Skip to content

Build2 publishers2 min readPublished

Russia names Ukrainian data center operators as targets after its drone hits Datagroup in Kyiv

Russia confirmed striking Datagroup's Kyiv data center and said it is also targeting sites owned by New-Telco, United DC, Kyivstar and Parkovyi. Hosting plans for Ukraine now need a recovery copy that survives losing a whole building to a strike.

The Engineer · Build desk

Photograph accompanying Russia names Ukrainian data center operators as targets after its drone hits Datagroup in Kyiv
Photo: yahoo.com

What happened

  • A Russian drone hit the facility in a central business district of Kyiv, and the BBC reported that four people in the area were killed.
  • Russia justified the Datagroup strike by claiming that Ukrainian military intelligence used the site.
  • The attacks have left about 100,000 households in Ukraine without internet connectivity.
  • A Ukrainian government official said the country's internet network is highly decentralized but that people should still expect some local disruptions.
  • Tom's Hardware counts Iran's March drone and missile attacks on AWS regional data centers in Dubai and Bahrain among the first deliberate strikes on commercial facilities.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure On Russia's stated logic, colocation tenants inherit the targeting risk of whoever else rents space in the same building.
  • constraint Decentralization limits how many subscribers one strike disconnects. It cannot bring back servers inside a building that was hit, so hosted workloads need their own recovery path.
  • precedent Kyiv follows the Gulf strikes on AWS sites, so physical attack belongs in the threat model for commercial hosting near any active conflict.

Disaster recovery plans are usually written around power and fiber failures, where the building comes back once the fault is fixed. The Datagroup strike [1] adds the case where the building does not come back. Russia has also named the other operators where it says it is aiming [3].

Counting Datagroup, Russia has named five operators [5]. Put a primary at one and a recovery copy at another, and both sit on the same list. The two sites are independent for a grid fault and correlated for the failure Russia has declared. Some companies have begun migrating data across the border to avoid disruption [7]. In my view that is where the recovery copy belongs: outside every named operator and outside the country under attack.

The restore drill changes with it. Failing over to a warm secondary tests replication. Losing the building tests something harder. The team rebuilds from backups on hardware abroad, and nobody can say when anyone will reach the original racks again. Any runbook step that begins with sending a technician to the site deserves a second read.

The same buildings carry more than commercial workloads. Foreign Minister Andrii Sybiha said the strikes would affect the flow of "life-saving information" [9]. He said "Rapid alerts about missile and drone threats are essential" [10]. "It is not a military target," Sybiha said [11]. "It is essential to keeping everyday life functioning." [12] President Volodymyr Zelensky wrote that "for Russia, all ordinary life is simply a target" [13].

The reporting confirms one strike on a named operator [1]. For the other four, the record so far is Russia's stated intent [3]. Tom's Hardware cites multiple reports of other data centers and network infrastructure hit across the country, without naming the sites [15].

What to watch

  • Whether any of the four other named operators, including Kyivstar, reports a confirmed strike on one of its facilities.
  • Whether Russia adds operators beyond these five to its stated target list.
  • Whether Ukrainian operators or their tenants disclose how much capacity has moved across the border and where it went.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories