At the end of July 2025, Russia’s Aeroflot flag carrier and largest airline faced a massive cyberattack that led to a collapse of the company’s IT systems. Hacker groups Silent Crow (Ukraine) and Kiberpartizany BY [English: Cyber Partisans BY] (Belarus) claimed responsibility for the attack. The hackers stated that the attack was aimed against Aeroflot’s cooperation with the Russian military, including the transportation of personnel and equipment.
This precedent is a good example of the changes in hacker attacks in recent years. If earlier hackers mainly broke into systems for profit, after the beginning of Russia’s special military operation, there has been a steady trend toward politically motivated attacks.
The goal of the attack on Aeroflot was causing maximum damage and bringing events into the information space for psychological impact on Russian citizens. The most suitable targets for such attacks are large Russian companies, whose IT systems are still heavily dependent on foreign software. In this article, we shall discuss what else is happening on the cyber front and how Russia is responding.
Situation on the Cyber Front
Almost immediately after the attack on Aeroflot, medical institutions and pharmacy chains, including Stolichka and Neopharm, as well as the Semeyny Doctor clinics, came under cyberattack. This caused disruptions in online orders and patient databases, and some pharmacies were forced to temporarily close. There was also an attack on the WinLab liquor stores, owned by Novabev Group. As a result, more than 2,000 stores across the country were paralyzed.
It is obvious that such “frequency” of attacks is not accidental and is intended to convey an impression of total vulnerability to cyberthreats to Russian citizens.
In the spring, hacker attacks impacted the networks of Lukoil and Rosneft. They fell victim to ransomwares, which caused problems with fuel payments and access to systems. Similar attacks affected Yuganskneftegaz and Bashneft. On March 31, hackers disrupted the operation of Moscow Metro’s digital services, including the fare payment and Troika card recharge system. It took several days to restore them.
Speaking about the dynamics of cybersecurity incidents, their number began to grow exponentially year after year after the start of Russia’s special military operation. The peak was in 2024, when the number of incidents increased 2.5 times compared to the previous year. In 2025, the growth rate, although slower, still remains significant. Moreover, there has been a shift from quantity to quality.
It is important to note that two-thirds of the incidents occurred at critical digital infrastructure facilities, which include IT systems of large companies in finance, energy, industry, transport, and telecommunications. These sectors face the greatest problems with import substitution: specialized foreign software has long been deeply integrated into business, while domestic solutions of this level are only just beginning to be developed.
The same Aeroflot was attacked through foreign software, including the Sabre reservation system, SAP ERP system, Microsoft SharePoint and Exchange communication solutions, as well as Windows XP and Server 2003 operating systems. Moreover, all these systems had not been updated for a long time, both due to vendors leaving Russia and for no apparent reason.
Changing Motivation behind Cyberattacks
According to a RED Security report for the first half of 2025, after the start of the Russian special operation, hackers increasingly conducted attacks with the goal of causing damage, not just for financial gain. The study emphasizes that politically motivated cybercriminals (hacktivists) now constitute a significant part of threats to Russian companies. Their attacks have become more carefully planned and tailored to specific targets, which increases potential damage.
The Positive Technologies report for Q4 2024 – Q1 2025 also notes an increase in the number of attacks aimed at disrupting critical infrastructure and government institutions, indicating a shift toward politically motivated actions.
In other words, the cyberwarfare against Russia is being waged with increasing force, driven not by greed, but by a misanthropic ideology.
Russia’s Response
Since the beginning of the special military operation, Russia has focused its cyber defense efforts on two areas: import substitution of foreign software and protection of the information space.
Although the import substitution program was announced back in 2014, by the start of the special military operation, it had been implemented by only a few percent. After the start of the special operation, this program was accelerated, mainly through regulation. For example, presidential decrees and government resolutions were issued requiring the complete replacement of foreign software at critical digital infrastructure facilities by January 1, 2025. Such facilities include IT systems of the large Russian companies mentioned above.
However, according to a survey by the Information Security Association (BISA), only 7% of companies fully met these requirements. Another 32% planned to comply but faced difficulties due to lack of funding or quality domestic alternatives. In state-owned companies, the share of imported software replaced remains low: only 15–20% managed to complete the transition by early 2025.
