Lyce · Hybrid Watch

hw_38a9631f7d0eeeb6

Denial-of-service attack knocks out Finnish Parliament website.

On 9 August 2022 the website of the Finnish Parliament was rendered inaccessible for several hours following a denial-of-service attack, as announced by the Finnish authorities. The hack was claimed by the pro-Russian hacker group “NoName057(16)”, which stated on Telegram it had targeted Finland in retaliation for its intent to join NATO. Finnish investigators with the National Bureau of Investigation (NBI) launched a probe into the “interference”, citing dozens of IP-addresses globally but providing no immediate public attribution beyond the hacktivist claim. While the attack did not produce physical damage, it targeted a core state institution at a moment of heightened geopolitical tension and therefore qualifies as hybrid-warfare pressure rather than mere vandalism. The geography (Finland’s capital) and timing (amid Russia-Ukraine conflict) underline Finland’s exposure even beyond its land border with Russia. The dynamics here emphasise digital intrusion as a precursor to or component of broader hybrid campaigns: degradation of governmental readiness, trust and digital sovereignty. Finnish authorities treated the event as part of the measurable threat environment, adjusting cyber-defence posture accordingly. Although no follow-on sabotage was publicly confirmed, the incident reinforced Finland’s shift toward recognising cyber and digital attacks as part of state-level hybrid aggression.

Occurrence
2022-08-09
Publication
2022-08-09T16:35:51Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
FI
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2022-08-09T16:35:51Z

    On 9 August 2022 the website of the Finnish Parliament was rendered inaccessible for several hours following a denial-of-service attack, as announced by the Finnish authorities. The hack was claimed by the pro-Russian hacker group “NoName057(16)”, which stated on Telegram it had targeted Finland in retaliation for its intent to join NATO. Finnish investigators with the National Bureau of Investigation (NBI) launched a probe into the “interference”, citing dozens of IP-addresses globally but providing no immediate public attribution beyond the hacktivist claim. While the attack did not produce physical damage, it targeted a core state institution at a moment of heightened geopolitical tension and therefore qualifies as hybrid-warfare pressure rather than mere vandalism. The geography (Finland’s capital) and timing (amid Russia-Ukraine conflict) underline Finland’s exposure even beyond its land border with Russia. The dynamics here emphasise digital intrusion as a precursor to or component of broader hybrid campaigns: degradation of governmental readiness, trust and digital sovereignty. Finnish authorities treated the event as part of the measurable threat environment, adjusting cyber-defence posture accordingly. Although no follow-on sabotage was publicly confirmed, the incident reinforced Finland’s shift toward recognising cyber and digital attacks as part of state-level hybrid aggression.