COMMENTARY: Russian Hackers Target Ukraine, EU and US Officials — Cyberwar Intensifies
On June 25, 2026, two of the world's most important intelligence and security agencies — the Security Service of Ukraine (SBU) and
- On June 25, 2026, two of the world's most important intelligence and security agencies — the Security Service of Ukraine (SBU) and
- Introduction: The SBU and FBI Sound the Alarm Together — Unprecedented
- A joint operation exposing Russian cyberwar on a grand scale
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
Introduction: The SBU and FBI Sound the Alarm Together — Unprecedented
A joint operation exposing Russian cyberwar on a grand scale
On June 25, 2026, two of the world's most important intelligence and security agencies — the Security Service of Ukraine (SBU) and the American Federal Bureau of Investigation (FBI) — jointly announced the exposure of a Russian hacking operation targeting the messaging apps of senior Ukrainian, European, and American officials. This joint disclosure is itself a diplomatic event: it confirms that cooperation between Kyiv and Washington on intelligence matters has reached an unprecedented operational level.
The objective of this Russian operation was simple in its ambition and terrifying in its implications: gaining access to sensitive military, political, and economic exchanges from officials of the three entities most engaged against Russian aggression. To steal plans, negotiating positions, information on weapons deliveries, compromising personal communications. A vast digital espionage program striking at the very heart of Western decision-making apparatus.
The targets: the people at the center of decisions on Ukraine
The targets of this operation were not chosen at random. They are the officials directly involved in the military, diplomatic, and economic decisions concerning the war in Ukraine. Officers from defense ministries, diplomats working on sanctions packages, coordinating intelligence officers, foreign policy officials. By penetrating their messaging apps, Russian services were seeking to obtain a decisive informational advantage that could have compromised military operations, diplomatic negotiations, or intelligence processes.
The public disclosure of the operation by the SBU and FBI is a form of informational counter-offensive: by exposing the method, targets, and actors, both agencies reduce the future effectiveness of the method, warn potential targets, and send a clear political message to Moscow — we are watching you and we are striking back publicly.
The Methods: How Russian Hackers Target Messaging Apps
Instant messaging attacks as a preferred vector
Instant messaging apps — Signal, WhatsApp, Telegram, secure government messaging systems — have become prime targets for Russian espionage. Unlike institutional emails, often better protected by layers of organizational security, mobile messaging is used more informally, sometimes for communications outside official channels. This asymmetry of protection makes it a particularly effective attack vector.
Russian special services target these messaging apps through several methods: targeted phishing (spear phishing), exploitation of vulnerabilities in mobile operating systems, compromising telecom infrastructure layers in third countries, and in some cases, recruiting insiders with access to targets' devices. The sophistication of these methods reflects years of investment in Russian offensive cyber capabilities.
A pattern that fits a systematic intelligence strategy
This operation is not an isolated incident. It fits within a systematic pattern of Russian cyber-espionage documented for years by Western intelligence agencies. The groups APT29 (Cozy Bear) and APT28 (Fancy Bear), attributed to the Russian FSB and GRU intelligence services respectively, have long records of attempted intrusions into Western, Ukrainian, and NATO government systems.
The difference from previous operations is the escalation in terms of targets: simultaneously targeting officials from Ukraine, the EU, and the USA in a coordinated operation represents a new scope and ambition. It suggests a Kremlin desire to gain large-scale informational advantage at the precise moment when the most important decisions on support for Ukraine are being made.
The SBU Also Neutralizes Internal Spy Networks
Eight people arrested for espionage and complicity in Russian strikes
Alongside the disclosure of the hacking operation, the SBU announced on June 23, 2026 the arrest of eight people accused of espionage and complicity in Russian strikes from within Ukraine. These individuals were accused of having applauded and facilitated Russian strikes on Ukrainian territory, by providing targeting information or coordinating their activities with Russian services.
These arrests illustrate the multidimensional nature of Russian hybrid warfare: beyond pure cyber operations, Moscow maintains human networks inside Ukraine that serve as relays for intelligence operations, sabotage, and disinformation. Dismantling these networks is a constant priority for the SBU, which dedicates considerable resources to it alongside its electronic counter-espionage missions.
The SBU also foils an FSB plot targeting a Kyiv building
Also on June 23, the SBU announced it had foiled an FSB plot aimed at blowing up a central administrative building in Kyiv. This type of operation — recruiting local accomplices for physical attacks on Ukrainian administrative infrastructure — represents a threat distinct from cyberwar but complementary to it: while hackers steal information remotely, human networks seek to cause physical destruction and disrupt the functioning of the Ukrainian state.
