● OVERVIEW OF 2024
SSSCIP CHIEF:
Russia operates
more covertly
in cyberspace
We learn about the cyberattacks thwarted in 2024 through an interview
with Brigadier General Oleksandr Potii, head of Ukraine’s State Service
of Special Communications and Information Protection (SSSCIP)
and a close partner of CERT-EE.
How have Russian cyberattack capabilities
evolved in 2024? What changes have you
observed compared with the previous year?
In 2023, we saw destructive cyberattacks by
Russian hacker groups targeting IT and telecommunications companies. At least 11 internet service providers suffered from such
attacks, culminating in the cyberattack on
Kyivstar in December 2023. These attacks were
accompanied by data leaks and publications on
Russian social media networks.
In 2024, Russia gradually shifted away from
publicising its cyberattacks, as it focused
instead on cyber intelligence operations targeting systems linked to war and politics, aiming
to remain undetected for as long as possible.
The main targets were Ukraine’s security and
defence sectors, as well as companies directly
supporting them.
There was also a significant increase in the
activity of Russian financially motivated groups
in 2024, including targeted cyberattacks on
large organisations and various fraud schemes.
We believe these criminal hacker groups operate under the direction or approval of the Rus16
sian government, as some engage in both financial theft and cyber espionage.
Have you observed AI-enabled cyberattacks
from Russia? Has the broader use of AI led to
any significant changes?
AI is already being used in cyberattacks, for
example, to generate phishing emails in Ukrainian or to facilitate interactions between hackers
and victims through messaging apps or email.
The use of AI components will undoubtedly
increase further.
In 2024, there was only one widely publicised
attack on Ukraine’s critical infrastructure – the
December attack on state registries. This seems
to suggest your defences have been largely
effective. Which critical sectors faced the
greatest threats last year?
Indeed, 2024 ended with a high-profile attack
on the Ministry of Justice’s registries. However,
attempts to target critical infrastructure were
detected throughout the year.
For example, in March, preparations by
UAC-0002 (also known as Sandworm) for
CYBER SECURITY IN ESTONIA 2025