Skip to content
The ColumnReportage· No. 3430

Ukraine's SBU Has Neutralized More Than 16,000 Russian Cyberattacks Since 2022

The cybersecurity department of Ukraine's Security Service, the SBU, has announced it has neutralized more than 16,000 Russian cyberattacks since the start

Premium reading
MadMax
Key takeaways
  1. The cybersecurity department of Ukraine's Security Service, the SBU, has announced it has neutralized more than 16,000 Russian cyberattacks since the start
  2. Introduction: The Invisible War the SBU Is Fighting
  3. A Number That Reveals the Scale of the Digital Front
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

Introduction: The Invisible War the SBU Is Fighting

A Number That Reveals the Scale of the Digital Front

The cybersecurity department of Ukraine's Security Service, the SBU, has announced it has neutralized more than 16,000 Russian cyberattacks since the start of the full-scale war in February 2022. This figure, confirmed by Brigadier General Volodymyr Karastelov, head of the department, illustrates the scale of a digital front largely invisible to the general public, yet just as strategic as the ground combat lines.

According to Karastelov, the preferred targets of these Russian attacks are Ukrainian government agencies, financial institutions, the defense sector, and, increasingly, Ukrainian media, seen as a prime strategic target in this information war.

Why the Media Became a Russian Priority

This systematic targeting of Ukrainian media is no accident: controlling or sabotaging a wartime country's information channels lets the aggressor sow confusion, spread propaganda under an appearance of local legitimacy, and weaken the informational cohesion of a population already under constant bombardment pressure.

This strategy fits Russia's hybrid warfare doctrine, which has for years combined physical strikes with digital influence operations to maximize the destabilizing effect on Ukrainian society.

I consider this figure of 16,000 neutralized cyberattacks one of the most underrated statistics of this war. Every blocked attack is a silent battle won, with no medal and no media coverage, yet just as vital to Ukraine's national resilience.

The Three-Hour DDoS Attack on National Television

A Digital Offensive of Rare Intensity

The most recent case documented by the SBU involves a distributed denial-of-service attack, or DDoS, lasting three hours, directed at the website of a Ukrainian national television channel. At its peak, the attack generated up to 200,000 requests per minute, a traffic volume designed to completely overwhelm the targeted servers.

The botnet used to carry out this attack was made up of nodes spread across Asia, Europe and the United States, an international architecture deliberately designed to mimic real user behavior, making detection harder and exhausting the target's server resources.

Technical Resilience That Averted the Worst

Thanks to the intervention of SBU cybersecurity specialists, the television channel's website remained operational without interruption despite the intensity of the attack, a result that reflects a digital defense capability considerably strengthened since the conflict began.

This technical resilience, though rarely covered in the media, is a tangible victory in a war where every public service kept running represents a direct failure for Russian destabilization objectives.

Two hundred thousand requests per minute against a news website is not a minor technical annoyance. It is a deliberate attempt to silence a Ukrainian voice at the exact moment free information matters most to the population.

The 2025 Precedent: A Propaganda Hijacking Attempt

A Two-Stage Attack Against Another Broadcast Group

In 2025, another Ukrainian television group was the target of a more sophisticated attack, carried out in two distinct stages: an initial phishing campaign aimed at obtaining fraudulent access, followed by an attempt to penetrate information infrastructure through adjacent systems connected to the main network.

The final goal of this operation was not simple technical disruption but the complete takeover of the digital resource in order to broadcast Russian propaganda under the name and credibility of the legitimate Ukrainian outlet targeted.

Timely Detection That Averted an Information Catastrophe

SBU specialists managed to detect this intrusion in time, preventing the takeover of the outlet and thereby averting an information catastrophe that could have misled thousands, even millions, of Ukrainian viewers about the authenticity of the broadcast content.

This precedent illustrates an escalation in the sophistication of Russian methods, moving from simple saturation attacks to complex attempts at hijacking media identity for mass disinformation purposes.

Imagine the impact of a legitimate Ukrainian television channel suddenly broadcasting Russian propaganda under its own name. The SBU prevented that nightmare scenario, and this success deserves to be known far beyond specialized cybersecurity circles.

The Structural Role of GRU Unit 29155

A Russian Military Unit Built for Cyberwarfare

Behind several of these campaigns looms the shadow of Unit 29155 of Russian military intelligence, the GRU, initially designed as a dedicated cyberwarfare arm before broadening its scope to other forms of hostile operations against Ukraine and its Western partners.

This unit has run spear-phishing campaigns directly targeting President Volodymyr Zelensky's office as well as several Ukrainian ministries, aiming to gain unauthorized access to sensitive communications at the highest levels of the state.

