CSIDB logo
Incident

Russian Federal Penitentiary Service

Incident posture

Attack window
Mar 2022
Location
Russia
Status
Unknown
CIA posture
Available to members
Updated
2026-08-28 20:54

Linked entities

Victim
Russian Federal Penitentiary Service
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Federal Penitentiary Service was among several Russian federal agencies whose websites were defaced after attackers compromised a third‑party statistics widget used to track visitor numbers across multiple government portals. By injecting their own content into the widget, the hackers caused the affected sites to display incorrect information and become temporarily inaccessible. Russian officials said the breach was quickly contained and the compromised websites were restored within an hour. The incident occurred amid heightened cyber hostilities, with Russia reporting a large list of foreign IP addresses allegedly involved in DDoS attacks and Ukraine announcing the formation of an IT army to conduct offensive operations against Russian networks.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Tuesday evening, Russian authorities discovered that several federal agency websites, including the one of the Federal Penitentiary Service, had been compromised after attackers published their own content and blocked access to the pages. The breach originated from a supply chain attack on a statistics widget that multiple government agencies used to track visitor numbers. By compromising the widget, the attackers were able to inject incorrect content onto the affected websites. The Federal Penitentiary Service site, along with those of the Energy Ministry, Federal State Statistics Service, Federal Bailiff Service, Federal Antimonopoly Service, Culture Ministry and other state agencies, displayed the unauthorized material. The press service of the Russian Ministry of Economic Development explained that direct compromise of such sites is difficult, so attackers target external services like the widget to gain indirect access. After the widget was hacked, the attackers promptly published false information and rendered the sites inaccessible. The incident was detected in the evening when the altered content became visible.

The Russian Digital Development Ministry stated that the affected agencies' websites were restored and brought back online within an hour after the breach was identified. Response actions included isolating the compromised widget and removing the malicious content, which the ministry described as prompt localization of the incident. The temporary disruption resulted in the Federal Penitentiary Service and other agencies presenting incorrect information to visitors and experiencing a brief loss of availability. In the aftermath, the Federal Security Service's National Coordination Center for Computer Incidents (NKTsKI) issued warnings to Russian organizations, urging them to take measures to counter threats to information security and sharing guidance on defending against similar supply chain attacks. The episode occurred amid heightened cyber tensions, as the Russian government had previously shared a list of more than 17,000 IP addresses allegedly used in DDoS attacks against its networks, and the Ukrainian Vice Prime Minister Mykhailo Fedorov had announced the creation of an 'IT army' to support Ukraine's cyber operations. These broader developments were noted in the same reporting but did not alter the factual timeline of the widget compromise and subsequent restoration.

Sources

Sources available to members: 1 source.

CSIDB