ZeroHour
The Recordpublished ()ingested

Hackers target Ukrainian agency managing assets seized from sanctioned Russians

mediumData breachimportance 45
AI summary · glm-5.3-flash

Ukraine's ARMA asset agency reported a cyberattack amid selecting a manager for seized IDS Ukraine assets linked to sanctioned Russians.

Ukraine's Asset Recovery and Management Agency (ARMA), which manages assets seized from criminals and sanctioned individuals, said Tuesday it had been targeted by a cyberattack, with the SBU investigating. The attack coincided with preparations to select a manager for seized corporate rights in IDS Ukraine, a major beverage producer seized in late 2022 from Russian shareholders including sanctioned billionaire Mikhail Fridman. ARMA reported other suspected interference since spring, including unauthorized access to an internal database of agency officials, but did not attribute the attack or release technical details. In April, ARMA employees were targeted in a cyberespionage campaign attributed to Russia-linked APT28, which failed to penetrate internal systems.

  • The SBU is investigating; the attackers were not identified and no technical details were released.
  • The agency reported unauthorized access to an internal database of officials since the spring.
  • The attack coincided with selecting a manager for seized IDS Ukraine corporate rights.
  • The IDS Ukraine management competition will proceed as planned.
  • April APT28-attributed espionage attempts against ARMA employees previously failed.
Full article453 words · extracted from therecord.media · click to collapse

Ukraine’s agency responsible for managing assets seized from criminals and sanctioned individuals said Tuesday that it had been targeted by a cyberattack as it investigates a potential coordinated effort to disrupt its operations.

The Asset Recovery and Management Agency, known as ARMA, manages assets seized by Ukrainian authorities, including those linked to sanctioned Russians and alleged collaborators with Moscow.

The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages.

“Over the years that the Russian oligarchic capital has operated in Ukraine, it has built up a network of people willing to serve its interests from within our country,” said Yaroslava Maksymenko, ARMA’s acting head.

ARMA did not identify who it believes was behind the cyberattack or provide technical details about the incident. Ukraine’s security service, the SBU, is investigating the attack.

ARMA said it has detected other signs of suspected unlawful interference in its work since the spring, including unauthorized access to an internal database of ARMA officials.

The agency is examining whether the incidents could be part of a coordinated effort to undermine the competition for the IDS Ukraine assets, but it has provided no public evidence linking the cyberattack to any groups or individuals.

ARMA said the competition to select a manager for the IDS Ukraine assets would proceed as planned.

Ukraine seized the corporate rights of Russian shareholders in IDS Ukraine in late 2022, following Russia’s full-scale invasion. The company’s shareholders include Mikhail Fridman, the Russian billionaire and co-founder of Alfa-Bank.

Fridman has been sanctioned by Ukraine and several Western governments since Russia’s invasion.

“Sanctioned Russian capital must not be allowed to retain control over assets seized in Ukraine,” ARMA said.

The agency claimed it had encountered resistance to transferring IDS Ukraine to independent management but did not identify those it accused of trying to influence the process.

Tuesday’s incident is not the first time ARMA has faced a cyber threat suspected of being linked to Russia.

In April, Ukrainian state officials said the agency’s employees had been targeted as part of a cyberespionage campaign attributed to APT28, a Russian state-linked hacking group also known as Fancy Bear, BlueDelta and Forest Blizzard. Maksymenko said at the time that the hackers had failed to penetrate ARMA’s internal systems.

No previous article

No new articles

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/hackers-target-ukraine-agency-sanctioned-russians