SecurityIndependently confirmed2 publishers3 min readPublished
Ukraine's asset agency was attacked on the tender calendar, not the network map
ARMA says intruders reached its servers just before the bid deadline for managing seized assets tied to Mikhail Fridman. The milestone set the clock, not the infrastructure.
The Watch · Security desk

What happened
- Ukraine's Asset Recovery and Management Agency (ARMA) said Tuesday it had been targeted by a cyberattack as it prepared to select a manager for seized corporate rights in IDS Ukraine.
- ARMA said its servers experienced unauthorized interference shortly before the August 22 deadline for applications to the competition to select a manager for assets controlled by sanctioned Russian oligarch Mikhail Fridman.
- ARMA manages assets seized by Ukrainian authorities, including assets linked to sanctioned Russian individuals and alleged collaborators with Moscow.
- IDS Ukraine is one of the country's largest producers of bottled mineral water and beverages.
- Ukraine seized the corporate rights of Russian shareholders in IDS Ukraine in late 2022, following Russia's full-scale invasion.
Why it matters
Ukraine's Asset Recovery and Management Agency, known as ARMA, said on Tuesday that it had been targeted by a cyberattack while preparing to select a manager for seized corporate rights in IDS Ukraine [1]. The agency said the unauthorized interference with its servers came shortly before the deadline for applications to that competition [2], which is the detail that matters: the operation was scheduled against a procurement milestone, not against a piece of technology.
ARMA manages assets seized by Ukrainian authorities, including assets linked to sanctioned Russians and alleged collaborators with Moscow [3]. IDS Ukraine is one of the country's largest producers of bottled mineral water and beverages [18]; Ukraine seized the corporate rights of its Russian shareholders in late 2022, after the full-scale invasion [19]. Those shareholders include Mikhail Fridman, the Russian billionaire and Alfa-Bank co-founder [4], who has been sanctioned by Ukraine and several Western governments since the invasion [5]. The competition announcement was published through Prozorro, Ukraine's public procurement system [6]. That is worth sitting with: the date an attacker would want to hit was posted on a public tender platform [20]. One note on the record, since precision is the point here: The Cyber Express gives the application deadline as August 22 in its narrative and as August 22, 2026 in its detail line [7], and the material does not reconcile the two.
The rest of the pattern is consistent with pressure on a process rather than theft from a system. ARMA said it has detected other signs of suspected unlawful interference since the spring, including unauthorized access to an internal database of agency officials [8], and that it will pass further information on possible unauthorized access to officials' email accounts to law enforcement [9]. The agency said the combination of cyber incidents, information activity and increased inquiries from some media outlets and members of parliament raised concerns about a coordinated campaign [10]. It has named no one, and has provided no technical details or public evidence linking the intrusion to any group or individual [11]. Ukraine's SBU is investigating the latest attack [12], while a broader National Anti-Corruption Bureau investigation examines earlier alleged interference [13].
This is not ARMA's first exposure. In April, Ukrainian state officials said agency employees had been targeted in a cyberespionage campaign attributed to APT28, the Russian state-linked group also called Fancy Bear, BlueDelta and Forest Blizzard [21]; acting head Yaroslava Maksymenko said at the time that the hackers failed to penetrate internal systems [22]. Maksymenko said the agency would continue the competition despite information pressure, political interference and attempts to gain unauthorized access to its resources [14], and ARMA said the selection will proceed on the procedures and timeframe set by law [15]. The agency has also started an audit of the financial indicators of the seized IDS group assets [16].
Watch whether the statutory timeframe actually holds, or whether the incident becomes the procedural grounds for a delay or a challenge by a losing bidder. Watch the email-access thread: material taken from officials' accounts is the raw input for the "information activity" ARMA is already complaining about [10]. And watch whether SBU or NABU name anyone, because ARMA has so far declined to, and says responsibility for identifying organizers and perpetrators rests with the investigations [17].
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence34
- Adoption28
- Hype gap+22
- Incentives66
- Confidence45
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Ukraine's Asset Recovery and Management Agency (ARMA) said Tuesday it had been targeted by a cyberattack as it prepared to select a manager for seized corporate rights in IDS Ukraine.
- [2]
ARMA said its servers experienced unauthorized interference shortly before the August 22 deadline for applications to the competition to select a manager for assets controlled by sanctioned Russian oligarch Mikhail Fridman.
- [3]
ARMA manages assets seized by Ukrainian authorities, including assets linked to sanctioned Russian individuals and alleged collaborators with Moscow.
- [4]
IDS Ukraine's shareholders include Mikhail Fridman, the Russian billionaire and co-founder of Alfa-Bank.
- [5]
Fridman has been sanctioned by Ukraine and several Western governments since Russia's invasion.
- [6]
The competition announcement was published through Ukraine's Prozorro public procurement system.
- [7]
The Cyber Express report states that the attack occurred shortly before the August 22 deadline for applications, and separately states that the deadline for applications is August 22, 2026.
- [8]
ARMA said it has detected other signs of suspected unlawful interference in its work since the spring, including unauthorized access to an internal database of ARMA officials.
- [9]
ARMA said additional information concerning possible unauthorized access to officials' email accounts and official information will be provided to law enforcement authorities for investigation and legal assessment.
- [10]
ARMA said the combination of cyber incidents, information activity and increased inquiries from some media outlets and members of parliament had raised concerns about a possible coordinated campaign.
- [11]
ARMA did not identify who it believes was behind the cyberattack, provided no technical details about the incident, and provided no public evidence linking the cyberattack to any groups or individuals.
- [12]
Ukraine's security service, the SBU, is investigating the attack.
- [13]
A broader National Anti-Corruption Bureau of Ukraine (NABU) investigation is examining earlier alleged interference.
- [14]
Acting ARMA head Yaroslava Maksymenko said the agency would continue the competition despite what it described as information pressure, political interference and attempts to gain unauthorized access to its resources.
- [15]
ARMA said the competition to select the IDS Ukraine asset manager will proceed according to the procedures and timeframe established by law.
- [16]
ARMA said it has started an audit of the financial indicators of seized IDS group assets to support the legality, objectivity and transparency of the transfer process.
- [17]
ARMA said final responsibility for determining the organizers, customers and perpetrators of the attack rests with the ongoing investigations.
- [18]
IDS Ukraine is one of the country's largest producers of bottled mineral water and beverages.
- [19]
Ukraine seized the corporate rights of Russian shareholders in IDS Ukraine in late 2022, following Russia's full-scale invasion.
- [20]
Because the competition announcement and its application deadline were published on the Prozorro public procurement platform, the date of the tender milestone was publicly available before the intrusion occurred.
- [21]
In April, Ukrainian state officials said ARMA's employees had been targeted as part of a cyberespionage campaign attributed to APT28, a Russian state-linked hacking group also known as Fancy Bear, BlueDelta and Forest Blizzard.
- [22]
Maksymenko said at the time of the April campaign that the hackers had failed to penetrate ARMA's internal systems.
Sources
2 independent publishers whose own reporting we read for this story.
- thecyberexpress.comCyberattack Hits Ukraine Agency Ahead of Major Asset Tender
1 article · August 18, 2026
- therecord.mediaHackers target Ukrainian agency managing assets seized from sanctioned Russians
1 article · August 18, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.