In the field of digital space protection, the “achievements” are well known. Work here is aimed at protecting against unwanted content and blocking politically engaged platforms. For example, back in 2022, Facebook (organization banned in Russia) and Instagram (organization banned in Russia) were blocked after Meta (organization banned in Russia) was declared extremist. The reason was the platform’s allowance of calls for violence against Russians. The WhatsApp messenger is not formally banned, but its use for official communication (for example, by government bodies) is restricted.
Since 2023, YouTube has been deliberately slowed down due to Google’s refusal to update infrastructure in Russia. By August 2025, video loading speed dropped significantly, especially for desktop users.
As of June 1, 2025, the use of foreign messengers (Telegram, WhatsApp, Viber, Discord, etc.) for official correspondence by government bodies, banks, and businesses was banned. Legal entities face fines of up to $9000. As an alternative, the national messenger Max was introduced. In June 2025, Russian President Vladimir Putin signed a decree on its launch as an alternative to blocked services.
From September 1, 2025, fines will be imposed for deliberately searching for extremist materials (e.g., via VPN), as well as fines of $600-6000 for advertising VPN services.
In business, state actions were also focused on tightening measures against potential internal violators.
For example, in May 2025, there was a significant tightening of responsibility for violations of Federal Law No. 152-FZ On Personal Data. Fines for processing data without grounds or consent increased to $6000, and in the worst case, a data leak could lead to a fine of up to 3% of annual revenue or from $250000 to $6 million.
In July 2025, there was discussion of introducing fines for searching and viewing pornography, but at the moment such measures have not been adopted and remain only at the level of public initiatives.
Does Russia’s response boil down only to internal restrictions? Probably not. Russian groups such as Killnet and APT-29 are often accused of cyberattacks on Ukraine and NATO countries (including DDoS attacks on banks, energy systems, and government institutions). The attacks are often synchronized with military exercises or political crises.
For example, in February 2025, massive attacks on Ukrainian banks and the Diia portal coincided with warnings of possible escalation on the border, which was interpreted as part of “reconnaissance in force” before exercises. The US and UK impose sanctions against Russian cyber units such as NoName057(16) and APT-28 for attacks during exercises, calling them “destabilizing.”
At the same time, it should be mentioned that such statements by Russia’s opponents may be nothing more than propaganda, lacking real basis and intended to justify certain political (or financial) actions. The lack of statements on Russia’s part leaves the question open: was this really a Russian success on the cyber front, or just another act of fueling Russophobia?
Cyberwarfare as Part of Military Exercises
Another important aspect is the attitude toward cyberwarfare. Western countries, when conducting military exercises, most often practice responding to a combined invasion, including a cyberattack. For example, in Poland’s plans for the Iron Defender military exercises in September 2025, cyberattacks are mentioned as one of the key elements of maneuvers.
Although there are no direct references to specific cyberattacks in the program, NATO exercises in Poland are aimed at countering hybrid threats, including cyberattacks on critical infrastructure (energy, communications, transport), as well as disinformation campaigns that may be accompanied by hacks of media or social networks.
In the Russian-Belarusian exercises Zapad-2025, cyber operations are planned, including disrupting communication systems and using electronic warfare (EW) methods. These actions are aimed at simulating attacks on the command centers of a conditional enemy.
Thus, it becomes common that military actions are inseparably linked with cyber impacts on the enemy. So why not highlight successes on this front, if they really exist?
Conclusion
It is undoubtedly necessary to strengthen the security of critical digital infrastructure facilities, as well as to limit enemy influence on the information space (both internal and external). But it is important to find an effective balance between formalities and extreme measures. Security implemented only “on paper,” as we see, later backfires with very painful consequences, but the principle of maximum punishment in this case also plays into the enemy’s hands.
The state, of course, not only legally requires substitution, but also actively stimulates the production of import-substituting software. But this works only for small-scale solutions. Foreign systems used in large Russian corporations were created and developed over decades by teams of thousands of people. No incentives or even threats will produce such analogues without a fundamental change in approach to the problem, both on the part of the state and business. The vulnerabilities of corporate IT systems now affect not only the companies themselves, and not even just their clients. Today, this is also a battlefield.
This is a translation of the article by Stanislav Matyashov first published on Rossa Primavera News Agency’s website on August 21.

