hw_61fe2658b4e241c4
Isländisches Parlament und mehrere Regierungswebsites während prorussischer hacktivistischer DoS-Kampagne offline genommen.
Am Morgen des 16. Mai 2023 kam es beim Webportal des isländischen Parlaments und bei mehreren weiteren kritischen Websites öffentlicher Institutionen zu Ausfällen, die Islands Cyberbehörden einer koordinierten Denial-of-Service-Kampagne zuschrieben. Islands CERT-IS (National Cyber Security Centre) erhöhte die „Ungewissheitsstufe“ des Zivilschutzes und bezeichnete die Störung öffentlich als ungewöhnlich breit angelegt, wobei es auf mehrere Hosting-Parteien und Infrastrukturabhängigkeiten verwies. Etwa zur gleichen Zeit reklamierte die prorussische hacktivistische Gruppe NoName057(16) die Verantwortung für Angriffe auf isländische Websites und deutete an, die Aktion sei Teil einer größeren, russlandnah ausgerichteten Hybridkampagne. Obwohl kein physischer Schaden entstand, unterstreicht die Zielauswahl im Verteidigungs- und Regierungsökosystem Islands die Anfälligkeit des Landes für Druck im Cyberraum als Teil hybrider Kriegsführung. Reykjavík beherbergt zentrale staatliche Institutionen, wodurch jede Störung dort im Kontext des Kleinstaates Island symbolisch wirkungsvoll und operativ bedeutsam ist. Die Dynamik spiegelt eine Störung der Verfügbarkeit statt Datenexfiltration wider, erzwingt die Umlenkung von Ressourcen von Bereitschaftsaufgaben zum Vorfallmanagement und ereignete sich im Vorfeld des in Reykjavík abgehaltenen Gipfels des Europarats, was den Signalwert erhöhte. Der Vorfall floss in die Heraufstufung der isländischen Bedrohungsbewertung ein, die anerkennt, dass Cyberangriffe auf Regierungsdomänen als Testfelder für gestaffelte hybride Operationen dienen können. Kurz gesagt zeigt dieses Ereignis, dass selbst ein digital abgelegener Inselstaat wie Island Teil des multidomänenübergreifenden Schauplatzes hybrider Kriegsführung ist, in dem Cyberangriffe Luft-, See- oder Infrastrukturbedrohungen vorausgehen oder sie begleiten.
E/M/R/S-Werte
- EExistenz0/4 · Nicht bewertet
- MAbsicht0/4 · Nicht bewertet
- RVerbindung zu russischem Akteur0/4 · Nicht bewertet
- SVerantwortung des russischen Staates0/4 · Nicht bewertet
Fakten
Keine Fakten
Quellen
-
- Rolle
- discovery_lead
- Datum
- 2023-05-15T22:00:00Z
On the morning of 16 May 2023 the web-portal of Iceland’s Parliament and a number of other critical public-institution websites experienced outages attributed by Iceland’s cyber-authorities to a coordinated denial-of-service campaign. Iceland’s CERT-IS (National Cyber Security Centre) elevated the civil-protection “uncertainty level” and publicly flagged the disruption as being unusually broad, citing multiple hosting-parties and infrastructure-dependencies. Around the same time the pro-Russian hacktivist group NoName057(16) claimed responsibility for attacks on Icelandic websites, suggesting the action was part of a larger Russia-aligned hybrid-campaign. Although no physical damage was inflicted, the targeting of the defence/government ecosystem in Iceland underscores the country’s exposure to cyber-domain pressure as part of hybrid warfare. Reykjavík hosts key state institutions, making any disruption there symbolically potent and operationally meaningful in the small-state context of Iceland. The dynamics reflect disruption of availability rather than data exfiltration, forcing resource diversion from readiness tasks to incident management, and occurring in the lead-up to the Council of Europe summit held in Reykjavík, which heightened the signalling value. The incident fed into Iceland’s threat-assessment upgrading—recognising that cyber-attacks on governmental domains can serve as test-beds for layered hybrid operations. In short, this event demonstrates how even a digitally remote island nation like Iceland is part of the multi-domain hybrid warfare theatre, where cyber-attacks precede or accompany air, sea or infrastructure threats.