ua en ru

War cyber front - How Ukraine's security service counters Russian attacks on critical infrastructure

War cyber front - How Ukraine's security service counters Russian attacks on critical infrastructure Photo: Ukraine counters Russian cyberattacks (Getty Images)
Author: Oleh Velhan

Since the start of Russia’s full-scale invasion, specialists from Ukraine’s Security Service cybersecurity department have neutralized more than 14,000 large-scale cyberattacks targeting government agencies and critical infrastructure facilities, according to the Security Service of Ukraine.

According to Volodymyr Karastelov, head of the Security Service of Ukraine’s Cybersecurity Department, in the documentary Ukraine’s Cyber Shield, the unit is simultaneously countering Russia’s specialized cyber units and affiliated hacker groups, as well as neutralizing Russian information and psychological operations conducted both against Ukraine and partner countries.

Karastelov said that in 2025 alone, cyber specialists repelled more than 3,000 attacks. Most of them were aimed at disabling digital services or destabilizing the operations of strategically important enterprises in the energy, transport, and defense sectors.

The unit also prevents Russian infiltration into government and military networks and counters DDoS attacks, phishing campaigns, cyber espionage, and digital terrorism.

At the same time, Karastelov noted that the Security Service of Ukraine is not only defending but also carrying out active operations in hostile digital space, the details of which are not being disclosed.

Russian cyberattacks

Russia carried out a series of cyberattacks on Poland’s energy sector at the end of 2025, nearly leaving the country without electricity.

According to Polish Minister of Digital Affairs Krzysztof Gawkowski, numerous attacks on the energy sector took place in late 2025, and the situation was difficult to control, particularly due to unfavorable weather conditions.

Russia continues to conduct cyberattacks across Europe. The European Commission has said such operations occur daily and primarily target critical infrastructure, including the energy sector, the banking system, and healthcare, with the aim of destabilizing public processes.

Russia is also waging hybrid cyber warfare against the United States. In November 2025, a Russian cyberattack targeting municipal infrastructure was recorded in the US.

Hackers gained access to the networks of an American engineering company working with contractors in water supply, transport systems, and emergency services.

As a result of the attack, the perpetrators obtained information on the company’s internal processes as well as access levels related to the management of critical infrastructure facilities.