Menu
Browse
Date:

Oct 2023

Location:

Czechia

Summary

A cyberattack disrupted the websites of the Czech Interior Ministry and police through a distributed denial-of-service (DDoS) attack, overwhelming their networks with excessive traffic. The pro-Russian hacker group NoName057 claimed responsibility, with cybersecurity firm GenDigital linking the same group to additional attacks targeting the Czech government's websites, parliamentary platforms, and Senate online services. The ministry implemented immediate protective measures, including restricting foreign access to mitigate the incident.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On October 24, 2023, the websites of the Czech Interior Ministry (Ministerstvo vnitra České republiky) and the Czech Police became inaccessible following a distributed denial-of-service (DDoS) attack. The incident occurred during the morning hours, disrupting public access to critical online services. Ondřej Krátoška, a spokesperson for the Interior Ministry, confirmed the cyberattack's nature, explaining that attackers overwhelmed the networks with an excessive volume of requests to render systems inoperable. The pro-Russian hacker group NoName057(16) claimed responsibility for the attack, as identified by cybersecurity firm GenDigital. This group also simultaneously targeted other Czech government institutions, including the national government portal, the Chamber of Deputies, and the Senate websites, indicating a coordinated effort to disrupt multiple branches of state infrastructure. The attack coincided with heightened geopolitical tensions, though no explicit motive was formally declared in the immediate aftermath.

Cyber Incident Image

The Interior Ministry implemented immediate countermeasures to mitigate the attack's impact, including restricting foreign access to affected systems through geoblocking measures. Officials communicated these actions publicly via the social media platform X (formerly Twitter) to maintain transparency. While service restoration timelines weren't specified, the containment strategy focused on isolating malicious traffic sources. No data breaches or system compromises beyond the temporary service outages were reported. The incident highlighted vulnerabilities in public-facing government digital infrastructure to volumetric attacks, though no long-term operational disruptions to internal ministry functions were disclosed. GenDigital's attribution provided early identification of the threat actor, though investigations into the attack's full scope remained ongoing at the time of reporting.

Sources
Sources available to members
1 source