Cyberattacks during the Russia–Georgia war

During the 2008 South Ossetia war a series of cyberattacks swamped and disabled websites of numerous South Ossetian, Russian, Georgian, and Azerbaijani organisations.

Details
On 5 August 2008, three days before Georgia launched its invasion of South Ossetia, the websites for OSInform News Agency and OSRadio were hacked. The OSinform website at osinform.ru kept its header and logo, but its content was replaced by a feed to the Alania TV website content. Alania TV, a Georgian government supported television station aimed at audiences in South Ossetia, denied any involvement in the hacking of the websites. Dmitry Medoyev, at the time the South Ossetian envoy to Moscow, claimed that Georgia was attempting to cover up information on events which occurred in the lead up to the war.

One such cyber attack caused the Parliament of Georgia and Georgian Ministry of Foreign Affairs websites to be replaced by images comparing Georgian president Mikheil Saakashvili to Adolf Hitler. Other attacks involved denials of service to numerous Georgian and Azerbaijani websites, such as when Russian hackers allegedly disabled the servers of the Azerbaijani Day.Az news agency. The governments of Estonia, Ukraine, and Poland offered technical assistance and mirrored web pages for Georgian websites to use during the attacks.

Analysis
While Day.az claimed that Russian intelligence services conducted the denial-of-service attacks (DDoS) on Georgian informational and governmental websites through a proxy in this period, the Russian government denied the allegations, stating that it was possible that individuals in Russia or elsewhere had taken it upon themselves to start the attacks. Others asserted that the St. Petersburg-based criminal gang known as the Russian Business Network (RBN) was behind many of these cyber attacks on Georgian and Azerbaijani sites, as it was for the attacks on Estonia in 2007.

In 2008, Gadi Evron, the former chief of Israel's Computer Emergency Response Team, believed the attacks on Georgian internet infrastructure resembled a cyber-riot, rather than cyber-warfare. Security researchers from Greylogic concluded that Russia's GRU and the FSB were likely to have played a key role in co-coordinating and organizing the attacks. Both these viewpoints are valid according to research by John Bumgarner a former intelligence officer and member of the United States Cyber Consequences Unit (US-CCU). Bumgarner’s research concluded that the first-wave of cyberattacks against Georgian targets were synchronized with Russian military operations and that a second wave was conducted by Russian sympathizers.