Reaching the core: could Russia cut Ukrainians off from the internet and mobile communications?

- 4 October, 17:59
Collage: Andrii Kalistratenko

Over the past week, the Kremlin has been expanding its campaign of terror to include new targets. In addition to hitting energy infrastructure and logistics hubs, Russia is now attacking the data centres that house equipment used by internet service providers, government services, banks and other digital systems, launching a wave of strikes on buildings where vital telecoms infrastructure is concentrated.

Telecoms industry representatives say it is not possible to cut Kyiv or Ukraine off from the internet by hitting data centres. There is no single facility whose destruction would take the country offline. But the objective of these attacks is not merely to carry out acts of terror. The goal is not the total destruction of the internet, but to degrade internet quality and overload backup routes, which could increase latency and destabilise networks.

And that may not be the worst-case scenario. The Russians have also started targeting mobile operator infrastructure, which may have more far-reaching consequences. Could these attacks disrupt communications across Ukraine? Where are the weak points in the country's telecoms infrastructure, and why is it that mobile networks could turn out to be significantly more vulnerable? Read on to find out.

From data centres to mobile network operators

On 23 September, Russian drones attacked a building in central Kyiv that housed one of the capital's data centres. A business centre was hit by several jet-powered Shahed drones in the course of an hour, and a fire then broke out.

Later that day, drones struck a similar data centre in another part of the city, and that evening, Russian forces hit yet another facility housing a data centre.

In one day, Russia had attacked at least three data centres in different parts of Kyiv. All housed equipment belonging to internet service providers. Some, notably the cloud service Fex.net, reported disruptions to their services. Ukraine's Ministry of Digital Transformation said around 100,000 users had problems accessing the internet.

Ekonomichna Pravda estimates that at least nine data centres in Kyiv may have been targeted since September, some of them more than once. The Protasiv Yar business centre, which housed the Cosmonova data centre, has been hit twice. Cosmonova suspended operations at the site as a result.

Four days later, the Russians turned their attention to mobile operators' infrastructure. Kyivstar, Ukraine's largest mobile operator, reported that a drone had struck one of its buildings, and Russia's Defence Ministry claimed that equipment belonging to Vodafone Ukraine had been damaged.

Internet service providers and mobile operators have suffered attacks to their networks before, but since 23 September the attacks have been on a different scale. Several data centres were hit within a few days, including some facilities that are critical to the telecoms industry.

For instance, a Russian attack destroyed a data centre that housed infrastructure belonging to hosting provider MiroHost. Founder Oleksandr Olshanskyi said MiroHost won't be able to bring its Ukraine-based infrastructure back online for at least the next three months.

Government digital services have also been disrupted, including state registries and electronic registration at centres run by Ukraine's Ministry of Internal Affairs that provide administrative services related to vehicles and driving licences.

The attacks on data centres have affected television broadcasts too. Disruptions have been reported by Army TV, Novyny.Live, We Are Ukraine, Pershyi, STB, 1+1, Channel 5, Suspilne Sport and Suspilne Culture.

Further evidence of the attacks is contained in a video posted by the Varyag Brigade, which is regarded as one of Russia's elite drone units alongside the better-known Rubicon unit. In the footage, Russian military personnel claim to have struck at least 11 data centres in Kyiv.

The exact dates of the strikes shown in the video cannot be established, but some appear to have taken place between 23 and 27 September. The footage clearly shows a strike on the Datagroup data centre on 25 September.

Read more: Fahrenheit 451: Russia has destroyed one-third of the books printed in Ukraine this year

The Ukrainian authorities had to respond. Following a meeting of the Staff of the Supreme Commander-in-Chief, President Volodymyr Zelenskyy said specific decisions had been taken to protect data centres and other critical communications infrastructure. The government is preparing for the worst. Prime Minister Serhii Koretskyi said the risk of widespread internet disruptions will persist for as long as Russia continues its strikes.

There is no one-size-fits-all way to protect this infrastructure. Some equipment can be moved underground; some can migrate to cloud environments or be relocated abroad. For some systems, a combination of these approaches may be used.

The government has allocated UAH 518.3 million (about US$11.5 million) to establish backup environments at separate locations, cloud infrastructure, and additional sites for state information systems. The funds will also be used to purchase server equipment, software, and data backup and recovery systems.

What happens if a data centre is attacked?

Much of the digital infrastructure Ukrainians rely on every day is built around data centres. The servers and storage systems they house keep websites, apps, state registers and banking services running.

Data centres are critical for internet service providers, as they house essential resources such as web, email and Domain Name System (DNS) servers, cloud infrastructure, and equipment belonging to providers and their clients.

Dmytro Kokhmaniuk, an expert on internet infrastructure and DNS, says some companies rent capacity in several data centres, others have their own facilities, and some combine both approaches. Spreading infrastructure across multiple sites helps make networks more resilient.

Repairing a data centre after an attack is a complex and lengthy process. "It's not just a room full of servers," Kokhmaniuk says. "It's a vast engineering system that includes a power supply, generators, cooling systems, ventilation, physical access control and network infrastructure. Damage to one or more of these elements can render the entire facility inoperable."

