REPORT: Russian spies hack the messaging apps of Ukrainian officers and officials
On June 25, 2026, the Ukrainian Security Service (SBU), in collaboration with the US Federal Bureau of Investigation, revealed a systematic campaign of Russian cyberattacks targeting the messaging applications used by government officials, military personnel, politicians and activists in Ukraine, across Europe and in the United States. These digital espionage operations are par
- On June 25, 2026, the Ukrainian Security Service (SBU), in collaboration with the US Federal Bureau of Investigation, revealed a systematic campaign of Russian cyberattacks targeting the messaging applications used by government officials, military personnel, politicians and activists in Ukraine, across Europe and in the United States. These digital espionage operations are par
- REPORT: Russian spies hack the messaging apps of Ukrainian officers and officials
- Introduction: The digital war strikes at the heart of Ukrainian communications
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
REPORT: Russian spies hack the messaging apps of Ukrainian officers and officials
Introduction: The digital war strikes at the heart of Ukrainian communications
A systematic cyberespionage campaign revealed on June 25
On June 25, 2026, the Ukrainian Security Service (SBU), in collaboration with the US Federal Bureau of Investigation, revealed a systematic campaign of Russian cyberattacks targeting the messaging applications used by government officials, military personnel, politicians and activists in Ukraine, across Europe and in the United States. These digital espionage operations are part of a documented intensification of Russian cyber operations against Ukraine and its Western allies throughout June 2026.
The methods employed reveal the growing sophistication of Russian cyber groups: SMS phishing messages posing as "customer support," imitation of official bots, and psychological pressure delivered through mass messages sent in the morning when users are less alert. The goal: access confidential military, political and economic communications — and compromise entire networks starting from a single account.
The strategic dimension of a parallel war
Russian cyberespionage is not a peripheral or opportunistic activity. It is a central pillar of Moscow's war strategy, running parallel to kinetic operations on the battlefield. Compromising the communications of a military commander or a government official can be worth as much as an artillery strike in terms of operational advantage. And unlike missiles, cyber operations carry no ammunition cost.
For Ukraine, securing communications is a matter of national survival. Any leak in messaging systems can betray positions, operational plans, sensitive foreign contacts or vulnerabilities in the state apparatus. The public disclosure of this campaign by the SBU and the FBI is itself a strategic act: alerting potential targets, forcing Russian groups to adapt their exposed methods, and signaling to Western allies the intensity of the threat.
Attack methods: phishing, impersonation and psychological pressure
SMS phishing: a mass vector of entry
One of the main methods documented in this campaign is SMS phishing. Victims receive messages claiming to come from the "customer support" of their messaging application — a convincing message at first glance, especially for mobile users under pressure who quickly glance at their notifications. These messages contain links or "account verification" requests designed to steal access credentials.
The psychology behind these attacks is carefully calculated. Messages are often sent early in the morning, when targets have just woken up and are less focused. They create false urgency — "your account will be suspended," "a suspicious connection was detected" — which pushes victims to act quickly without checking the authenticity of the request. It is work in psychological precision, not just technical precision.
Impersonation of official bots and government services
A second documented method involves creating bots that imitate official services on messaging applications. In the Ukrainian context, where the state has widely integrated messaging applications into its official communications — government notifications, military alerts, administrative exchanges — distinguishing between an official bot and a malicious one can be very difficult for an ordinary user.
These fraudulent bots can request identification information, collect metadata about contacts, map communication networks and even, in some cases, take control of an account to monitor future exchanges. Once one account is compromised within a network of officers or officials, the attacker can progressively access the entire network through the compromised account's contacts.
The targets: beyond Ukraine's borders
Identified targets across Europe and the United States
A crucial element revealed by the SBU and the FBI is that this campaign does not only target Ukrainians. European officials, military personnel, politicians and activists in the United States and across Europe are among the identified targets. This is confirmation that Russia's cyber war against the West is global, coordinated and targets the entire ecosystem of Ukraine's allies.
This transatlantic dimension explains the FBI's participation in the joint disclosure. American intelligence services have a direct interest in exposing these operations, some of which targeted American officials or US government assets in contact with their Ukrainian counterparts.
Ordinary accounts as a vector for intelligence collection
The SBU also reported that the campaign is not limited to high-level targets. Accounts belonging to ordinary Ukrainians were also targeted, potentially as part of a broader data collection scheme. These accounts can be used as entry points into more sensitive networks — a simple citizen may be in contact with a friend who is an officer, or a neighbor who works for a government agency.
