Ukraine's SBU Has Neutralized More Than 16,000 Russian Cyberattacks Since 2022
The cybersecurity department of Ukraine's Security Service, the SBU, has announced it has neutralized more than 16,000 Russian cyberattacks since the start
- The cybersecurity department of Ukraine's Security Service, the SBU, has announced it has neutralized more than 16,000 Russian cyberattacks since the start
- Introduction: The Invisible War the SBU Is Fighting
- A Number That Reveals the Scale of the Digital Front
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
Introduction: The Invisible War the SBU Is Fighting
A Number That Reveals the Scale of the Digital Front
The cybersecurity department of Ukraine's Security Service, the SBU, has announced it has neutralized more than 16,000 Russian cyberattacks since the start of the full-scale war in February 2022. This figure, confirmed by Brigadier General Volodymyr Karastelov, head of the department, illustrates the scale of a digital front largely invisible to the general public, yet just as strategic as the ground combat lines.
According to Karastelov, the preferred targets of these Russian attacks are Ukrainian government agencies, financial institutions, the defense sector, and, increasingly, Ukrainian media, seen as a prime strategic target in this information war.
Why the Media Became a Russian Priority
This systematic targeting of Ukrainian media is no accident: controlling or sabotaging a wartime country's information channels lets the aggressor sow confusion, spread propaganda under an appearance of local legitimacy, and weaken the informational cohesion of a population already under constant bombardment pressure.
This strategy fits Russia's hybrid warfare doctrine, which has for years combined physical strikes with digital influence operations to maximize the destabilizing effect on Ukrainian society.
The Three-Hour DDoS Attack on National Television
A Digital Offensive of Rare Intensity
The most recent case documented by the SBU involves a distributed denial-of-service attack, or DDoS, lasting three hours, directed at the website of a Ukrainian national television channel. At its peak, the attack generated up to 200,000 requests per minute, a traffic volume designed to completely overwhelm the targeted servers.
The botnet used to carry out this attack was made up of nodes spread across Asia, Europe and the United States, an international architecture deliberately designed to mimic real user behavior, making detection harder and exhausting the target's server resources.
Technical Resilience That Averted the Worst
Thanks to the intervention of SBU cybersecurity specialists, the television channel's website remained operational without interruption despite the intensity of the attack, a result that reflects a digital defense capability considerably strengthened since the conflict began.
This technical resilience, though rarely covered in the media, is a tangible victory in a war where every public service kept running represents a direct failure for Russian destabilization objectives.
The 2025 Precedent: A Propaganda Hijacking Attempt
A Two-Stage Attack Against Another Broadcast Group
In 2025, another Ukrainian television group was the target of a more sophisticated attack, carried out in two distinct stages: an initial phishing campaign aimed at obtaining fraudulent access, followed by an attempt to penetrate information infrastructure through adjacent systems connected to the main network.
The final goal of this operation was not simple technical disruption but the complete takeover of the digital resource in order to broadcast Russian propaganda under the name and credibility of the legitimate Ukrainian outlet targeted.
Timely Detection That Averted an Information Catastrophe
SBU specialists managed to detect this intrusion in time, preventing the takeover of the outlet and thereby averting an information catastrophe that could have misled thousands, even millions, of Ukrainian viewers about the authenticity of the broadcast content.
This precedent illustrates an escalation in the sophistication of Russian methods, moving from simple saturation attacks to complex attempts at hijacking media identity for mass disinformation purposes.
The Structural Role of GRU Unit 29155
A Russian Military Unit Built for Cyberwarfare
Behind several of these campaigns looms the shadow of Unit 29155 of Russian military intelligence, the GRU, initially designed as a dedicated cyberwarfare arm before broadening its scope to other forms of hostile operations against Ukraine and its Western partners.
This unit has run spear-phishing campaigns directly targeting President Volodymyr Zelensky's office as well as several Ukrainian ministries, aiming to gain unauthorized access to sensitive communications at the highest levels of the state.
