Are Russia and Ukraine on the Verge of an All-Out Cyberwar?

Ukraine original: <a href="http://commons.wikimedia.org/wiki/File:Ukraine_flag_map.png">DDima</a>/Wikimedia Commons; ASCII effect: <a href=http://www.degraeve.com/img2txt.php">DeGraeve.com</a>. Photoillustration by <a href="http://adops.motherjones.com/authors/matt-connolly">Matt Connolly</a>.

Fight disinformation: Sign up for the free Mother Jones Daily newsletter and follow the news that matters.


For the past week, reports of physical violence have been rolling out of Ukraine: Russian troops storming a base in Crimea, officers beating journalists, and violent brawls at rallies. But as tensions escalate, another part of the conflict appears to be playing out in a cloudier realm: cyberspace.

On Saturday, Ukraine’s top security agency—the National Security and Defense Council of Ukraine—announced at a briefing that it had been hit by severe denial-of-service (DDoS) attacks, “apparently aimed at hindering a response to the challenges faced by our state.” This comes on the heels of a number of alleged hacks involving Russian and Ukrainian targets, including attacks on news outlets and blocking reception to the cellphones of Ukrainian parliament members.

Security experts say the region is currently seeing an unusually high number of DDoS attacks, which aim to shut down networks, usually by overwhelming them with traffic. But many of those seem to be coming from third parties, rather than government entities. In terms of state-sponsored cyberwarfare, “we haven’t seen that much,” says Dmitri Alperovitch, CTO of CrowdStrike, a California-based cybersecurity firm. Alperovitch adds, though, that his firm has seen a significant amount of cyber-espionage on the part of the Russian intelligence services—including tracking the activities of Putin opponents in both Russia and Ukraine—but he would not disclose names of those being monitored.

Ukraine is situated in a region of the world known for breeding some of the most talented cyber criminals. Several Russian universities offer top-notch hacking training, and a Ukrainian hacker is suspected in December’s theft of 40 million credit card numbers from Target. But Ukraine and Russia aren’t on equal footing when it comes to their cyberwarfare capabilities. “Russia is a Tier 1 cyber power,” says Alperovitch. “Ukraine isn’t even in Tier 3.” So Russia has a leg up in this arena—and, during past conflicts with former Soviet bloc countries, it has flexed its cyberwarfare muscles. In April 2007, hackers unleashed a wave of cyberattacks on Estonian government agencies, banks, businesses, newspapers, and political parties, following a spat over the removal of a Soviet war memorial in Tallin, the country’s capital. (The Kremlin took only partial credit for the crippling three-week attack.) Georgia was targeted with similar attacks in 2008 in the days leading up to its invasion of the secessionist republic of South Ossetia. (Russian involvement was widely suspected.)

Ukraine has yet be targeted with these type of widespread cyberassaults on key infrastructure—but it may not be long. “I anticipate continued escalation,” says Jason Healey, director of the Atlantic Council’s Cyber Statecraft Initiative and the former White House director of cyber infrastructure protection during the Bush administration. So far, the cyberskirmish is playing out differently than past attacks, Healey says. While the Estonia and Georgia attacks were strictly digital, in Ukraine’s case, pro-Moscow forces have also deployed more hands-on attacks on information: “This old-school, Cold War style physical manipulation of equipment. Getting in and physically messing with the switches so Ukrainian civic leaders don’t have phone service,” Healey says. In Ukraine, these sorts of attacks ?are likely to be a bigger threat, because much of the telecommunications infrastructure was installed by Russians during the Soviet era. “Cyberattacks the way we tend to look at them—denial-of-service attacks, and so forth—you don’t have to do those when you’ve got physical access to the guy’s switch!” says Healey.

Here’s a run-down of what has transpired so far: 

Media and government:

  • According to the National Security and Defense Council of Ukraine, state-run news agency Ukrinform suffered DDoS attacks in recent weeks.
  • Ukrainian newswire UNIAN said that it fought off a massive DDoS attack on March 3.
  • Glavnoe and Gordon, two other Ukrainian web publications, both said they’d been attacked by hackers.
  • Last week, the Russia Today website was hacked, with each mention of the word “Russia” replaced by “Nazi,” leading to headlines like, “Russian senators vote to use stabilizing Nazi forces on Ukrainian territory.”
  • The site of Rossiskaya Gazeta, a Russian paper, was hacked last Friday. The paper attributed the hit to a Ukrainian hacker group called “Kibersotnya” (?i????????). The editor in chief called the hack “a little digital rock thrown from the Maidan.” On its Facebook page, Kibersotnya denied responsibility for the attack.
  • Anonymous Ukraine posted a video online in late February promising to target Russian sites because of the Ukraine conflict. The group later claimed it hacked Russian government and military websites, including that of Russia’s narcotics control agency and the general directorate of special programs for the president.
  • On March 3, Roskomnadzor, Russia’s telecommunications watchdog, ordered VKontakte (Russia’s Facebook spinoff) to block access to the online communities of 13 Ukrainian nationalist organizations, alleging that they were encouraging terrorist activity. VKontakte complied. 

