kyiv
Image: Oleksandr Zhabin via Unsplash

Hackers target Ukrainian agency managing assets seized from sanctioned Russians

Ukraine’s agency responsible for managing assets seized from criminals and sanctioned individuals said Tuesday that it had been targeted by a cyberattack as it investigates a potential coordinated effort to disrupt its operations.

The Asset Recovery and Management Agency, known as ARMA, manages assets seized by Ukrainian authorities, including those linked to sanctioned Russians and alleged collaborators with Moscow.

The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages.

“Over the years that the Russian oligarchic capital has operated in Ukraine, it has built up a network of people willing to serve its interests from within our country,” said Yaroslava Maksymenko, ARMA’s acting head.

ARMA did not identify who it believes was behind the cyberattack or provide technical details about the incident. Ukraine’s security service, the SBU, is investigating the attack.

ARMA said it has detected other signs of suspected unlawful interference in its work since the spring, including unauthorized access to an internal database of ARMA officials.

The agency is examining whether the incidents could be part of a coordinated effort to undermine the competition for the IDS Ukraine assets, but it has provided no public evidence linking the cyberattack to any groups or individuals.

ARMA said the competition to select a manager for the IDS Ukraine assets would proceed as planned.

Ukraine seized the corporate rights of Russian shareholders in IDS Ukraine in late 2022, following Russia’s full-scale invasion. The company’s shareholders include Mikhail Fridman, the Russian billionaire and co-founder of Alfa-Bank.

Fridman has been sanctioned by Ukraine and several Western governments since Russia’s invasion.

“Sanctioned Russian capital must not be allowed to retain control over assets seized in Ukraine,” ARMA said.

The agency claimed it had encountered resistance to transferring IDS Ukraine to independent management but did not identify those it accused of trying to influence the process.

Tuesday’s incident is not the first time ARMA has faced a cyber threat suspected of being linked to Russia.

In April, Ukrainian state officials said the agency’s employees had been targeted as part of a cyberespionage campaign attributed to APT28, a Russian state-linked hacking group also known as Fancy Bear, BlueDelta and Forest Blizzard. Maksymenko said at the time that the hackers had failed to penetrate ARMA’s internal systems.

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.