The Deployment of the Destructive WhisperGate Malware

Even before the full-scale invasion began, this same unit had deployed the destructive WhisperGate malware, designed to irreversibly wipe data from Ukrainian computer systems, a digital sabotage operation preparing the ground for the military aggression that would follow.

This prior deployment shows that Russia's hybrid war against Ukraine began well before the first tanks crossed the border, confirming that preparation for this invasion played out simultaneously on military and digital fronts.

WhisperGate deployed before the physical invasion is not an incidental technical detail. It is proof that Moscow was planning this war well before publicly admitting it, while still denying its intentions to the entire world.

The Cybersecurity Resilience Program for Regional Media

A Joint Initiative Between the SBU and the Broadcasting Regulator

Faced with this persistent threat, the SBU launched a cybersecurity resilience project for local and regional media outlets, in partnership with Ukraine's National Council of Television and Radio Broadcasting, the country's broadcasting regulator.

This program acknowledges an important strategic reality: major national outlets are not the only potential targets, and regional structures, often less technically equipped, represent a vulnerable link that urgently needed reinforcement.

Nationwide Coverage in 2026

In 2026, the SBU organized a series of hands-on cybersecurity training sessions in 20 regional locations, covering media representatives from all 21 oblasts in Ukraine, near-complete territorial coverage that reflects the scale of the effort deployed.

Nearly 450 participants took part in these sessions, including media managers, journalists, editors-in-chief and technical specialists, a diversity of profiles that reflects the need for cybersecurity awareness at every level of a media organization.

Training 450 media professionals across 21 oblasts is not a mere bureaucratic exercise. It is a clear-eyed recognition that a wartime country's informational resilience rests as much on well-trained journalists as on technical firewalls.

Financial Institutions, a Quiet but Critical Target

A Sector Vital to Economic Stability in Wartime

Beyond the media, Ukrainian financial institutions are among the priority targets identified by the SBU, a threat that takes on particular weight in a country whose economy must stay functional despite constant bombardment and the logistical challenges of a prolonged war.

A successful attack on Ukraine's banking infrastructure could paralyze routine transactions, affect the payment of salaries and pensions, and undermine citizens' already fragile confidence in their country's economic stability in the middle of a war.

Financial Defenses Strengthened by the Experience of Conflict

Experience accumulated since 2022 has allowed Ukrainian financial institutions, in coordination with the SBU, to develop increasingly sophisticated defense protocols, significantly reducing the window of opportunity for successful attacks against this critical sector.

This collective skill-building illustrates a broader dynamic observed across the entire Ukrainian cybersecurity sector: every repelled attack becomes a lesson built into future defenses, a virtuous circle forged under the pressure of war.

It is the least visible institutions in the media, such as banks, that often carry the heaviest weight of this silent digital war. Their resilience deserves recognition equal to that given to soldiers on the physical front.

The Defense Sector, Target Number One

Attacks Aimed Directly at Ukrainian Military Capability

Ukraine's defense sector remains a prime target for Russian cyberattacks, the goal being to obtain information on military capabilities, troop movements or weapons supply chains, data whose strategic value to the aggressor is immediately exploitable on the battlefield.

This dimension explains why the SBU devotes considerable resources to protecting this specific sector, since every potential breach could translate directly into human and material losses on the front lines.

Strengthened Cooperation With Western Partners

Given the scale of this threat, Ukraine has developed increased cooperation with its Western partners on cyberdefense, a sharing of intelligence and best practices that benefits Kyiv as much as it benefits Western countries themselves, now facing similar campaigns from Russia.

This transatlantic cybersecurity cooperation illustrates a broader strategic reality: Ukrainian digital defense is no longer just a national issue, it has become a learning laboratory for all Western democracies facing the same hybrid threat.

Ukraine has become, against its will, the world's largest cyberdefense laboratory against Russia. The lessons learned in Kyiv now directly benefit the digital security of the entire West.

The Growing Sophistication of Russian Methods

From Simple Denial-of-Service to Complex Social Engineering

The evolution of methods documented by the SBU, from simple traffic-saturation denial-of-service to complex phishing campaigns followed by infrastructure penetration, reveals a growing technical sophistication among Russian operators over the years of conflict.

This technical escalation is unsurprising: it reflects sustained investment by Moscow in its offensive cyber capabilities, viewed as a full-fledged tool of war, cheaper and politically less risky than a conventional military strike.

Constant Adaptation Required on the Ukrainian Side

This growing sophistication forces the SBU and its partners into permanent technical adaptation, with every newly detected attack method requiring immediate analysis to anticipate future variants and strengthen defenses accordingly.

This digital cat-and-mouse game, though less visible than ground combat, engages considerable human and technological resources on both sides, with stakes just as real for the overall outcome of the conflict.

