Kyivstar, Ukraine’s largest mobile operator, suffered an attack in December 2023 that removed service for a subscriber base reported at around 24 million mobile and over a million home internet customers, for several days.
Illia Vitiuk, head of the Security Service of Ukraine’s cyber security department, reported that the investigation found the attackers had been in Kyivstar’s systems since May 2023 and held full access by November at the latest. The SSU attributed the activity to Sandworm.
Seven Months Of Access, Then Destruction
The corpus records long dwell times regularly — ten months at 26-0620, nine and a half years of exposure at 23-0512. What separates this file is what the dwell was for.
Most intrusions in this database end in extraction: data leaves and is monetised. Here the reported end state was destruction of the environment, which means the months of access were preparation for a single irreversible action rather than a sustained harvest.
The Harm Reached The Air Raid Alerts
Reporting described the disruption extending to air raid alert systems. In a country under bombardment, a telecommunications outage is not an inconvenience to be measured in lost revenue.
The corpus argues throughout that availability harm is under-recorded because no regime asks for it. This is the file where the argument stops being about accounting: the missing measurement is warnings that did not reach people.
The Destruction Figures Are The Attackers’ Own
A group associated with Sandworm claimed to have destroyed 10,000 computers, more than 4,000 servers and all cloud storage and backup systems. Those figures come from the people claiming the attack.
The desk does not carry them in the record, for the same reason it does not carry leak-site volumes at 23-0203 or a ransom claim at 23-1108. That the destruction was severe is established by the outage; the inventory is advertising.
Built on contemporaneous reporting of the attack and of statements by the head of the SSU’s cyber security department. The subscriber figures, the multi-day outage, the presence in systems since May 2023, full access by November and the attribution to Sandworm are the SSU’s findings and Kyivstar’s figures as reported. The claimed counts of destroyed computers, servers and backup systems originate with a group claiming responsibility and are labelled as claims in the body; they are not in the record. The effect on air raid alert systems is as reported. This desk has read no primary SSU document and relies on reporting of those statements. Graded high. Corrections: corrections@forensicpost.com.
- Ukraine Blames Russian Sandworm Hackers for Kyivstar AttackInfosecurity Magazine
- Russian Sandworm Group Spied on Kyivstar Networks for MonthsBankInfoSecurity