---
title: "Moles, Not Registries: A Study Reveals How Russia Actually Learns About Ukraine's Defense Industry"
description: "A YouControl study of SBU materials from 2020–2026 showed that Russia obtains data on Ukraine's defense-industrial complex primarily through agents and spotters, not through open registries."
date: 2026-09-15T10:44:03.000Z
lang: en
url: https://xab.info/en/posts/how-russia-learns-about-ukraines-defense-industry
tags: [ukraine, opk, sbu, espionage, defense-industry, telegram, intelligence]
publisher: "XAB.info"
---

# Moles, Not Registries: A Study Reveals How Russia Actually Learns About Ukraine's Defense Industry

![Soldering an electronic circuit board at a Ukrainian defense electronics plant: production processes that Russian intelligence targets through insiders](https://xab.info/media/2026/09/15/kak-rossiya-uznaet-ob-ukrainskom-ope/kak-rossiya-uznaet-ob-ukrainskom-ope-1.webp)

## 🎯 Key Points

- YouControl analysts analyzed 7,362 SBU news items from 2020–2026 and identified 131 materials on threats to the defense-industrial complex.
- The main leak channel is the human factor: agents, "moles," spotters, and recruitment via Telegram.
- The sample contains not a single case of leakage through open state registries.
- This calls into question the effectiveness of Cabinet Decree No. 1257 on the removal of open data on the defense-industrial complex.
- The SBU detained a National Guard officer in Odesa Oblast who had been passing combat-activity data and preparing a terrorist act.

Ukrainian outlet RBC-Ukraine, citing the analytics firm YouControl, published a study that revises the conventional narrative about where Russia sources sensitive information on Ukraine's defense-industrial complex. The analysts processed 7,362 news items on the SBU website covering the period from January 2020 to August 2026 and identified 131 materials directly related to threats to the defense-industrial complex, from which they determined seven key leak channels. The study's main conclusion: the adversary obtains data primarily through agents, informants, and spotters, rather than through open state registries.

### The Human Factor as the Main Vulnerability

The human factor takes center stage in the study. Under Article 111 of the Criminal Code of Ukraine ("Treason"), the analysts counted 149 publications on the exposure of "moles" and spies at strategic enterprises and in state bodies, a further 179 messages concerning FSB agents, informants, and couriers, and 117 on entire agent networks and groups of spotters. In total, Article 111 appears in 1,428 materials in the sample, with a sharp rise in dynamics after 2022: if there were 45 such messages in 2020, by 2025 the figure had reached 355. In addition, 269 messages on fire adjustment and the guidance of strikes on Ukrainian facilities were recorded, along with 43 cases in which agents personally photographed and filmed defense-industrial enterprise sites, and 33 cases of targeted collection of data on the deployment of specific military and defense facilities in 2025–2026.

### Telegram as a Recruitment Channel

A separate and, in the analysts' assessment, systemic recruitment channel has become the Telegram messenger. Of 90 publications on the search for informants through social networks, 84 (93%) concerned precisely this channel. Notably, in 40 cases the subject was female informants, who were recruited under the pretext of "easy money" or using family and domestic motives. This indicates that the operations against the defense-industrial complex are not only technical but also socio-psychological intelligence, aimed at vulnerable social groups.

### Open Registries Do Not Feature Among Leak Channels

The key and, perhaps, most surprising result of the work: among the recorded leak channels for information on the defense-industrial complex, open state data do not feature at all. In the studied set of SBU messages, not a single case was identified in which the obtaining of information on defense facilities was linked to the use of public registries. Separately, the analysts highlighted 14 publications across 11 criminal proceedings in which classified information leaked outward through the very employees of law-enforcement and supervisory bodies — most often tax and fiscal services.

### Contradictory Data

Here a direct contradiction arises between the logic of state regulation and the study's conclusions. The Cabinet of Ministers issued Decree No. 1257 on the removal of open data on the defense-industrial complex, thereby establishing the principle that public registries of legal entities are a significant vector of leakage. However, YouControl states plainly: if the main leak channels lie outside public registries, then the removal of basic information on legal entities in itself cannot be an effective tool for protecting the defense industry. Thus, the position underlying the decree and the analysts' empirical conclusion diverge: the state is protecting one channel, whereas according to SBU data the real threats pass through others — agent-based and human ones.

### Operational Practice: From Odesa to Operation "Postman"

The SBU regularly records the exposure of agents within the Defense Forces. Thus, at the end of August 2026, counterintelligence detained in Odesa Oblast a career officer — the commander of a National Guard special-operations group — who for a long time had been passing Russians secret data on the combat activities of his unit and was preparing a terrorist act on the Kremlin's orders. In parallel, according to RBC-Ukraine sources, Russia has rolled out Operation "Postman" — a campaign of fake appeals aimed at discrediting commanders of units with high moral and psychological standing, in particular in the Ground Forces, the Air Assault Forces, the National Guard, and the Unmanned Systems Forces. This complements the picture: alongside physical reconnaissance, the adversary is actively using information pressure on the command staff.

## 🔍 Fact-Check Verification

- [Moles, Not Registries: How the Adversary Actually Learns About Ukraine's Defense Industry — A Study](https://www.rbc.ua/ukr/news/kroti-reestri-k-vorog-naspravdi-diznaetsya-1789468898.html) - Единственный источник. Цифры исследования (7362 новости, 131 материал, 1428 упоминания ст. 111, 84/90 по Telegram и т.д.) и вывод об отсутствии утечек через публичные реестры согласованы с текстом. Оговорка: информация об операции «Почтальон» приведена по анонимным источникам РБК-Украина, а не по публичным заявлениям СБУ.

## ❓ FAQ

### Q: Through which channels does Russia obtain data on Ukraine's defense-industrial complex?
**A:** According to the YouControl study, primarily through agents, informants, "moles" at strategic enterprises, and groups of spotters, as well as through recruitment on Telegram. Open state registries did not feature in the recorded leak cases.

### Q: Is the leakage linked to open data on legal entities?
**A:** No. In the set of SBU messages analyzed by the analysts, not a single case was identified in which information on defense facilities was obtained through public registries. Cases of leakage through employees of tax and fiscal services were noted separately.

### Q: What does this mean for Cabinet Decree No. 1257?
**A:** YouControl points out that if the main leak channels lie outside public registries, then the removal of basic open information on legal entities in itself cannot be an effective tool for protecting the defense-industrial complex.