The Security Service of Ukraine (SBU), in cooperation with the U.S. Federal Bureau of Investigation (FBI), has revealed details of a large-scale operation by Russian intelligence services. Experts have found that Moscow is conducting systematic cyberattacks on messengers used by officials, military personnel, and politicians in Ukraine, European countries, and the United States.
The main goal of these attacks is to gain access to confidential military, political, and economic information, as well as to steal users' personal data. Russian hackers do not limit themselves to attacking state structures; they also deliberately hack the personal accounts of citizens.
Social engineering methods
Cybersecurity specialists note the enemy's use of sophisticated social engineering methods. To trick users into revealing passwords, criminals often send SMS messages disguised as technical support services.
A distinctive feature of these attacks is their timing: messages arrive in the morning hours. At this time, users are most vulnerable due to their physical and emotional state, which increases the likelihood of successful phishing. The messages are styled to look like official bots to gain the victim's trust.
Global context of cyber threats
The activity of pro-Kremlin and allied hacker groups worldwide has increased significantly in recent times. This is confirmed by a number of high-profile incidents that have occurred in different countries:
- Mass attack on messengers: In March, news emerged of a large-scale operation by Russian hackers in Signal and WhatsApp services. The criminals attempted to hack the accounts of military personnel and government officials.
- Hack in the Netherlands: The Ministry of Finance of the Netherlands was subjected to a cyberattack. Hackers managed to block part of the systems ensuring the department's core processes.
- FBI incident: In the US, criminals hacked the personal email of FBI Director Kash Patel. American authorities announced a multi-million dollar reward for information on Iranian hackers involved in this attack.
Experts also note that Russian intelligence services have changed their tactics. Now they are trying to cause physical damage to European infrastructure using destructive cyberattacks.
Recommendations for citizens
In light of the growing threats, the SBU urges citizens to remain vigilant and take care of their own cybersecurity. The Security Service strongly recommends complying with basic rules of cyber hygiene to minimize the risks of personal data leaks and unauthorized access to accounts.