Cyber Incident Victim: Ukrainian National Police
Date:
Sep 2020
Location:
Ukraine
Summary
The Ukrainian National Police website was temporarily shut down following a cyberattack involving unauthorized access that led to the publication of inaccurate information on regional police department pages. Authorities detected the intrusion and disabled the site to address the compromise, with specialists working to resolve the issue; the incident reflects a pattern of cyberattacks targeting critical Ukrainian infrastructure, including previous breaches affecting energy, postal, nuclear, and aviation systems.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 9 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On September 23, 2020, at approximately 11:45 am Eastern European Summer Time (EEST), unauthorized actors compromised the official website of the Ukrainian National Police. The intrusion led to the publication of inaccurate information across multiple internet pages operated by regional police departments. Authorities detected the interference promptly and initiated an immediate response by temporarily disconnecting the National Police website from public access. A Facebook statement issued by the National Police confirmed the incident, characterizing it as "unauthorized interference" while acknowledging the dissemination of unreliable content through regional office pages. The organization publicly apologized for service disruptions caused by the website shutdown and assured the public that technical specialists were actively working to resolve the issue.

The cyberattack's exact methodology and full scope remained undetermined at the time of reporting, with no public confirmation regarding how attackers bypassed the website's enhanced security measures. Historical context indicates Ukraine experienced multiple high-impact cyber incidents prior to this event, including a Bitcoin ransomware attack against the Ministry of Energy's website, malware campaigns targeting critical infrastructure such as nuclear plants and airports, and compromises affecting the national postal service. The National Police did not disclose technical details about containment procedures, forensic findings, or potential attribution during the initial response phase. Hackread.com attempted to solicit additional information from authorities but received no further commentary by the article's publication timestamp. Regional police page alterations constituted the primary confirmed impact alongside the central website's temporary unavailability, with no verified reports of data exfiltration or secondary disruptions to police operations.
