CSIDB logo
Incident

Kraft-S

Incident posture

Attack window
Dec 2025
Location
Russia
Status
Unknown
CIA posture
Available to members
Updated
2026-02-05 21:15

Linked entities

Victim
Kraft-S
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Dec 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Russian internet service provider, Kraft-S, suffered a cyberattack where Ukrainian hacktivists wiped its network routers, causing extended connectivity disruptions for customers. The incident was claimed by the BO Team, a Ukrainian group that also targeted another Russian ISP during the same campaign, employing similar disruptive tactics to compromise critical infrastructure.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Ukrainian hacktivists from the BO Team executed a disruptive cyberattack against Russian internet service provider Kraft-S in Samara during the New Year's Eve period. The attackers infiltrated Kraft-S's network infrastructure and deliberately wiped the configuration data from routers, causing widespread connectivity outages for customers. Service disruptions persisted for multiple days as technicians worked to restore router configurations and re-establish network operations. The incident mirrored a simultaneous attack against SimStar, another Russian ISP based in Crimea, which the same group claimed to have compromised using identical methods. Kraft-S did not publicly disclose technical specifics regarding the intrusion vector, the number of affected routers, or the total customer impact. No evidence suggested data theft or secondary objectives beyond network disruption.

The BO Team openly claimed responsibility for both ISP attacks through undisclosed channels, framing the operations as part of ongoing hacktivist activities against Russian entities during the Ukraine conflict. Kraft-S issued no detailed public statements regarding incident response timelines, forensic findings, or mitigation measures beyond acknowledging the service interruption. The company's restoration efforts focused on rebuilding router configurations to resume connectivity, though the timeline for full recovery remained unclear. No ransomware deployment, financial demands, or data leaks accompanied the attack, distinguishing it from contemporaneous incidents like the Copec ransomware attack or the Anubis group's dark web posts. The disruption highlighted vulnerabilities in ISP network management systems, particularly regarding configuration integrity protections against destructive attacks.

Sources

Sources available to members: 1 source.

CSIDB