The combination of these three disclosures within a few days — messaging hacks, internal spy network, sabotage plot — paints a picture of a massive and multifaceted Russian hybrid war being waged simultaneously on Ukrainian territory and in the information systems of its allies. Ukraine is facing it with a defensive agility that deserves recognition.
The American Paradox: DOGE Cut CISA, Russian Hackers Are Delighted
40% of the American cybersecurity agency's staff eliminated
While the Russian cyber threat reaches new heights, the United States has weakened its own digital defenses. According to data published on June 25, 2026, the DOGE program — the federal cost-reduction initiative driven by the executive — has cut 40% of CISA's staff, the Cybersecurity and Infrastructure Security Agency. CISA is the primary cyber defense institution of the American federal government. Reducing its workforce by 40% at the precise moment when Russian hackers are intensifying their operations is, to say the least, a strategically problematic choice.
Analysts following this issue point to a fundamental contradiction in American policy: on one hand, Washington publicly exposes Russian cyber operations with the FBI and SBU; on the other, it dismantles the institutional capacities that allow detecting, preventing, and responding to those very same operations. This disconnect between rhetoric and real capabilities is exactly what Russian services need to operate with fewer constraints.
A window of opportunity Moscow will not hesitate to exploit
From the Russian services' standpoint, the 40% reduction in CISA staffing is a windfall. It reduces early detection capacity for cyber operations, it weakens inter-agency coordination on cyber threats, and it decreases incident response speed. These weaknesses never go unexploited for long in the world of electronic intelligence.
The question now is one of American national security governance in the context of intense hybrid warfare. Can short-term budgetary imperatives justify weakening the main cyber defense agency of the country most targeted by Russian state hackers? That is a question American lawmakers will need to ask — and quickly, before the cost of this decision is felt in a catastrophic way.
SBU Alpha: A Combat Record That Commands Respect
32 years of special operations in service of Ukraine
On June 23, 2026, the Special Operations Center Alpha of the SBU celebrated the 32nd anniversary of its creation. On this occasion, the unit's operational record was partially declassified: since the start of the full-scale war, Alpha contributed to the destruction of 540 Russian electronic warfare systems and 23,517 Russian drones as of June 23, 2026.
These figures give a measure of the operational intensity of Ukrainian electronic and anti-drone warfare. The destruction of 540 Russian electronic warfare systems is not trivial — these systems are central to Russia's GPS jamming capabilities, neutralizing Ukrainian communications, and defending against drones. Destroying them partially restores the communication and navigation capabilities of Ukrainian forces.
Electronic warfare: an invisible front with decisive stakes
The destruction of 23,517 Russian drones illustrates another dimension of this war: the drone battle is being fought at an industrial scale that few previous conflicts had seen. Each destroyed drone represents not only a neutralized weapons system, but also resources consumed in the Russian production chain — materials, electronic components, skilled labor. At this scale, drone destruction itself becomes a tool of economic attrition.
Electronic warfare and cyberwar are the two least visible but potentially most decisive fronts over the long term. Ukraine's intelligence and electronic countermeasure capabilities, forged in urgency since 2022, are now among the most advanced in Europe — a remarkable transformation for a country that was fighting with Soviet-era equipment just four years ago.
Russian Cyberwar in the Context of the Authoritarian Axis
Coordination between Russian, Chinese, and Iranian cyber capabilities
Russian cyberwar does not operate in isolation. Western intelligence agencies have documented for several years exchanges of techniques and tools between Russian, Chinese, and Iranian cyber services. These three powers share a common interest in weakening Western democracies and undermining confidence in institutions, elections, and government communications.
Coordination is not necessarily centralized — it may take the form of mutual learning, malware exchanges, sharing of target databases or exploitable vulnerabilities. The result is a cyber threat environment that is more than the sum of its parts: the offensive capabilities of the global authoritarian axis are amplified by this informal but real coordination.
What this means for Western cyber defense
Faced with this coordinated threat, the response must also be coordinated. The joint SBU-FBI disclosure of June 25 is a model — not merely a political statement, but an operational demonstration that intelligence cooperation works. Extending this model to European partners, strengthening information sharing between EU and NATO member states' cyber agencies, and investing in common response capabilities — that is the necessary roadmap.
The reduction in CISA staffing moves in exactly the opposite direction. And in a context where Russian hackers are simultaneously targeting Kyiv, Brussels, and Washington, a cyber defense chain only as strong as its weakest link is insufficient. Every weakening of a partner is an opportunity for the adversary.
