Cyber Incident Victim: Région de Bruxelles-Capitale
Date:
Feb 2024
Location:
Belgium
Summary
A pro-Russian hacker group known as NoName057(16) conducted a distributed denial-of-service (DDoS) attack against multiple Belgian government websites, including those of the Prime Minister, the House of Representatives, and Brussels-related services. The attack caused intermittent outages for approximately two hours, disrupting public access intermittently. The group claimed responsibility via Telegram, citing Belgium's financial support for Ukraine as motivation, and the incident followed diplomatic tensions involving the summoning of Russia's ambassador. Cybersecurity authorities resolved the disruption, noting that such targeted websites remain frequent targets for similar attacks.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On February 20, 2024, Russian hacker collective NoName057(16) executed a cyber attack against Belgian government digital infrastructure, publicly claiming responsibility via Telegram. The group cited Belgium’s financial support for Ukraine and its "Russophobic" stance as motivations, specifically referencing Prime Minister Alexander De Croo’s recent summons of the Russian ambassador following Alexei Navalny’s death. Targets included the official websites of Prime Minister De Croo, the Belgian House of Representatives, and the Brussels regional government. The attack commenced during Tuesday afternoon, causing intermittent outages described by the Center for Cybersecurity as a "two-hour cat and mouse game," where websites fluctuated between operational and inaccessible states due to overwhelming traffic volumes. Technical analysis confirmed the attack as a distributed denial-of-service (DDoS) campaign, a method previously deployed against Belgian systems, which floods servers with artificial traffic to disrupt legitimate access.

The incident resulted in temporary service degradation for approximately two hours, though no permanent data compromise or system damage was reported. Cybersecurity authorities resolved the disruptions by filtering malicious traffic and restoring normal operations, noting that previously targeted government sites remain persistent objectives for hostile actors. While the attack caused no lasting operational impacts, it highlighted recurring vulnerabilities in public-facing infrastructure. The Center for Cybersecurity’s spokeswoman Katrien Eggers acknowledged the transient nature of the disruption, emphasizing that such incidents require continuous defensive adaptations. NoName057(16)’s Telegram post explicitly linked the timing to Belgium’s diplomatic actions regarding Navalny, demonstrating the attack’s retaliatory intent against perceived political adversaries.
