Skip to content

SecurityIndependently confirmed2 publishers3 min readPublished

Ukraine's asset agency was attacked on the tender calendar, not the network map

ARMA says intruders reached its servers just before the bid deadline for managing seized assets tied to Mikhail Fridman. The milestone set the clock, not the infrastructure.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Ukraine's asset agency was attacked on the tender calendar, not the network map
Generated illustration

What happened

  • Ukraine's Asset Recovery and Management Agency (ARMA) said Tuesday it had been targeted by a cyberattack as it prepared to select a manager for seized corporate rights in IDS Ukraine.
  • ARMA said its servers experienced unauthorized interference shortly before the August 22 deadline for applications to the competition to select a manager for assets controlled by sanctioned Russian oligarch Mikhail Fridman.
  • ARMA manages assets seized by Ukrainian authorities, including assets linked to sanctioned Russian individuals and alleged collaborators with Moscow.
  • IDS Ukraine is one of the country's largest producers of bottled mineral water and beverages.
  • Ukraine seized the corporate rights of Russian shareholders in IDS Ukraine in late 2022, following Russia's full-scale invasion.

Why it matters

Ukraine's Asset Recovery and Management Agency, known as ARMA, said on Tuesday that it had been targeted by a cyberattack while preparing to select a manager for seized corporate rights in IDS Ukraine [1]. The agency said the unauthorized interference with its servers came shortly before the deadline for applications to that competition [2], which is the detail that matters: the operation was scheduled against a procurement milestone, not against a piece of technology.

ARMA manages assets seized by Ukrainian authorities, including assets linked to sanctioned Russians and alleged collaborators with Moscow [3]. IDS Ukraine is one of the country's largest producers of bottled mineral water and beverages [18]; Ukraine seized the corporate rights of its Russian shareholders in late 2022, after the full-scale invasion [19]. Those shareholders include Mikhail Fridman, the Russian billionaire and Alfa-Bank co-founder [4], who has been sanctioned by Ukraine and several Western governments since the invasion [5]. The competition announcement was published through Prozorro, Ukraine's public procurement system [6]. That is worth sitting with: the date an attacker would want to hit was posted on a public tender platform [20]. One note on the record, since precision is the point here: The Cyber Express gives the application deadline as August 22 in its narrative and as August 22, 2026 in its detail line [7], and the material does not reconcile the two.

The rest of the pattern is consistent with pressure on a process rather than theft from a system. ARMA said it has detected other signs of suspected unlawful interference since the spring, including unauthorized access to an internal database of agency officials [8], and that it will pass further information on possible unauthorized access to officials' email accounts to law enforcement [9]. The agency said the combination of cyber incidents, information activity and increased inquiries from some media outlets and members of parliament raised concerns about a coordinated campaign [10]. It has named no one, and has provided no technical details or public evidence linking the intrusion to any group or individual [11]. Ukraine's SBU is investigating the latest attack [12], while a broader National Anti-Corruption Bureau investigation examines earlier alleged interference [13].

This is not ARMA's first exposure. In April, Ukrainian state officials said agency employees had been targeted in a cyberespionage campaign attributed to APT28, the Russian state-linked group also called Fancy Bear, BlueDelta and Forest Blizzard [21]; acting head Yaroslava Maksymenko said at the time that the hackers failed to penetrate internal systems [22]. Maksymenko said the agency would continue the competition despite information pressure, political interference and attempts to gain unauthorized access to its resources [14], and ARMA said the selection will proceed on the procedures and timeframe set by law [15]. The agency has also started an audit of the financial indicators of the seized IDS group assets [16].

Watch whether the statutory timeframe actually holds, or whether the incident becomes the procedural grounds for a delay or a challenge by a losing bidder. Watch the email-access thread: material taken from officials' accounts is the raw input for the "information activity" ARMA is already complaining about [10]. And watch whether SBU or NABU name anyone, because ARMA has so far declined to, and says responsibility for identifying organizers and perpetrators rests with the investigations [17].

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence34
Adoption28
Hype gap+22
Incentives66
Confidence45
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Ukraine's Asset Recovery and Management Agency (ARMA) said Tuesday it had been targeted by a cyberattack as it prepared to select a manager for seized corporate rights in IDS Ukraine.

  2. [2]

    ARMA said its servers experienced unauthorized interference shortly before the August 22 deadline for applications to the competition to select a manager for assets controlled by sanctioned Russian oligarch Mikhail Fridman.

  3. [3]

    ARMA manages assets seized by Ukrainian authorities, including assets linked to sanctioned Russian individuals and alleged collaborators with Moscow.

Sources

2 independent publishers whose own reporting we read for this story.

  1. thecyberexpress.com

    1 article · August 18, 2026

    Cyberattack Hits Ukraine Agency Ahead of Major Asset Tender
  2. therecord.media

    1 article · August 18, 2026

    Hackers target Ukrainian agency managing assets seized from sanctioned Russians

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

  • Ukraine-Russia cyber conflictFollow
  • Public procurement and tender integrityFollow
  • Government agency securityFollow
  • Sanctioned asset seizure and managementFollow
  • Attribution and disclosure gaps in incident reportingFollow

Entities

Loading related stories