The Deployment of the Destructive WhisperGate Malware
Even before the full-scale invasion began, this same unit had deployed the destructive WhisperGate malware, designed to irreversibly wipe data from Ukrainian computer systems, a digital sabotage operation preparing the ground for the military aggression that would follow.
This prior deployment shows that Russia's hybrid war against Ukraine began well before the first tanks crossed the border, confirming that preparation for this invasion played out simultaneously on military and digital fronts.
The Cybersecurity Resilience Program for Regional Media
A Joint Initiative Between the SBU and the Broadcasting Regulator
Faced with this persistent threat, the SBU launched a cybersecurity resilience project for local and regional media outlets, in partnership with Ukraine's National Council of Television and Radio Broadcasting, the country's broadcasting regulator.
This program acknowledges an important strategic reality: major national outlets are not the only potential targets, and regional structures, often less technically equipped, represent a vulnerable link that urgently needed reinforcement.
Nationwide Coverage in 2026
In 2026, the SBU organized a series of hands-on cybersecurity training sessions in 20 regional locations, covering media representatives from all 21 oblasts in Ukraine, near-complete territorial coverage that reflects the scale of the effort deployed.
Nearly 450 participants took part in these sessions, including media managers, journalists, editors-in-chief and technical specialists, a diversity of profiles that reflects the need for cybersecurity awareness at every level of a media organization.
Financial Institutions, a Quiet but Critical Target
A Sector Vital to Economic Stability in Wartime
Beyond the media, Ukrainian financial institutions are among the priority targets identified by the SBU, a threat that takes on particular weight in a country whose economy must stay functional despite constant bombardment and the logistical challenges of a prolonged war.
A successful attack on Ukraine's banking infrastructure could paralyze routine transactions, affect the payment of salaries and pensions, and undermine citizens' already fragile confidence in their country's economic stability in the middle of a war.
Financial Defenses Strengthened by the Experience of Conflict
Experience accumulated since 2022 has allowed Ukrainian financial institutions, in coordination with the SBU, to develop increasingly sophisticated defense protocols, significantly reducing the window of opportunity for successful attacks against this critical sector.
This collective skill-building illustrates a broader dynamic observed across the entire Ukrainian cybersecurity sector: every repelled attack becomes a lesson built into future defenses, a virtuous circle forged under the pressure of war.
The Defense Sector, Target Number One
Attacks Aimed Directly at Ukrainian Military Capability
Ukraine's defense sector remains a prime target for Russian cyberattacks, the goal being to obtain information on military capabilities, troop movements or weapons supply chains, data whose strategic value to the aggressor is immediately exploitable on the battlefield.
Discover
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
REPORT: Kaduna, Benue, Rural Nigeria Left Alone Against Its…
At least 30 people were killed when gunmen attacked a village…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
This dimension explains why the SBU devotes considerable resources to protecting this specific sector, since every potential breach could translate directly into human and material losses on the front lines.
Strengthened Cooperation With Western Partners
Given the scale of this threat, Ukraine has developed increased cooperation with its Western partners on cyberdefense, a sharing of intelligence and best practices that benefits Kyiv as much as it benefits Western countries themselves, now facing similar campaigns from Russia.
This transatlantic cybersecurity cooperation illustrates a broader strategic reality: Ukrainian digital defense is no longer just a national issue, it has become a learning laboratory for all Western democracies facing the same hybrid threat.
The Growing Sophistication of Russian Methods
From Simple Denial-of-Service to Complex Social Engineering
The evolution of methods documented by the SBU, from simple traffic-saturation denial-of-service to complex phishing campaigns followed by infrastructure penetration, reveals a growing technical sophistication among Russian operators over the years of conflict.
This technical escalation is unsurprising: it reflects sustained investment by Moscow in its offensive cyber capabilities, viewed as a full-fledged tool of war, cheaper and politically less risky than a conventional military strike.
Constant Adaptation Required on the Ukrainian Side
This growing sophistication forces the SBU and its partners into permanent technical adaptation, with every newly detected attack method requiring immediate analysis to anticipate future variants and strengthen defenses accordingly.
This digital cat-and-mouse game, though less visible than ground combat, engages considerable human and technological resources on both sides, with stakes just as real for the overall outcome of the conflict.
