Ukraine has faced significant cyber attacks following recent acts of aggression from Russia.
The public-facing arm of the spy agency GCHQ has encouraged UK organizations to read new guidance published on its website entitled: “Actions to take when the cyber threat is heightened.”
Paul Chichester, director of operations at the National Cyber Security Centre (NCSC), said: “While we are unaware of any specific cyber threats to UK organizations in relation to events in Ukraine, we are monitoring the situation closely and it is vital that organizations follow the guidance to ensure they are resilient.
“Over several years, we have observed a pattern of malicious Russian behavior in cyber space. Last week’s incidents in Ukraine bear the hallmarks of similar Russian activity we have observed before.”
Officials from the NCSC are “urgently” helping the Ukrainian government investigate the attack and discover who was behind it.
70 Ukrainian websites were targeted and brought offline on the 14 of January, including several key government websites.
By midday most of these websites were brought back online, with the attacks now being considered an act of shock and fearmongering rather than an attempt to gain sensitive data.
These attacks have come while 100,000 Russia troops have been amassed around the Ukrainian border, leading many to believe Russia is behind the attack.
Some of the attacks led to text being displayed in Ukrainian, Russian, and Polish:
“Ukrainian! All your personal data was uploaded to the public network. All data on the computer is destroyed, it is impossible to restore it,”
“All information about you has become public, be afraid and expect the worst. This is for your past, present and future.”
Despite this claim, there has not yet been any recognized data leak from any major Ukrainian organization due to the attack.
Russia has also repeatedly denied any involvement in the attack.
Critical information to take from this attack:
- The Polish used in the message was badly written, containing many grammatical and spelling errors, and so was unlikely to have been written by a native Polish speaker.
- The attack was targeted at public-facing websites, so no important data could have been stolen, even though some of the websites were run by organizations that do store critical personal information about Ukrainian citizens.
- The SBU security service in Ukraine has managed to prevent 1,200 attacks in the last 9 months, suggesting this attack was more sophisticated or from an unexpected source.
- Due to the lack of real damage cased by this attack, it is more likely that Ukraine was targeted by one of Russia’s many nationalistic hacker groups, rather than by a Kremlin-ordered cyber offensive.
- Kremlin cyber offensives target communications networks, with the aim of destabilizing and confusing military personnel, as seen in the 2014 annexation of Crimea.
- NATO is signing a deal with Ukraine to grant the country access to the alliance’s malware information sharing platform, a move that should minimize damage from future attacks.
GCHQ’s warning to “Bolster Defenses” comes from the risk that nationalistic hacker groups from Russia will attempt to target UK businesses. The aim of these attacks would be to ransom critical data from U.K. businesses in order to fund further attacks, or to gain control of organizations’ websites in order to shock customers and clients.
Due to the comparatively smaller scale of these hacker groups, typical attacks might take the form of Phishing or the exploitation of vulnerabilities that companies have unwittingly left open on the edge of their networks. Often these vulnerabilities occur where organizations had the best of intentions to put security in place for homeworking or another purpose, and either the original methodology or a failure to patch the service over time, has in fact left an open door that is advertised to those looking for it.
For phishing attacks, Tec Sec provides a service that helps train your entire organization to detect and report these kind of scams. In order to test for vulnerabilities, we will send your staff a fake phishing emails, and then conduct training sessions on any staff members who were fooled and clicked on an accompanying link.
If you would like to know if your organization is open to vulnerabilities and or you would like to put measures in place to heighten your security and keep your staff aware, TecSec can help you to do this with a Free Scan.
Get in touch with us to talk about how we can help defend your business.







