Cyberattack in Ukraine targets government websites

Advertisement

Advertise with us

KYIV, Ukraine (AP) — A cyberattack left a number of Ukrainian government websites temporarily unavailable Friday, officials said.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 14/01/2022 (1729 days ago), so information in it may no longer be current.

KYIV, Ukraine (AP) — A cyberattack left a number of Ukrainian government websites temporarily unavailable Friday, officials said.

While it wasn’t immediately clear who was responsible, the disruption came amid heightened tensions with Russia and after talks between Moscow and the West failed to yield any significant progress this week.

Ukrainian Foreign Ministry spokesman Oleg Nikolenko told The Associated Press it was too soon to say who was behind it, “but there is a long record of Russian cyber assaults against Ukraine in the past.”

In this undated handout photo released by Ukrainian Foreign Ministry Press Service, the building of Ukrainian Foreign Ministry is seen during snowfall in Kyiv, Ukraine. Ukrainian officials and media reports say a number of government websites in Ukraine are down after a massive hacking attack. While it is not immediately clear who was behind the attacks, they come amid heightened tensions with Russia and after talks between Moscow and the West failed to yield any significant progress this week. (Ukrainian Foreign Ministry Press Service via AP)
In this undated handout photo released by Ukrainian Foreign Ministry Press Service, the building of Ukrainian Foreign Ministry is seen during snowfall in Kyiv, Ukraine. Ukrainian officials and media reports say a number of government websites in Ukraine are down after a massive hacking attack. While it is not immediately clear who was behind the attacks, they come amid heightened tensions with Russia and after talks between Moscow and the West failed to yield any significant progress this week. (Ukrainian Foreign Ministry Press Service via AP)

Moscow had previously denied involvement in cyberattacks against Ukraine.

About 70 websites of both national and regional government bodies were targeted in the attack but no critical infrastructure was affected and no personal data accessed, according to Victor Zhora, deputy chair of the State Service of Special Communication and Information Protection.

The hack amounted to a simple defacement of government websites, said Oleh Derevianko, a leading private sector expert and founder of the ISSP cybersecurity firm. The hackers got into a content management system they all use, but “didn’t get access to the websites themselves.”

The main question, said Derevianko, is whether this is a standalone hacktivist action — “patriotic” Russian freelancers — or part of a larger state-backed operation.

A message posted by the hackers in Russian, Ukrainian and Polish claimed Ukrainians’ personal data was placed online and destroyed. It told Ukrainians to “be afraid and expect the worst.” In response, Poland’s government issued a statement noting that Russia has a history of such disinformation campaigns and that the Polish in the message was clearly not from a native speaker.

Tensions between Ukraine and Russia have been running high in recent months after Moscow amassed an estimated 100,000 troops near Ukraine’s border.

NATO Secretary-General Jens Stoltenberg said Friday that the alliance will continue to provide “strong political and practical support” to Ukraine in light of the cyberattacks.

“In the coming days, NATO and Ukraine will sign an agreement on enhanced cyber cooperation,” Stoltenberg said in a statement.

Russia has a long history of cyberattacks against Ukraine, including nearly thwarting its 2014 national elections and briefly crippling parts of its power grid during the winters of 2015 and 2016. In 2017, Russia unleashed one of most damaging cyberattacks on record with the NotPetya virus that targeted Ukrainian businesses and caused more than $10 billion in damage globally.

Ukrainian cybersecurity professionals have been fortifying the defenses of critical infrastructure ever since. Zhora has told the AP that officials are particularly concerned about Russian attacks on the power grid, rail network and central bank.

Experts have said recently that the threat of another such cyberattack is significant as it would give Russian President Vladimir Putin the ability to destabilize Ukraine and other ex-Soviet countries that wish to join NATO without having to commit troops.

“If you’re trying to use it as a stage and a deterrent to stop people from moving forward with NATO consideration or other things, cyber is perfect,” Tim Conway, a cybersecurity instructor at the SANS Institute, told the AP in an interview last week.