This strategy of infiltration through peripheral connections, known as the "value chain approach," is a well-documented method in state cyber operations. Rather than attacking a well-protected target directly, you start by compromising its least-secure contacts, then progressively work your way up the chain of trust.
The context: an intensification of cyber operations in June 2026
A documented escalation since the start of the year
The disclosure of this campaign fits within a context of notable intensification of Russian cyber operations in 2026. As early as February 2026, CERT-EU had documented a sophisticated phishing campaign targeting the Signal application, aimed at high-level figures across Europe — politicians, military personnel, journalists. The attack, suspected to be APT28 (the Russian group linked to the GRU), impersonated Signal's support bot to prompt victims to re-enter their PIN or re-register their devices.
These operations are not new. The group APT28 — also known as Fancy Bear or Sofacy — has been active since at least 2007 and has been responsible for some of the most high-profile cyber operations of the past decade: the hacking of the American Democratic National Committee in 2016, attacks on the German Bundestag, and the compromise of government networks in the Baltic states. In Ukraine, its activity has never ceased since 2014.
The French cyber defense regiment: learning from Ukraine
It is in this context that information revealed on June 24, 2026 by Intelligence Online takes on full significance: the French army's cyber defense regiment is sending specialists to Ukraine to acquire direct operational field experience. Ukraine has become the world's living laboratory for cyber warfare — and allied armies are seeking to draw lessons from this laboratory in real time.
This French initiative illustrates a reality that military professionals understand better than politicians: Ukraine's experience in cyber warfare is irreplaceable. No training exercise, no simulation, can reproduce the reality of a high-intensity conflict in which cyber and kinetic operations are conducted simultaneously by both belligerents at full scale.
The tools of Russian cyber warfare: a sophisticated toolkit
APT28, Sandworm and the GRU and FSB cyber groups
Russia has several elite cyber groups linked to its intelligence agencies. APT28 and Sandworm are associated with the GRU (military intelligence). The Turla group is linked to the FSB. APT29 (Cozy Bear) is generally attributed to the SVR (foreign intelligence). Each of these groups has distinct specializations: APT28 targets governments and political parties in particular, Sandworm critical infrastructure, Turla foreign intelligence services.
The June 2026 campaign targeting Ukrainian messaging apps bears the signatures of several of these groups, according to threat analysts. The convergence of operations from multiple Russian intelligence agencies against the same targets is characteristic of a high-level intelligence priority defined at the apex of Russian power.
Discover
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
REPORT: Kaduna, Benue, Rural Nigeria Left Alone Against Its…
At least 30 people were killed when gunmen attacked a village…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
The most common attack vectors in 2026
Beyond SMS phishing and bot impersonation, Russian cyber operations against Ukraine use a range of tools and vectors: malware concealed in apparently official documents, zero-day vulnerability exploitation in popular applications, software supply chain attacks targeting updates of legitimate software used by targets, and sophisticated social engineering exploiting crisis contexts to deceive users under pressure.
CERT-EU documented in 2026 the exploitation by the group APT28 of a critical vulnerability (CVE-2026-21509) in Microsoft Office RTF files, enabling the installation of email-stealing malware and backdoors in targeted systems in Ukraine, Slovakia and Romania.
The Ukrainian response: the SBU on the front line
An organization that has reinvented itself under pressure
The SBU (Ukrainian Security Service) has profoundly transformed its cyber capabilities since the start of the war. Its cyber defense teams operate continuously to detect, counter and document Russian attacks — often working with partners like the FBI, CERT-EU, and private cybersecurity companies like ESET and Mandiant.
The decision to make this June 2026 campaign public is itself a defensive strategy: by exposing the attackers' methods, the SBU forces Russian groups to adapt their tools and methods — a process costly in time and resources for the adversary. It is a form of defense through transparency, with the additional advantage of alerting potential targets in allied countries.
SBU-FBI cooperation: a model cyber alliance
The cooperation between the SBU and the FBI in documenting and exposing these cyber campaigns illustrates a bilateral cooperation model that has deepened since 2022. The United States has provided Ukraine not only with weapons and intelligence, but also with substantial cyber cooperation — training, threat intelligence sharing, and incident response assistance.
This cooperation has a strategic character for both parties. For Ukraine, it provides access to the FBI's analytical capabilities and databases to identify and document threat actors. For the United States, Ukraine is a unique observation window into the tactics, techniques and procedures of Russian cyber groups — knowledge directly applicable to the defense of American systems.
