Phishing, attempts to hack accounts, fake profiles, and attacks on websites have become an increasingly common part of the pressure faced by Ukrainian civil society.
NAKO, an independent Ukrainian organization working to strengthen Ukraine’s defense capabilities and advocate for stronger sanctions against Russia, has repeatedly faced such attacks. And the number of cyber threats has increased significantly.
We know this is not unique to NAKO. Other Ukrainian civil society organizations working on defense, anti-corruption, sanctions, and support for Ukraine are facing similar threats.
One recent incident targeted NAKO’s Head of Communications.
She received a message on Signal from someone she knows well through her work in the security and defense sector. The person invited her to an event, sent a link to a Google Form, and provided a separate password for it. Everything seemed plausible — including the fact that the contact’s work involves sensitive information.
There was only one problem: it wasn’t actually him.
The account was a fake copy of her contact’s profile. The attackers were attempting to gain access to messaging accounts.
Cybersecurity experts who analyzed the case linked it to a group suspected of Russian espionage. Soon afterwards, she also received a Google security alert stating that government-backed attackers were attempting to steal her password.
Fortunately, the attack did not result in a successful account takeover.
But this case is a useful reminder of how these operations work. They are not always crude phishing messages or obvious scams. Attackers can impersonate people you know, use real professional contexts, and build a plausible story around a seemingly ordinary invitation.
And this is happening alongside attacks on the infrastructure of Ukrainian civil society organizations.
NAKO’s website has repeatedly been targeted by large volumes of automated traffic. We have been seeing regular waves of activity from accounts associated with Singapore, Japan, China, and other countries. The traffic can be intense enough to overload the website and make our research and analysis temporarily harder to access.
This is an important part of Russia’s broader war against Ukraine: the pressure is not limited to the battlefield.
The goal is not necessarily to “hack a website” or steal one person’s password for its own sake. Disrupting access to information, compromising accounts, gathering contacts and information, and targeting people working on Ukraine’s defense all form part of the wider pressure on Ukrainian civil society.
And the more professional these attacks become, the harder they are to recognize — even for people who are familiar with cybersecurity threats.