CSIDB logo
Incident

Ministry of Energy of the Russian Federation

Incident posture

Attack window
Mar 2022
Location
Russia
Status
Resolved
CIA posture
Available to members
Updated
2026-08-28 19:47

Linked entities

Victim
Ministry of Energy of the Russian Federation
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2022
Discovered
Mar 2022
Disclosed
Mar 2022
Resolved
Mar 2022

Summary

Attackers compromised a statistics widget used by several Russian federal agencies, allowing them to insert false content and block access to the affected sites, including the Energy Ministry’s website. The breach was quickly contained and the agencies’ online services were restored within an hour. The incident occurred amid heightened cyber hostilities between Russia and Ukraine, following Ukrainian calls for an IT army and Russian warnings about foreign DDoS traffic.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Tuesday evening in March 2022, attackers compromised a statistics widget used by several Russian federal agencies to track visitor numbers. By exploiting this widget, the attackers were able to inject their own content onto the affected websites and block access to them. Among the sites affected were the website of the Energy Ministry, along with those of the Federal State Statistics Service, the Federal Penitentiary Service, the Federal Bailiff Service, the Federal Antimonopoly Service, the Culture Ministry, and other Russian state agencies. The compromised widget allowed the threat actors to display false information and render the sites inaccessible to visitors.

The Russian Ministry of Economic Development's press service explained that direct compromise of the sites is difficult, so attackers target external services such as the widget to gain entry. After the widget was breached, the attackers posted incorrect content on the agency pages, but the incident was promptly localized. The Russian Digital Development Ministry stated that the affected state agency websites, including the Energy Ministry's site, were restored within an hour of the breach. Restoration efforts brought the sites back online, removing the unauthorized content and reestablishing normal access.

The incident occurred amid reports of mutual cyber hostilities between Russia and Ukraine, with each side accusing the other of conducting network attacks. The Federal Security Service's National Coordination Center for Computer Incidents warned Russian organizations to take measures to counter threats to their information security. Around the same time, Ukrainian Vice Prime Minister Mykhailo Fedorov announced the formation of an "IT army" to conduct cyber operations against Russian targets. The attack took place alongside announcements of the Ukrainian IT army formation and Russian warnings about cyber threats.

Sources

Sources available to members: 1 source.

CSIDB