OPEN LETTER: To the FBI and the SSU — thank you for naming the Russian hackers
On June 25, 2026, cybersecurity experts from the Security Service of Ukraine (SSU), working in cooperation with the US Federal Bureau of Investigation (FBI), revealed the existence of a Russian cyberespionage campaign targeting the messaging accounts of government officials, military personnel, politicians, and activists in Ukraine, Europe, and the United States. This campaign,
- On June 25, 2026, cybersecurity experts from the Security Service of Ukraine (SSU), working in cooperation with the US Federal Bureau of Investigation (FBI), revealed the existence of a Russian cyberespionage campaign targeting the messaging accounts of government officials, military personnel, politicians, and activists in Ukraine, Europe, and the United States. This campaign,
- OPEN LETTER: To the FBI and the SSU — thank you for naming the Russian hackers
- Introduction: A joint investigation that crosses borders
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
OPEN LETTER: To the FBI and the SSU — thank you for naming the Russian hackers
Introduction: A joint investigation that crosses borders
The SSU and FBI uncover a Russian cyberespionage campaign
On June 25, 2026, cybersecurity experts from the Security Service of Ukraine (SSU), working in cooperation with the US Federal Bureau of Investigation (FBI), revealed the existence of a Russian cyberespionage campaign targeting the messaging accounts of government officials, military personnel, politicians, and activists in Ukraine, Europe, and the United States. This campaign, conducted by Russian intelligence services and associated hacker groups, aimed to infiltrate secure communications to obtain sensitive military, political, and economic information.
This open letter is addressed to the teams at the SSU and FBI who worked to document and make this campaign public. It is also addressed to everyone — officials, military personnel, journalists, activists — whose accounts were targeted or compromised. And it is addressed to Western political leaders who, perhaps, have not yet fully grasped the scale of the digital war that Russia is waging against them.
The method: fake SMS messages posing as tech support
Social engineering in the age of instant messaging
The primary method of this campaign is devastatingly effective in its simplicity. The hackers send SMS messages that appear to come from the support services of messaging applications — Signal, Telegram, WhatsApp. These messages ask targets to verify their account, confirm their identity, or reset their password. The messages are often disguised as communications from "official services" or "bots." They are typically sent in the early morning hours, when recipients are less vigilant due to physical fatigue or emotional stress.
If the target clicks the fraudulent link and enters their credentials, the hackers gain full access to their messaging account. They can then read all past and present conversations, access shared files, and impersonate the target in future exchanges. In the case of government officials or military personnel, this access gives Russian operators a direct window onto sensitive communications that do not pass through official encrypted channels — the informal conversations where real decisions are sometimes discussed.
The targets: governments, militaries, politicians, activists
A systematic, large-scale campaign
The SSU clarifies that Russian intelligence services and associated hacker groups target not only government institutions, officials, and public figures, but also the personal accounts of ordinary citizens. The data that hackers seek to obtain includes sensitive military information, political and economic intelligence, and personal user data. In April, the agency Reuters reported that Russian hackers had compromised more than 170 email accounts belonging to Ukrainian prosecutors and investigators — those responsible for fighting corruption and identifying Russian agents. The same hackers had targeted dozens of officials in Romania, Greece, Bulgaria, and Serbia.
This list of targeted countries — Romania, Greece, Bulgaria, Serbia — represents a significant geography. These are all Balkan or Eastern European countries with complex political dynamics regarding Russia. The targeting of their officials suggests a strategy broader than simple intelligence gathering: understanding internal political vulnerabilities, identifying entry points for influence, mapping decision-making networks at their most human and informal level.
What the SSU recommends — and what we should all do
Cyberhygiene as an act of resistance
The SSU publishes clear recommendations for all potential targets. First: regularly check active sessions in messaging applications and disconnect unrecognized sessions. Second: enable two-factor authentication (2FA) on all sensitive accounts. Third: never share verification codes or passwords with anyone. Fourth: avoid clicking on suspicious links, even if they appear to come from friends or contacts — their accounts may already be compromised.
These recommendations are frustratingly basic — they are fundamental cyberhygiene rules that most experts have been repeating for years. But they remain unimplemented by the majority of users. An official who receives an SMS at 3 a.m. asking them to "verify their Signal account" — exhausted, anxious, accustomed to a constant flow of notifications — may click without thinking. The Russian campaign exploits precisely this universal human vulnerability. The defense is known. The implementation rate remains the gap.
The SSU-FBI cooperation: a model of transatlantic response
Discover
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
BILLET: Altman and Huang Head to the Senate as…
According to Boursorama , Sam Altman of OpenAI and Jensen Huang…
When allies combine their cybersecurity capabilities
The joint SSU-FBI investigation is an example of what transatlantic cybersecurity cooperation can produce. Ukraine has extremely experienced cybersecurity teams, hardened by years of massive Russian attacks since 2014 — including the destruction of the Ukrainian power grid in 2015, the NotPetya attacks of 2017, and dozens of similar operations since. The FBI brings its attribution capabilities and its information-sharing networks with NATO allies' intelligence services.
