Cyber Incident Victim: Telex
Date:
Mar 2022
Location:
Hungary
Summary
A coordinated cyber attack targeted multiple government-critical news portals and an opposition party's website through DDoS attacks, causing temporary service disruptions. The affected platforms, including Telex, were overwhelmed by significantly increased traffic, with attackers also defacing sites with a message accusing them of being state propaganda. Similar incidents occurred against pro-government media and political party websites in preceding days, with investigations ongoing across all cases.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 31, 2022, multiple Hungarian websites experienced cyberattacks, including the independent news portals Telex and 444, alongside the liberal opposition party Momentum's site. The attacks began in the morning with Momentum's website suffering an overload attack that rendered it inaccessible. Momentum reported no material damage due to existing protective systems but emphasized the operational disruption during an election period, impairing voter communication. That afternoon, Telex's servers were targeted by a distributed denial-of-service (DDoS) attack, flooding them with twenty times the normal traffic volume. Attackers simultaneously attempted to overload Telex’s homepage. IT staff resolved the technical issues, restoring functionality. Around the same time, 444 endured a similar DDoS incident, causing temporary unavailability.

A defacement message appeared simultaneously on all affected platforms, declaring: "This Website is part of the state propaganda media! We have brought you the truth!..." The attacks occurred amid a broader pattern of cyber incidents targeting both government-critical and pro-government entities. In the preceding week, Hungary’s ruling Fidesz party website and allied media portals had also been hacked. Police investigations into all attacks remained ongoing at the time of reporting. No group claimed responsibility, and the full technical scope of the intrusions beyond the DDoS disruptions and defacement was not detailed in available reports. Momentum’s statement highlighted the strategic timing of the attack during pre-election activities, though no long-term operational or financial consequences were confirmed for any entity.