The threat to Western allies: the Ukrainian lesson
What Ukraine is teaching the West about cyber warfare
Ukraine's experience in cyber warfare since 2022 — and even since 2014 — offers lessons of incalculable value for allied armies and governments. Ukraine has been the testing ground for all forms of state cyber attacks: attacks against energy infrastructure (the NotPetya attack of 2017, Industroyer), coordinated disinformation operations, compromise of military command chains, disruption of critical communications.
These experiences have transformed Ukraine into an exceptionally cyber-resilient country — and its experts into strategic resources of interest to allies. This is precisely why the French cyber defense regiment is sending its specialists to Ukraine: to learn at first hand from practitioners who have been fighting these threats in real conditions for more than a decade.
The vulnerabilities of Western states facing a similar offensive
The question raised by the intensification of Russian cyber attacks against Ukraine is directly applicable to Western Europe: would we be capable of withstanding a similar campaign targeting our own officials, military personnel and communications infrastructure? The honest answer is: perhaps not, or not as effectively as Ukraine.
European administrations often remain inadequately trained in cyber risks, messaging security protocols are rarely applied with the required rigor, and the culture of operational security (OPSEC) is still too rare in civilian and political circles. Ukraine, under the pressure of war, was forced to develop this culture at forced march. Its allies have not yet faced the same constraint.
Signal and encrypted messaging apps: the prime target
Why messaging apps are priority targets
Messaging apps like Signal, Telegram and WhatsApp have become trusted communication channels for many Ukrainian officials and military personnel — precisely because they offer end-to-end encryption. But that encryption only protects transmission: if the attacker takes control of the sender's or receiver's account, the encryption is worthless.
That is where the Russian attack concentrates: not attempting to break the encryption (technically extremely difficult), but compromising account access through phishing and impersonation techniques. By stealing the access credentials to a Signal account, an attacker can read all messages not yet deleted, monitor future exchanges and map the victim's contact network.
Recommended protective measures and their limits
The SBU and the FBI have issued protective recommendations: activate two-factor authentication, never click on links received by SMS or messaging without prior verification, be suspicious of any message requesting identification information, use dedicated phone numbers for security applications. These recommendations are reasonable but insufficient against sufficiently sophisticated and persistent adversaries.
The reality of the Ukrainian cyber field is that users under constant operational pressure cannot maintain the necessary level of vigilance indefinitely. A front-line officer receiving dozens of messages per hour will statistically be susceptible, at some point, to clicking on a malicious link. Operational cybersecurity cannot rest solely on human vigilance — it must be architecturally reinforced by technical systems.
The implications for NATO cyber doctrine
A call to integrate Ukrainian lessons into allied doctrine
The intensification of Russian cyber operations against Ukraine and its allies in June 2026 arrives precisely as NATO prepares for its Ankara summit on July 7-8, which should see major announcements on allied defensive capabilities. The cyber dimension of the Alliance's collective security will inevitably be at the heart of discussions.
The French initiative to send specialists to Ukraine should be extended to all NATO allies. The Alliance's cyber doctrine would benefit from revision in the light of Ukrainian lessons — not in 5 years, after several cycles of bureaucratic revision, but now, while the experience is being acquired.
Cyberwarfare as a conflict domain in its own right
Since 2016, NATO has officially recognized cyberspace as a conflict domain on par with land, sea, air and space. But the translation of this doctrinal recognition into concrete capabilities remains uneven across Alliance members. The most advanced countries — United States, United Kingdom, Estonia — have robust cyber commands. Other members remain vulnerable.
The creation in 2022 of NATO's Cyber Coordination Center in Brussels and the scaling up of NATO's Cyber Centre of Excellence in Tallinn are steps in the right direction. But the war in Ukraine shows that the pace of adaptation of allied institutions remains too slow relative to the rapid evolution of threats.
The information war and the cyber war: linked instruments
Cyber espionage and disinformation: two sides of the same offensive
The Russian cyber espionage operations documented in June 2026 must not be understood in isolation from the disinformation and influence operations Russia conducts simultaneously. These two dimensions are linked: data collected through cyberespionage feeds disinformation campaigns — stolen information can be selected, manipulated and disseminated to create compromising narratives, sow discord or discredit Ukrainian or allied officials.
