Full Report
TV channels Novyny.Live and Armiia TV both temporarily suspended operations following Russian strikes on Kyiv.
Analysis Summary
# Incident Report: Physical Kinetic Attacks on Kyiv Data Centers and Media Infrastructure
## Executive Summary
Between September 23 and September 26, 2026, Russian forces executed a series of systematic kinetic strikes, including drone attacks, targeting critical data centers and internet infrastructure across Kyiv, Ukraine. The physical destruction of these facilities disrupted multiple internet service providers (ISPs), cloud services, and public broadcasting infrastructure. Consequently, several major media outlets, including Novyny[.]Live and Armiia TV, were forced to temporarily suspend operations, and over 100,000 households experienced severe internet blackouts.
## Incident Details
- **Discovery Date:** September 23, 2026
- **Incident Date:** September 23–26, 2026
- **Affected Organization:** Multiple entities, including Cosmonova, UTELS, Fex[.]net, Domonet, Kievnet, Faust, MiroHost, Datagroup, Suspilne, Novyny[.]Live, and Armiia TV.
- **Sector:** Telecommunications, Information Technology (Cloud/Hosting), and Media
- **Geography:** Kyiv, Ukraine
## Timeline of Events
### Initial Access
- **Date/Time:** September 23, 2026
- **Vector:** Physical Kinetic Strike (Airstrike/Drone)
- **Details:** Russian forces targeted a primary data center in Kyiv housing core network equipment for internet provider UTELS and cloud service provider Fex[.]net, initiating a wave of infrastructure-focused physical attacks.
### Lateral Movement
- *Not Applicable:* This incident involved physical destruction propagating disruptions through interconnected infrastructure dependencies and shared upstream data centers, rather than digital network lateral movement.
### Data Exfiltration/Impact
- **September 23, 2026:** Destruction of UTELS and Fex[.]net infrastructure cuts off internet access for approximately 100,000 households.
- **September 24, 2026:** Strikes target and destroy a data center hosting MiroHost's infrastructure. Outages spread to ISPs Domonet, Kievnet, and Faust due to localized infrastructure damage.
- **September 25, 2026:** A drone strike damages a Datagroup data center and causes structural fires at a business center. Simultaneously, the Cosmonova data center suffers its first wave of damage.
- **September 26, 2026:** A follow-up strike hits the Cosmonova data center a second time, knocking it entirely out of operation. This failure disables the video players on the public broadcaster Suspilne's website. TV channels Novyny[.]Live and Armiia TV completely suspend operations due to downstream infrastructure failures.
### Detection & Response
- **Immediate Detection:** Automated network monitoring systems triggered widespread blackouts, corroborated by visual confirmation of physical strikes and structural fires.
- **September 25, 2026:** President Volodymyr Zelensky met with senior military officials to implement a high-level government directive to physically reinforce and protect data centers and critical communications facilities.
- **Ongoing Response:** Affected providers initiated disaster recovery protocols to reroute traffic through auxiliary channels and assess physical hardware replacement timelines.
## Attack Methodology
- **Initial Access:** Physical kinetic military strikes (loitering munitions/drones and missiles) targeting the geographic coordinates of critical IT infrastructure.
- **Persistence:** Repeated and sequential daily bombardments targeting the same facilities (e.g., Cosmonova data center) to ensure total operational failure.
- **Privilege Escalation:** N/A (Physical perimeter breach via kinetic payload).
- **Defense Evasion:** Deployment of daytime and nighttime drone waves designed to saturate and bypass localized air defense systems.
- **Credential Access:** N/A
- **Discovery:** Prior military intelligence and reconnaissance mapping of critical internet exchange points and hosting facilities.
- **Lateral Movement:** N/A
- **Collection:** N/A
- **Exfiltration:** N/A
- **Impact:** Gross physical destruction of hardware, facility power grids, and fiber optic lines, causing high-availability Denial of Service (DoS).
## Impact Assessment
- **Financial:** Severe capital losses stemming from completely destroyed server hardware, facilities, and lost revenue from prolonged business downtime.
- **Data Breach:** No digital data exfiltration detected; however, there is a high probability of localized data destruction on physical drives (e.g., MiroHost infrastructure destruction).
- **Operational:** Critical impact. Massive disruption to public broadcasting, total suspension of TV station operations, and blackouts affecting 100,000+ consumer broadband endpoints.
- **Reputational:** N/A; public perception recognized the outages as acts of war rather than organizational security failures.
## Indicators of Compromise
- **Network Indicators:** Total loss of BGP routing advertisements for affected autonomous systems (ASNs); abrupt drop in ping telemetry across Kyiv-based IP blocks.
- **File Indicators:** N/A
- **Behavioral Indicators:** Sudden, unannounced power and connectivity loss originating from physical data center facility nodes matching localized air raid alerts.
## Response Actions
- **Containment Measures:** Deployment of municipal emergency services to extinguish structural fires on affected facilities to prevent further hardware degradation.
- **Eradication Steps:** Government-mandated military reinforcement of air defense perimeters around vital communication corridors and exchange hubs.
- **Recovery Actions:** IT infrastructure teams began duplicating network equipment and shifting traffic loads to distributed backup communication routes located outside the primary strike zones.
## Lessons Learned
- Physical security and geographic placement are single points of failure for digital infrastructure during active conflicts.
- Centralizing data centers within a capital city heightens vulnerability to targeted, systematic kinetic campaigns.
- Smaller service providers lacked the financial runway to maintain redundant, geographically distributed nodes, leaving them disproportionately vulnerable compared to larger conglomerates.
## Recommendations
- **Geographic Diversification:** Implement multi-region hybrid architectures, distributing core infrastructure across multiple physical locations, including hosting critical backups outside national boundaries.
- **Redundant Routing:** Maintain automated, hot-standby backup paths utilizing alternative communication technologies (such as satellite internet and distributed internet exchange points).
- **Physical Hardening:** Collaborate with national defense authorities to prioritize tactical air defense coverage and physical fortifying measures for remaining on-premises infrastructure.