During 2022, based on the mandate granted by the National Security Council, the NÚKIB
worked on a bill aiming to significantly limit the impact of high-risk contractors on the
country‘s most important infrastructure. While cybersecurity threats arising from technology
supply chains have long been known, there is still no comprehensive legal mechanism in the
Czech legal system to enable targeted assessment and mitigation of the risks arising from
these threats (more in the chapter: Ensuring Cybersecurity on a National Level: Strengthening
Resilience against Cyber Threats).
Cyber Threat Actors
!
State-sponsored and cybercrime activities in cyberspace have long been among
the most serious threats to the Czech Republic’s cybersecurity.
!
State-sponsored groups are typically highly sophisticated actors using a wide range of techniques
to achieve their goals and constantly refining their tools. Russian state actors in particular
represented an increased risk for the Czech Republic during the last year. In the context of the
Russian invasion, a cyberattack from early 2022 was attributed by all member states through
the process of coordinated attribution to the Russian Federation. This attack had also indirect
impact on Czech entities (see Box).
Cyberattack on Satellite Internet Provider Viasat
In the early morning of February 24, 2022, around the same time as the invasion of the
Russian armed forces, a cyberattack was launched against Viasat‘s ground terminals providing
satellite internet connectivity in Ukraine. The attack gradually limited their functionality, with
a spillover effect impacting tens of thousands of users in North Africa, the Middle East and
Europe, including some in the Czech Republic. Thanks to the relatively low number of Viasat
users, this attack had no significant impact on the Czech Republic.
In 2022, the NÚKIB also registered a cyber espionage campaign against one of the national
strategic institutions, highly likely (75-85 %) carried out by the Russian state-sponsored actor
APT29 (also known as Cozy Bear, The Dukes, or NOBELIUM). This actor is usually attributed to
the Russian Foreign Intelligence Service (SVR). In this campaign, the email account of one of the
target institution’s employees was compromised. The attacker then used the account to send
spear-phishing emails to over a thousand addresses of partner organizations. The list of victims
of this campaign indicates that the actor’s goal was to gain access to strategic information.
Last year, the NÚKIB also registered increased activity of pro-Russian hacktivist groups Killnet
and Anonymous Russia, which carried out DDoS attacks against a number of Czech entities.
These groups represent rather less sophisticated actors and the effects of their attacks have
been marginal.
20