Summary
- A Russian strike damaged Kyivstar’s Kyiv headquarters, while other Ukrainian telecom and data-centre facilities were hit during September.
- Kyivstar reported no employee casualties from its headquarters strike, while other attacks disrupted internet and hosting services.
- The incidents expose how telecoms, cloud infrastructure, public warnings, and business continuity depend on physical protection as well as cyber defence.
A Russian strike has damaged the Kyiv headquarters of Kyivstar, Ukraine’s largest mobile operator, as a wider series of attacks on data centres and telecoms facilities turns physical digital infrastructure into an increasingly visible part of the war.
Kyivstar said its head-office building was damaged during the 27 September attack but that its employees were safe. The company was assessing the damage and coordinating further action, while there was no reported interruption to mobile service from the headquarters strike.
The incident followed several attacks on facilities supporting Ukrainian internet, hosting, and communications services during September. A data centre housing core equipment belonging to internet provider Utels was damaged on 23 September, several providers subsequently reported infrastructure damage, and a facility containing MiroHost equipment was destroyed, according to Ukrainian reporting.
Russia’s defence ministry also said it had struck a data centre belonging to Vodafone Ukraine. Vodafone did not confirm that claim to Reuters, while Ukrainian President Volodymyr Zelenskyy separately said a Kyiv data centre had been struck twice and that two children and an adult were wounded. The ownership of the facility described by Zelenskyy was not publicly identified.
Connectivity becomes physical infrastructure again
Business continuity planning often separates cyber security from facilities management, yet the Ukrainian experience shows how quickly the distinction can collapse. Mobile networks, cloud services, hosting platforms, digital identity systems, payments, media operations, and public-warning services ultimately depend on buildings, fibre routes, electricity, generators, radio equipment, and technicians able to reach damaged sites.
Ukraine has spent years building resilience into those systems because communications infrastructure has been repeatedly disrupted since Russia’s full-scale invasion in 2022. Operators have invested in backup power, alternative routes, restoration teams, distributed network design, and the ability to maintain service through electricity failures and physical damage, alongside conventional cyber defences.
The September attacks nevertheless demonstrate how concentration creates operational risk. A single data-centre building can contain infrastructure belonging to several companies, while a failure at a telecom or hosting node can affect businesses with no direct relationship to the physical operator responsible for the site.
Ukraine’s digital ministry said attacks on data centres and internet providers over the preceding week caused outages affecting roughly 100,000 households in Kyiv and the surrounding region. Media organisations were also among those reporting disruption, underlining how damage to hosting and network infrastructure can spread across organisations that otherwise appear unrelated.
A further attack on 28 September damaged a facility belonging to Ukrtelecom, although the operator said its services remained available and engineers were carrying out stabilisation work. Damage to a building does not necessarily translate directly into customer downtime where networks have sufficient redundancy and teams can route traffic elsewhere.
Resilience extends beyond cyber controls
The European security debate has increasingly treated digital infrastructure as part of a wider hybrid-threat environment rather than a narrow information-security problem. French intelligence services have similarly urged companies to broaden security planning beyond conventional cyber intrusion, reflecting the way sabotage, physical disruption, disinformation, cyber operations, and supply-chain pressure can overlap.
Ukraine represents an extreme operating environment rather than an ordinary planning assumption for operators elsewhere in Europe, but several underlying lessons travel beyond the conflict. Network resilience depends on geographic diversity, spare equipment, backup power, alternative connectivity, clear restoration priorities, and contractual understanding of where supposedly redundant services are physically located.
That last point can be particularly difficult in cloud and hosting environments. Two applications may appear to use separate providers while still depending on the same carrier, exchange point, power substation, or physical data-centre campus, leaving a common failure mode hidden behind different commercial contracts.
European governments have tightened resilience expectations for critical infrastructure through cyber and operational-resilience rules, but regulation addresses only part of the problem. Organisations also need accurate maps of dependencies between communications providers, cloud platforms, colocation sites, internal systems, and emergency procedures, because restoring a digital service requires knowing which physical component has actually failed.
Ukraine is also unusual because communications systems carry an immediate public-safety function during air attacks. Mobile alerts, messaging services, media distribution, emergency coordination, and access to current information are not merely commercial conveniences when missiles and drones are being tracked.
Kyivstar’s ability to keep services running despite damage to its headquarters shows one side of that resilience, while outages elsewhere show its limits. As attacks reach deeper into communications infrastructure, the contest is increasingly not only about protecting data from intrusion but keeping the systems carrying it powered, connected, repairable, and dispersed enough to survive repeated damage.












