Russian hackers have had access to Kyivstar since at least May 2023. This was stated by Illia Vitiuk, head of the SBU cybersecurity department, Reuters reports.
He called the cyberattack on the operator "a big message not only to Ukraine but to the entire Western world."
"This attack is a big message, a big warning not only for Ukraine, but for the entire Western world, so that they understand that no one is really safe," the SBU representative said.
According to Vitiuk, the cyberattack erased "almost everything," including thousands of virtual servers and computers. This may be the first example of a devastating cyberattack that "completely destroyed the core of a telecommunications operator."
During the investigation, the SBU found that the hackers had probably been trying to break into Kyivstar since March or earlier.
"At the moment, we can say with certainty that they have been in the system at least since May 2023," he said. - "I can't say now how long they had full access: probably since November at least.
The SBU estimates that the hackers could have stolen personal information, located phones, intercepted SMS messages, and possibly stolen Telegram accounts with the level of access they had, he said.
A Kyivstar spokesperson said the company is working closely with the SBU to investigate the attack and will take all necessary measures to eliminate future risks, adding: "No facts of leakage of personal and subscriber data have been found."
At the same time, according to Vitiuk, the cyberattack did not have a major impact on the Ukrainian military. They do not rely on telecom operators and use "different algorithms and protocols."
Vitiuk is "almost certain" that the cyberattack was carried out by Sandworm, a Russian group linked to the GRU. Earlier, the Solntsepek group, which the SBU links to Sandworm, claimed responsibility for the attack.
As Vitiuk says, the SBU is working to find out how the hackers entered Kyivstar and the type of programs they used. If it was an inside job, the insider who helped the hackers did not have a high level of authorization at the company, as the hackers used malware used to steal password hashes, the SBU official said. Samples of this malware have been recovered and are being analyzed.
It is unclear why the hackers chose December 12, he said, adding, "Maybe some colonel wanted to become a general."





