Why hasn’t Ukraine suffered a debilitating Russian cyberattack?

Why hasn’t Ukraine suffered a debilitating Russian cyberattack?
Ukrainian flag displayed on a laptop and binary code code on a screen.
Jakub Porzycki via Reuters Connect

Russia’s invasion of Ukraine in February fueled expectations it would launch a devastating campaign of cyberattacks against the neighboring country. Since 2014, state-run Russian cyber units, state-affiliated hackers, and independent cyber-criminal groups have frequently trained their sights on targets in Ukraine. They have, among other things, forced government websites offline, caused the largest-ever cyber-induced blackout of a nation’s power grid, and deployed the most destructive and costly malware to date. So, why hasn’t there been another such attack since the war began? We talked to Eurasia Group geotech analyst Sienna Tompkins to get some answers.

We’ve come to see cyberattacks as a big part of Russia’s playbook. Has that changed?

Not really. While a large-scale attack with significant repercussions or international contagion has not yet materialized, there has been a steady drumbeat of cyber activity by Russian military and intelligence units against Ukrainian targets. In a recent report, Microsoft said there have been at least 2-3 cyber operations since the eve of the invasion. Nuisance-level attacks have overloaded key government and institutional websites with traffic, several wiper malwares have been deployed, and the hack of satellite provider, Viasat, caused widespread communications outages on the first day of the invasion.

Why nothing bigger?

One reason might be that military attacks are generally more effective when it comes to disabling critical infrastructure. There has also been speculation that Russian cyber units were caught off-guard by the invasion, without sufficient notice to plan and execute large, sophisticated attacks. Moreover, Russian leaders may be wary of US retaliation or of triggering NATO’s Article 5 collective defense clause if a NATO member is affected by the fallout. Lastly, expectations of a quick and decisive victory may also have influenced the calculus to keep critical infrastructure operational for the use of a puppet regime installed by Moscow.

That said, there is also an element of uncertainty and misdirection that occurs in times of war. Cyber operations that have yet to be activated or detected could ultimately meet the threshold of a major attack. Targets may not know they have been compromised or that the root cause of a cyber operation is cyber-induced. Moreover, in a context of widespread physical destruction, it can be hard to tell if there have been contributing cyber actions as well.

What did we learn from the recent foiled attack against Ukraine’s electric grid?

It lends weight to the theory that Moscow may have wanted to keep critical infrastructure intact in expectation of a quick victory in the war. Sandworm, a group thought to be part of the hacking operations of the GRU, Russian military intelligence, infected the Ukrainian energy company’s network in February. That was prior to the invasion, yet Sandworm only attempted to cut power months later in April.

The episode also highlights Ukraine’s increased cyber resiliency. The foiled cyberattack would have affected 2 million people, making it the largest-ever cyber-induced power outage, but was discovered prior to activation. After years of being targeted by Russia, Ukraine has ramped up investment in its defenses and in cultivating cyber talent.

Has Western assistance been a factor in bolstering Ukraine’s defenses?

Yes. The US, EU, and NATO have all contributed: US Cyber Command sent a surge team to Ukraine ahead of the invasion to hunt for compromised networks; NATO admitted Ukraine to its Cooperative Cyber Defence Centre of Excellence and included Ukrainian experts in its recent digital war simulation “Locked Shields”; and the EU mobilized its newly formed Cyber Rapid Response Team to work with its Ukrainian counterparts.

Private companies have also been playing an outsized role. Major service providers, as the main conduits for many attacks, are tracking known cyber actors and taking remedial action. Microsoft recently obtained a court order to take over seven internet domains used by Strontium, another GRU cyber unit, and redirect them to blunt their impact.

Are you worried about other countries helping Russia wage cyberwarfare?

Russia is a highly sophisticated cyber actor and perfectly capable of waging cyber warfare on its own. Additional actors could add to the chaos and disruption in Ukraine in a way that is useful to Russia, but to be strategically or tactically impactful and avoid undue escalation with the US and NATO, there would need to be a level of formal cooperation. There has been some speculation that China could get involved, but it is unlikely to take such an aggressive step and there is no evidence that it has done so yet.

What about cyberattacks by Ukraine?

Ukraine has primarily been focused on what has been called “persistent defense” — fending off Russian cyber intrusions and attempted attacks. But in a new twist, Ukrainian officials have also mobilized a civilian “IT army.” The volunteer corps is focused on taking down or defacing Russian government websites, hack-and-leak operations revealing confidential datasets, and attempting to undermine propaganda on Russian TV networks. Russia’s Ministry of Digital Development and Communications has reported unprecedented volumes of attacks against government websites. Nevertheless, the attacks remain nuisance-level and serve primarily as information warfare.

