A cyberattack of rare intensity
The most recent case documented by the SBU involves a three-hour distributed denial-of-service (DDoS) attack targeting the website of a Ukrainian national television network. At its peak, the attack generated up to 200,000 requests per minute—a volume of traffic designed to completely overwhelm the targeted servers.
The botnet used to carry out this attack consisted of nodes spread across Asia, Europe, and the United States—an international architecture that deliberately mimicked the behavior of real users to make detection more difficult and to exhaust the target’s server resources.
Technical Resilience Averted the Worst
Thanks to the intervention of the SBU’s cybersecurity specialists, the television network’s website remained fully operational despite the intensity of the attack—a result that demonstrates a significantly strengthened digital defense capability since the start of the conflict.
This technical resilience, though rarely covered by the media, constitutes a tangible victory in a war where every public service that remains operational represents a direct setback for Russia’s destabilization objectives.
Two hundred thousand requests per minute against a news site is not merely a technical glitch. It is a deliberate attempt to silence a Ukrainian voice at the very moment when free information matters most to the population.
The 2025 Precedent: An Attempt at Propaganda Manipulation
A Two-Pronged Attack Against Another TV Group
In 2025, another Ukrainian television group was the target of a more sophisticated attack, carried out in two distinct stages: an initial phishing campaign aimed at obtaining unauthorized access, followed by an attempt to penetrate the information infrastructure through adjacent systems connected to the main network.
The ultimate goal of this operation was not merely technical disruption, but the complete takeover of the digital platform to broadcast Russian propaganda under the name and credibility of the legitimate Ukrainian media outlet that was targeted.
Timely Detection Averted an Information Disaster
SBU specialists managed to detect this intrusion in time, preventing the takeover of the media outlet and thus averting an information catastrophe that could have misled thousands, if not millions, of Ukrainian viewers regarding the authenticity of the broadcast content.
This incident illustrates an escalation in the sophistication of Russian methods, moving from simple denial-of-service attacks to complex attempts to hijack media identities for the purpose of mass disinformation.
Imagine the impact of a legitimate Ukrainian television station suddenly broadcasting Russian propaganda under its own name. The SBU prevented this nightmare scenario, and this success deserves to be recognized far beyond specialized cybersecurity circles.
The Structural Role of GRU Unit 29155
A Russian Military Unit Designed for Cyberwarfare
Behind many of these campaigns looms the shadow of Unit 29155 of Russia’s military intelligence agency, the GRU, which was initially established as a unit dedicated to cyberwarfare before expanding its scope to include other forms of hostile operations against Ukraine and its Western partners.
This unit has carried out spear-phishing campaigns directly targeting President Volodymyr Zelensky’s office as well as several Ukrainian ministries, with the aim of gaining unauthorized access to sensitive communications at the highest levels of government.
The Deployment of the Destructive WhisperGate Malware
Even before the full-scale invasion began, this same unit had deployed the destructive malware WhisperGate, designed to irrevocably erase data from Ukrainian computer systems—an act of digital sabotage in preparation for the military aggression that would follow.
This preemptive deployment demonstrates that Russia’s hybrid war against Ukraine had begun well before the first tanks crossed the border, confirming that preparations for this invasion took place simultaneously on both the military and digital fronts.
The deployment of WhisperGate prior to the physical invasion is not a trivial technical detail. It is proof that Moscow was planning this war long before it publicly acknowledged it, while it was still denying its intentions to the entire world.
The Cybersecurity Resilience Program for Regional Media Outlets
A joint initiative between the SBU and the audiovisual regulator
In response to this persistent threat, the SBU has launched a cybersecurity resilience project for local and regional media, in partnership with the National Council on Television and Radio Broadcasting of Ukraine, the country’s audiovisual regulator.
This program acknowledges an important strategic reality: major national media outlets are not the only potential targets, and regional organizations—which are often less technically equipped—represent a vulnerable link that urgently needed to be strengthened.