Together, they can attribute attacks to specific actors, document methods, and share this information with allied countries that are targets. The decision to publish this investigation — rather than keep it classified — is itself a strategic choice: warn potential targets and show Russian operators that their methods are known, documented, and published. Transparency as deterrence. Naming as a form of defense. The public record is itself a shield.
Digital warfare in the broader context of the conflict
Cyberespionage as an extension of conventional warfare
This cyberespionage campaign cannot be understood outside the overall military context. Russian hackers target officials responsible for aid to Ukraine, military personnel involved in coordinating weapons deliveries, politicians who might be influenced or compromised to weaken Western support. These targets are not chosen randomly — they correspond to the pressure points of Western support for Ukraine. The campaign maps the coalition and probes its human vulnerabilities.
By compromising sensitive communications, Russia seeks an informational advantage: anticipating allies' decisions, identifying fractures in the coalition, finding leverage on individual decision-makers. Digital warfare is a direct extension of military strategy — not a separate domain. That is why it must be taken as seriously as missiles and tanks. Every compromised official account is a potential strategic asset in Moscow's hands. The digital front is as real as the front in Zaporizhzhia.
What this open letter asks of leaders
Investment, training, protocols
On the same topic
INVESTIGATION: Epstein a Foreign Agent? The Letter That Moves…
On July 21, 2026 , Jamie Raskin, Ranking Member of the…
EDITORIAL: Measles — America Gives Up a Twenty-Six-Year-Old Public…
There is a line , in a table the CDC updates…
ESSAY: Fourth Heat Wave — Europe Enters the Age…
On July 28, 2026, the New York Times reports that the…
This letter is also addressed to political and institutional leaders who have under their authority officials who are potentially targeted. It is time to invest seriously in cybersecurity training for all personnel who have access to sensitive information — not only IT managers, but everyone who uses personal messaging applications for professional communications. It is time to impose clear protocols on the use of commercial messaging for official exchanges.
These measures are not responses to a hypothetical threat. They respond to a documented, active campaign targeting officials in at least five allied countries. The SSU and FBI's decision to make this campaign public is precisely so that political leaders will act. The ball is now in their court — and the cost of inaction is measured in compromised data and lives potentially put at risk. The warning has been issued. The response is a choice.
Romania, Greece, Bulgaria, Serbia: Eastern Europe in the crosshairs
Why these specific countries are targeted
The targeting of government officials in Romania, Greece, Bulgaria, and Serbia reveals a precise strategy. These four countries share certain characteristics: a complex history with Russia, communities that maintain cultural or economic ties with Moscow, and internal political dynamics where pro-Russian parties are present and sometimes influential. Serbia in particular maintains ambiguous diplomatic relations — a member of NATO's Partnership for Peace but refusing to join sanctions against Russia.
Compromising officials in these countries can serve several simultaneous objectives: monitoring internal debates about support for Ukraine, identifying individuals who might be approached or recruited, and anticipating the diplomatic decisions of capitals that can sometimes be friction points within the Western coalition. Romania is a NATO member hosting bases essential to supporting Ukraine. Greece is a NATO member whose foreign policy is sometimes less aligned with the common position. These nuances are precisely what Russian operators seek to map and exploit. The campaign is a cartography of coalition vulnerability.
Conclusion: Cybersecurity is everyone's business
Beyond officials: civil society is also targeted
The SSU states it explicitly: Russian intelligence services target not only officials and military personnel, but also the personal accounts of ordinary citizens. Activists, journalists, human rights defenders, researchers covering Russia or Ukraine — all are potential targets. Protecting their communications is all the more critical because they do not necessarily have access to the security training and protocols available to official institutions. They are exposed with fewer resources to defend themselves.
Thank you, SSU and FBI — and keep going
This open letter ends as it began: with a thank you. Making this campaign public, naming the methods, publishing the recommendations — this is a public service. This is transparency in service of collective security. Keep going. And may everyone who receives this information read it, retain it, and act accordingly. The next target could be you. This sentence is not dramatic flourish — it is a documented statistical probability.
By Maxime Marquette, columnist
Columnist's transparency note
Editorial positioning
This open letter is written by a columnist convinced that transparency about Russian cyberespionage operations is a tool of democratic defense. The author has no access to classified information and relies exclusively on information made public by the SSU and FBI, as reported by Militarnyi on June 25, 2026, and on previous Reuters reporting.
Limits
The full scope of the campaign — total number of compromised accounts, identities of targeted individuals, data potentially exfiltrated — is not publicly available. The description here is based on information that authorities chose to make public, which likely represents a fraction of what is known to the investigating agencies.
Sources
Primary sources
Secondary sources
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). OPEN LETTER: To the FBI and the SSU — thank you for naming the Russian hackers. MadMax. https://mad-max.co/en/article/lettre-ouverte-au-fbi-et-au-ssu-merci-d-avoir-nomme-les-hackers-russes
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.