CSIDB logo
Incident

MTS Ukraine

Incident posture

Attack window
Jun 2017
Location
Ukraine
Status
Unknown
CIA posture
Available to members
Updated
2026-09-27 01:44

Linked entities

Victim
MTS Ukraine
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The provided sources describe multiple cyber incidents affecting Ukrainian entities, such as the NotPetya attack distributed via compromised M.E.Doc updates. They list affected sectors including government, banking, transport, media, large companies, mobile providers (Lifecell, Kyivstar, Vodafone Ukraine), medicine, and gas stations. No mention of MTS Ukraine appears in any of the excerpts. Because the material does not contain information about an incident involving MTS Ukraine, a summary cannot be formulated from the given data.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The provided source material focuses on cyber incidents affecting Ukraine in 2016‑2017, particularly the NotPetya attack that spread through the M.E.Doc accounting software update mechanism. It describes how the malicious update was distributed to users of M.E.Doc, leading to encryption and wiper activity across numerous organizations. The text enumerates a wide range of affected sectors, including government ministries, banks, transport, media, large companies, mobile providers, medical facilities, and gas stations. Specific names such as Oschadbank, Kyivstar, Boryspil Airport, and Naftogaz of Ukraine appear in the lists of victims. Throughout the excerpts there is no mention of the telecommunications operator MTS Ukraine or any incident involving its networks or services.

Because MTS Ukraine does not appear in the enumerated victim lists or in any of the descriptive passages, the sources do not contain information about a cyber incident affecting that entity. Consequently, no factual chronology of events, impact assessment, or response actions concerning MTS Ukraine can be extracted from the supplied material. The absence of reference to MTS Ukraine means that any narrative detailing its involvement would rely on information outside the given sources. Since the instructions prohibit fabrication or speculation, only the confirmed absence of data can be reported. Therefore, a detailed narrative of an MTS Ukraine incident cannot be produced based solely on the evidence provided in the prompt.

Sources

Sources available to members: 1 source.

CSIDB