CSIDB logo
Incident

Russian Railways

Incident posture

Attack window
Apr 2025
Location
Russia
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 11:20

Linked entities

Victim
Russian Railways
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A distributed denial-of-service (DDoS) attack targeted Russian Railways, disrupting access to its website and mobile application for ticket purchases and online services, while physical ticket sales at station offices remained operational. The incident followed a similar disruption to Moscow's subway digital platforms days earlier, and Russian Railways did not disclose the scale of the attack or an estimated restoration time. The attack's perpetrator has not been identified. The event came shortly after suspected Russian hackers targeted Ukraine's national railway operator with tailored malware affecting its app and website, though without disrupting train schedules.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 1, 2025, Russian Railways (RZD), the state-owned railway operator of Russia, confirmed that its website and mobile application had been targeted by a distributed denial-of-service (DDoS) attack, rendering its online services temporarily unavailable to users. The company issued a statement on Tuesday acknowledging the disruption, noting that its digital platforms were experiencing outages as a result of the attack. RZD emphasized that ticket sales continued to function through physical offices located across stations and terminals, indicating that the core operational rail services were not directly impacted by the cyber incident. The railway operator stated that it was "working to restore their operation as quickly as possible," though it did not provide specific details regarding the scale of the attack or an estimated timeline for full restoration of its digital services. Downdetector, an outage monitoring platform, continued to display ongoing disruptions to RZD's digital services at the time the incident was reported, with Russian users describing their inability to load the railway's app or website, or to complete online ticket purchases. The perpetrator behind the DDoS attack remained unidentified in the immediate aftermath, with no group or actor claiming responsibility for the specific incident at the time of reporting.

The cyberattack on RZD represented the second incident within the same week involving a Russian transportation agency, following disruptions experienced by Moscow's subway system on the preceding Monday. The timing of these sequential attacks against Russian transportation infrastructure came shortly after a separate cyber incident targeting Ukraine's national railway operator, Ukrzaliznytsia, which was attributed to suspected Russian hackers. That earlier attack against Ukrzaliznytsia had disrupted the Ukrainian railway's mobile application and website, both of which were primarily used for ticket purchases, though train schedules themselves remained unaffected. Ukrainian cyber officials commented on the Ukrzaliznytsia incident on Tuesday, noting that the hackers involved had deployed unique malware that was specifically developed with the targeted infrastructure in mind, suggesting a significant level of preparation and resources. The back-to-back nature of these incidents underscored the ongoing cyber conflict between Russian and Ukrainian actors, with each country's transportation infrastructure being targeted by suspected adversary operations within a short window of time. RZD had previously experienced cyberattacks on its digital services, including an earlier incident in 2025 during which the pro-Ukrainian hacker group CyberSec claimed responsibility for leaking data from RZD's corporate portal, an incident that reportedly involved the exposure of over half a million records containing employee information such as names, titles, phone numbers, email addresses, and vacation dates for the year 2025, though RZD itself did not publicly comment on that prior breach.

Sources

Sources available to members: 1 source.

CSIDB