Full Territorial Coverage by 2026
In 2026, the SBU organized a series of hands-on cybersecurity training sessions in 20 regional locations, reaching media representatives from all 21 of Ukraine’s oblasts—a near-complete territorial coverage that demonstrates the scale of the effort.
Nearly 450 participants took part in these sessions, including media managers, journalists, editors-in-chief, and technical specialists—a diverse range of profiles that reflects the need for cybersecurity awareness at all levels of a media organization.
Training 450 media professionals in 21 oblasts is not merely a bureaucratic exercise. It is a clear recognition that the informational resilience of a country at war depends as much on well-trained journalists as it does on technical firewalls.
Financial institutions: a silent but critical target
A Vital Sector for Economic Stability in Times of War
Beyond the media, Ukrainian financial institutions are among the priority targets identified by the SBU—a threat that takes on particular significance in a country whose economy must remain functional despite constant bombardment and the logistical challenges of a protracted war.
A successful attack on Ukraine’s banking infrastructure could paralyze day-to-day transactions, disrupt the payment of wages and pensions, and undermine citizens’ already fragile confidence in their country’s economic stability amid the war.
Financial Defenses Strengthened by the Experience of Conflict
The experience gained since 2022 has enabled Ukrainian financial institutions, in coordination with the SBU, to develop increasingly sophisticated defense protocols, significantly reducing the window of opportunity for successful attacks against this critical sector.
This growth in collective capability illustrates a broader trend observed across Ukraine’s entire cybersecurity sector: every repelled attack becomes a lesson incorporated into future defenses—a virtuous cycle forged under the strain of war.
It is the institutions least visible in the media—such as banks—that often bear the heaviest burden of this silent digital war. Their resilience deserves recognition equal to that accorded to soldiers on the physical front lines.
The defense sector: the number one strategic target
Attacks Directly Targeting Ukraine’s Military Capabilities
The Ukrainian defense sector remains a prime target for Russian cyberattacks, the goal being to obtain information on military capabilities, troop movements, or weapons supply chains—data whose strategic value to the aggressor can be immediately exploited on the battlefield.
This reality explains why the SBU devotes considerable resources to protecting this specific sector, as any potential breach could directly result in human and material losses on the front lines.
Enhanced Cooperation with Western Partners
Faced with the scale of this threat, Ukraine has developed closer cooperation with its Western partners in the area of cyber defense, sharing intelligence and best practices that benefit both Kyiv and the Western countries themselves, which are now facing similar campaigns originating from Russia.
This transatlantic cooperation on cybersecurity illustrates a broader strategic reality: Ukraine’s digital defense is no longer merely a national issue; it has become a learning laboratory for all Western democracies facing the same hybrid threat.
Ukraine has, despite itself, become the world’s largest cyberdefense laboratory in the face of Russia. The lessons learned in Kyiv now directly benefit the digital security of the entire West.
The Increasing Sophistication of Russian Methods
From Simple Denial-of-Service Attacks to Complex Social Engineering
The evolution of methods documented by the SBU—from simple denial-of-service attacks via traffic saturation to complex phishing campaigns followed by infrastructure breaches—reveals the growing technical sophistication of Russian operators over the years of conflict.
This technical escalation is not surprising: it reflects Moscow’s sustained investment in its offensive cyber capabilities, which are viewed as a full-fledged tool of war—one that is less costly and less politically risky than a conventional military strike.
A Constant Need for Adaptation on the Ukrainian Side
This growing sophistication requires the SBU and its partners to constantly adapt technically; each new attack method detected must be immediately analyzed to anticipate future variants and strengthen defenses accordingly.
This digital game of cat and mouse, though less visible than ground combat, involves considerable human and technological resources on both sides, with stakes that are just as real for the overall outcome of the conflict.
This growing sophistication of Russian attacks must never be underestimated. Every technical advance by Moscow in this area forces Ukraine to remain vigilant at all times, with no room for complacency.