The Implications for Cybersecurity Policy in Europe
On the same topic
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
BILLET: Altman and Huang Head to the Senate as…
According to Boursorama , Sam Altman of OpenAI and Jensen Huang…
Europe must draw lessons from the SBU-FBI disclosure
The European Union has made significant progress on cybersecurity in recent years — the NIS2 directive, the Cyber Resilience Act, the ENISA mandates. But the June 25 disclosure illustrates that these instruments, while necessary, are insufficient against state actors with unlimited resources and an aggressive offensive doctrine.
What Europe still lacks is a coordinated offensive response capability — not only defense, but deterrence through counter-attack. If a state knows that its cyber operations will not only be detected but publicly exposed and followed by real consequences, the cost-benefit calculation of aggression changes. The SBU-FBI model must become the EU-NATO-allies model.
Sanctions as an indispensable complement to technical defense
The European Union included in its 20th sanctions package designations linked to FIMI (Foreign Information Manipulation and Interference). This is an important evolution that recognizes that the information war — cyber, disinformation, manipulation — is a tool of Russian aggression that deserves a response within the sanctions framework. This logic must be continued and deepened.
The logical next step would be to specifically sanction the individuals and entities involved in the messaging hacking operations disclosed on June 25. Naming, designating, and sanctioning Russian cyber operators — not just oligarchs and generals — would send a deterrence message directly to the threat actors.
The Future of Cyberwar: The Threat Will Intensify in 2026–2027
A predictable escalation as military pressure intensifies
The more military and economic pressure on Russia intensifies, the more Russian services will be incentivized to compensate their battlefield losses with informational gains. This is a near-mechanical law of intelligence: when you lose tanks, you try to steal plans. When you lose refineries, you try to discover future Ukrainian targets. Cyberwar will therefore intensify in proportion to the degradation of Russia's position on the ground.
The priority targets of this escalation will be the same as those of the operation exposed on June 25: the officials making the most important decisions on support for Ukraine. Defense ministers, intelligence directors, diplomatic negotiators — all are high-value targets in the doctrine of Russian cyber-espionage. Vigilance must be commensurate with the risk, and the risk is at its maximum.
Cyber resilience as a condition of strategic victory
Discover
COMMENTARY: A Supermarket in Chernihiv — the Normalization of…
On the night of July 27 to 28, 2026 , the…
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
A democracy that cannot protect its government communications is a democracy vulnerable in its most fundamental decisions. Cyber resilience — the capacity to maintain secure communications despite intrusion attempts — is a basic condition of national sovereignty in the 21st century. Without it, all military and diplomatic efforts can be compromised by an information leak at the wrong moment.
This is why investments in cyber defense must be treated as national security investments in their own right — not as discretionary budget items to be cut under fiscal pressure. The decision to cut 40% of CISA's staff must be reversed. Not because bureaucracy is always right, but because the threats themselves are not reducing.
Conclusion: Russian Cyberwar Is Not Stopping Soon — the Response Must Be Equal
A threat that will intensify as the conflict evolves
The joint SBU-FBI disclosure of June 25, 2026 is not the end of a story — it is an episode in a cyber war that will last as long as the Russian aggression against Ukraine. The more military and economic pressure on Russia intensifies, the more Russian services will be incentivized to compensate their battlefield losses with informational gains — by stealing plans, compromising communications, sowing mistrust among allies.
Ukraine and its allies must invest in cyber defense as in conventional defense
The conclusion is inescapable: cyber defense must be funded, coordinated, and developed with the same urgency as conventional military aid. Cutting CISA's budget by 40% during intense hybrid warfare is a major strategic error. Strengthening the SBU, funding ENISA, deepening cooperation between NATO cyber agencies — these are national security investments, not discretionary budget items.
Signed Maxime Marquette, columnist
Columnist's transparency box
This commentary is based on open sources published between June 23 and 25, 2026. The facts cited — joint SBU-FBI disclosure, 8 arrests for espionage, FSB plot against a Kyiv building, 540 electronic warfare systems destroyed, 23,517 Russian drones destroyed, 40% of CISA staff eliminated — all come from verifiable sources listed below. No invention, no fabricated testimony. Maxime Marquette's editorial line supports Ukraine and defends democratic values against the cyber aggression of authoritarian regimes.
Sources
Primary sources
Secondary sources
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). COMMENTARY: Russian Hackers Target Ukraine, EU and US Officials — Cyberwar Intensifies. MadMax. https://mad-max.co/en/article/commentaire-hackers-russes-contre-fonctionnaires-d-ukraine-d-ue-et-des-usa-la-cy
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.