Expert Statement of the Critical Infrastructure Association of the Slovak Republic (AKI SR) on the Serious Cybersecurity Incident at the Ministry of Economy of the Slovak Republic

3. decembra 2025

The Critical Infrastructure Association of the Slovak Republic (AKI SR) expresses serious concern over the cybersecurity incident that was identified at the Ministry of Economy of the Slovak Republic

Information from the ministry and independent media confirms that this was an attack that had the potential to affect key components of the ministry's infrastructure. State specialized cybersecurity teams are responding on site – the government CSIRT and SK-CERT at the National Security Authority – which confirms the high severity of the event.

Although the ministry stated that early detection prevented the encryption of data and direct damage to information systems, the very fact of successful penetration into part of the infrastructure represents a serious breach of state administration security. In international practice, it is known that ransomware groups and advanced persistent threats (APT) often operate in multiple phases: from initial penetration, through lateral movement, data exfiltration, to activation of encryption or extortion mechanisms. The fact that the attack was intercepted before transitioning to the next phase should be evaluated positively, but at the same time points to the need for a deeper review of security mechanisms throughout the ministry and the broader state administration.

From available information, the actor behind the incident pursued a more extensive goal than just damaging a single system. In such cases, the attackers' motivation may be to gain access to network identifiers, administrator accounts, or systems that can serve as a pivot for further attacks on other state authorities, enterprises, or critical infrastructure entities. This aspect is precisely why AKI SR considers the incident extremely serious, even if the immediate impacts were minimized.

The Ministry of Economy of the Slovak Republic stated that data related to targeted energy assistance were not stored on the affected infrastructure. While this information contributes to public reassurance, the incident simultaneously questions the adequate coordination and unified architecture of information security across state administration ministries. In an environment where ministries manage interconnected data registers and processes, it is not possible to rely on the isolated infrastructure of one ministry eliminating systemic risk.

AKI SR considers it essential that the investigation of the incident not focus exclusively on the technical analysis of individual systems, but bring broader findings about the state of organizational preparedness of the state administration, the level of network segmentation, privilege policy, traffic monitoring and logging systems, as well as the level of implementation of security frameworks that the Slovak Republic must fulfill according to the NIS2 directive, Cyber Resilience Act (CRA), as well as national legislation in the field of cybersecurity.

It is equally important to examine whether state institutions have sufficient capacity to implement modern security architectures including zero-trust models, identity and access management (IAM), regular penetration tests and red-team exercises, real-time security monitoring, as well as the gradual deployment of cryptographic mechanisms resistant to future threats, including post-quantum cryptography.

The incident also confirms a long-known problem: public administration in Slovakia is technically and procedurally heterogeneous, which creates space for new types of attacks and increases the risk of chain propagation of compromises. Cyber threats in 2025 differ dramatically from those against which many systems were originally designed: these are no longer isolated attacks, but organized operations with long-term preparation that utilize advanced automation, abuse of legitimate tools, and finally, vulnerabilities in the software and hardware supply chain.

The Critical Infrastructure Association of the Slovak Republic therefore calls for comprehensive modernization of the state's cybersecurity. Slovakia needs a unified, robust architecture based on international standards, clear risk management, regular resilience testing, immediate implementation of corrective measures, and professional capacities that will be able to face modern threats. The goal must be not only to resolve individual incidents, but to build a level of resilience that minimizes the likelihood that penetrations of a similar type will have systemic or societal impacts in the future.

AKI SR will continue to analyse the incident, provide expert recommendations, and coordinate sectoral positions aimed at increasing the security level of the state and protection of critical infrastructure.

14. septembra 2026
The Critical Infrastructure Association of the Slovak Republic continues its series of articles focusing on basic services under Act No. 367/2024 Coll. on Critical Infrastructure. This time, we look at a basic service that remains largely invisible to the public, yet its disruption can have an immediate impact on transport, industry and the wider economy – the operation of pipelines for the transportation of crude oil and fuels.
14. septembra 2026
Asociácia kritickej infraštruktúry SR pokračuje v sérii článkov venovaných základným službám podľa zákona č. 367/2024 Z. z. o kritickej infraštruktúre. Tentoraz sa venujeme základnej službe, ktorá zostáva pre verejnosť väčšinou neviditeľná, no jej výpadok môže mať veľmi rýchly vplyv na dopravu, priemysel aj fungovanie ekonomiky: prevádzkovaniu potrubí na prepravu ropy a pohonných látok.
8. septembra 2026
Several incidents in the space of a single week. And in one case, 4.2 GW of generation capacity was temporarily taken offline. Germany is dealing with a series of attacks on its electricity grid that highlights one important point: the target does not necessarily have to be the power plant itself.
8. septembra 2026
Niekoľko incidentov v priebehu jediného týždňa. A v jednom prípade dočasne vyradená výrobná kapacita 4,2 GW. Nemecko rieši sériu útokov na elektrickú sieť, ktorá ukazuje dôležitú vec: terčom nemusí byť samotná elektráreň.
5. septembra 2026
District heating and cooling are an important part of the energy infrastructure of cities and municipalities. Their role is not limited to providing thermal comfort; they create stable conditions for the functioning of households, public institutions, industry and other facilities. As energy systems become increasingly technologically complex, the importance of their reliability, preparedness and ability to respond to operational disruptions is also growing.
5. septembra 2026
Diaľkové vykurovanie a chladenie predstavujú významnú súčasť energetickej infraštruktúry miest a obcí. Ich úlohou nie je len zabezpečiť tepelný komfort, ale vytvárať stabilné podmienky pre fungovanie domácností, verejných inštitúcií, priemyslu a ďalších prevádzok. S rastúcou technologickou komplexnosťou energetických systémov zároveň rastie aj význam ich spoľahlivosti, pripravenosti a schopnosti reagovať na narušenie prevádzky.
2. septembra 2026
On Monday, 31 August 2026, a working meeting took place at the Ministry of Interior of the Slovak Republic with State Secretary of the Ministry of Interior Patrik Krauspe, Director General of the Crisis Management Section Jaroslav Kmeť, Naďa Trelová Sonogová from the Department of International Cooperation of the Ministry of Interior, and representatives of the Critical Infrastructure Association of the Slovak Republic (AKI SR).
2. septembra 2026
Na Ministerstve vnútra Slovenskej republiky sa v pondelok 31. augusta 2026 uskutočnilo pracovné rokovanie štátneho tajomníka MV SR Patrika Krauspeho, generálneho riaditeľa sekcie krízového riadenia MV SR Jaroslava Kmeťa, Nade Trelovej Sonogovej z odboru medzinárodnej spolupráce MV SR a predstaviteľov Asociácie kritickej infraštruktúry Slovenskej republiky (AKI SR).
28. augusta 2026
The Government of the Slovak Republic has approved a draft act on the cybersecurity of products with digital elements, also referred to as the cyber resilience act. This is a further step in the legislative process; the bill will subsequently be debated in the National Council of the Slovak Republic.
28. augusta 2026
Vláda Slovenskej republiky schválila návrh zákona o kybernetickej bezpečnosti produktov s digitálnymi prvkami, označovaný aj ako zákon o kybernetickej odolnosti. Ide o ďalší krok v legislatívnom procese, návrh zákona bude následne predmetom prerokovania v Národnej rade Slovenskej republiky.