What This Digital War Reveals About Russia's Overall Strategy
A Hybrid War That Knows No Respite
This ongoing cyber campaign, which the SBU has been documenting for more than four years, confirms that Russia’s strategy against Ukraine is never limited to a single front. Missile strikes, ground offensives, and cyberattacks are all part of the same doctrine of total war aimed at exhausting every aspect of Ukraine’s resilience.
This multidimensional approach explains why Ukraine’s defense, to be effective, must itself operate on multiple fronts simultaneously—a reality that demands exceptional coordination among the armed forces, intelligence services, and civilian institutions.
A Model of Resilience That Inspires Beyond Ukraine’s Borders
Ukraine’s ability to keep its critical infrastructure operational despite thousands of documented cyberattacks serves as a model of digital resilience that is increasingly studied by Western experts facing similar—though generally less intense—threats.
This expertise, gained under fire—literally—now places Ukraine among the world’s most experienced nations in applied cyberdefense—a skill acquired at great cost but one that could prove invaluable in postwar negotiations on security cooperation with the West.
There is a bitter irony in the fact that Ukraine, a victim of this war, has become one of the world’s most competent nations in cyber defense. This expertise, paid for with blood and destroyed infrastructure, must be recognized and valued by its Western allies.
The Human Impact Behind the Technical Statistics
Journalists on the Front Lines of a Digital War
Behind every statistic on a thwarted cyberattack are Ukrainian journalists, technicians, and media workers who labor daily under the constant threat of digital intrusion, in addition to the already considerable physical risks associated with covering an active war on their own soil.
This dual pressure—technical and physical—weighs heavily on media professionals already worn down by more than four years of conflict, who must now incorporate cybersecurity as a core professional skill rather than a technical subject reserved for IT specialists.
Professional resilience forged under pressure
The training sessions organized by the SBU across Ukraine’s 21 oblasts reflect this need for rapid professional adaptation, transforming journalists and media managers into active participants in their own cyberdefense rather than mere passive victims of external attacks.
This growth in collective expertise, though born of the tragic necessity of war, could become a lasting legacy for the Ukrainian media sector long after the conflict’s hoped-for end.
These Ukrainian journalists, who are learning about cybersecurity between air raid alerts, deserve recognition that extends far beyond specialized circles. Their daily resilience is an essential component of Ukraine’s national resistance.
Lessons for Western Democracies
A Preview of Future Threats to Europe and North America
The documented methods used against Ukraine—from massive DDoS attacks to sophisticated attempts at media manipulation—offer a troubling glimpse into the tactics Russia might deploy against other Western democracies should geopolitical tensions escalate further.
Several Western cybersecurity experts are now actively drawing on the Ukrainian experience to strengthen their own defense protocols, recognizing that what is unfolding in Kyiv today could well foreshadow similar threats elsewhere tomorrow.
A Need for Heightened Collective Vigilance
This situation calls for increased international cooperation in cyber defense, where intelligence-sharing between Ukraine and its Western partners is becoming a strategic investment in the collective security of the entire democratic world.
Ignoring these lessons from Ukraine would amount to repeating the mistakes of underpreparedness that allowed Russia to develop its offensive cyber capabilities for years without a sufficient coordinated response from the international community.
What Ukraine is learning today under the onslaught of Russia’s cyberwar, the West should study with the utmost attention. Ignoring these lessons would be a strategic oversight that we could come to bitterly regret.
The Geopolitical Dimension of This Digital War
A front that is part of the global rivalry with authoritarian regimes
This Russian cyberwar against Ukraine cannot be separated from a broader dynamic in which China, Iran, and North Korea are also developing considerable offensive cyber capabilities, often in tacit or explicit coordination with Moscow as part of their growing strategic convergence.
This authoritarian convergence in the cyber domain constitutes an additional dimension of the structural challenge these regimes pose to the collective security of Western democracies, far beyond the Ukrainian theater alone.