What should we expect in the cyber dimension of the Ukraine war going forward?

The story is far from over. The risks of major Russian cyberattacks against Ukraine, or countries backing it, remain elevated. The Five Eyes intelligence alliance comprising Australia, Canada, New Zealand, the UK, and the US recently warned of preparations to conduct significant cyberattacks against critical infrastructure in countries that have sanctioned Russia or otherwise shown their support for Ukraine. Western governments are exhorting companies to upgrade their cyber resilience. A significant attack is likely a matter of not if but when.

More from GZERO Media

- YouTube

AI for Good is more than a buzzword—it's a powerful tool tackling global challenges like food security, disaster response, and water conservation. Microsoft’s Brad Smith highlights real-world examples, such as using AI to analyze water data in Kenya, offering actionable solutions for governments and communities. Through collaborations with universities and NGOs, AI is driving progress on the UN's Sustainable Development Goals, turning technology into a force for societal improvement.

- YouTube

President Xi Jinping has made it clear he wants to bring Taiwan under Chinese control. But how would he actually send troops to the island? And after watching Russia get bogged down in two years of grinding war in Ukraine, has his calculus changed? On Ian Explains, Ian Bremmer lays out Xi’s strategies for achieving his primary political goal: reunification with Taiwan.

- YouTube

AI has immense potential, but guardrails alone won’t ensure its benefits reach everyone. According to Microsoft Vice Chair and President Brad Smith, policies must ensure AI is safe and secure, but equitable access requires more—investment. Just as electricity took over a century to reach parts of the world, Mr. Smith says AI’s widespread adoption depends on economic strategies that go beyond values. It's a balance of ethics and action to ensure AI’s benefits are felt globally.

- YouTube

Disinformation is running rampant in today’s world. The internet, social media, and AI — combined with declining trust in major institutions — have created an ecosystem ripe for exploitation by nefarious actors aiming to spread false and hateful narratives. Meanwhile, governments worldwide are struggling to get big tech companies to take substantive steps to combat disinformation. And at the global level, the UN’s priorities are also being hit hard by these trends.

- YouTube

What issues matter most to women and girls around the world? The United Nations wanted to understand how women all over the globe feel about the future and what they’d like to see for the next generation. The UN's We the Women campaign includes an ambitious survey of 25,000 women in 185 countries and a report on the priorities of women worldwide. GZERO’s Tony Maciulis spoke with Annemarie Hou, Executive Director of the UN Office for Partnerships, which conducted the campaign, to learn more.

We know that people will make more conscious spending decisions if armed with the information to do so. As a global payment network, Mastercard sits at the heart of the consumer-purchasing journey and is at work creating an ecosystem that inspires, informs, and enables more sustainable choices. To accelerate this progress, Mastercard Start Path will further open its doors to high-potential, climate-focused startups that share in our mission to connect and power an inclusive digital economy, with support from Mastercard’s Sustainability Innovation Lab. Learn more here.

Technology is rapidly changing how modern wars are being fought, and the United States needs to reevaluate its national security priorities to adapt. Former NATO Supreme Allied Commander, Admiral James Stavridis, joins Ian Bremmer on the GZERO World Podcast to discuss the transformation of war, China’s calculus in Taiwan, and the biggest threats facing the US, both inside the border and abroad.

Israel's Prime Minister Benjamin Netanyahu addresses the 79th United Nations General Assembly at U.N. headquarters in New York, U.S., September 27, 2024.
REUTERS/Eduardo Munoz

Israel's Prime Minister Benjamin Netanyahu gave a defiant speech at the UN on Friday, framing Israel’s campaigns in Gaza and Lebanon as a fight for the country’s survival, while criticizing the UN. Meanwhile, the Israeli military launched an airstrike in Beirut that killed longtime Hezbollah leader Hassan Nasrallah.

Japan's ruling Liberal Democratic Party lawmaker Shigeru Ishiba speaks during an interview with Reuters at his office in Tokyo, Japan August 31, 2020.

REUTERS/Kim Kyung-Hoon

Shigeru Ishiba has won the leadership election of Japan’s governing Liberal Democratic Party in a tight second-round run-off Friday morning and is set to become the country’s next prime minister.