Lyce · Hybrid Watch

hw_dbdf60775a6e8fc3

DDOS cyberattack on Lithuania by the Russian-linked hacker group Killnet.

On 27 June 2022, Killnet publicly claimed responsibility for a distributed-denial-of-service (DDOS) cyberattack against Lithuania, stating that they had “demolished 1,652 web resources” and that their campaign would continue until Lithuania lifted its transit restrictions to the Russian exclave of Kaliningrad. The motive cited by the hackers was Lithuania’s enforcement of European Union sanctions that blocked certain sanctioned goods from transiting through Lithuania to Kaliningrad. The dynamics here reflect how Moscow-aligned or state-tolerated groups use asymmetric means—cyberattacks—to impose costs and shape policies without conventional military engagement. The incident sent a signal to Lithuania and other Baltic states: enforcing sanctions and acting against Russian interests may provoke digital retaliation. For Lithuania, the incident underscored the need to bolster not only physical defense but also cyber resilience, particularly given its frontline proximity to the Russian exclave and supply corridors. The event also shows that hybrid warfare operations often follow policy decisions (in this case transit sanctions) rather than without trigger. Although no lasting major outage was reported publicly, the scale of claimed targets (1,652 resources) implies either significant capability or at least credible threat, raising alarm in Lithuanian cyber-security circles.

Occurrence
2022-06-27
Publication
2022-06-26T22:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
LT
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2022-06-26T22:00:00Z

    On 27 June 2022, Killnet publicly claimed responsibility for a distributed-denial-of-service (DDOS) cyberattack against Lithuania, stating that they had “demolished 1,652 web resources” and that their campaign would continue until Lithuania lifted its transit restrictions to the Russian exclave of Kaliningrad. The motive cited by the hackers was Lithuania’s enforcement of European Union sanctions that blocked certain sanctioned goods from transiting through Lithuania to Kaliningrad. The dynamics here reflect how Moscow-aligned or state-tolerated groups use asymmetric means—cyberattacks—to impose costs and shape policies without conventional military engagement. The incident sent a signal to Lithuania and other Baltic states: enforcing sanctions and acting against Russian interests may provoke digital retaliation. For Lithuania, the incident underscored the need to bolster not only physical defense but also cyber resilience, particularly given its frontline proximity to the Russian exclave and supply corridors. The event also shows that hybrid warfare operations often follow policy decisions (in this case transit sanctions) rather than without trigger. Although no lasting major outage was reported publicly, the scale of claimed targets (1,652 resources) implies either significant capability or at least credible threat, raising alarm in Lithuanian cyber-security circles.