What This Digital War Reveals About Overall Russian Strategy
A Hybrid War That Never Pauses
This ongoing cyber campaign, documented by the SBU for more than four years, confirms that Russian strategy against Ukraine is never limited to a single front. Missile strikes, ground offensives and cyberattacks fit into the same doctrine of total war aimed at exhausting every dimension of Ukrainian resilience.
This multidimensional approach explains why Ukrainian defense, to be effective, must itself operate on several fronts simultaneously, a reality that demands exceptional coordination among the armed forces, intelligence services, and civilian institutions.
A Model of Resistance That Inspires Beyond Ukraine's Borders
Ukraine's ability to keep its critical infrastructure operational despite thousands of documented cyberattacks is a model of digital resistance increasingly studied by Western experts facing similar, though generally less intense, threats.
This expertise, accumulated literally under fire, now places Ukraine among the world's most experienced nations in applied cyberdefense, a skill acquired at great cost but one that could prove valuable in postwar negotiations on security cooperation with the West.
The Limits of Transparency on This Sensitive File
What the SBU Cannot Reveal Publicly
By nature, cyberdefense operations require a degree of necessary confidentiality: publicly revealing every detection and neutralization method used by the SBU would hand Russian attackers valuable information for bypassing these defenses in the future.
This confidentiality constraint explains why certain technical details of the 16,000 neutralized attacks remain deliberately vague in the Ukrainian security service's public communications, an understandable methodological caution given the context of active war.
A Trust That Must Still Rest on Verifiable Facts
Despite this necessary confidentiality, the specific figures and cases made public by the SBU, such as the 200,000-requests-per-minuteDDoSattack or the 2025 media hijacking precedent, offer enough verifiable detail to establish the general credibility of the security service's claims.
This partial transparency, balanced against operational security imperatives, allows the Ukrainian and international public to gauge the real scale of this digital war without compromising the country's defensive capabilities.
The Human Impact Behind the Technical Statistics
Journalists on the Front Line of a Digital War
Behind every neutralized cyberattack statistic are journalists, technicians and Ukrainian media employees who work daily under the constant threat of a digital intrusion, on top of the already considerable physical risks of covering an active war on their own territory.
This dual pressure, technical and physical, weighs on media professionals already worn down by more than four years of conflict, who must now treat cybersecurity as a basic professional skill rather than a technical subject reserved for IT specialists.
Professional Resilience Forged Under Pressure
The training sessions organized by the SBU across Ukraine's 21 oblasts reflect this need for rapid professional adaptation, turning journalists and media managers into active participants in their own cyberdefense rather than passive victims of outside attacks.
This collective skill-building, though born of the tragic necessity of war, could become a lasting legacy for Ukraine's media sector well beyond the hoped-for end of the conflict.
Lessons for Western Democracies
A Preview of Future Threats for Europe and North America
The methods documented against Ukraine, from massive DDoS attacks to sophisticated media hijacking attempts, offer a troubling preview of the tactics Russia could deploy against other Western democracies should geopolitical tensions intensify further.
Several Western cybersecurity experts are now actively studying the Ukrainian experience to strengthen their own defense protocols, recognizing that what is happening in Kyiv today could well foreshadow similar threats elsewhere tomorrow.
A Need for Stronger Collective Vigilance
This situation calls for greater international cooperation on cyberdefense, where intelligence sharing between Ukraine and its Western partners becomes a strategic investment in the collective security of the entire democratic world.
Ignoring these Ukrainian lessons would mean repeating the under-preparation mistakes that allowed Russia to develop its offensive cyber capabilities for years without a sufficiently coordinated response from the international community.
On the same topic
OPINION: ChatGPT Takes Your Pulse — Public Health Entrusted…
OpenAI states, on the page announcing the launch of "Health in…
EDITORIAL: Measles — America Gives Up a Twenty-Six-Year-Old Public…
There is a line , in a table the CDC updates…
FACT-CHECK: Bloody Hazing, a Secret Service Agent Faces Justice
A U.S. Secret Service agent stationed in South Florida was arrested…
The Geopolitical Dimension of This Digital War
A Front That Fits Into the Global Rivalry With Authoritarian Regimes
This Russian cyberwar against Ukraine cannot be separated from a broader dynamic in which China, Iran and North Korea are also developing considerable offensive digital capabilities, often in tacit or explicit coordination with Moscow as part of their growing strategic convergence.
