Menu
Browse

Cyber Incident Victim: Cabinet of Ministers of Ukraine

Date:

Jan 2022

Location:

Ukraine

Summary

Multiple Ukrainian government websites, including the Cabinet of Ministers portal, were compromised and defaced, leading to temporary takedowns. Attackers exploited a critical vulnerability (CVE-2021-32648) in an outdated content management system to post multilingual messages falsely claiming citizen data breaches, though authorities confirmed no personal information was compromised. The incident, which also potentially affected Polish military databases, displayed linguistic errors suggesting foreign involvement, with researchers linking it to the Belarus-aligned GhostWriter group amid regional tensions. Ukrainian cyber-police and IT teams worked to restore services while investigating the attack’s origins and broader implications.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On January 14, 2022, multiple Ukrainian government websites were compromised and defaced, including those of the Ministry of Foreign Affairs, Ministry of Agriculture, Ministry of Education and Science, Ministry of Security and Defense, and the Cabinet of Ministers' online portal. At least 15 public institution websites were affected. Attackers replaced content with messages in Ukrainian, Russian, and Polish falsely claiming that all citizen data uploaded to Ukraine's public networks had been compromised. Ukrainian cyber-police quickly confirmed no personal data was actually breached and denounced the warnings as disinformation. The attackers exploited CVE-2021-32648, a critical vulnerability in outdated October CMS software that enabled unauthorized password resets. Ukrainian authorities identified this vulnerability as the intrusion vector. IT teams took the affected websites offline for restoration, with some remaining inaccessible during initial recovery efforts.

Cyber Incident Image

The defacement messages contained grammatical inconsistencies suggesting possible machine translation, with investigators noting potential Russian involvement or misuse of Yandex translation tools. Polish defense officials separately reported breaches of military databases potentially linked to the incident. Ukrainian cyber-police made no definitive attribution but disclosed an unrelated ransomware gang arrest around the same timeframe. Cybersecurity researchers publicly suspected involvement of GhostWriter, an advanced persistent threat group historically associated with Belarusian interests. The incident occurred against heightened geopolitical tensions between Ukraine and Russia, though no explicit motive was established. Ukrainian authorities maintained focus on forensic investigations and full service restoration without confirming operational impacts beyond website disruptions.

Sources
Sources available to members
1 source