The Main Intelligence Directorate (GUR) of the Ukrainian Defense Ministry claims to have carried out a cyberattack against the Russian defense and aerospace company Tupolev , known for developing Russia's supersonic bombers.

As reported by Ukrainian media, a source within GUR revealed that the agency managed to hack Tupolev's internal systems and extract 4.4 gigabytes of sensitive data, including:
- Personal information of company personnel,
- Internal correspondence between senior executives,
- Procurement related documents,
- Biographical engineers and designers,
- Confidential meeting minutes.
See also: Russian APT28 targets organizations supporting Ukraine
The length of time the Ukrainian hackers on Tupolev's network has not been disclosed, but the same source said they remained "for quite some time," gathering information with potentially strategic value for future operations in the Russian defense sector.
“The importance of the data obtained is enormous. Now, almost nothing remains secret for Tupolev regarding the Ukrainian side,” the source reportedly told the Kyiv Post.
The same source pointed out that the information includes names and roles of individuals who contribute to the operation of the Russian air force, suggesting that the effects of this digital operation will also have an impact on the battlefield.
Tupolev website hacked
The attack on Tupolev by Ukrainian intelligence appears to have been more than just data collection. The Ukrainian hackers are also said to have defaced the company 's official website , adding an image of an owl holding an aircraft in its talons – a symbolic indication of "digital dominance" over the target.
The incident comes a few days after a targeted strike by the SBU (Security Service of Ukraine), which allegedly used FPV drones to hit 41 Russian warplanes at four military airfields.
See also: Ukrainian extradited to the US for Nefilim ransomware attacks
GUR has also previously claimed to have breached state institutions Russian, including:
- The Ministry of Defense (Minoborony),
- The Russian Air Transport Agency (Rosaviatsia),
- The Center for Space Hydrometeorology,
- And the Russian Tax Service (FNS).
In two of the cyberattacks, the agency allegedly destroyed databases and deleted backups, causing operational paralysis.

In addition to state-owned enterprises, Ukrainian digital activists remain active in cyberspace. In January, the Ukrainian Cyber Alliance (UCA) group attacked Russian internet provider Nodex , deleting systems and backup files.
Since the beginning of the Russian invasion, Ukrainian cyber operations have evolved into advanced and multi-layered attacks, targeting Russia's critical infrastructure on both the physical and digital levels.
The Ukrainian Cyber Alliance (UCA), one of Ukraine's most active cyber activist groups, claims to have carried out a series of successful digital infiltrations of critical Russian structures and officials.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
According to announcements from the group, the objectives of its operations included:
- Vladislav Surkov, a close political associate of Russian President Vladimir Putin,
- The Russian Ministry of Defense,
- The Ministry of Coal and Energy
- The Commonwealth of Independent States Institute (CIS Institute), a think tank that is reportedly financially supported by the state-owned company Gazprom,
- As well as many Russian military officials and state media.
These violations are part of a broader cyberwarfare campaign, with UCA stating that it is continuing its destabilization and intelligence-gathering operations against the Russian war machine and its supporters.
See also: Cyberattacks in Ukraine with WRECKSTEEL Malware
From a technical and geopolitical point of view, the actions of GUR and UCA:
- They demonstrate a high level of organization and coordination in the field of cyber warfare on the Ukrainian side.
- They create pressure on Russia's morale and image, undermining confidence in the security of its infrastructure .
- They send a message internationally that Ukraine is not just defensive, but has the capacity for active digital counterattack.
Unlike older models of warfare, information, leakage, and data-driven destabilization are now front-line weapons. Attacks on organizations like Tupolev are not just acts of destruction, but operations of strategic intimidation and vulnerability exposure.
If the results of these operations are confirmed over time, then Ukraine may have set a model for how smaller countries can defend themselves against superior forces through cyberspace.
source: www.bleepingcomputer.com
