Become an OC Media MemberSupport independent journalism in the Caucasus:
Join Today
Media logo
Cybersecurity

‘Russian hackers’ take down websites of Georgian media and president

A screenshot purportedly of the Georgian President’s website published by Publika.
A screenshot purportedly of the Georgian President’s website published by Publika.

The websites of Georgia’s President and two leading TV stations have been temporarily taken offline in an apparent cyberattack by Russian hackers.

The website of Georgian President Salome Zurabishvili was offline on Friday morning, with local media reporting that the site initially displayed a message attributing the attack to a Russian hacking network.

Screenshots purportedly of the site showed the message ‘HACKED BY COZY BEAR SLAVA [glory to] RUSSIA’ on a black background with an image of a green skull.

Cozy Bear is a hacking group that Western intelligence agencies have accused of being linked to the Russian security services. Several high-profile attacks, including on US government agencies have been attributed to the group.

The attack against the President’s website on Friday was at least the fourth target to be hit in Georgia within the last week.

Two major TV channels, Formula and Mtavari Arkhi had their sites breached over the past week.

In the early hours of Friday morning, Formula reported that their website was unusable due to a cyberattack. The head of Formula’s digital department, Mariam Bajelidze, said the attack started at dawn.

‘It was an attack attempt coming from several countries’, she said. ‘Users who entered the website were informed that the site was hacked by a Russian bear and it was written “Slava [glory to] Russia” there’.

Bajelidze said the attack was likely ‘an attempt to hack critical, oppositional websites’.

The previous day, Mtavari Arkhi said they had lost access to a part of their database, with their sit for several hours stating that they had been ‘hacked by NIGGERS’.

On Tuesday, the SovLab, whose stated aim is ‘analysis and exploration of the Soviet totalitarian past’, said they had been targetted by a ‘coordinated attack from Russia’.

‘Over the past several days, the intensity of the attacks has been growing exponentially, especially from Russia’, the organisation stated.

As of Friday afternoon, all four websites appeared to be operating normally.

Andro Gotsiridze, a cybersecurity expert, told Formula the hacks could be a form of ‘Russian aggression’.

‘When a cyber attack is carried out against Georgia in general and critical infrastructure, it is difficult not to think of Russia’, he said, adding little evidence had emerged either way so far.

Previous cyberattacks allegedly coming from Russia have also targeted government agencies and media outlets in Georgia, including large-scale attacks during the August 2008 war.

In October 2019, approximately 15,000 websites in Georgia, including those of major government institutions, broadcasters, online newspapers, and private businesses, were hit by a large-scale cyber attack.

The President’s Office has yet to publicly acknowledge the latest hack, and did not respond to a request for comment.

Read in Georgian on On.ge.
Read in Armenian on CivilNet.

Related Articles

Photo via social media.
Cybersecurity

Georgia fines Yandex taxi service for sharing user data with Russia

O

The Personal Data Protection Service of Georgia has fined Ridetech Georgia LLC, the company which provides the Yandex taxi apps, ₾4,000 ($1,500) for sharing the personal information of users and drivers in Georgia with Russia. On Monday, the agency said they had discovered during an inspection that the Yandex GO app for passengers and the Yandex Pro app for drivers connected to servers in Russia as part of the process of verifying users had an internet connection. In doing so, the IP addres

Armenian Government building. Image vis Factor.am
Armenia

Russian hackers reportedly attack Armenian government database

A

Russian hackers have reportedly hacked into an Armenian government-operated database. Armenia has previously been the target of a number of cyberattacks by Russian hackers amidst an ongoing deterioration of its relations with Russia. Reports of the attack first emerged on Wednesday, with RFE/RL citing a Telegram post in a private, inaccessible channel allegedly run by a Russian hacking group that claimed to have successfully infiltrated the database using an FTP code transfer system. ‘The da

Illustration: Dato Parulava/OC Media.
Azerbaijan

Azerbaijani news outlet Mikroskop taken down by ransomware attack

I

Azerbaijani news outlet Mikroskop has been taken offline in an apparent ransomware attack, with its management speculating that the government could be behind the attack. Mikroskop’s website was taken down on Saturday with a message purportedly from the attackers appearing demanding 0.5 bitcoin ($13,000) to unblock the website. The website remained offline as of Monday morning.  The outlet’s co-founder, editor-in-chief Fatima Karimova, told OC Media that a hacker group was behind the attack.

An image of former Georgian President Mikheil Saakashvili was displayed on many of the hacked websites.
2019 Georgia Cyber Attack

Russian military intelligence ‘was behind’ October cyberattack in Georgia

O

Russia’s military intelligence service, the GRU, was behind a massive cyberattack on Georgia in October 2019 that affected around 15,000 websites, British intelligence has alleged. The websites affected included those of major government institutions, broadcasters, online newspapers, and private businesses. Most of the hacked websites went offline or displayed a sliding image of a smiling former Georgian President Mikheil Saakashvili with the text: ‘I’ll be back’. [Read more about the cybera

Most Popular

Editor‘s Picks