Liverpool City Council has disclosed repeated cyberattacks from a Russian-state-linked group over the past two years. These attacks aimed to disrupt municipal systems and services using large botnets. They demonstrate increasing cyberwarfare risk in UK local government.
Who is behind the attacks
The attacks come from Noname057(16), a pro-Russian hacktivist group. They typically target Western governments, healthcare systems, and other institutions opposed to Kremlin interests. These threats now extend to local authorities in the UK.
Nature of the attacks
The primary tactic has been distributed denial of service (DDoS) attacks. Large volumes of traffic flood council systems, attempting to overwhelm them. The attackers use botnets to send waves of requests. Their goal is disruption rather than theft or long-term infiltration.
Liverpool Council confirmed these attacks as “many” in number. To defend itself, the council deployed ISP-level anti-DDoS systems, updated firewalls, intrusion prevention tools, and traffic management solutions.
Wider pattern and context
Noname057(16) originally focused on attacking systems in Ukraine. Since the conflict began, they expanded into supporting countries, particularly those backing Ukraine. The UK, including Liverpool, falls into that category. Other cities in the UK also face similar DDoS threats.
Law enforcement agencies have partially responded. In Operation Eastwood, for example, authorities raided multiple locations worldwide, arrested suspects, and disrupted parts of the group’s infrastructure.
What this means for local councils
Local governments are becoming regular targets for geopolitical cyber warfare. Even non-critical systems can suffer outages that disrupt essential services. Councils must view DDoS protection and infrastructure resilience as priority areas.
Defence strategies
- Implement scalable anti-DDoS infrastructure with ISP-level support.
- Use intrusion prevention systems and traffic filtering to block malicious traffic.
- Monitor system logs for unusual patterns like traffic surges.
- Invest in redundancy and backup to reduce system downtime.
- Coordinate with regional and national cybersecurity agencies to share threat intelligence.
Conclusion
Liverpool cyberattacks highlight the growing threat Russian hackers pose to UK local government. These repeated disturbances, driven by botnets and DDoS attacks, show that such entities cannot afford to treat cyber risk as distant. Councils must act now—reinforce defences, build resilience, and anticipate further escalation.


0 responses to “Liverpool cyberattacks by Russian hackers renew concern”