This cyber-information integration is at the heart of what Russian strategists call "hybrid war" — a doctrine that refuses the distinction between war and peace, between military and civilian domains, and which seeks to defeat adversaries through attrition rather than battlefield victory.
The stakes for democracy and institutions
Ultimately, it is confidence in democratic institutions that is targeted by these combined operations. If officials can be compromised, if confidential communications can be stolen and disseminated, if manufactured rumors about the behavior of senior officials can circulate on social networks, the democratic space and the capacity of governments to govern are directly threatened.
Ukraine has been facing this for years and has developed remarkable resilience. But its Western allies, who have not yet experienced this information war at full intensity on their own soil, potentially remain more vulnerable. The protection of our cyber systems is not just a matter of national security — it is a matter of democratic health.
Perspectives: toward strengthened collective cyber defense
Available technical and doctrinal solutions
Concrete responses to the threat documented in June 2026 exist. On the technical side: generalization of physical security keys (hardware tokens) for authentication of government and military accounts, strict compartmentalization of communications by sensitivity level, use of sovereign and certified messaging systems for the most sensitive exchanges. On the operational side: ongoing training, regular phishing exercises, a culture of incident reporting.
Several NATO countries have already deployed these measures for their most sensitive communications. The question is extending these protections more broadly into administrations, down to the intermediate levels that remain entry vectors for attackers seeking to work their way toward higher-value targets.
The challenge of large-scale training
The most difficult challenge remains large-scale training. A country can deploy the best cybersecurity technologies in the world — if its users don't understand the risks or don't follow protocols, those technologies will be bypassed. Training hundreds of thousands of officials, military personnel and elected representatives in good cyber reflexes is an organizational, budgetary and cultural challenge that takes years.
Ukraine was forced to accelerate this training under the pressure of war. The rest of the West must undertake this effort proactively, without waiting to be forced into it by a crisis. Ukraine's experience shows that the question is not whether our governments' messaging systems will be attacked by Russian or Chinese cyber groups — but when.
NATO and the Ankara summit: cyber capabilities at the heart of discussions
Expected announcements on common defensive capabilities
The NATO summit in Ankara on July 7-8, 2026 should be the occasion for major announcements on collective defensive capabilities — including cyber capabilities. Secretary General Mark Rutte announced that new defense contracts for "tens of billions of dollars" would be signed, covering autonomous systems and long-range strike. The cyber dimension of these capabilities has not yet been detailed publicly, but it is at the heart of preparatory discussions.
For Ukraine, participation in these Ankara discussions is strategically important. The country wants to ensure that the lessons of its cyber war are integrated into the Alliance's collective doctrine — and that the cyber support of allies continues to intensify, not only during the war but in the perspective of a secure reconstruction and a future anchoring in Western security structures.
Cyber capabilities in the NATO membership equation
Ukraine is not yet a NATO member. But its cyber capabilities — built through real battles against the world's top state cyber groups — already make it a potential net contributor to the Alliance's security. Paradoxically, the country that has suffered the most from Russian cyberattacks has become one of those that best understands and counters them.
This reality should accelerate, rather than complicate, the process of integrating Ukraine into Western security structures. A country that can share operational cyber experience unmatched anywhere in the world is not a burden for the Alliance — it is a strategic asset.
The long-term implications for European security architecture
A structural turning point in continental security relations
The developments described in this article are part of a broader transformation of European security architecture. The European Union, long perceived as an essentially normative and economic power, is acquiring a real and substantial military dimension. The instruments created since 2022 — SAFE, APF, reinforced PESCO, bilateral industrial cooperation — together constitute an institutional foundation for a European defense that did not exist five years ago.
This structural change is irreversible insofar as it responds to real, documented and growing security needs. As long as Putin's Russia maintains an aggressive posture and the democracies on Europe's eastern periphery are threatened, the movement toward a more robust European defense will continue. Debates over national sovereignty, cost-sharing and national priorities will remain — but they will not reverse the underlying trend. Collective security requires collective structures. And Europe is building them.
On the same topic
COMMENTARY: A Supermarket in Chernihiv — the Normalization of…
On the night of July 27 to 28, 2026 , the…
EDITORIAL: Measles — America Gives Up a Twenty-Six-Year-Old Public…
There is a line , in a table the CDC updates…
INVESTIGATION: Epstein a Foreign Agent? The Letter That Moves…
On July 21, 2026 , Jamie Raskin, Ranking Member of the…
What this evolution means for Ukraine
For Ukraine, these developments are directly linked to its immediate security and long-term future. In the short term, every billion invested in European defense, every military capability developed, every contract signed with Ukrainian producers strengthens its capacity to resist. Over the longer term, a solid European defense is the best guarantee that Western support for Ukraine will not evaporate with the next change of government in the United States or elsewhere.
