Menu
Browse

Cyber Incident Victim: Monobank

Date:

Jul 2024

Location:

Ukraine

Summary

Monobank experienced an extremely large-scale DDoS attack lasting multiple days, with its co-founder reporting 5.5 billion malicious requests during the incident while confirming the bank remained operational. The attack, which initially generated approximately one billion requests within three hours, prompted assistance from Amazon Web Services personnel who noted its atypical scale, alongside offers of support from Ukrainian special services; the situation was described as under control despite the unprecedented volume of traffic.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On the evening of 16 August 2024, Monobank, a Ukrainian financial institution, experienced the initial wave of an extensive distributed denial-of-service (DDoS) attack targeting its digital services. Co-founder Oleh Horokhovsky publicly disclosed the incident via Telegram, reporting approximately one billion malicious requests directed at the bank's systems within the first three hours of the assault. The attack persisted continuously for at least three days, escalating to 5.5 billion cumulative requests by 1 August 2024 according to Horokhovsky's updates. The sustained bombardment represented an unusually large-scale offensive against the bank's infrastructure, though specific technical details regarding affected systems or customer service disruptions were not disclosed in public statements. Monobank's operational resilience was maintained throughout the incident, with Horokhovsky emphasizing "We are still standing" despite the volumetric attack.

Cyber Incident Image

The bank's response involved coordinated efforts with Amazon Web Services (AWS) infrastructure specialists, who intervened due to the atypical scale of the attack even by cloud service standards. Ukrainian intelligence agencies independently offered operational assistance to Monobank, though the nature and extent of their involvement remained unspecified in public communications. Horokhovsky characterized the situation as "under control" while acknowledging the impressive magnitude of the assault. No threat actor attribution, financial impact assessments, or data compromise indicators were disclosed during the reported timeframe. The incident represented one of the largest publicly disclosed DDoS attacks against Ukraine's financial sector at the time, though comparative metrics against previous incidents weren't provided.

Sources
Sources available to members
1 source