Conway was in Ukraine last month conducting a simulated cyberattack on the country’s energy sector. The U.S. has been helping Ukraine bolster its cyber defenses through agencies including the Department of Energy and USAID.

The White House didn’t immediately respond to a request seeking comment.

In a separate development Friday, Russia’s Federal Security Service, or FSB, announced the detention of members of the REvil ransomware gang, which was behind last year’s Fourth of July weekend supply-chain attack targeting the Florida-based software firm Kaseya. The attack crippled more than 1,000 businesses and public organizations globally.

European Union foreign policy chief Josep Borrell answers media as he arrives for a meeting of European Union foreign ministers in Brest, France, Friday, Jan. 14, 2022. The European Union is prolonging economic sanctions against Russia for six months for failing to live up to its commitments to the peace agreement in Ukraine. (AP Photo/Thibault Camus)
European Union foreign policy chief Josep Borrell answers media as he arrives for a meeting of European Union foreign ministers in Brest, France, Friday, Jan. 14, 2022. The European Union is prolonging economic sanctions against Russia for six months for failing to live up to its commitments to the peace agreement in Ukraine. (AP Photo/Thibault Camus)

The FSB claimed to have dismantled the gang, but REvil effectively disbanded in July. Cybersecurity experts say its members largely moved to other ransomware syndicates. They cast doubt Friday on whether the arrests would significantly impact Russian-speaking ransomware gangs, whose activities have only moderately eased after a string of high-profile attacks on critical U.S. infrastructure last year including the Colonial Pipeline.

The FSB said it raided the homes of 14 group members and seized over 426 million rubles ($5.6 million), including in cryptocurrency as well as computers, crypto wallets and 20 elite cars “bought with money obtained by criminal means.” All those detained have been charged with “illegal circulation of means of payment,” a criminal offense punishable by up to six years in prison. The suspects weren’t named.

According to the FSB, the operation was conducted at the request of U.S. authorities, who reported the leader of the group to officials in Moscow. It’s the first significant public action by Russian authorities since U.S. President Joe Biden warned Putin last year that he needed to crack down on ransomware gangs in his country.

Experts said it was too early to know if the arrests signal a major Kremlin crackdown on ransomware criminals — or if it may just have been a piecemeal effort to appease the White House.

Bill Siegel, CEO of the ransomware response firm Coveware, said he’ll be watching to see what kind of prison time those arrested get. “The follow-through on sentencing will send the strongest signal one way or another as to IF there has truly been a change in how tolerant Russia will be in the future to cyber criminals,” he said via email.

Yelisey Boguslavskiy, research director at Advanced Intelligence, said that while the arrests do follow a pattern of Kremlin pressure on ransomware criminals — including in some cases prompting them to hand over decryption keys — those arrested could simply be low-level affiliates, not the core group that managed the data-scrambling malware. The REvil syndicate also apparently ripped off some affiliates so it had enemies in the criminal underground, he said.

REvil’s attacks crippled tens of thousands of computers worldwide and yielded at least $200 million in ransom payments, Attorney General Merrick Garland said in November when announcing charges against two hackers affiliated with the gang.

Such attacks brought significant attention from law enforcement officials around the world. The U.S. announced charges against two affiliates in November, hours after European law enforcement officials revealed the results of a lengthy, 17-nation operation. As part of that operation, Europol said, a total of seven hackers linked to REvil and another ransomware family have been arrested since February.

The AP reported last year that U.S. officials, meanwhile, shared a small number of names of suspected ransomware operators with Russian officials, who have said they were investigating.

Brett Callow, a ransomware analyst with the cybersecurity firm Emsisoft, said that “whatever Russia’s motivations may be, the arrests would “certainly send shockwaves through the cybercrime community. The gang’s former affiliates and business associates will invariably be concerned about the implications.”

___

Frank Bajak reported from Boston, Litvinova reported from Moscow. Catherine Gaschka in Brest, France, Alan Suderman in Richmond, Virginia, and Eric Tucker in Washington, contributed to this report.