Ukraine is not only a beneficiary of these developments — it is also an essential driver of them. Its combat experience, its growing industries, its technological innovations in drones and electronic warfare systems directly feed the investment choices and operational doctrines of the allies. Europe learns from Ukraine as much as it provides to it. And that mutual learning partnership is one of the most enduring legacies this war will leave to the continent's collective security.
The international response and the support of the Atlantic community
Allies facing the evolving situation
Ukraine's Western partners have followed recent developments with close attention. European chancelleries, NATO general staffs and allied intelligence services have integrated this information into their analyses and planning. The decisions described in this article are not made in a strategic vacuum — they are part of a permanent dialogue between Kyiv and its partners, a technical, political and military dialogue conducted through dozens of formal and informal channels.
That dialogue has produced concrete results visible in weapons deliveries, soldier training programs, intelligence sharing and coordinated diplomatic decisions. The institutional framework of this support — NATO, EU, bilateral coalitions — has expanded considerably since 2022 and today operates with an effectiveness no one would have predicted at the start of the conflict. Ukraine is no longer alone. And that reality fundamentally changes the strategic equation vis-à-vis Russia.
Future commitments: durability and depth
The durability of Western support is a legitimate question Ukraine raises regularly. Political changes in allied democracies — elections, changes of government, popular pressure on budgets — can cause fluctuations in the level of engagement. This is why Ukraine seeks to institutionalize support through bilateral treaties, multi-year industrial contracts and financing mechanisms with long-term commitments that transcend electoral cycles.
Investment in the Ukrainian defense industry, pilot training on Gripens, 45-year SAFE financing guarantees — all these decisions pursue exactly this objective: creating irreversible commitments that can only be undone by a costly and deliberate political decision. That is conscious institutional strategy. And it reflects the maturity that Ukrainian decision-makers and their partners have acquired since the start of the conflict.
Conclusion: The invisible war that shapes the visible battles
Cyber as a force multiplier in the Ukrainian war
The Russian cyberattacks against the messaging apps of Ukrainian officials and military personnel revealed in June 2026 are not an isolated incident. They are a permanent, systematic and growing dimension of a war being fought across all domains simultaneously. Russia's ability to penetrate Ukrainian communications is directly linked to its ability to anticipate Ukrainian movements on the battlefield — and therefore to the effectiveness of kinetic operations.
Ukrainian resilience on this cyber front, supported by its allies and developed in the heat of action, is one of the conditions for Ukraine's military resistance. Investing in Ukrainian cyber defense means investing in Ukraine's capacity to hold — and to win. Training programs, technological tools provided by allies, cooperation with the SBU: all of this has a direct impact on the war.
The cyber legacy of the Ukrainian war for the West
When this war ends — however that happens — the West will have access to the full documented record of Ukrainian experience in cyber warfare. That is an archive of considerable strategic value: years of real-condition operations against first-rank state adversaries, with all the lessons of successes and failures. Allied armies and governments that know how to integrate these lessons will be structurally better prepared for the next generation of cyber conflicts.
The war in Ukraine has permanently changed our understanding of what security means in the 21st century. The invisible front of compromised messaging apps, hacked accounts and infiltrated networks is as crucial as the visible front of trench lines and missile strikes. Ignore one and you lose the other.
By Maxime Marquette, columnist
Columnist's transparency note
My sources and their limits
This article draws on the public statements of the SBU, the FBI and CERT-EU, as well as specialized cybersecurity media. I am not a cybersecurity expert in the technical sense. My analysis focuses on the strategic, political and human dimensions of cyberwarfare, not on the technical details of the exploits and malware used. I have no access to classified intelligence sources.
Biases and positioning
I believe that Russia is waging an information and cyber war that represents a real threat to Western democracies. I support Ukrainian and allied cyber defense efforts. I believe that resources devoted to cybersecurity in NATO countries remain insufficient. These positions shape my analysis, which I publicly acknowledge.
Sources
Primary sources
Secondary sources
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). REPORT: Russian spies hack the messaging apps of Ukrainian officers and officials. MadMax. https://mad-max.co/en/article/reportage-les-espions-russes-piratent-les-messageries-des-officiers-et-fonctionn
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.