FACT-CHECK: Did Ukraine's IT Army really pivot toward Russian military targets?
I want to begin with a warning I apply to myself: it is easy to glorify the IT Army because it is fighting for a country that deserves our solidarity. But solidarity must not replace rigor. If certain
- I want to begin with a warning I apply to myself: it is easy to glorify the IT Army because it is fighting for a country that deserves our solidarity. But solidarity must not replace rigor. If certain
- Introduction: fact-checking what is said about Ukrainian cyberwarfare
- The claims circulating about the IT Army
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
Introduction: fact-checking what is said about Ukrainian cyberwarfare
The claims circulating about the IT Army
Since the start of the full-scale Russian invasion in February 2022, the Ukrainian IT Army has become one of the most commented-upon phenomena of the digital war. The accounts circulating about it pile up the superlatives: attacks on banks, infiltration of surveillance cameras, disruption of Russian Starlink terminals, surveillance of drone operators, creation of fake recruitment channels — all with growing sophistication. But what has been verified? What falls under careful inference? And what remains in the gray zones where unsubstantiated claims proliferate?
This fact-check examines the main claims about the evolution of the Ukrainian IT Army — its transition from economic to military targets, its most documented operations, and its real limitations. It draws on verifiable primary sources and maintains a rigorous distinction between what is established, what is plausible, and what goes beyond the available evidence. Cyberwarfare is a domain where disinformation — on both sides — is a tactical instrument. Factual clarity is therefore an obligation here, not an option.
Claim #1: The IT Army pivoted from economic to military targets
What is established: TRUE, with nuance
The Ukrainian IT Army, founded by the Ukrainian government in February 2022 via an announcement by Digital Transformation Minister Mykhailo Fedorov, has indeed evolved in its target selection. In its first weeks, it focused on distributed denial-of-service (DDoS) attacks against the websites of Russian banks, businesses, and government institutions — high-visibility symbolic targets but with limited military impact. This first phase is well documented.
The shift toward more military targets is corroborated by multiple sources. Operations targeting Russian Starlink terminals, military communication systems, and surveillance cameras (CCTV) in conflict zones are mentioned in Western and Ukrainian security reports. The Foundation for Defense of Democracies (FDD) and several specialized publications have documented this evolution. VERDICT: TRUE, partially confirmed — the pivot is real, even if the full scope of operations cannot be entirely verified from the outside.
Claim #2: Ukrainian hackers infiltrated the chatrooms of Russian drone operators
What is established: PLAUSIBLE but not officially confirmed
The claim that Ukrainian computer specialists infiltrated communication channels of Russian drone operators using Belarusian cellular towers, tracking their launch routes for six months before transmitting the data to Ukrainian defenses, circulates in several specialized publications. The level of detail is notable — the six-month duration, the Belarusian cellular method, the transmission to air defenses. These elements are consistent with the known capabilities of the IT Army and with the Ukrainian doctrine of intelligence-air defense fusion.
However, this claim has not been officially confirmed by the Ukrainian government or by independently verifiable sources as of the writing of this article. It belongs to the category of information that is plausible and consistent with known capabilities, but not documented with accessible primary evidence. The most successful intelligence operations are precisely those that are not discussed while they are still active. VERDICT: PLAUSIBLE but not verified by independent primary sources.
Claim #3: Fake Starlink channels allowed Ukrainian forces to locate Russian units
What is established: PARTIALLY CONFIRMED
The operation of creating fake Starlink registration channels to collect data on Russian units, their contacts, and the location of their terminals has been described in multiple security reports and journalistic investigations. This tactic fits within a broader strategy of exploiting Russian operational security failures in their use of commercial technologies. Russian soldiers using Starlink terminals for internet access frequently underestimated the location and tracking risks that such use entails.
Corroborating elements exist: the Ukrainian government has documented and communicated on operations of this type in general terms, without revealing operational details that would compromise still-active capabilities. The operation's logic is sound from an offensive security standpoint. Starlink is used extensively by both sides, and its vulnerabilities have been documented in academic and industry publications. VERDICT: PARTIALLY CONFIRMED — a credible operation consistent with known methods, corroborated in its broad outlines but without complete primary documentation.
Claim #4: Five Eyes confirmed that 10,000 surveillance systems were compromised
More analysis
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
FACT-CHECK: Kumamoto, a Magnitude 7.1 Earthquake Reopens the Seismic…
On July 28, 2026 , a magnitude 7.1 earthquake struck the…
FACT-CHECK: Bloody Hazing, a Secret Service Agent Faces Justice
A U.S. Secret Service agent stationed in South Florida was arrested…
What is established: NOT VERIFIED in its exact wording
The claim that the British NCSC — the United Kingdom's national cybersecurity agency — confirmed that 10,000 surveillance systems had been compromised to spy on Western aid to Ukraine circulates in some cyberwarfare summaries. That precise figure of 10,000 and its attribution to the NCSC could not be verified in the official public reports of that agency at the time of writing this article.
What is independently confirmed: the Five Eyes has published joint alerts on Russian cyber threats targeting Western infrastructure and Ukraine support networks. Civilian surveillance systems (CCTV) are regularly identified as espionage vectors in Western security bulletins. But the figure of 10,000 systems compromised specifically to spy on aid to Ukraine, attributed to an explicit NCSC confirmation, goes beyond what available public documents allow one to assert. VERDICT: NOT VERIFIED in its exact wording — the threat to surveillance systems is real, the specific figure is not corroborated by accessible primary sources.
Claim #5: Offensive AI could reshape cyberwarfare in months, according to Five Eyes
What is established: TRUE in its broad outlines
Western intelligence alliances, including the Five Eyes, have indeed published assessments on the potential of offensive artificial intelligence in cyber operations. These assessments express growing concerns about the use of AI to automate attacks, accelerate vulnerability discovery, and sophisticate disinformation campaigns. The formulation "offensive AI could reshape cyberwarfare in months" is consistent with the tone of recent bulletins.
