Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
operational-disruptiongovernment-diplomatic-threatfinancial-sector-threathacktivist-operation

Ukraine Hit by Coordinated Cyberattacks on Government Sites and Banks

Updated 28d agoFirst seen May 25, 202614 sources

Ukraine faced a series of disruptive cyberattacks targeting government ministries, the Defense Ministry, state portals, and major banks, culminating in what officials called the largest DDoS campaign in the country’s history. On 15 February, attacks knocked or degraded access to services at PrivatBank, Oschadbank, the Ministry of Defense, government websites, and the Diia platform, with Ukrainian officials saying roughly 15 banks were affected. Authorities said the operation had been prepared in advance, originated from multiple countries, and was intended to destabilize society and trigger panic; they also said no theft of funds or personal data had been confirmed, while U.S. partners helped provide technical support and additional protections.

The February disruption followed an earlier January intrusion in which multiple Ukrainian ministry websites were hit and a defacement message in Russian, Polish, and Ukrainian falsely warned that citizens’ personal data had been leaked and destroyed. Ukrainian officials said no personal data leak was verified, while the EU and NATO publicly backed Kyiv and expanded cyber assistance, including closer cooperation and access to malware-sharing resources. The incidents fit a longer pattern of cyber operations against Ukraine, including the NotPetya attack that previously disrupted government bodies, banks, utilities, logistics firms, and airport operations and was later publicly attributed by the UK and US to Russia, an accusation Moscow has denied in more recent cases.

Share:
Ukraine Hit by Coordinated Cyberattacks on Government Sites and Banks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Feb 18, 20224y ago

US and UK attribute Ukraine DDoS attacks to Russia's GRU

On 2022-02-18, the White House and UK government publicly attributed the February DDoS attacks on Ukrainian banks and defense entities to Russia's GRU. US officials said technical evidence tied known GRU infrastructure to the activity and warned it could be part of broader preparation for disruptive or destructive operations.

White House and UK Gov attribute DDoS attacks on Ukraine to Russia's GRU
Feb 16, 20224y ago

Ukraine says most February attack disruptions were mitigated

By 2022-02-16, Ukrainian officials said most affected services had been restored even though the attack was still ongoing. The Defense Ministry added that attackers had also probed for vulnerabilities in website code, and US partners were providing technical support and additional protection services.

Feb 15, 20224y ago

Ukraine links February DDoS campaign to Russia

On 2022-02-15, Ukrainian officials said the cyberattack had been prepared in advance, likely cost millions of dollars, and was intended to destabilize society and spread panic. They attributed responsibility to Russia, while the Kremlin denied involvement.

Major DDoS attack hits Ukrainian banks and government services

On 2022-02-15, Ukraine suffered what officials described as the largest DDoS attack in its history, targeting the Defense Ministry, government portals, the Diia service, and banks including PrivatBank and Oschadbank. Around 15 Ukrainian banks were reportedly affected, causing service disruptions but no reported theft of funds or personal data.

Jan 14, 20224y ago

EU and NATO pledge cyber support after January attack

On 2022-01-14, the European Union condemned the attack on Ukrainian government websites and said it would mobilize resources to assist Kyiv. NATO also pledged continued support and announced enhanced cyber cooperation, including access to its malware information-sharing platform.

Ukraine says no data was leaked in January website attack

On 2022-01-14, Ukrainian authorities said several ministries were affected by the website incident but reported that no personal data had been leaked. At that time, Kyiv had not officially attributed the attack.

Ukrainian government websites defaced in overnight cyberattack

During the night of 2022-01-13 to 2022-01-14, multiple Ukrainian ministry websites were disrupted and displayed a threatening defacement message in Russian, Polish, and Ukrainian. The message falsely claimed Ukrainians' personal data had been leaked and destroyed.

Feb 15, 20188y ago

UK publicly blames Russia for the NotPetya attack

On 2018-02-15, the UK formally attributed the 2017 NotPetya cyberattack to Russia. The same reporting noted the US joined the UK in assigning responsibility to the Russian state.

Jun 28, 20179y ago

Ukraine says June 2017 cyberattack has been halted

By 2017-06-28, Ukraine's government said the cyberattack on state and corporate networks was under control and that specialists were working to restore lost data. Officials reported that key state-security-related enterprises were continuing to function normally.

Jun 27, 20179y ago

NotPetya disrupts Ukrainian government and corporate networks

On 2017-06-27, a large-scale cyberattack attributed to Petya/NotPetya hit Ukrainian government bodies and major companies, disrupting banks, utilities, logistics providers, and Boryspil airport. Ukrainian authorities said strategic enterprises continued operating despite the widespread impact.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.