Report Error Submit a Tip

More Stories

Dozens of Uber, Lyft drivers switched to cheaper insurance coverage: MPI probe

Erik Pindera 5 minute read Preview

Dozens of Uber, Lyft drivers switched to cheaper insurance coverage: MPI probe

Erik Pindera 5 minute read Updated: 6:09 PM CDT

Ride-service drivers have been defrauding Manitoba Public Insurance by improperly insuring their vehicles as for personal use.

The public insurer and the City of Winnipeg, which regulates ride-hailing services like Uber and Lyft, discovered the widespread fraud after MPI conducted a review in December last year.

“When a driver changes their coverage from ride-share insurance to a personal vehicle coverage and continues to operate as a ride-share driver, that is fraud, plain and simple,” said MPI chief executive officer Satvir Jatana at a news conference Thursday.

MPI’s review looked at a random sample of 408 ride-hailing vehicles and found 108 were operating without the proper vehicle-for-hire insurance coverage. In order to register with the city as a ride-service driver, a vehicle must have such insurance and proof must be provided to the ride-booking company.

Read
Updated: 6:09 PM CDT

Canadian Mennonite University students, staff victims of cyberattack

Free Press staff 3 minute read Preview

Canadian Mennonite University students, staff victims of cyberattack

Free Press staff 3 minute read Updated: Yesterday at 6:29 PM CDT

Canadian Mennonite University fell victim to a cyberattack that compromised the data of current and former students and employees last month.

School officials became aware of the cybersecurity incident, in which an “unknown third party” accessed its information technology systems without authorization, on Sept. 18, university president Cheryl Pauls said in a recent statement.

The university has since confirmed the third party used that access to steal information from its systems.

“We immediately initiated our incident response plan, retained expert assistance, and informed the university community whose workflows were affected as soon as we became aware of the incident,” Pauls said. “We also reported this incident to law enforcement and will be filing a report with the Office of the Privacy Commissioner of Canada.”

Read
Updated: Yesterday at 6:29 PM CDT

Dog feces vandalism shuts down food pantry

Kelly-Anne Riess 4 minute read Preview

Dog feces vandalism shuts down food pantry

Kelly-Anne Riess 4 minute read 6:54 PM CDT

A few shelves set up beneath a West End community notice board were meant to offer a place where neighbours could leave food for anyone who needed it.

Read
6:54 PM CDT

Cyberattack in Ukraine targets government websites

Yuras Karmanau, Frank Bajak And Dasha Litvinova, The Associated Press 7 minute read Preview

Cyberattack in Ukraine targets government websites

Yuras Karmanau, Frank Bajak And Dasha Litvinova, The Associated Press 7 minute read Friday, Jan. 14, 2022

KYIV, Ukraine (AP) — A cyberattack left a number of Ukrainian government websites temporarily unavailable Friday, officials said.

While it wasn't immediately clear who was responsible, the disruption came amid heightened tensions with Russia and after talks between Moscow and the West failed to yield any significant progress this week.

Ukrainian Foreign Ministry spokesman Oleg Nikolenko told The Associated Press it was too soon to say who was behind it, "but there is a long record of Russian cyber assaults against Ukraine in the past.”

Moscow had previously denied involvement in cyberattacks against Ukraine.

Read
Friday, Jan. 14, 2022

Puzzles Palace

1 minute read Monday, Jul. 27, 2026

To solve our puzzles, please subscribe with this special offer: |

Indigenous leaders meet with Governor General during first official visit to Manitoba

Chris Kitching 4 minute read Preview

Indigenous leaders meet with Governor General during first official visit to Manitoba

Chris Kitching 4 minute read Updated: Yesterday at 6:09 PM CDT

Three Indigenous leaders were encouraged after discussing reconciliation and the need to confront residential school denialism with Gov. Gen. Louise Arbour, while she began her first official visit to Manitoba Wednesday.

Read
Updated: Yesterday at 6:09 PM CDT