Ukrainian government, military, banking, and energy targets were repeatedly disrupted by cyber operations tied to Russia and the war around Ukraine. Reports describe attacks on a Ukrainian power station, outages affecting the websites of Ukraine’s defense ministry and major banks, and broader disruptive activity against the country’s financial sector. The UK government later said technical analysis by the National Cyber Security Centre assessed that Russia’s GRU was almost certainly involved in the February 2022 distributed denial-of-service attacks on Ukrainian banking targets, framing the incidents as part of continued Russian aggression.
The campaign also expanded beyond Ukraine through both state-linked and pro-Russian actors. Killnet, a Russia-aligned hacktivist group, claimed retaliatory DDoS attacks on Lithuanian government and business websites after restrictions affecting transit to Kaliningrad, while other reporting said Russian-backed actors continued destructive operations against Ukraine, including wiper malware and attempted power-grid attacks. At the same time, pro-Ukrainian hackers mounted hack-and-leak operations against Russian institutions, underscoring how the conflict evolved into a broader regional cyber confrontation affecting governments, critical infrastructure, and financial services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
By May 2025, Russia was accused of attempting to hack security cameras at border crossings used to move assistance into Ukraine. The alleged activity represented a cyber effort aimed at interfering with logistics and aid delivery rather than the previously documented attacks on banks, telecoms, or the power grid.
In December 2023, Ukraine's largest telecom operator Kyivstar was hit by a destructive cyberattack attributed to Russia that caused major service outages. The company's CEO later said the attack wiped thousands of virtual servers and PCs, highlighting the scale of the intrusion.
By 2023-04-11, reporting said Russian hackers were attempting to access internet-connected security cameras inside Ukraine, including devices in locations such as coffee shops. The activity suggested an effort to gather real-time visual intelligence from civilian and commercial environments during the war.
In June 2022, pro-Russian hacktivist group Killnet conducted distributed denial-of-service attacks against Lithuanian government and business websites, including the State Tax Inspectorate and accounting provider B1.lt. The group said the operation was retaliation for Lithuania's restrictions on transit to Kaliningrad and threatened further disruption.
By April 2022, hackers aligned with Ukraine or sympathetic to its cause claimed breaches of dozens of Russian institutions, including Roskomnadzor and the F.S.B., and released emails and internal documents online. The leaks were presented as part of the cyber dimension of the Russia-Ukraine war, though much of the material was difficult to independently verify.
In April 2022, Russian state-linked Sandworm actors attempted to deploy Industroyer2 malware against Ukrainian electrical substations. Ukrainian defenders disrupted the operation before it could cause a larger power outage, revealing a new phase of cyber targeting against the country's energy infrastructure.
By 2022-03-04, a senior Ukrainian cyber official said Russian operators had hijacked about 10 local government websites to post false surrender messages and were running targeted email campaigns that delivered destructive malware. He also said Ukraine had identified attempts to infect individual citizens' devices, indicating an expansion of Russian cyber tactics beyond earlier DDoS and phishing activity.
By 2022-02-28, major technology companies including Microsoft were publicly described as assisting Ukraine in defending government and critical networks against ongoing Russian cyberattacks during the invasion. The support marked a notable private-sector response alongside the previously documented disruptive attacks on Ukrainian institutions.
On 2022-02-25, Ukrainian cyber officials warned that a new wave of phishing attacks was targeting users amid the broader conflict. The alert marked a shift from the earlier disruptive DDoS activity to credential-theft and social-engineering operations affecting Ukrainian networks.
On 2022-02-24, a cyberattack hit Viasat's KA-SAT satellite communications network, disrupting modems in Ukraine and elsewhere in Europe. The incident affected communications used around the opening of Russia's invasion and later became a major example of spillover risk in satellite infrastructure.
On 2022-02-24, destructive malware attacks reportedly affected a Ukrainian bank and Ukrainian government contractors in Latvia and Lithuania as Russia's invasion began. The activity showed cyber operations accompanying the kinetic assault and extending beyond Ukraine's borders to supporting organizations in neighboring countries.
On 2022-02-18, the UK government said technical analysis by the National Cyber Security Centre assessed that Russia's Main Intelligence Directorate was almost certainly involved in the DDoS attacks against Ukraine on 15 and 16 February. The statement framed the activity as part of continued Russian aggression toward Ukraine.
Disruptive attacks against Ukraine's banking and financial sector continued on 2022-02-16, extending the impact beyond the initial wave the previous day. The multi-day activity became the basis for later public attribution by the UK government.
On 2022-02-15, disruptive cyberattacks knocked offline or degraded the websites of Ukraine's defense ministry, armed forces, and major banks including PrivatBank and Oschadbank. Ukrainian officials said the incidents were large-scale DDoS attacks occurring amid heightened tensions with Russia.
On 2022-01-14, multiple Ukrainian government websites were taken offline or defaced in a cyberattack. The incident marked an earlier wave of disruptive activity against Ukraine's public sector before the February attacks on banks and defense-related sites.
On 2021-02-24, Ukrainian officials said attackers had compromised a government document-management portal and uploaded malicious files disguised as official documents. Ukraine linked the activity to Russia, describing it as part of ongoing cyber operations against state institutions.
A cyberattack disrupted a Ukrainian power transmission station in December 2016, causing a brief blackout in part of Kyiv. Researchers later linked the incident to malware known as Industroyer/CrashOverride, marking another major attack on Ukraine's power grid.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
20 references tracked. Mallory keeps watching after this page renders.
theguardian.com
Open sourcetherecord.media
Open sourcetheguardian.com
Open sourcebloomberg.com
Open sourcethehackernews.com
Open sourcearstechnica.com
Open sourceweb.archive.org
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.