Consequently, a strike on a data centre can disrupt its operations even if the servers themselves escape damage. That does not necessarily mean, however, that the data stored there would be lost.

If up-to-date backups are stored at another independent site, the data can be restored. But getting everything back up and running requires computing resources, system configuration, and time. The impact of an attack therefore depends on how the particular service is set up and operated.

Since the start of Russia's full-scale war, a significant proportion of Ukraine's state registers and digital infrastructure has been moved to cloud services and backup environments in other countries.

So even if Russia destroys a Ukrainian data centre, the resulting outage may not last long. The attack may, however, cause temporary disruptions, loss of access and damage to equipment, and make it necessary to repair or relocate infrastructure.

Internet connectivity must also be restored separately. Damage to routers or an internet provider's cables can cut users off even when the service itself continues to operate. In that case, access can be restored using backup routes and equipment that survived intact, or by repairing the damaged network.

Internet speeds may drop

The events of 23 September offer some insight into what Russia may be trying to achieve by targeting Ukrainian network infrastructure.

One of the organisations affected that day was the internet service provider Pavutyna, which notified users of disruptions to its network. Co-owner and director Oleksandr Arutiunian said it was the third strike on the company's infrastructure, but the latest attack hit equipment at several locations almost simultaneously.

"The first two attacks were less disruptive because the backup systems worked better and the damage didn't all happen at the same time," Arutiunian says. "During the third attack, two locations were hit at once. The network could not recover automatically, so some users were left without a connection for between one and two hours. Repair crews then brought the network back online."

It appears that the Russians' target is not so much individual government services as the infrastructure that provides internet access. To this end, they are striking large data centres that house equipment used by several providers.

The telecoms industry representatives interviewed by Ekonomichna Pravda say these attacks cannot cut Ukrainians off from the internet entirely, because providers' network nodes are not only located in data centres.

"Networks have become much more decentralised in recent years," Arutiunian explains. "An operator can have far more than just one, two or five nodes. If necessary, backup equipment can be deployed at another site. In many cases this happens automatically, and engineers only need to step in when the damage is more serious."

If Ukrainian networks have numerous connections and backup routes, then what can Russia realistically achieve by attacking data centres?

Ekonomichna Pravda's sources say providers' network nodes and internet exchange points (IXPs) could potentially be targets. Network nodes support the operation of providers' networks, while IXPs allow different networks to exchange data. There are around 20 IXPs in Ukraine, and their equipment can be located at a single site or several.

The destruction of some of these facilities would not result in a nationwide internet blackout. As long as alternative connections are intact, internet service providers could reroute traffic through other operators, direct connections and international IXPs, just as traffic is diverted when a road is closed. Networks without an alternative route, however, could lose connectivity if their infrastructure is damaged.

The problem may lie elsewhere. Backup routes often have less capacity and are not set up to handle additional traffic. This could result in slower internet speeds and dropped connections for users.

That is what happened to internet provider Fiberlink after Russian attacks damaged the infrastructure of one of its backbone partners. The company rerouted traffic through a backup channel and warned users that internet speeds could temporarily drop. Further damage could lead to more significant disruptions.

According to Kokhmaniuk, poorer connection quality and slower data transfer speeds could be likely. In any event, operators will also have to absorb the additional cost of repairing infrastructure, deploying emergency repair crews and constructing backup lines. If the attacks continue, this could ultimately drive up the cost of broadband for subscribers.

"Operators will need to decentralise their networks further and expand the number of nodes and backup sites, which will increase the cost of providing services," Arutiunian says. "They will need more equipment, more staff and more resources to maintain and support this infrastructure."

Mobile network operator infrastructure

Mobile communications are another area of concern. If Russia continues to hit facilities belonging to mobile network operators, as it did on 27 September, this could have more serious consequences than attacks on data centres.

The Russians would not need to strike tens of thousands of base stations. The mobile core network, which manages subscriber registration, calls, text messages and mobile internet access, may be a far more vulnerable target.

If attacks were to disrupt critical functions of a core network beyond what its backup systems can handle, the consequences could be similar to those of the cyberattack on Kyivstar, which left millions of subscribers without access to calls, text messages or mobile internet.

Operators maintain backup infrastructure, but a fully-fledged mobile core network cannot simply be replicated by installing spare equipment at another node. Ekonomichna Pravda's sources estimate that building an additional core could cost each operator US$40-50 million. How many layers of redundancy would be needed if attacks on this infrastructure became sustained is an open question.

Ekonomichna Pravda's sources say the state and operators are taking steps to build more redundancy into critical network components. Some of these measures have been introduced only recently and will take time to implement. Russian attacks on mobile infrastructure could therefore pose a greater risk to communications.

What does this mean for users? In a critical situation, it's best to have more than one way of accessing the internet – for example, broadband from one provider and mobile internet from another. The more independent connections there are, the lower the risk of losing access during a large-scale attack.

Translated by Artem Yakymyshyn

Edited by Teresa Pearce