{"id":8369,"date":"2022-04-25T10:00:00","date_gmt":"2022-04-25T10:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-3628\/"},"modified":"2026-07-04T10:23:48","modified_gmt":"2026-07-04T10:23:48","slug":"cyber-war-in-ukraine-how-companies-can-protect-themselves-against-spillover-attacks","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2022\/04\/25\/cyber-war-in-ukraine-how-companies-can-protect-themselves-against-spillover-attacks\/","title":{"rendered":"Cyber War in Ukraine: How Companies Can Protect Themselves Against Spillover Attacks"},"content":{"rendered":"<p><strong>Since Russia\u2019s invasion of Ukraine in February 2022, the cyber threat landscape for European companies has intensified dramatically. Wiper malware, DDoS attacks, and targeted espionage campaigns threaten not only Ukrainian targets  &#8211;  spillover effects are also hitting German firms.<\/strong><\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li><strong>Wiper malware:<\/strong> HermeticWiper and WhisperGate destroy data permanently  &#8211;  no ransom demand, only destruction.<\/li>\n<li><strong>Spillover risk:<\/strong> NotPetya in 2017 began as a Ukraine-focused attack but caused $10 billion in global damage.<\/li>\n<li><strong>BSI alert level Orange:<\/strong> The BSI (Federal Office for Information Security) has elevated Germany\u2019s threat level to \u201celevated.\u201d<\/li>\n<li><strong>Kaspersky warning:<\/strong> The BSI warns against using Kaspersky products.<\/li>\n<li><strong>Critical infrastructure:<\/strong> Energy providers and logistics companies are primary spillover targets.<\/li>\n<\/ul>\n<h2>Cyber warfare running parallel to ground warfare<\/h2>\n<p>Hours before Russia\u2019s invasion on 24 February 2022, Ukrainian government systems were hit with HermeticWiper  &#8211;  a wiper malware. Unlike ransomware, wiper malware demands no ransom; it erases data irreversibly. Simultaneously, Ukrainian banks and media outlets were crippled by DDoS attacks.<\/p>\n<p>Russia\u2019s cyber warfare strategy combines state-backed actors (e.g., Sandworm, Fancy Bear) and criminally affiliated groups acting out of patriotic motivation  &#8211;  or direct instruction. The line between state-sponsored and criminal cyber activity is increasingly blurred.<\/p>\n<h2>Why German companies are at risk<\/h2>\n<p>The 2017 NotPetya incident demonstrates that cyberattacks launched amid geopolitical conflict rarely remain confined to their intended target country. Shipping giant Maersk lost $300 million; pharmaceutical company Merck lost $870 million  &#8211;  despite having no operational ties to Ukraine. As a result, the BSI has raised its national threat level to Orange and explicitly warned of spillover effects.<\/p>\n<p>Companies especially at risk include those with subsidiaries in Ukraine or Russia, suppliers to critical infrastructure, users of Russian software (per the BSI\u2019s Kaspersky warning), and firms operating in energy, logistics, and finance sectors.<\/p>\n<h2>Immediate protective measures to implement now<\/h2>\n<p>The BSI recommends concrete, urgent actions: verify and test offline backups; update and rehearse incident response plans; strengthen network segmentation; shorten patching cycles to 24 hours; evaluate alternatives to Kaspersky; and analyze threat intelligence on Russian APT groups. Companies should also assess their incident response capabilities  &#8211;  and consider retaining an external incident response (IR) provider.<\/p>\n<h2>Key Facts at a Glance<\/h2>\n<p><strong>BSI alert level:<\/strong> Orange (elevated threat level since February 2022)<\/p>\n<p><strong>Known wipers:<\/strong> HermeticWiper, WhisperGate, IsaacWiper, CaddyWiper<\/p>\n<p><strong>NotPetya damage (2017):<\/strong> Over $10 billion globally<\/p>\n<p><strong>Kaspersky warning:<\/strong> BSI advisory dated 15 March 2022<\/p>\n<p><strong>Sources:<\/strong> BSI security advisory, CISA Shields Up Advisory, March 2022<\/p>\n<p><strong>Fact:<\/strong> According to IBM, 95 percent of all cybersecurity incidents stem from human error.<\/p>\n<p><strong>Fact:<\/strong> According to Bitkom, German companies invest an average of 14 percent of their IT budget in cybersecurity.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>What is wiper malware  &#8211;  and how does it differ from ransomware?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Wiper malware destroys data permanently, without demanding a ransom. While ransomware encrypts data and offers decryption keys in exchange for payment, wipers have one sole objective: maximum destruction. Backups are the only viable recovery option.