Menu
Browse

Cyber Incident Victim: Czech Republic

Date:

Jan 2023

Location:

Czechia

Summary

Websites of Czech presidential candidates experienced DDoS attacks causing intermittent outages, with traffic flooding from various European IP addresses. The Russian-affiliated group NoName057 claimed responsibility via Telegram, citing opposition to Ukraine-related military training in the country and aiming to disrupt the electoral process. This group, active since early 2022, previously targeted European government and financial sectors. Czech cyber authorities confirmed collaborating with victims on multiple election-related attacks but withheld operational details. The incidents reflect sustained attempts to compromise political infrastructure through service-denial tactics during a sensitive electoral period.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On January 13, 2023, the campaign websites of Czech presidential candidates Petr Pavel and Tomáš Zima experienced significant disruption due to distributed denial-of-service (DDoS) attacks. Pavel's electoral website became inaccessible to some users starting Friday morning, with his spokesperson Eva Hromádková confirming the site was under heavy attack. The website's operator noted the assault originated from multiple IP addresses across Europe. While service was partially restored, intermittent outages persisted as attacks continued throughout the day. Simultaneously, Zima's campaign team reported similar disruptions, characterizing this incident as more severe than a previous attack they had experienced just two days earlier on January 11. Karel Křivan, a Zima campaign collaborator, stated technicians were working to restore full functionality but provided no estimated resolution timeline.

Cyber Incident Image

The attacks specifically targeted website availability through volumetric DDoS techniques designed to overwhelm servers with excessive traffic, preventing legitimate user access. Russian-aligned hacker group NoName057(16) claimed responsibility via their Telegram channel, explicitly linking the attacks to Czech Republic's upcoming presidential elections and criticizing the country's military training of Ukrainian soldiers at the Libavá base. This group, active since March 2022 following Russia's invasion of Ukraine, previously targeted Polish government websites in December 2022 and Danish financial infrastructure. The Czech National Office for Cyber and Information Security (NÚKIB) confirmed multiple election-related DDoS incidents through spokesperson Marek Vala, who acknowledged collaboration with affected parties but declined to disclose technical details or attribution assessments. Both campaigns maintained operational continuity through alternative communication channels despite persistent website instability throughout the election period.

Sources
Sources available to members
1 source