CSIDB logo
Incident

Federal State Statistics Service

Incident posture

Attack window
Mar 2022
Location
Russia
Status
Unknown
CIA posture
Available to members
Updated
2026-08-28 20:56

Linked entities

Victim
Federal State Statistics Service
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Federal State Statistics Service was among several Russian government agencies whose websites were compromised after attackers infiltrated a visitor‑tracking widget used across multiple state sites. The breach allowed the attackers to post unauthorized content and temporarily block access to the affected portals. Authorities reported that the incident was contained quickly and the sites were restored within an hour. The attack occurred amid heightened cyber tensions between Russia and Ukraine, following Ukrainian calls for an IT army and Russian warnings about DDoS threats from abroad.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Tuesday, unknown attackers compromised a statistics widget used by multiple Russian federal agencies to track visitor numbers. The compromise allowed them to inject incorrect content and block access to the affected websites, including the Federal State Statistics Service, Energy Ministry, Federal Penitentiary Service, Federal Bailiff Service, Federal Antimonopoly Service, Culture Ministry, and other state agencies. The breach was discovered Tuesday evening when the attackers published their own material and rendered the sites inaccessible.

According to the press service of the Russian Ministry of Economic Development, the attack succeeded because direct compromise of the sites is difficult, so attackers exploited the external widget. After hacking the widget, they were able to publish incorrect content on the pages. The incident was promptly localized. The Russian Digital Development Ministry stated that the affected agencies' websites were restored within an hour of the breach. Additionally, the Federal Security Service's National Coordination Center for Computer Incidents issued warnings to Russian organizations to take measures against information security threats and shared defensive guidance.

The attack occurred amid heightened cyber hostilities between Russia and Ukraine, following the Russian government's publication of a list of over 17,000 IP addresses allegedly used in DDoS attacks against Russian networks. This followed after Ukrainian Vice Prime Minister Mykhailo Fedorov announced the formation of an "IT army" to support Ukraine's cyber front. The Ukrainian IT Army's creation was linked to recruitment by Ukraine's Defense Ministry of underground hacker community members for attacks on Russia, described as part of a massive wave of hybrid warfare. On the preceding Monday, the Russian Digital Development Ministry denied reports of plans to disconnect Russia from the global internet, emphasizing ongoing foreign cyberattacks and preparedness to ensure accessibility of Russian online resources.

Sources

Sources available to members: 1 source.

CSIDB