A suspected cyberattack on the Asset Recovery and Management Service of Ukraine (ARMA) is at the center of an investigation, as it occurred at a particularly critical time for a tender for the management of frozen assets of IDS Ukraine. The agency announced that unauthorized interference was detected on its servers, just days before the deadline for submitting applications on August 22.

The incident takes on added significance given the nature of the assets managed by ARMA, as well as previous indications of interference in its processes. Ukrainian authorities are now examining whether the attack was an isolated incident or part of a broader effort to influence the organization’s operations.
The competition for IDS Ukraine is in the spotlight
ARMA is responsible for managing assets seized or frozen by Ukrainian authorities. This includes assets linked to Russian nationals who are under sanctions, as well as individuals accused of collaborating with Moscow.
See also: Foster City Cyberattack: Service Outage and Data Breach Fears
The latest cyberattack coincided with the final phase of the process of selecting a manager for IDS Ukraine assets, which are linked to Russian oligarch Mikhail Fridman. The deadline for submitting applications is set for August 22, 2026, and the procedure has been published through the Ukrainian public procurement system Prozorro.
The timing of the attack has raised reasonable questions, but it has not yet been proven that the cyber incident is directly linked to the competition.
Investigation by Ukrainian authorities
The Security Service of Ukraine (SBU) has taken over the investigation of the recent cyberattack, while the National Anti-Corruption Bureau (NABU) is examining broader complaints regarding possible interference in ARMA's activities.
According to the agency, signs of unauthorized activity had already appeared since the spring. Among other things, unauthorized access to the ARMA executive registry had been recorded, which heightened concerns about the security of its information systems.
At the same time, ARMA is examining reports of possible access to electronic accounts and official documents. This information is expected to be forwarded to the relevant authorities for further technical and legal assessment.

A broader pattern under consideration
ARMA is not treating the latest incident as an isolated incident. The agency has reported previous attempts at intervention, which were combined with increased activity around its procedures, information sharing and public inquiries from the media and members of parliament.
See also: De Bijenkorf in Amsterdam hit by cyberattack on the accounting chain
These events alone do not prove a coordinated campaign, but the combination of cyber incidents, potential leaks, and actions occurring close to critical processes has led authorities to the need for a deeper investigation.
The key question is whether the attacks are aimed at data breaches, disrupting ARMA's operations, or exerting pressure in view of the decision on the management of the frozen assets.
The competition continues as usual
Despite the attack, ARMA clarified that the process of selecting a manager for IDS Ukraine will continue based on the planned timetable and the applicable legal framework.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The service has also initiated an audit of the financial data of the frozen assets of the IDS group, with the aim of ensuring the legality, objectivity and transparency of the process.
The acting head of ARMA, Yaroslava Maksymenko, stressed that the organization is not going to abandon the process due to the incidents she characterized as pressure, political interference and attempts at unauthorized access.
The broader geopolitical context
The case is set in a particularly sensitive environment, as Ukraine seeks to prevent sanctioned individuals from retaining control of assets frozen. ARMA has a critical role in this process, as it must ensure that the management of the assets cannot be influenced through intermediaries or leverage.
See also: Anthropic: The first AI-orchestrated cyberattack used the Claude Code to spy on 30 targets

Mikhail Fridman is under sanctions by Ukraine and other Western governments following the Russian invasion.
No one has yet claimed responsibility for the cyberattack. ARMA stresses that the identification of the perpetrators, possible instigators and any organizers is the subject of ongoing investigations. The coming period is expected to show whether this is a limited cyberattack or part of a broader effort to interfere in a competition with significant economic and geopolitical implications.