The Ukrainian context amplifies these concerns: the war in Ukraine is the first high-intensity conflict in which both parties have access to the latest generation of commercial and military AI tools. Reports from CNBC in July 2026 confirm that China is also using AI-powered cyberattacks against American technology companies, signaling a convergence of state-sponsored cyber threats. VERDICT: TRUE — Five Eyes assessments on the risks of offensive AI are real and documented, even if the exact wording of the citation may vary across reports.
Claim #6: Russia also uses cyberspace — the symmetric threat
Russian cyberattacks against Ukraine and the West: current state
Any analysis of Ukrainian cyberwarfare would be incomplete without examining the Russian dimension. Russia maintains a considerable offensive cyber arsenal, deployed by entities such as the GRU, the FSB, and affiliated groups like APT28 (Fancy Bear), APT29 (Cozy Bear), and Sandworm. These actors have targeted Ukrainian critical infrastructure — power grids, communications systems, government databases — repeatedly since 2014 and with increased intensity since 2022. The NotPetya attacks of 2017, technically attributed to Russia, caused billions of dollars in global damage — that is the level of capability to which the Ukrainian IT Army is responding.
Western intelligence services have regularly warned of Russian operations aimed at spying on Ukraine support networks — notably weapons supply logistics chains, diplomatic communications, and port infrastructure. The Kyiv Post reported in June 2026 that Latvian intelligence had detected Russian preparations for hybrid operations against the Baltic states and Poland. This symmetric context is essential for evaluating Ukrainian cyberwarfare: the IT Army is not operating in a vacuum; it operates in an environment where the adversary possesses equally sophisticated capabilities.
Lessons for NATO cybersecurity
What the war in Ukraine has produced most usefully for Western partners is an unprecedented accumulation of operational experience in cybersecurity under real wartime pressure. Intrusion detection systems, incident response protocols, threat hunting tactics developed or tested in this context are directly transferable to the defense of Atlantic Alliance infrastructure. Cybersecurity companies such as Microsoft, CrowdStrike, and European players have established operational partnerships with Ukrainian agencies, creating a two-way skills transfer. Ukraine transmits cyber combat knowledge just as it transmits drone warfare lessons to its allies.
For NATO, the cyber dimension of the Ukrainian conflict has reinforced awareness that collective cyber defense is not a theoretical subject. Alliance communication systems are targets. The critical infrastructure of NATO members is vulnerable. And the tools developed by the Ukrainian IT Army and its partners to respond to these threats in real time constitute a catalog of best practices that NATO would be unwise not to study systematically.
Fact-check assessment and a real portrait of the IT Army in 2026
What the IT Army has actually accomplished
Beyond the specific claims verified or refuted, there is an overall picture of the Ukrainian IT Army that emerges from available reliable sources. The organization has demonstrated real capabilities for disrupting Russian services, conducting information operations, and supporting air defense through the collection of intelligence via digital channels. It has contributed to documenting and exposing Russian violations of international law, notably through the collection of geospatial data and open-source analysis (OSINT).
It has also evolved from a disorganized volunteer force into a more professional structure, integrated to varying degrees with Ukraine's official intelligence services. Partnerships with Western private cybersecurity companies have strengthened its technical capabilities. Italy, according to a United 24 Media report from June 2026, allocated a new million euros to strengthen Ukrainian cyber defense — a sign that allies are taking this dimension of the conflict seriously. Ukrainian cyberwarfare is real, documented, and supported. What demands exaggeration is what falls short of the mark.
Conclusion: Ukrainian cyberwarfare, between impressive reality and amplified narrative
What the fact-check tells us about the information war
This fact-check highlights a tension inherent in covering cyberwarfare: the most successful operations are precisely those that cannot be discussed while they are still active. The Ukrainian IT Army has real successes — but complete external validation of its most sensitive operations arrives with a structural delay. Unverifiable claims are not necessarily false. They may simply reflect real operations whose public documentation is not yet available.
What we can state with certainty: Ukraine has developed remarkable cyber capabilities since 2022. These capabilities have evolved from economic to military targets, in line with the needs of the war. They benefit from Western partner support. And they exist within a global context where major powers — Russia, China, Iran — use cyberspace as a full theater of war. Vigilance is necessary. Factual rigor is too.
Sources
Primary sources
Discover
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
FACT-CHECK: Kumamoto, a Magnitude 7.1 Earthquake Reopens the Seismic…
On July 28, 2026 , a magnitude 7.1 earthquake struck the…
FACT-CHECK: Bloody Hazing, a Secret Service Agent Faces Justice
A U.S. Secret Service agent stationed in South Florida was arrested…
Secondary sources
By Maxime Marquette, columnist
Columnist's transparency note
Who I am and my acknowledged biases
I am a columnist and analyst, not a cybersecurity expert. I am pro-Ukrainian in this conflict — that conviction has not altered my willingness to distinguish verified facts from unsubstantiated claims in this article. I applied the same verification criteria I would apply to any other source. Where evidence is lacking, I say so.
What I do not know and my method
Active cyber operations cannot be fully verified by civilian journalists. Some claims I classified as "plausible but unverified" may be confirmed in the future when classification is lifted. My method: cross-reference each claim with at least two independent sources before qualifying it as "confirmed." Sources used are cited. Gaps are indicated. Honesty is the only acceptable method.
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). FACT-CHECK: Did Ukraine's IT Army really pivot toward Russian military targets?. MadMax. https://mad-max.co/en/article/fact-check-l-it-army-ukrainienne-a-t-elle-vraiment-pivote-vers-les-cibles-milita
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.