Lyce · Hybrid Watch

hw_dada4930cb00d87d

Pro-Kremlin hacker group Killnet targets Latvia’s national parliament website after the Saeima officially declares Russia a “state sponsor of terrorism”.

A group of pro-Russian hacktivists known as Killnet claimed responsibility for a distributed‐denial‐of‐service (DDoS) attack that temporarily took down the Latvian parliament’s website shortly after its members voted to designate Russia as a state sponsor of terrorism. Riga is the political-administrative hub of Latvia, and the timing of the cyber‐strike aligned with a diplomatic assertion that shifted Latvia further into the conflict circle with Russia. By using non‐kinetic digital means, the adversary targeted national sovereignty, forced resources into IT-mitigation, signalled capability and intent, while staying below the threshold of open warfare. Latvia’s national CERT reported that the parliament’s operations were not disrupted thanks to pre-existing defensive measures, but the attack nonetheless raised concerns about the vulnerability of legislative digital infrastructure. Analysts noted that the Latvian vote triggered the attack, marking a pattern: whenever Baltic states make symbolic moves against Russia, they are hit by cyber‐pressure shortly after. Although the direct attribution to the Russian Federation government was not formally declared, the direction and method align with the Russian hybrid toolkit as applied against Baltic nations.

Occurrence
2022-08-11
Publication
2022-08-10T22:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
LV
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2022-08-10T22:00:00Z

    A group of pro-Russian hacktivists known as Killnet claimed responsibility for a distributed‐denial‐of‐service (DDoS) attack that temporarily took down the Latvian parliament’s website shortly after its members voted to designate Russia as a state sponsor of terrorism. Riga is the political-administrative hub of Latvia, and the timing of the cyber‐strike aligned with a diplomatic assertion that shifted Latvia further into the conflict circle with Russia. By using non‐kinetic digital means, the adversary targeted national sovereignty, forced resources into IT-mitigation, signalled capability and intent, while staying below the threshold of open warfare. Latvia’s national CERT reported that the parliament’s operations were not disrupted thanks to pre-existing defensive measures, but the attack nonetheless raised concerns about the vulnerability of legislative digital infrastructure. Analysts noted that the Latvian vote triggered the attack, marking a pattern: whenever Baltic states make symbolic moves against Russia, they are hit by cyber‐pressure shortly after. Although the direct attribution to the Russian Federation government was not formally declared, the direction and method align with the Russian hybrid toolkit as applied against Baltic nations.