<\/p>\n<\/details>\n<details>\n<summary><strong>Why is the BSI warning against Kaspersky?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The BSI sees a significant risk that Kaspersky could be instrumentalized by Russian authorities for cyber warfare. Its software enjoys deep system-level access and routinely communicates with servers located in Russia. The BSI recommends migrating to alternative solutions.<\/p>\n<\/details>\n<details>\n<summary><strong>How likely is a spillover attack against German companies?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">NotPetya proves spillover effects are both real and devastating. The BSI assesses the likelihood as elevated. Companies with operational links to Ukraine or Russia  &#8211;  and operators of critical infrastructure  &#8211;  are particularly vulnerable.<\/p>\n<\/details>\n<details>\n<summary><strong>What does BSI alert level Orange mean?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Orange is the BSI\u2019s second-highest alert level and signals a business-critical escalation in threat severity. Companies must immediately implement protective measures, activate emergency response plans, and maintain heightened vigilance across all IT systems.<\/p>\n<\/details>\n<details>\n<summary><strong>Which specific immediate actions does the BSI recommend?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Verify and test offline backups; update emergency response plans; tighten network segmentation; shift to 24-hour patching cycles; evaluate Russian software usage; enforce multi-factor authentication (MFA); and train staff to recognize current phishing campaigns.<\/p>\n<\/details>\n<h2>Further Reading Online<\/h2>\n<p>Cloud security during crises on cloudmagazin: <a href=\"https:\/\/www.cloudmagazin.com\" target=\"_blank\" rel=\"noopener\">cloudmagazin.com<\/a><\/p>\n<p>Geopolitical risks for IT strategy on Digital Chiefs: <a href=\"https:\/\/www.digital-chiefs.de\" target=\"_blank\" rel=\"noopener\">digital-chiefs.de<\/a><\/p>\n<p>Business continuity during crises on mybusinessfuture: <a href=\"https:\/\/www.mybusinessfuture.com\" target=\"_blank\" rel=\"noopener\">mybusinessfuture.com<\/a><\/p>\n<h2>Related Articles<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2024\/11\/25\/post_id-3649\/\">AI-powered SOCs: How automated security operations address the skills shortage<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/?p=5044\">ChatGPT and cybersecurity: Why AI is reshaping both attack and defense<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2022\/12\/15\/post_id-3643\/\">NIS2 Directive adopted: What lies ahead for companies<\/a><\/li>\n<\/ul>\n<p style=\"text-align: right;\"><em>Header Image Source: Pexels \/ Markus Winkler<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"Since Russia\u2019s invasion of Ukraine in February 2022, the cyber threat landscape for European companies has intensified dramatically. Wiper malware, DDoS attacks, and targeted espionage campaigns threaten not only Ukrainian targets &#8211; spillover effects are also hitting German firms. TL;DR Wiper malware: HermeticWiper and WhisperGate destroy data permanently &#8211; no ransom demand, only destruction. Spillover [&hellip;]","protected":false},"author":55,"featured_media":3629,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"cyber war","_yoast_wpseo_title":"Cyber War in Ukraine: How Companies Can Protect Themselves Against Spillover Att","_yoast_wpseo_metadesc":"Cyber war in Ukraine spillover: Protect your company from rising cyber threats. Learn how to defend against malware & DDoS attacks. Act now.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-3628"],"footnotes":""},"categories":[255],"tags":[],"class_list":["post-8369","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-praxis-umsetzung-en"],"evm_reading_time_minutes":5,"wpml_language":"en","wpml_translation_of":3628,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8369","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=8369"}],"version-history":[{"count":6,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8369\/revisions"}],"predecessor-version":[{"id":18708,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/8369\/revisions\/18708"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/3629"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=8369"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=8369"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=8369"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}