Hacked communications

  • In late February, Voice of Russia published emails allegedly written by Vitali Klitschko, leader of the Ukranian opposition party, that were sent to an adviser to Lithuania’s president. In one, Klitchko thanked the Lithuanian president for funding Ukraine’s protests. Anonymous Ukraine took credit for the email leak, saying that “the e-mails released by Anonymous prove that Vitaly Klichko is a puppet of the West and is being financed through intermediaries in Lithuania.” (Strangely, the amorphous hacker collective has targeted both sides in the conflict, acknowledging that its members are in disagreement about which side to back.)
  • Russian state television channels publicized a phone call leaked on YouTube between European Union Foreign Policy Chief Catherine Ashton and Estonian Foreign Minister Urmas Paet. In the hacked call, Paet suggests that snipers who killed dozens of Kiev protesters may have been working for the opposition, not deposed Ukrainian president Viktor Yanukovych.
  • The head of Ukraine’s security service announced last week that Ukrainian phone carrier Ukrtelecom had been targeted. He said that equipment had been installed in front of the Ukrtelecom offices in Crimea that blocked the cellphones of Ukrainian parliament members and other deputies.
  • Earlier, Ukrtelecom had said that armed men had forced themselves into the company’s Crimea facilities and tampered with cables, causing outages in the region. For a time, almost all internet and phone access in Crimea was cut off.

WE'LL BE BLUNT

It is astonishingly hard keeping a newsroom afloat these days, and we need to raise $253,000 in online donations quickly, by October 7.

The short of it: Last year, we had to cut $1 million from our budget so we could have any chance of breaking even by the time our fiscal year ended in June. And despite a huge rally from so many of you leading up to the deadline, we still came up a bit short on the whole. We can’t let that happen again. We have no wiggle room to begin with, and now we have a hole to dig out of.

Readers also told us to just give it to you straight when we need to ask for your support, and seeing how matter-of-factly explaining our inner workings, our challenges and finances, can bring more of you in has been a real silver lining. So our online membership lead, Brian, lays it all out for you in his personal, insider account (that literally puts his skin in the game!) of how urgent things are right now.

The upshot: Being able to rally $253,000 in donations over these next few weeks is vitally important simply because it is the number that keeps us right on track, helping make sure we don't end up with a bigger gap than can be filled again, helping us avoid any significant (and knowable) cash-flow crunches for now. We used to be more nonchalant about coming up short this time of year, thinking we can make it by the time June rolls around. Not anymore.

Because the in-depth journalism on underreported beats and unique perspectives on the daily news you turn to Mother Jones for is only possible because readers fund us. Corporations and powerful people with deep pockets will never sustain the type of journalism we exist to do. The only investors who won’t let independent, investigative journalism down are the people who actually care about its future—you.

And we need readers to show up for us big time—again.

Getting just 10 percent of the people who care enough about our work to be reading this blurb to part with a few bucks would be utterly transformative for us, and that's very much what we need to keep charging hard in this financially uncertain, high-stakes year.

If you can right now, please support the journalism you get from Mother Jones with a donation at whatever amount works for you. And please do it now, before you move on to whatever you're about to do next and think maybe you'll get to it later, because every gift matters and we really need to see a strong response if we're going to raise the $253,000 we need in less than three weeks.

payment methods

WE'LL BE BLUNT

It is astonishingly hard keeping a newsroom afloat these days, and we need to raise $253,000 in online donations quickly, by October 7.

The short of it: Last year, we had to cut $1 million from our budget so we could have any chance of breaking even by the time our fiscal year ended in June. And despite a huge rally from so many of you leading up to the deadline, we still came up a bit short on the whole. We can’t let that happen again. We have no wiggle room to begin with, and now we have a hole to dig out of.

Readers also told us to just give it to you straight when we need to ask for your support, and seeing how matter-of-factly explaining our inner workings, our challenges and finances, can bring more of you in has been a real silver lining. So our online membership lead, Brian, lays it all out for you in his personal, insider account (that literally puts his skin in the game!) of how urgent things are right now.

The upshot: Being able to rally $253,000 in donations over these next few weeks is vitally important simply because it is the number that keeps us right on track, helping make sure we don't end up with a bigger gap than can be filled again, helping us avoid any significant (and knowable) cash-flow crunches for now. We used to be more nonchalant about coming up short this time of year, thinking we can make it by the time June rolls around. Not anymore.

Because the in-depth journalism on underreported beats and unique perspectives on the daily news you turn to Mother Jones for is only possible because readers fund us. Corporations and powerful people with deep pockets will never sustain the type of journalism we exist to do. The only investors who won’t let independent, investigative journalism down are the people who actually care about its future—you.

And we need readers to show up for us big time—again.

Getting just 10 percent of the people who care enough about our work to be reading this blurb to part with a few bucks would be utterly transformative for us, and that's very much what we need to keep charging hard in this financially uncertain, high-stakes year.

If you can right now, please support the journalism you get from Mother Jones with a donation at whatever amount works for you. And please do it now, before you move on to whatever you're about to do next and think maybe you'll get to it later, because every gift matters and we really need to see a strong response if we're going to raise the $253,000 we need in less than three weeks.

payment methods

We Recommend

Latest

Sign up for our free newsletter

Subscribe to the Mother Jones Daily to have our top stories delivered directly to your inbox.

Get our award-winning magazine

Save big on a full year of investigations, ideas, and insights.

Subscribe

Support our journalism

Help Mother Jones' reporters dig deep with a tax-deductible donation.

Donate