This authoritarian convergence in the cyber domain adds another dimension to the structural challenge these regimes pose to the collective security of Western democracies, far beyond the Ukrainian theater alone.
Why This File Reaches Well Beyond Ukraine's National Borders
Ukraine's digital resistance, documented through these 16,000 neutralized cyberattacks, must therefore be understood as part of a global confrontation between democracies and authoritarian regimes, where every Ukrainian defensive victory also represents a strategic gain for the entire free world.
This broader perspective justifies increased international support, not only military and humanitarian, but also technical and financial, to further strengthen the cyberdefense capabilities of a country that is ultimately protecting far more than its own digital borders.
The Funding and Resources This Defense Requires
A Considerable Budgetary Effort in the Middle of War
Maintaining a cyberdefense capability able to neutralize more than 16,000 attacks requires considerable budgetary resources, in a context where every available hryvnia must also fund the conventional military effort, the reconstruction of destroyed infrastructure, and support for populations displaced by the war.
This structural budgetary tension explains why international support for cybersecurity, whether financial, technical or in training, represents a valuable complement to Ukraine's national effort, allowing the SBU to maintain and improve its defensive capabilities despite severe budget constraints.
Technology Partnerships That Strengthen National Resilience
Several Western technology companies have developed direct partnerships with Ukrainian authorities to strengthen the country's digital defenses, support that goes beyond the strictly governmental framework to include the global private technology sector in this collective effort.
These partnerships, often less visible than conventional military aid, nonetheless play a decisive role in the SBU's continued ability to identify, analyze and neutralize increasingly sophisticated cyber threats coming from Russia.
Conclusion: A Digital Resilience That Deserves Recognition
A Record That Commands Respect Despite the Odds
More than 16,000 neutralized Russian cyberattacks since 2022, a massive DDoSattack repelled without service interruption, and a media hijacking attempt foiled in time: this record, compiled by the SBU, reflects a Ukrainian digital resilience forged under the most extreme adversity.
This defensive performance, achieved amid active war and limited resources, deserves international recognition equal to its strategic importance, both for Ukraine itself and for all the Western democracies watching and learning from this experience.
A Fight That Continues, Invisible but Decisive
As the physical war continues along Ukraine's eastern front lines, this parallel digital war also continues without letup or pause, demanding constant vigilance from SBU teams and their Western partners.
This invisible fight, however little media coverage it gets compared with images of trenches and bombardments, remains just as decisive for the final outcome of a conflict that is shaping Ukraine's future and, by extension, that of European security as a whole.
By Maxime Marquette, columnist
Columnist's transparency note
My Acknowledged Biases
I sign this report while acknowledging clear support for Ukrainian resistance to Russian aggression, while striving to precisely cite every statistic and every official statement used in this piece, without exaggeration or artificial dramatization.
What I Do Not Claim to Know
I do not know the precise technical details of the detection methods used by the SBU, information that legitimately falls under operational secrecy in a context of active war. This report relies exclusively on information made public by Ukrainian authorities and the media that documented it.
Sources
Primary sources
Ukraine's Ministry of Defense — national security context, July 2026
Euromaidan Press — Ukraine's media are top Russian cyber target, July 1, 2026
Armyinform — Ukrainian defense context coverage, July 2026
Secondary sources
Foreign Policy — analysis of Russian hybrid warfare, 2026
The Guardian International — cybersecurity and Ukraine war coverage, 2026
Axios — geopolitical and technology coverage, 2026
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). Ukraine's SBU Has Neutralized More Than 16,000 Russian Cyberattacks Since 2022. MadMax. https://mad-max.co/en/article/le-sbu-a-neutralise-plus-de-16-000-cyberattaques-russes-depuis-2022
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.