This growing sophistication of Russian attacks must never be underestimated. Every technical advance Moscow makes in this domain forces Ukraine into constant vigilance, with no room to let up.

What This Digital War Reveals About Overall Russian Strategy

A Hybrid War That Never Pauses

This ongoing cyber campaign, documented by the SBU for more than four years, confirms that Russian strategy against Ukraine is never limited to a single front. Missile strikes, ground offensives and cyberattacks fit into the same doctrine of total war aimed at exhausting every dimension of Ukrainian resilience.

This multidimensional approach explains why Ukrainian defense, to be effective, must itself operate on several fronts simultaneously, a reality that demands exceptional coordination among the armed forces, intelligence services, and civilian institutions.

A Model of Resistance That Inspires Beyond Ukraine's Borders

Ukraine's ability to keep its critical infrastructure operational despite thousands of documented cyberattacks is a model of digital resistance increasingly studied by Western experts facing similar, though generally less intense, threats.

This expertise, accumulated literally under fire, now places Ukraine among the world's most experienced nations in applied cyberdefense, a skill acquired at great cost but one that could prove valuable in postwar negotiations on security cooperation with the West.

There is a bitter irony in the fact that Ukraine, a victim of this war, has become one of the world's most capable nations in cyberdefense. This expertise, paid for in blood and destroyed infrastructure, deserves recognition and support from its Western allies.

The Limits of Transparency on This Sensitive File

What the SBU Cannot Reveal Publicly

By nature, cyberdefense operations require a degree of necessary confidentiality: publicly revealing every detection and neutralization method used by the SBU would hand Russian attackers valuable information for bypassing these defenses in the future.

This confidentiality constraint explains why certain technical details of the 16,000 neutralized attacks remain deliberately vague in the Ukrainian security service's public communications, an understandable methodological caution given the context of active war.

A Trust That Must Still Rest on Verifiable Facts

Despite this necessary confidentiality, the specific figures and cases made public by the SBU, such as the 200,000-requests-per-minuteDDoSattack or the 2025 media hijacking precedent, offer enough verifiable detail to establish the general credibility of the security service's claims.

This partial transparency, balanced against operational security imperatives, allows the Ukrainian and international public to gauge the real scale of this digital war without compromising the country's defensive capabilities.

I understand and respect this necessary operational confidentiality, but I insist on the importance of making enough concrete cases public so that the Ukrainian population and its allies can measure the reality of this invisible war.

The Human Impact Behind the Technical Statistics

Journalists on the Front Line of a Digital War

Behind every neutralized cyberattack statistic are journalists, technicians and Ukrainian media employees who work daily under the constant threat of a digital intrusion, on top of the already considerable physical risks of covering an active war on their own territory.

This dual pressure, technical and physical, weighs on media professionals already worn down by more than four years of conflict, who must now treat cybersecurity as a basic professional skill rather than a technical subject reserved for IT specialists.

Professional Resilience Forged Under Pressure

The training sessions organized by the SBU across Ukraine's 21 oblasts reflect this need for rapid professional adaptation, turning journalists and media managers into active participants in their own cyberdefense rather than passive victims of outside attacks.

This collective skill-building, though born of the tragic necessity of war, could become a lasting legacy for Ukraine's media sector well beyond the hoped-for end of the conflict.

These Ukrainian journalists learning cybersecurity between air raid alerts deserve recognition that goes far beyond specialized circles. Their daily resilience is an essential component of Ukraine's national resistance.

Lessons for Western Democracies

A Preview of Future Threats for Europe and North America

The methods documented against Ukraine, from massive DDoS attacks to sophisticated media hijacking attempts, offer a troubling preview of the tactics Russia could deploy against other Western democracies should geopolitical tensions intensify further.

Several Western cybersecurity experts are now actively studying the Ukrainian experience to strengthen their own defense protocols, recognizing that what is happening in Kyiv today could well foreshadow similar threats elsewhere tomorrow.

A Need for Stronger Collective Vigilance

This situation calls for greater international cooperation on cyberdefense, where intelligence sharing between Ukraine and its Western partners becomes a strategic investment in the collective security of the entire democratic world.

Ignoring these Ukrainian lessons would mean repeating the under-preparation mistakes that allowed Russia to develop its offensive cyber capabilities for years without a sufficiently coordinated response from the international community.

What Ukraine is learning today under fire from Russian cyberwarfare, the West should study with the utmost attention. Ignoring these lessons would be a strategic negligence we could bitterly regret.

