In 2023, NÚKIB registered a total of 262 cybersecurity incidents, the highest number to date. 2018 54 2019 78 2020 99 2021 157 2022 146 2023 This marks an increase of nearly 80 % compared to 146 incidents registered in 2022. 262 0 50 100 150 200 250 300 Figure 1: Evolution of the number of incidents registered by NÚKIB in 2018–2023 This increase was driven primarily by repeated waves of DDoS attacks, led mostly by Russian-affiliated hacktivist groups. DDoS attacks accounted for a significant portion of all incidents in 2023. The group NoName057(16) was identified as the most frequent perpetrator of these attacks, which regularly targeted Czech entities. First DDoS campaign by NoName057 (16) Further DDoS campaigns by NoName057 (16) Second DDoS campaign by NoName057 (16) 40 35 30 25 20 15 10 Jan. Feb. March April May June July Aug. Sept. Oct. Nov. Dec. 262 incidents in total The NoName057(16) campaigns against Czech targets typically coincided with events or statements linked to the conflict in Ukraine or other major occurrences. Examples include attacks in response to announcements of material or other assistance to Kyiv, or statements by Czech political leaders regarding the conflict in Ukraine. The Czech Republic was among the European countries most often targeted by this actor (Fig. 3). Figure 2: Evolution of the number of incidents registered by NÚKIB in 2023 However, the impact of the reported attacks was not severe and resulted, in most cases, in temporary unavailability of the targeted entities’ websites. DDoS attacks generally disrupt traffic on websites and services accessible from the internet without compromising the internal information systems of organisations. 11

Select target paragraph3