Three years of reporting, funded by our readers — become a member now and help us prepare for 2025.
Goal: 1,000 new members for our birthday. Gift a membership to your friend and help us prepare for what 2025 might bring.
Become a member Gift membership
Skip to content
Edit post

SBU cybersecurity chief: Hackers had access to Kyivstar months before December attack

by Nate Ostiller January 4, 2024 11:00 AM 3 min read
A Kyivstar building in Kyiv, Ukraine, on Dec. 25, 2012. (Wikimedia Commons/Maksym Kozlenko)
This audio is created with AI assistance

Russian hackers who shut down Kyivstar had penetrated the company's internal system months before the attack and likely had access to a variety of users' personal data, said Illia Vitiuk, the cybersecurity chief of the Security Service of Ukraine (SBU), in an interview with Reuters published on Jan. 4.

Ukraine came under a massive cyberattack on Dec. 12, which targeted Kyivstar, the largest telecommunications provider, and one of the country's most important banks, Monobank. People across the country reported internet and network outages, as well as issues with air raid alerts.

A Russian hacker group called Solntsepek claimed responsibility for the attack against Kyivstar in a statement published on Telegram on Dec. 13.

Vitiuk said that he was "pretty sure" the attack was carried out by Sandworm, a unit of Russia's military intelligence (GRU), which the SBU has linked to Solntsepek.

Kyivstar CEO Oleksandr Komarov said that hackers had managed to break through the company's cyber security measures through the compromised account of an employee.

The day after the attack, the company denied that any computers or servers had been destroyed and claimed that subscribers' personal data remained safe.

Kyivstar reiterated to Reuters on Jan. 4 that "no facts of leakage of personal and subscriber data have been revealed," adding that the company was cooperating closely with the SBU to investigate the attack.

A Kyivstar spokesperson, Iryna Lelichenko, said on Facebook the same day that "various versions (of how the attack took place) are being considered and voiced, but none of them can be seen as final until the official conclusion of the investigation."

"The cyber attack on the Kyivstar network affected some technological systems responsible for communication, but they were restored within a few days thanks to the professional work of the company's specialists and partners."

According to Lelichenko, Kyivstar has already carried out additional measures for cyber protection, including strengthening access control and implementing additional server and workstation control systems, and is planning further steps to bolster cyber security.

Vitiuk refuted that assertion, saying that the attack wiped "almost everything," which included servers. He added that it was likely one of the first examples of a hacking attack that "completely destroyed the core of a telecoms operator."

Since the hackers had access to Kyivstar servers since May 2023 and full access since November, they could likely have been able to "steal personal information, understand the locations of phones, intercept text messages and perhaps steal Telegram accounts with the level of access they gained."

The attack did not impact Ukraine's military, Vitiuk said, because it has a different cybersecurity configuration and does not rely on private telecoms providers.

He added that it was important not to underestimate the threat posed by such attacks, noting that Kyivstar is a wealthy company with highly developed cybersecurity systems.

"This attack is a big message, a big warning, not only to Ukraine but for the whole Western world to understand that no one is actually untouchable," Vitiuk said.

A complete investigation on how the hackers managed to penetrate Kyivstar's cybersecurity is still ongoing, he said, including analyzing the possibility that there was someone on the inside who assisted in the attack.

Ukraine war latest: 230 Ukrainians freed from Russian captivity in large-scale prisoner exchange
Key developments on Jan. 3: * 230 Ukrainians, POWs and civilians, return home from Russian captivity in largest prisoner exchange since start of full-scale war * NATO-Ukraine Council to hold emergency meeting in response to Russia’s mass strikes on Ukraine, Kuleba says * NATO agrees on deal to b…

Three years of reporting, funded by our readers.
Millions read the Kyiv Independent, but only one in 10,000 readers makes a financial contribution. Thanks to our community we've been able to keep our reporting free and accessible to everyone. For our third birthday, we're looking for 1,000 new members to help fund our mission and to help us prepare for what 2025 might bring.
Three years. Millions of readers. All thanks to 12,000 supporters.
It’s thanks to readers like you that we can celebrate another birthday this November. We’re looking for another 1,000 members to help fund our mission, keep our journalism accessible for all, and prepare for whatever 2025 might bring. Consider gifting a membership today or help us spread the word.
Help us get 1,000 new members!
Become a member Gift membership
visa masterCard americanExpress

News Feed

3:44 PM

Russian ICBM strike would be 'clear escalation,' EU says.

"While we're assessing the full facts, it's obvious that such (an) attack would mark yet another clear escalation from the side of (Russian President Vladimir Putin," EU foreign affairs spokesperson Peter Stano said, according to AFP.
1:40 PM

Merkel describes Trump as 'fascinated by Putin' in her memoir.

"(Donald Trump) saw everything from the point of view of a property developer, which is what he was before he came into politics. Every plot of land could only be sold once, and if he didn't get it, someone else would," Angela Merkel says in her memoir.
11:54 PM

Biden seeks to cancel over $4.5 billion of Ukraine's debt.

"We have taken the step that was outlined in the law to cancel those loans, provide that economic assistance to Ukraine, and now Congress is welcome to take it up if they wish," U.S. State Department spokesperson Matthew Miller said on Nov. 20.
MORE NEWS

Editors' Picks

Enter your email to subscribe
Please, enter correct email address
Subscribe
* indicates required
* indicates required
Subscribe
* indicates required
* indicates required
Subscribe
* indicates required
Subscribe
* indicates required
Subscribe
* indicates required

Subscribe

* indicates required
Subscribe
* indicates required
Subscribe
* indicates required
Explaining Ukraine with Kate Tsurkan
* indicates required
Successfuly subscribed
Thank you for signing up for this newsletter. We’ve sent you a confirmation email.