7 July 2025

Kyivstar Cyber Attack: A Deep Dive Into Cyber Warfare in Ukraine

Evans Mugari

In 2022, amidst the ongoing Russo-Ukrainian conflict, one of the largest cyber attacks fell upon Kyivstar, the largest telecommunications provider in Ukraine, leaving millions without mobile and internet services. This attack underlined the vulnerability of national infrastructure but also served as a chilling reminder of how cyber warfare can be leveraged in geopolitical disputes. Kyivstar provides services to some 24 million subscribers; its disruption would thus constitute a critical blow to civilian communications and those military operations dependent on secure and reliable networks.

Threats Identified

Scale of Impact: The result of the cyber attack in Kyivstar was widely disruptive, with no services on voice calls, SMS and internet connectivity for hours that affected daily life and emergency responses. For example, public transportation in Kyiv, dependent upon mobile connectivity to pay tickets and schedule current time en masse, had been cast into chaos. Hospitals were cut off from important services that used mobile phone networks for their communications. This incident has shown how cyber attacks can bring a nation to its knees—from disrupting economic activities to affecting national security.

Attack Methodology: Cybersecurity experts believe the attack on Kyivstar is the work of an APT group, possibly sponsored by Russian state actors, due to their advanced cyber capabilities. The attack likely consisted of phishing, malware deployment and exploitation of network software vulnerabilities. A similar trick was used in the 2017 NotPetya attack, where Russian hackers targeted accounting software used by Ukrainian businesses with devastating global consequences. The Kyivstar breach could have been initiated with stolen employee credentials or zero-day exploits, which would showcase the careful planning and execution so typical of state-sponsored cyber operations.

No comments: