Ukraine — Cyber Threat Profile

CERT-UA reports that cyber incident volume declined in the second half of 2025 versus the first half, the first such drop since Russia's 2022 invasion. No critical incidents were recorded, and low-severity cases fell 87 percent. Rather than an escalating surge, CERT-UA describes a shift in tactics: after early-2025 "steal-and-go" credential theft, Russian-linked groups moved toward maintaining long-term access, revisiting previously breached infrastructure to see whether old credentials and footholds still work; APT28 and Void Blizzard are among the groups CERT-UA names. Ukraine's new cybersecurity law, aligning the country with the EU's NIS2 directive, took effect in April 2025, replacing the old CISS certification regime with a risk-based security authorization framework.

Latest Ukraine coverage

Threat actors targeting Ukraine

Most targeted sectors

Recent claimed incidents

Read the full analysis on IntelFusions