Kiev’s data centers hit again—telethon disrupted as cyber gangs weaponize WAF bypasses
On 2026-09-26, reports linked to the Russia–Ukraine war described renewed disruption of Ukraine’s digital infrastructure after attacks on multiple data centers in Kyiv. A first incident was said to follow an attack on several data centers in Kyiv, where an online telethon was disrupted. Minutes later, a second strike was reported against the data center of the internet provider COSMONOVA|NET in the “Protasov” business center in Kyiv, with claims that the facility ceased operations. In parallel, separate cybercrime reporting highlighted how extortion and malware operators are improving exploitation and evasion techniques, including ShinyHunters using a URL-encoding trick to bypass web application firewall (WAF) rules mitigating Oracle PeopleSoft CVE-2026-35273. Another report described Lunex Stealer abusing an AMD driver to disable security monitoring and steal browser credentials, distributed via compromised Ukrainian websites using Cloudflare-style verification checks. Geopolitically, the Kyiv data-center strikes fit a broader pattern of pressure on Ukraine’s wartime resilience: degrading availability of communications and digital services can amplify psychological impact while complicating civil and government operations. The immediate beneficiaries are typically the attacker’s operational tempo and the ability to disrupt coordination, while the losers are Ukrainian service providers and any institutions dependent on stable connectivity and hosted infrastructure. The cybercrime findings matter because they show the threat ecosystem is not static—criminal groups are actively refining techniques to defeat defensive controls like WAFs and to neutralize endpoint monitoring. That combination increases the probability that wartime infrastructure disruptions will be accompanied by follow-on credential theft, persistence attempts, and exploitation of exposed enterprise systems. Even where the articles do not explicitly connect the gangs to state actors, the overlap in targeting methods (WAF bypass, credential theft, and infrastructure disruption) raises the risk that Ukraine’s defenders face both kinetic and cyber pressure simultaneously. Market and economic implications center on digital infrastructure reliability, enterprise software exposure, and cybersecurity spending. If Kyiv-based data centers are taken offline, the near-term effect is likely to be localized service degradation and higher operational costs for affected ISPs, cloud-adjacent services, and enterprises relying on those providers. The Oracle PeopleSoft angle points to potential enterprise risk in finance and HR workflows, which can translate into compliance and remediation costs; meanwhile, WAF-bypass techniques can increase the probability of successful intrusions, raising demand for managed security services and WAF tuning. On the malware side, credential theft and monitoring disablement can drive higher costs for identity security, endpoint detection and response (EDR), and incident response. While the articles do not provide direct commodity or FX figures, the practical market signal is elevated cyber risk premia for Ukrainian digital operators and for global vendors whose products are implicated (Oracle, endpoint security ecosystems, and WAF providers). What to watch next is whether the Kyiv incidents expand beyond the reported providers and whether service restoration timelines lengthen, indicating sustained disruption rather than a transient outage. Defenders should monitor for follow-on exploitation attempts tied to Oracle PeopleSoft CVE-2026-35273, especially on internet-facing instances where WAF rules may be bypassed via encoding tricks. For the Lunex Stealer campaign, indicators to track include AMD driver abuse patterns, attempts to disable security monitoring, and credential harvesting from browsers after CAPTCHA/verification workflows are emulated. On the geopolitical side, escalation triggers include additional strikes on critical hosting facilities, broader telecommunication disruptions, or evidence of coordinated cyber follow-through targeting government or essential services. In the next 24–72 hours, the key decision points are likely to be incident-response disclosures, emergency hardening of exposed services, and any public attribution or mitigation guidance that could shape both defensive posture and market sentiment.
Geopolitical Implications
- 01
Disrupting data centers in Kyiv can degrade wartime coordination and civil communications, increasing psychological and operational pressure.
- 02
The coexistence of infrastructure attacks and rapidly evolving cybercrime tradecraft suggests defenders may face multi-layered campaigns (availability + credential theft + enterprise exploitation).
- 03
Improved WAF bypass and endpoint-monitoring disablement indicate that baseline cyber hardening may be insufficient without continuous rule validation and telemetry integrity.
Key Signals
- —Whether Kyiv data-center services remain down beyond initial outage windows and whether additional providers are targeted.
- —Evidence of scanning/exploitation attempts for Oracle PeopleSoft CVE-2026-35273 using encoding-based WAF bypass patterns.
- —Telemetry showing AMD driver manipulation and security-monitoring disablement consistent with Lunex Stealer TTPs.
- —Public incident-response guidance or attribution that could shift defensive posture and market sentiment.
Topics & Keywords
Related Intelligence
Full Access
Unlock Full Intelligence Access
Real-time alerts, detailed threat assessments, entity networks, market correlations, AI briefings, and interactive maps.