Lyce · Hybrid Watch

hw_ac45edb9cd2f52f0

Large-scale cyber-attack on Slovenian government web portals attributed to Russian intelligence-linked hackers.

The Embassy of Ukraine in Slovenia reported that a hacking group linked to Russian intelligence services (referred to as “Russia Reborn”) had carried out coordinated attacks on Slovenian government websites shortly after Slovenia committed to providing military aid to Ukraine. The affected portals included those of the Office of the President and other state institutions, temporarily disrupting access and raising concerns about data integrity and readiness. The cyber-attack hit Slovenia’s internal government infrastructure rather than occurring at its borders or involving maritime or air-space intrusion. The dynamics illustrate how Russian-linked actors are targeting allied states’ governmental networks to impose cost, undermine trust, and signal potential escalation, especially following policy moves favourable to Ukraine. While the incident did not publicly report destruction of infrastructure or direct sabotage, the targeting of key state digital systems elevates it beyond mere espionage, into the hybrid-warfare realm of disruption. Slovenia’s rapid acknowledgement of the attack and its link to Russian-intelligence-style methods underscores how small NATO/EU members are already in the cross-hairs of grey-zone operations.

Occurrence
2024-03-30
Publication
2024-03-29T23:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
SI
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2024-03-29T23:00:00Z

    The Embassy of Ukraine in Slovenia reported that a hacking group linked to Russian intelligence services (referred to as “Russia Reborn”) had carried out coordinated attacks on Slovenian government websites shortly after Slovenia committed to providing military aid to Ukraine. The affected portals included those of the Office of the President and other state institutions, temporarily disrupting access and raising concerns about data integrity and readiness. The cyber-attack hit Slovenia’s internal government infrastructure rather than occurring at its borders or involving maritime or air-space intrusion. The dynamics illustrate how Russian-linked actors are targeting allied states’ governmental networks to impose cost, undermine trust, and signal potential escalation, especially following policy moves favourable to Ukraine. While the incident did not publicly report destruction of infrastructure or direct sabotage, the targeting of key state digital systems elevates it beyond mere espionage, into the hybrid-warfare realm of disruption. Slovenia’s rapid acknowledgement of the attack and its link to Russian-intelligence-style methods underscores how small NATO/EU members are already in the cross-hairs of grey-zone operations.