kind of massive cyberattack – which would typically involve visible manipulation of content on the websites, penetration of servers, or apparent theft or destruction of data or devices.
The Defense Ministry shared in a tweet that it received an unusually high volume of requests to load the website, suggesting attackers were flooding the servers with illegitimate requests in an attempt to overload them and prevent citizens from accessing the site.
The State Service of Special Communication and Information Protection of Ukraine, which was leading a recent investigation into a website defacement and data destruction campaign linked to Russian hackers last month, published a statement claiming "there is a powerful DDoS attack on a number of information resources of Ukraine," though it also noted that as of Tuesday evening, banking services have already been restored.
Wave of fake messages saying ATMs were down is debunked
There were also reports from the Ukrainian Cyber Police on Tuesday morning debunking a wave of fake SMS messages sent to Ukrainian citizens claiming ATM services were down.
Given that only a few organizations experienced disruptions and the outages were not long-lasting, the impact on Ukrainians' access to their banks and government websites seemed extremely limited. People in Ukraine posted tweets about still being able to access their bank accounts through ATMs, or by using their digital bank cards, and the government agencies were able to communicate with the world through social media during the outage.
But given the heightened tensions in the region and the looming threat of a Russian invasion, these kinds of attacks could have a bigger psychological impact.
Olena Prokopenko, a visiting fellow for the public policy think tank the German Marshall Fund and the co-founder of the Transatlantic Task Force on Ukraine, told NPR these kinds of digital attacks "have been our major concern" over the past few hours. "Hybrid warfare in action," she continued.
For the people of Ukraine, she said, there's some uncertainty because the government has not been communicating clearly about what to do in an emergency.
"People don't understand what to do in case of escalation, so they just choose to carry on, hoping that the military and the government will take care of things," Prokopenko said.
This attack, while rather unsophisticated and short-lived, could be one of the early salvos in a Russian invasion, though it hasn't yet been linked directly to Russia.
DDoS attacks are 'notoriously difficult to attribute'
"Though we've anticipated disruptive Russian attacks against Ukraine, we've seen no evidence of responsibility at this time, and denial of service attacks are notoriously difficult to attribute," said John Hultquist, the vice president of intelligence analysis for the cybersecurity firm Mandiant.
Ukrainian citizens, however, have become used to regular digital attacks from Russia since at least 2014, often much more serious ones, including shutting off the power grid.
John Graham-Cumming, the Chief Technology Officer of Cloudflare, a company that specializes in defending against denial of service attacks, told NPR that his company has actually not seen a huge uptick in malicious traffic on Tuesday that has impacted its customers in Ukraine. The websites and banks impacted, however, are not Cloudflare customers, he said, and Graham-Cumming said it's possible attackers chose to avoid organizations protected by Cloudflare purposely.
Graham-Cumming noted a small uptick in broader attack traffic around lunchtime, but nothing "particularly noteworthy," as well as an increase in digital congestion across the Internet in Ukraine around midday, potentially suggesting an increase in internet searches.
Cybersecurity company Akamai also specializes in defending against denial of service attacks, though it had limited visibility into the attacks in Ukraine on Tuesday. Still, according to Akamai's Chief Security Officer, Boaz Gelbord, "In times of international conflict, DDoS is often the attack tool of choice of threat actors."
veryGood! (279)
Related
- New Mexico governor seeks funding to recycle fracking water, expand preschool, treat mental health
- New Jersey denies bulkhead for shore town with wrecked sand dunes
- After Washington state lawsuit, Providence health system erases or refunds $158M in medical bills
- Woman's murder in Colorado finally solved — after nearly half a century
- Meet the volunteers risking their lives to deliver Christmas gifts to children in Haiti
- South Carolina to provide free gun training classes under open carry bill passed by state Senate
- FedEx driver who dumped $40,000 worth of packages before holidays order to pay $805 for theft
- Middle school workers win $1 million Powerball prize after using same numbers for years
- Retirement planning: 3 crucial moves everyone should make before 2025
- The 'Harvard of Christian schools' slams Fox News op/ed calling the college 'woke'
Ranking
- The 401(k) millionaires club keeps growing. We'll tell you how to join.
- The Best Waterproof Shoes That Will Keep You Dry & Warm While Elevating Your Style
- No quick relief: Why Fed rate cuts won't make borrowing easier anytime soon
- Georgia Senate passes sports betting bill, but odds dim with as constitutional amendment required
- Working Well: When holidays present rude customers, taking breaks and the high road preserve peace
- Think the news industry was struggling already? The dawn of 2024 is offering few good tidings
- OxyContin marketer agrees to pay $350M rather than face lawsuits
- Reports: Commanders name former Cowboys defensive coordinator, Dan Quinn, new head coach
Recommendation
Bill Belichick's salary at North Carolina: School releases football coach's contract details
Alec Baldwin Pleads Not Guilty to Involuntary Manslaughter in Rust Shooting Case
Maine man who fled to Mexico after hit-and-run killing sentenced to 48 years
Gisele Bündchen pays tribute to her late mother: You were an angel on earth
Jamie Foxx reps say actor was hit in face by a glass at birthday dinner, needed stitches
Sen. Tom Cotton repeatedly grills Singaporean TikTok CEO if he's a Chinese Communist
No quick relief: Why Fed rate cuts won't make borrowing easier anytime soon
Bruce Springsteen’s mother Adele Springsteen, a fan favorite who danced at his shows, dies at 98