Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ukrainian security officials said Russian-linked hackers had access to Kyivstar’s network for months before the telecom provider’s December 12, 2023 cyberattack disrupted service. SBU cybersecurity chief Illia Vitiuk said the attackers may have gained access as early as May and potentially full access by November. Kyivstar did not confirm that timeline at the time, and the reported access does not establish that customer data was stolen.

What happened to Kyivstar on December 12, 2023?

Kyivstar, one of Ukraine’s major telecommunications providers, said a widespread hacker attack caused a technical failure on the morning of December 12, 2023. Mobile and home internet services were disrupted. Contemporaneous coverage reported that roughly 24 million users were affected; that figure describes the scale of service impact, not a confirmed number of people whose data was exposed. VEON’s December 12 filing described the initial attack and technical failure.

How long were hackers reportedly inside the network?

In a Reuters interview reported by CyberScoop on January 4, 2024, SBU cybersecurity chief Illia Vitiuk said attackers had access to Kyivstar’s network since at least May 2023 and may have gained full access by November. These are Vitiuk’s reported assessments, not a duration Kyivstar confirmed.

Kyivstar told CyberScoop that it could not confirm how long attackers had access, that its official investigation was ongoing, and that investigators were considering multiple versions of events. The company’s qualification and Vitiuk’s account address different things: the first describes what Kyivstar had established during its investigation at the time; the second is the SBU official’s assessment of the intrusion timeline. CyberScoop’s account and the Kyiv Independent’s republication of Reuters report these statements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who did Ukrainian officials blame?

Ukrainian officials attributed the attack to Sandworm, a unit associated with Russian military intelligence. A persona calling itself Solntsepek publicly claimed responsibility, and Ukrainian officials linked it to Sandworm. This is an attribution by Ukrainian authorities and a public claim of responsibility; the available contemporaneous material does not establish independent forensic confirmation. The National Security and Defense Council of Ukraine’s cyber digest records the official Ukrainian account.

Does the reported access mean customer data was stolen?

No. Vitiuk said the attackers’ level of access could have enabled them to steal personal information, infer phone locations, intercept SMS messages, and perhaps access Telegram accounts. Those are potential capabilities he described, not confirmed actions or proof that information was exfiltrated.

Kyivstar said at the time that it had seen no evidence of personal-data leakage. That statement does not settle the intrusion timeline, just as the SBU official’s account of possible access does not prove data theft. VEON’s December 12, 2023 filing confirms the company’s initial report of a widespread attack and technical failure; it does not substantiate the later May-to-November timeline or actor attribution.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the timeline does—and does not—establish

  • December 12, 2023: Kyivstar reported a widespread cyberattack and technical failure that disrupted service.
  • May 2023 and November 2023: Vitiuk said attackers had access by at least May and may have gained full access by November; Kyivstar did not confirm the duration at the time.
  • Attribution: Ukrainian officials blamed Sandworm and linked the Solntsepek claim to that unit; the cited material does not establish independent forensic confirmation.
  • Data exposure: The access described could have enabled several forms of surveillance or data theft, but those possibilities were not evidence that the actions occurred. Kyivstar said it had seen no evidence of personal-data leakage.

These are contemporaneous claims and disclosures from 2023–2024. They do not establish the present status of Kyivstar’s investigation or any later forensic findings. Vitiuk described the incident as “a big message, a big warning, not only to Ukraine, but for the whole Western world to understand that no one is actually untouchable,” as quoted by CyberScoop in its January 4, 2024 account.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.