CSIDB logo
Incident

Česká televize

Incident posture

Attack window
Apr 2022
Location
Czechia
Status
Historical
CIA posture
Available to members
Updated
2025-10-19 00:00

Linked entities

Victim
Česká televize
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Apr 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The ČT24 website experienced a DDoS attack, causing temporary disruptions alongside issues at a related media outlet's server, initially mitigated by defenses but compounded by technical failures at an external provider. The same Russian-affiliated hacker group previously claimed similar attacks on government and transportation websites, threatening media over perceived pro-Kremlin labeling. These incidents occurred amid heightened cybersecurity alerts linked to geopolitical tensions, with national authorities urging organizations to update systems and guard against common attack methods.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 28, 2022, the website of Czech television news channel ČT24 experienced a distributed denial-of-service (DDoS) attack beginning approximately at 13:15 local time. The attack involved overwhelming the website with high-volume simultaneous access attempts from multiple computers. ČT24's protective systems initially detected and intercepted the malicious traffic. However, technical outages subsequently occurred in the infrastructure of ČT24's external service provider, prolonging the disruption beyond the immediate attack. Separately, the iROZHLAS.cz news website operated by Czech Radio encountered outages around 19:00, though initial assessments attributed this to network infrastructure issues at their operator rather than a confirmed cyberattack. Both media outlets restored normal operations by approximately 23:00 that evening.

This incident occurred amid a broader pattern of cyberattacks targeting Czech entities over the preceding two weeks. Government websites including the Ministry of Interior, police, fire rescue services, and Czech Railways had suffered DDoS disruptions on April 27 and during the prior week. The Russian hacker group Killnet claimed responsibility for those earlier attacks and explicitly threatened Czech media outlets on April 27, demanding they cease labeling Killnet as pro-Kremlin. The National Office for Cyber and Information Security (NÚKIB) had issued repeated warnings about elevated risks of cyber espionage and attacks linked to geopolitical tensions surrounding Russia's invasion of Ukraine. NÚKIB emphasized the need for organizations to patch known vulnerabilities and maintain vigilance against common attack techniques, noting Czech military support for Ukraine as a potential motivator for retaliatory cyber operations.

Sources

Sources available to members: 1 source.

CSIDB