Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Russian intelligence-linked cyber incidents recorded by Ukraine’s CERT-UA rose from 2,543 in 2023 to 4,315 in 2024—an increase of about 69.7%. Yet only 55 incidents were classified as high severity and four as critical. The figures point to a widening gap between the volume of activity and its visible damage, not to an attack campaign that had no effect.
What the 70% increase counts
The comparison is for calendar years 2023 and 2024, not a current measure of activity. CERT-UA recorded 1,772 more incidents attributed to Russian intelligence services in 2024: 4,315, compared with 2,543 the year before. That is approximately 69.7%, rounded to 70%, according to Dark Reading’s May 1, 2025 report on the figures.
An incident count is not a count of successful breaches. It does not establish that 70% more systems were compromised, that 70% more victims were affected, or that every incident caused disruption. Nor does it describe missile or drone attacks, every Russia-linked actor, or cyber activity in 2025 or 2026. “Putin’s attacks” is shorthand in the original headline; the more precise description is incidents attributed to Russian intelligence services. It does not show that Russia’s president personally ordered each operation.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Many incidents, few high-severity outcomes
Of the 4,315 incidents recorded for 2024, CERT-UA classified 55 as high severity and four as critical. Together, those 59 incidents amount to about 1.4% of the recorded total. That ratio gives context to the phrase “little effect,” but it is not a direct success rate: detection, reporting, and severity-classification methods shape both the numerator and denominator.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
The report highlights one critical event: the disruption of Ukraine’s Ministry of Justice state registries on December 19, 2024. A low critical-incident count suggests that most recorded activity did not produce consequences of that scale. It does not establish that the other incidents were harmless. An intrusion can yield credentials, surveillance, or access useful later without causing an immediate outage, and intelligence gains can be difficult to measure publicly.
Activity accelerated in the second half of 2024
The increase was not evenly spread across the year. CERT-UA recorded 1,739 incidents in the first half of 2024 and 2,576 in the second, a rise of approximately 48%. Over that same half-on-half comparison, attacks on government organizations increased 41%, those affecting local authorities rose 53%, and military cyberattacks increased 82%, according to the reported CERT-UA figures.
The target mix is more revealing than the headline number
Government agencies and local authorities accounted for 58% of Russian cyberattacks in 2024, compared with an estimated 20% to 25% historically since 2021. The share affecting Ukraine’s security and defense sectors also rose, from 7% in 2023 to 18% in 2024. Those shifts matter because a campaign directed at ministries, municipal services, defense organizations, or military communications can have strategic value even when it does not cause a long, widespread outage.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Reported operations included attempts to compromise Delta, Ukraine’s battlefield-management system, and to target phones used by military personnel. One operation used fake QR codes to direct Signal users to command-and-control infrastructure in Russia. The report does not establish how much these efforts helped Russian forces; the military impact could not be fully assessed. That uncertainty is important: targeting a sensitive system is evidence of intent, not proof of access or battlefield success.
Even limited access could, in principle, expose planning or communications, provide credentials for later use, or help an adversary understand how government services respond under pressure. Those are possible forms of value, not documented outcomes for every incident in the count.
Why volume and damage can move in different directions
The available figures do not prove why the incident count climbed while the number of critical outcomes remained small. Several explanations are plausible:
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
- Stronger defense and recovery: Ukrainian organizations may have become better at detecting activity, containing intrusions, isolating affected systems, and restoring services.
- More attempts without a matching rise in success: Automation or repeated campaigns can increase detected activity without producing a proportional increase in effective compromises. This is a possible explanation, not a demonstrated cause.
- Different operational aims: Some operations may seek information or persistent access rather than immediate disruption. Those objectives do not necessarily appear in critical-incident totals.
- Detection and classification effects: Improved monitoring can surface more incidents; classification rules and later investigation can also affect how severity is recorded.
These explanations can coexist. The count may reflect more activity, better detection, and a change in targeting at the same time. Without comparable detail on successful access, dwell time, data taken, and recovery, incident totals alone cannot settle how effective the campaign was.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →“Little effect” is not the same as “no effect”
Effectiveness depends on the measure. By the measure of critical disruption, the reported figures show few severe outcomes relative to thousands of incidents. By the measure of operational pressure, the sustained and accelerating activity still matters. By the measure of intelligence value, the public severity figures are incomplete: espionage, credential theft, and access that is held for later use may not create an obvious crisis.
A fuller assessment would ask how many incidents led to unauthorized access, what information was exposed, how long attackers retained access, what services were disrupted, how quickly organizations recovered, and whether operations produced battlefield or political advantage. It would also weigh the defensive effort required to handle the campaign against the resources Russia spent. The cited data supplies incident and severity counts, not all those measures.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
The defensible conclusion is therefore narrower than either “Russia’s cyberattacks failed” or “the attacks were devastating.” Russia substantially increased its recorded cyber pressure in 2024, with a marked shift toward government, local-authority, security, and defense targets. The reported severity count shows that relatively few incidents reached the high or critical categories, but it cannot rule out less visible intelligence gains or future use of access.
What the figures can—and cannot—tell defenders
For defenders, the numbers argue for tracking more than alert volume. Useful measures include confirmed compromises, sensitive accounts or data exposed, service disruption and recovery time, repeat access, and incidents affecting military or government operations. A rising incident count can mean heavier pressure; it can also reflect stronger visibility. Neither interpretation should be assumed without evidence.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsThe figures in this report describe 2024 activity and were reported in 2025; they are not a 2026 snapshot. Future comparisons will be most informative if they preserve clear attribution and consistent definitions, while separately tracking attempted activity, confirmed access, severity, and operational consequences.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

