Skip to content
Research

Revolution Hacking — Nikolay Koval, in Cyber War in Perspective: Russian Aggression against Ukraine

NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) · 2015

First-hand technical account by the head of Ukraine's Computer Emergency Response Team (CERT-UA) at the time. States that CyberBerkut compromised the Central Election Commission on 21 May 2014, disabling core network nodes and components of the election system, and that for nearly 20 hours the software displaying real-time vote-count updates did not work properly. Records that on election day, 12 minutes before polls closed at 19:48 EET, the attackers posted an image on the CEC website falsely claiming Right Sector leader Dmytro Yarosh had won, and that the image was immediately shown on Russian TV channels. Reports that CERT-UA found APT28 (Sofacy/Sednit) espionage malware on the CEC network and that reconnaissance began in mid-March 2014. Concludes that the attack could in no way have determined the outcome, because votes are cast on paper ballots that are manually verified and physically delivered for aggregation.

IssuerNATO Cooperative Cyber Defence Centre of Excellence (CCDCOE)
Jurisdictionua
LanguageEN
RetrievedJuly 23, 2026
OriginalArchive pending

Cited by