2022_cyberattacks_on_Romania

2022 DDoS attacks on Romania

2022 DDoS attacks on Romania

Series of cyberattacks on Romanian government and websites


Beginning 29 April 2022, at 04:05 EEST, a series of multiple DDoS attacks were launched against several Romanian government, military, bank and mass media websites. Behind the attacks was the pro-Kremlin hacking group Killnet, who resorted to this in response to a declaration made by Florin Cîțu, the then-President of the Senate of Romania, that Romania would provide Ukraine with military aid. The Russian Federation, who invaded the latter, publicly spoke against Western military support for Ukraine, stating that it would result in "lightning-fast retaliatory strikes". The DDoS attacks continued until 1 May.

Background

On 26 April 2022, the President of the Chamber of Deputies of Romania Marcel Ciolacu, Prime Minister Nicolae Ciucă and Minister of Foreign Affairs Bogdan Aurescu visited Kyiv, Ukraine, to meet with Ukrainian President Volodymyr Zelenskyy, Ukrainian Prime Minister Denys Shmyhal, and with the president of the Verkhovna Rada, Ruslan Stefanchuk. In the meeting, Romania reiterated its support for Ukraine and its European integration aspirations, as well as committing to active involvement in the reconstruction of the country.[1]

The meeting was planned since as early as 13 April, with the Romanian delegation initially consisting of the President of the Senate Florin Cîțu and the President of the Chamber of Deputies Marcel Ciolacu, both visiting Kyiv on 27 April at the invitation of Stefanchuk.[2] Prime Minister Ciucă justified the absence of Cîțu around the fact that there were two state visits separately planned, under condition by the safety measures imposed in Kyiv due to the 2022 Russian invasion of Ukraine.[3] Nevertheless, Florin Cîțu visited Kyiv by himself on 27 April 2022,[4] after which he stated that Romania should do more for Ukraine, supporting them with military equipment.[5]

Russia claimed that Western military support for Ukraine are "posing a threat to European security". Russian President Vladimir Putin stated that "if someone intends to intervene in the ongoing events [Russian invasion of Ukraine] from the outside, and create strategic threats for Russia that are unacceptable to us, they should know that our retaliatory strikes will be lightning-fast".[6]

Cyberattack

On 29 April 2022, at 04:05 EEST, the websites of the Ministry of National Defence (MApN), the Romanian Border Police, the Government of Romania, and of CFR Călători were taken down by a DDoS attack. According to the MApN, the cyberattack did not compromise the functioning of its website, but rather prevented user access to it. The government stated that IT specialists at the structures at governmental level are collaborating with experts from specialized institutions to restore access and identify the causes. In the meantime, CFR Călători issued alternative means of purchasing train tickets digitally.[7]

The Romanian Intelligence Service (SRI) stated that the hackers behind the cyberattack used network equipment from outside Romania.[8] The pro-Kremlin hacking group Killnet claimed the attacks through Telegram, stating that "the president of the Romanian Senate, Marcel Ciolacu issued a statement promising the Ukrainian authorities "maximum assistance" in supplying lethal weapons to Kyiv". Furthermore, they revealed a list of websites that it took down through the DDoS attack, where the website of OTP Bank (the Romanian division) was also listed.[9] The Directorate for Investigating Organized Crime and Terrorism (DIICOT) was notified in the case, and access to the websites was restored.[7][10]

At 19:30 EEST, another DDoS attack was launched, this time on the website of the Ciolacu-led Social Democratic Party (PSD), taking it down in a similar manner. In response, the party's IT department quickly took action and restored access to the website within 15 minutes.[10]

In retaliation, Romania's National Cybersecurity Directorate (DNSC) published a list of 266 IP addresses involved in the 29 April DDoS attacks to its official website. On 30 April, at approximatively 2:30 EEST, this website had also been taken down through a further DDoS attack by the pro-Kremlin hacking group, with user access restored by 8:30 EEST.[11] Later the same day, a further DDoS attack took down the website of the Romanian Police.[12]

The pro-Kremlin hacking group threatened to take down another 300 Romanian websites in a similar manner, including websites of stores, military, government, mass-media, banks, hospitals, educational institutions, political parties, etc. Some websites using Moldovan (.md) domains were also included in the list.[13]

On 1 May 2022, Killnet took down the websites of seven Romanian airports (including those located in Bucharest, Cluj-Napoca, etc.), as well as of the TAROM airline and several news media websites, including Digi24, among others.[14]

It has been suspected that a Romanian resident in the United Kingdom helped Killnet take down Romanian websites, translating content in Romanian into Russian. They were put in custody.[15] In retaliation, Killnet threatened to "destroy Romania, the United Kingdom and Moldova" if they are not released in 48 hours.[16]

Public reactions

Romania's Minister of Defence, Vasile Dîncu described the cyberattacks as "symbolic attacks".[17] The President of the Chamber of Deputies of Romania Marcel Ciolacu called his nominalization as "Senate president" by Killnet a mistake (as the presidency of the Senate was held by Florin Cîțu),[18] and stated that "if needed, Romania is ready both legally and morally to take this step [to supply Ukraine with military equipment]. At this moment [at the time of the first attacks], there is no decision".[19] In the meantime, the Romanian hacking group "Anonymous Romania" stated that it launched a counterattack against a Russian governmental website.[20]

Florin Cîțu, the president of the Senate, reacted as well: "First of all, I do not know what kind of hackers are those who do not know who the president of the Senate or the president of the Chamber of Deputies is [...]. Secondly, if we look at that [Killnet's] statement it is bizarre to have the picture of the President of the Chamber of Deputies, to have the correct name, but to mistake his position [...]. A simple search on Wikipedia and you would have found out who the president of the Senate is".[21]

See also


References

  1. "Imagini cu Marcel Ciolacu și Nicolae Ciucă la Kiev, cu Volodimir Zelenski. Vizita ar fi trebuit să aibă loc mâine, împreună cu Florin Cîțu". www.antena3.ro (in Romanian). Retrieved 2022-04-29.
  2. "Marcel Ciolacu și Florin Cîțu merg la Kiev pe 27 aprilie". www.digi24.ro (in Romanian). Retrieved 2022-04-29.
  3. "Site-ul PSD inactiv după ce a fost atacat de hakerii ruși de la Killnet". www.antena3.ro (in Romanian). Retrieved 2022-04-29.
  4. "Continuă seria de atacuri de tip DDoS asupra site-urilor românești". www.antena3.ro (in Romanian). Retrieved 2022-04-30.

Share this article:

This article uses material from the Wikipedia article 2022_cyberattacks_on_Romania, and is written by contributors. Text is available under a CC BY-SA 4.0 International License; additional terms may apply. Images, videos and audio are available under their respective licenses.