CSIDB logo
Incident

Culture Ministry

Incident posture

Attack window
Mar 2022
Location
Russia
Status
Unknown
CIA posture
Available to members
Updated
2026-08-28 20:58

Linked entities

Victim
Culture Ministry
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The attack targeted a visitor statistics widget used by multiple Russian government agencies, allowing intruders to replace content and block access to the affected sites. Among the compromised domains were those of the Energy Ministry, the Federal State Statistics Service, the Federal Penitentiary Service, the Federal Bailiff Service, the Federal Antimonopoly Service, the Culture Ministry and other state bodies. Authorities reported that the defacement was quickly contained and the websites were restored within an hour of the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Tuesday evening in March 2022, attackers compromised a statistics widget that multiple Russian federal agencies used to track visitor numbers, gaining unauthorized access to the associated websites. The compromised widget allowed the intruders to publish incorrect content on the affected pages and to block access to those sites. Among the agencies whose online portals were affected were the Energy Ministry, the Federal State Statistics Service, the Federal Penitentiary Service, the Federal Bailiff Service, the Federal Antimonopoly Service, and the Culture Ministry, along with other state bodies. The breach was discovered after the attackers posted their own material and rendered the websites inaccessible. The Russian Ministry of Economic Development’s press service explained that direct compromise of the sites is difficult, so the attackers exploited the external service to display false information.

The Russian Digital Development Ministry stated that the incident was promptly localized and that the affected agencies’ websites were restored within an hour of the breach. Officials confirmed that after hacking the widget, the attackers were able to alter the displayed content, but the response teams managed to contain the activity quickly. The Federal Security Service’s National Coordination Center for Computer Incidents (NKTsKI) issued warnings to Russian organizations, urging them to implement measures to counter information‑security threats and providing guidance on defending against similar supply‑chain attacks. These warnings followed a broader pattern of heightened cyber tensions between Russia and Ukraine. The NKTsKI’s advisory was part of the government’s effort to raise awareness of the ongoing threat landscape.

Earlier in the week, the Russian government had published a list of more than 17,000 IP addresses it claimed were used in distributed denial‑of‑service attacks against its networks. The warnings from NKTsKI came after Ukrainian Vice Prime Minister Mykhailo Fedorov announced the formation of an “IT army” to support Ukraine’s cyber operations, a move that followed recruitment efforts by Ukraine’s Defense Ministry targeting the country’s underground hacker community. On the preceding Monday, the Russian Digital Development Ministry denied reports that Russia planned to disconnect itself from the global internet, emphasizing that continuous cyberattacks from abroad necessitated preparedness to keep online resources accessible. A spokesperson told Interfax that there were no intentions to switch off the internet from within the country.

Sources

Sources available to members: 1 source.

CSIDB