CSIDB logo
Incident

Ukrainian State Enterprise Ukrposhta

Incident posture

Attack window
Apr 2022
Location
Ukraine
Status
Historical
CIA posture
Available to members
Updated
2026-03-09 15:56

Linked entities

Victim
Ukrainian State Enterprise Ukrposhta
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Apr 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Ukraine's national postal service experienced a distributed denial-of-service (DDoS) cyberattack that disrupted its online store and other operational systems following the launch of a controversial postage stamp depicting a Ukrainian soldier gesturing at a Russian warship. The attack caused significant service interruptions, prompting the company's director general to publicly apologize and coordinate restoration efforts with internet providers. This incident occurred amid heightened warnings from Ukrainian officials about potential cyber threats targeting critical infrastructure during the ongoing conflict.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 22, 2022, Ukraine's national postal service, Ukrposhta, experienced a cyberattack following the online launch of sales for a commemorative postage stamp. The stamp depicted a Ukrainian soldier making a crude gesture toward a Russian warship, referencing the sinking of the Russian Black Sea Fleet's flagship Moskva earlier that month. Ukraine claimed it struck the cruiser with missiles, while Russia attributed the sinking to an onboard ammunition explosion during stormy seas. The stamp's physical release at Ukrposhta's Kyiv headquarters had already drawn significant public interest, with queues forming during its initial sale. The cyberattack coincided with the digital rollout of stamp sales, disrupting Ukrposhta's online operations.

Ukrposhta Director General Ihor Smilianskyi publicly confirmed the incident as a distributed denial-of-service (DDoS) attack, which overwhelmed systems and caused temporary outages. Affected services included the online store and other internal operational systems. Smilianskyi apologized to customers via Facebook, stating teams were collaborating with internet providers to restore functionality. He did not attribute responsibility for the attack. Ukrainian authorities had repeatedly warned of heightened cyber threats from Russian actors since Russia's February 24 invasion, though Moscow consistently denied involvement in cyber operations against Ukraine. This incident occurred weeks after Ukraine reported thwarting a separate Russian cyberattack targeting its power grid.

Sources

Sources available to members: 2 sources.

CSIDB