UzCERT: Mass RDP attacks hit Uzbekistan government and private sector
Uzbekistan's Cyber Security Center has issued an emergency advisory warning of mass cyberattacks on systems of government bodies and private companies across the country. Attackers exploited exposed Remote Desktop Protocol (RDP) services to gain unauthorized access. Data on some affected systems was encrypted. The advisory calls for immediate action on MFA, password hygiene, and incident reporting.
What UzCERT reported
UzCERT's advisory states that attackers gained unauthorized access via exposed RDP services, with command-and-control infrastructure traced to foreign IP addresses. On affected systems, data was encrypted, indicating either ransomware or a deliberate encryption campaign aimed at disrupting operations. No specific attribution has been made public. The advisory translated from Russian: "Hackers are massively attacking organizations of Uzbekistan. UzCERT has issued an urgent warning."
Why this matters for the region
The attacks arrive during an active phase of Uzbekistan's 2026-2030 Cybersecurity Strategy. Dedicated cybersecurity units were established in key ministries from April 1, 2026. Mandatory independent critical infrastructure assessments launched via a dedicated platform from August 1. A registry of approved cybersecurity providers for state bodies also became active on August 1. The attacks suggest that implementation timelines have not moved fast enough to close existing exposure before threat actors noticed.
RDP exposure is a persistent and well-documented entry point. Mass-scanning for open RDP (port 3389) is among the most common automated reconnaissance activities observed globally. Uzbekistan's public-sector digitization drive has expanded the attack surface faster than security controls have been deployed in some organizations, and this advisory is a direct consequence of that gap.
What to do
UzCERT's immediate recommendations: enforce complex passwords, enable multi-factor authentication on all remote-access services, review security logs for suspicious activity, and disconnect affected systems from the network immediately if an attack is detected. Report incidents to UzCERT. If port 3389 is publicly accessible from the internet, close it. Use a VPN or jump host for all remote administration. Enable Network Level Authentication (NLA) as a minimum baseline if RDP must remain accessible.
For organizations operating in Uzbekistan's regulated sectors, the national cybersecurity strategy's registry of approved providers is now active. Engaging a listed provider for incident response and remediation is likely the expected regulatory path under the new framework.
Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if your organization operates in Central Asia and needs help with RDP hardening or incident response coordination.