The Geopolitical Dimension of This Digital War

A Front That Fits Into the Global Rivalry With Authoritarian Regimes

This Russian cyberwar against Ukraine cannot be separated from a broader dynamic in which China, Iran and North Korea are also developing considerable offensive digital capabilities, often in tacit or explicit coordination with Moscow as part of their growing strategic convergence.

This authoritarian convergence in the cyber domain adds another dimension to the structural challenge these regimes pose to the collective security of Western democracies, far beyond the Ukrainian theater alone.

Why This File Reaches Well Beyond Ukraine's National Borders

Ukraine's digital resistance, documented through these 16,000 neutralized cyberattacks, must therefore be understood as part of a global confrontation between democracies and authoritarian regimes, where every Ukrainian defensive victory also represents a strategic gain for the entire free world.

This broader perspective justifies increased international support, not only military and humanitarian, but also technical and financial, to further strengthen the cyberdefense capabilities of a country that is ultimately protecting far more than its own digital borders.

This Ukrainian digital war is not an isolated conflict. It is the forward front line of a global confrontation between democracies and authoritarian regimes, and every Russian cyberattack repelled in Kyiv is a victory that benefits all of us.

The Funding and Resources This Defense Requires

A Considerable Budgetary Effort in the Middle of War

Maintaining a cyberdefense capability able to neutralize more than 16,000 attacks requires considerable budgetary resources, in a context where every available hryvnia must also fund the conventional military effort, the reconstruction of destroyed infrastructure, and support for populations displaced by the war.

This structural budgetary tension explains why international support for cybersecurity, whether financial, technical or in training, represents a valuable complement to Ukraine's national effort, allowing the SBU to maintain and improve its defensive capabilities despite severe budget constraints.

Technology Partnerships That Strengthen National Resilience

Several Western technology companies have developed direct partnerships with Ukrainian authorities to strengthen the country's digital defenses, support that goes beyond the strictly governmental framework to include the global private technology sector in this collective effort.

These partnerships, often less visible than conventional military aid, nonetheless play a decisive role in the SBU's continued ability to identify, analyze and neutralize increasingly sophisticated cyber threats coming from Russia.

This Western private-sector technology support for Ukrainian cyberdefense deserves recognition equal to that given to traditional military aid. Without these partnerships, Ukraine's digital resilience would be considerably more fragile against such a determined adversary.

Conclusion: A Digital Resilience That Deserves Recognition

A Record That Commands Respect Despite the Odds

More than 16,000 neutralized Russian cyberattacks since 2022, a massive DDoSattack repelled without service interruption, and a media hijacking attempt foiled in time: this record, compiled by the SBU, reflects a Ukrainian digital resilience forged under the most extreme adversity.

This defensive performance, achieved amid active war and limited resources, deserves international recognition equal to its strategic importance, both for Ukraine itself and for all the Western democracies watching and learning from this experience.

A Fight That Continues, Invisible but Decisive

As the physical war continues along Ukraine's eastern front lines, this parallel digital war also continues without letup or pause, demanding constant vigilance from SBU teams and their Western partners.

This invisible fight, however little media coverage it gets compared with images of trenches and bombardments, remains just as decisive for the final outcome of a conflict that is shaping Ukraine's future and, by extension, that of European security as a whole.

I end this report with a firm conviction: the courage of Ukrainian soldiers on the physical front has an equally real equivalent among the SBU specialists defending the country's digital infrastructure day and night. Both deserve our equal respect.

By Maxime Marquette, columnist

Columnist's transparency note

My Acknowledged Biases

I sign this report while acknowledging clear support for Ukrainian resistance to Russian aggression, while striving to precisely cite every statistic and every official statement used in this piece, without exaggeration or artificial dramatization.

What I Do Not Claim to Know

I do not know the precise technical details of the detection methods used by the SBU, information that legitimately falls under operational secrecy in a context of active war. This report relies exclusively on information made public by Ukrainian authorities and the media that documented it.

Sources

Primary sources

Ukraine's Ministry of Defense — national security context, July 2026

Euromaidan Press — Ukraine's media are top Russian cyber target, July 1, 2026

Armyinform — Ukrainian defense context coverage, July 2026

Secondary sources

Foreign Policy — analysis of Russian hybrid warfare, 2026

The Guardian International — cybersecurity and Ukraine war coverage, 2026

Axios — geopolitical and technology coverage, 2026

Get the geopolitics analyses

Conflicts, powers, alliances: the MadMax thread without the noise.

Cite this article

Maxime Marquette (2026). Ukraine's SBU Has Neutralized More Than 16,000 Russian Cyberattacks Since 2022. MadMax. https://mad-max.co/en/article/le-sbu-a-neutralise-plus-de-16-000-cyberattaques-russes-depuis-2022

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Reportage2 reads3183 words17 min read