Ukraine’s Asset Recovery and Management Agency (ARMA) said it was hit by a cyberattack while handling assets seized from sanctioned Russians, and it is also probing unauthorized access to an internal database of ARMA officials. The agency said the incident came as it prepared to choose a manager for seized corporate rights in IDS Ukraine, a major beverage company. Ukraine’s security service, the SBU, is investigating, but ARMA did not attribute the attack or provide technical details.
Why it matters: This matters because a government agency handling politically sensitive seized assets says attackers may be trying to disrupt or influence its work. Ukrainian authorities and organizations connected to sanctions enforcement should watch for related intrusion and espionage activity, especially around staff accounts and internal databases.
2026.08.18
100% relevant
This article establishes a distinct incident: a newly disclosed cyberattack and suspected coordinated interference targeting ARMA during its management of seized IDS Ukraine assets, separate from the earlier APT28 targeting mentioned only as background.
← Back to all stories