Lyce · Hybrid Watch

hw_35ac9fd2fde05efc

Moldova reports massive cyber-attack on election infrastructure, blaming Russian-linked actors.

Moldova’s Information Technology and Cybersecurity Service (STISC) announced it had blocked a series of cyber-attacks targeting its parliamentary election infrastructure, including the website of the Central Electoral Commission (CEC), cloud servers used for election processing, and overseas diaspora voting stations. The attacks reportedly involved massive distributed-denial-of-service (DDoS) waves—one campaign registered over 16 million automated session attempts—aimed at degrading availability of key state electoral systems just days before the vote. While the government attributed the activity to “foreign actors” and found patterns connected to Russian-linked hacking groups, formal attribution to the Russian state was not fully disclosed. The disruption spans Moldova’s national capital region and its diaspora/voting networks abroad, illustrating how hybrid threats can reach beyond immediate territorial borders. The hybrid-warfare dynamics are clear: by targeting the electoral process rather than kinetic assets, adversarial actors seek to undermine democratic legitimacy, erode trust in institutions and impose defensive burdens on a smaller allied or candidate state.

Occurrence
2025-09-28
Publication
2025-09-27T22:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
MD
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2025-09-27T22:00:00Z

    Moldova’s Information Technology and Cybersecurity Service (STISC) announced it had blocked a series of cyber-attacks targeting its parliamentary election infrastructure, including the website of the Central Electoral Commission (CEC), cloud servers used for election processing, and overseas diaspora voting stations. The attacks reportedly involved massive distributed-denial-of-service (DDoS) waves—one campaign registered over 16 million automated session attempts—aimed at degrading availability of key state electoral systems just days before the vote. While the government attributed the activity to “foreign actors” and found patterns connected to Russian-linked hacking groups, formal attribution to the Russian state was not fully disclosed. The disruption spans Moldova’s national capital region and its diaspora/voting networks abroad, illustrating how hybrid threats can reach beyond immediate territorial borders. The hybrid-warfare dynamics are clear: by targeting the electoral process rather than kinetic assets, adversarial actors seek to undermine democratic legitimacy, erode trust in institutions and impose defensive burdens on a smaller allied or candidate state.