Why This Issue Extends Far Beyond Ukraine’s National Context
Ukraine’s cyber resilience, documented by these 16,000 thwarted cyberattacks, must therefore be understood as part of a global confrontation between democracies and authoritarian regimes, in which every Ukrainian defensive victory also represents a strategic gain for the entire free world.
This broader perspective justifies increased international support—not only military and humanitarian, but also technical and financial—to further strengthen the cyberdefense capabilities of a country that, ultimately, is protecting far more than just its own digital borders.
This Ukrainian cyberwar is not an isolated conflict. It is the front line of a global confrontation between democracies and authoritarian regimes, and every Russian cyberattack repelled in Kyiv is a victory that benefits us all.
The funding and resources needed for this defense
A Considerable Budgetary Effort in the Midst of War
Maintaining a cyberdefense capability capable of neutralizing more than 16,000 attacks requires substantial budgetary resources, in a context where every available hryvnia must also fund conventional military efforts, the reconstruction of destroyed infrastructure, and support for populations displaced by the war.
This structural budgetary strain explains why international support for cybersecurity—whether financial, technical, or in the form of training—serves as a valuable complement to Ukraine’s national efforts, enabling the SBU to maintain and improve its defensive capabilities despite severe budgetary constraints.
Technology Partnerships That Strengthen National Resilience
Several Western technology companies have developed direct partnerships with Ukrainian authorities to strengthen the country’s digital defenses—support that extends beyond strictly governmental frameworks to include the global private-sector technology industry in this collective effort.
These partnerships, though often less visible than conventional military aid, nevertheless play a crucial role in the SBU’s ongoing ability to identify, analyze, and neutralize increasingly sophisticated cyber threats originating from Russia.
This technological support from the Western private sector for Ukraine’s cyber defense deserves to be recognized just as much as traditional military aid. Without these partnerships, Ukraine’s digital resilience would be considerably more fragile in the face of such a determined adversary.
Conclusion: Digital Resilience That Deserves Recognition
A track record that commands respect despite adversity
More than 16,000 Russian cyberattacks thwarted since 2022, a massive DDoS attack repelled without any service disruption, and an attempt to hijack media coverage foiled in time: this record, compiled by the SBU, attests to Ukraine’s digital resilience forged in the face of the most extreme adversity.
This defensive achievement, accomplished amid active warfare and limited resources, deserves international recognition commensurate with its strategic importance—both for Ukraine itself and for all Western democracies that are observing and learning from this experience.
A battle that continues, unseen but decisive
While the physical war rages on along Ukraine’s eastern front lines, this parallel digital war also continues, relentlessly and without pause, demanding constant vigilance from SBU teams and their Western partners.
This invisible battle—however little media attention it receives compared to images of trenches and bombings—remains just as crucial to the final outcome of this conflict, which is shaping the future of Ukraine and, by extension, that of European security as a whole.
I conclude this report with a firm conviction: the courage of Ukrainian soldiers on the physical front has an equally real counterpart among the SBU specialists who defend the country’s digital infrastructure day and night. Both deserve our equal respect.
By Maxime Marquette, columnist
Columnist's Transparency Box
My Openly Stated Biases
I write this report with a clear commitment to supporting the Ukrainian resistance against Russian aggression, while striving to accurately cite every statistic and official statement used in this text, without exaggeration or artificial dramatization.
What I Do Not Claim to Know
I am not familiar with the precise technical details of the detection methods used by the SBU, as this information is legitimately classified as operational secrecy in the context of active warfare. This report is based exclusively on information made public by Ukrainian authorities and the media outlets that have documented it.
Sources
Primary Sources
Ministry of Defense of Ukraine — National Security Context, July 2026
Euromaidan Press — “Ukraine’s Media Are Top Russian Cyber Target,” July 1, 2026
Armyinform — coverage of the Ukrainian defense context, July 2026
Secondary Sources
Foreign Policy — Analysis of Russia’s Hybrid Warfare, 2026
The Guardian International — coverage of cybersecurity and the war in Ukraine, 2026
This content was created with the help of AI.