Federal Antimonopoly Service
Incident posture
Linked entities
- Victim
- Federal Antimonopoly Service
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Russian government websites, including those of the Energy Ministry, Federal State Statistics Service, Federal Penitentiary Service, Federal Bailiff Service, Federal Antimonopoly Service, Culture Ministry and other state agencies, were compromised in a supply chain attack that targeted a visitor statistics widget used by multiple agencies. Attackers used the compromised widget to post their own content and block access to the sites, but the incident was quickly contained and the affected websites were restored within an hour. The breach occurred amid heightened cyber exchanges between Russia and Ukraine, following Ukrainian calls for an IT army and Russian warnings about foreign DDoS activity.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Tuesday evening, unknown attackers compromised a third‑party statistics widget that multiple Russian federal agencies used to track visitor numbers, including the Federal Antimonopoly Service. By exploiting this external service, the intruders gained the ability to alter the content displayed on the agency’s website and to block access to the site for visitors. The breach was detected when the attackers published their own material on the Federal Antimonopoly Service’s pages and prevented users from reaching the site. The press service of the Russian Ministry of Economic Development noted that direct compromise of such government websites is difficult, so the attackers chose to target an external resource as a stepping stone. Once the widget was hacked, the intruders were able to post incorrect content on the affected agency’s pages and to disrupt normal service availability across the compromised sites. The incident was reported publicly after the attackers’ content appeared and access was denied, prompting an immediate response from the responsible ministries.
After the breach was identified, the incident was promptly localized, meaning the malicious activity was confined to the compromised widget and its downstream effects. The Russian Digital Development Ministry reported that the state agencies’ websites, including that of the Federal Antimonopoly Service, were restored to normal operation within an hour of the breach. Officials emphasized that the response involved removing the malicious content from the widget, verifying the integrity of the affected web pages, and ensuring that no further unauthorized changes could be made. In parallel, the Federal Security Service’s National Coordination Center for Computer Incidents issued warnings to Russian organizations, urging them to implement defensive measures against similar supply‑chain attacks and sharing guidance on how to detect and mitigate such threats. The ministry also stated that the breach had been contained quickly and that the affected sites were brought back online without prolonged disruption.
The cyber incident occurred amid heightened tensions between Russia and Ukraine, following the Russian government’s publication of a list of more than 17,000 IP addresses allegedly used in DDoS attacks against Russian networks and the announcement by Ukraine’s Vice Prime Minister of an “IT army” intended to conduct cyber operations against Russia. In the same reporting, the Russian Digital Development Ministry denied claims that Russia planned to disconnect from the worldwide web, stating that preparations were being made to ensure the accessibility of online resources amid ongoing cyberattacks. These broader developments were mentioned in the source material but do not change the factual description of the supply‑chain compromise that specifically affected the Federal Antimonopoly Service’s website.
Sources
Sources available to members: 1 source.