Entering the Cyber Battlespace
Digital Systems as Mission Terrain Evidence, Threat Intelligence, and Incident Response Authorization, Ethics, and Safe Practice What Cyberwarfare Is—and Is Not Cyberspace as an Operational Environment
The Road to Persistent Cyber Conflict
Estonia, Georgia, Stuxnet, and the First Shock Ukraine, 2015–2026: Campaigning Under Fire
Actors, Proxies, and Strategic Behavior
The State Cyber Ecosystem Strategic Cultures Without Stereotypes
Law, Authority, and Civilian Protection
Below Armed Conflict: Sovereignty, Intervention, Force, and Responsibility Armed Conflict: IHL and Cyber Effects
Intelligence, Indications, and Attribution
Intelligence Support to Cyber Operations Attribution Under Deception
Campaign Design and Command
From Policy Aim to Cyber Campaign Command, Authorities, and Deconfliction
Target Systems, Access, and Operational Security
Target-System Analysis and Cyber Key Terrain Access Stewardship, Capability Fit, and OPSEC
Effects Engineering and Campaign Assessment
Designing and Bounding Cyber Effects Measuring What the Campaign Changed
Critical Infrastructure and Cross-Domain Operations
Operational Technology, Safety, and Restoration Space, Telecommunications, and Multi-Domain Integration
Influence, Perception, and Public Truth
Cyber-Enabled Influence Operations Defending Truth, Trust, and Decision Space
Daily Defence in Competition and War
Mission Assurance and the Wartime Operations Floor Continuity, Recovery, and Collective Defence
Deterrence, Emerging Change, and the Final Campaign
Deterrence, Norms, and Collective Response The 2026 Horizon: AI, Supply Chains, Edge, and Identity Capstone: Build, Challenge, and Defend a Cyber Campaign
The Road to Persistent Cyber Conflict

Ukraine, 2015–2026: Campaigning Under Fire

Follow a decade of power disruption, destructive malware, satellite effects, espionage, influence, adaptation, and resilience.

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.

In this lesson, you will learn to:

  • Construct a campaign timeline linking at least eight cyber operations to military, political, and defensive developments.
  • Explain why tactical technical success may coexist with limited strategic effect and significant civilian harm.

Ukraine, 2015–2026: Campaigning Under Fire

Ukraine provides the richest public record of cyber operations across competition and armed conflict. This lesson rejects a search for one decisive cyber weapon and instead studies persistence, combined effects, operational learning, civilian exposure, and defender adaptation.

From grid disruption to global spillover

In December 2015, attackers disrupted electricity distribution for roughly 225,000 Ukrainian customers. The operation combined months of preparation, stolen access, remote interaction with control interfaces, denial of operator control, destructive components, and disruption of customer communications. Restoration through manual operations limited duration. The lesson is not “malware turned off the grid.” Coordinated human action, knowledge of the distribution environment, and attacks on recovery processes created the effect; practiced manual capability helped contain it. CISA’s Russian state-sponsored threat summary also links the 2016 transmission event with CrashOverride/Industroyer.

NotPetya in June 2017 used a compromised Ukrainian software-update mechanism and worm-like movement to produce destruction disguised as ransomware. It escaped the intended geographic and organizational context, disrupting shipping, medicine, logistics, and other firms worldwide. The US Department of Justice indictment attributes the operation to GRU officers and describes nearly one billion dollars in losses among three named victims alone. NotPetya remains a warning about tightly coupled supply chains: operational reach can exceed target intent, and global civilian consequences can overwhelm any claim of technical precision.

Full-scale invasion revealed integration and limits

Before and during the February 2022 invasion, Ukrainian organizations faced defacement, false ransomware, multiple wipers, espionage, and communications disruption. Microsoft reported at least six Russia-aligned state actors conducting destructive or espionage activity and later documented operations against dozens of agencies and enterprises. The EU stated that the KA-SAT attack occurred about one hour before the invasion and facilitated military aggression while causing cross-border outages.

These events show integration in several forms: timing around military action, collection against diplomatic and defence targets, disruption of government and communications, cyber-enabled influence, and targeting of organizations supporting the war effort. Integration does not mean cyber effects replaced missiles or maneuver. Many services were restored, migrated, or rerouted. Cloud relocation, vendor support, threat-intelligence sharing, backups, distributed administration, and rapid incident response reduced persistence.

Mandiant’s 2024 APT44 assessment argues that Sandworm became more integrated with conventional forces while shifting relative emphasis toward intelligence collection as the war continued. That shift is strategically important. When durable disruption is hard or expensive, access may serve targeting, situational awareness, influence, and preparation. Analysts should therefore track mission alignment and collection requirements, not count only wipers and outages.

Measure warfighting value and human cost together

A balanced assessment asks two questions at once: what military or political advantage did the operation create, and what harm or risk did it impose on civilians and shared infrastructure? Cyber operations may produce localized, temporary advantage while still causing broad humanitarian or economic consequences. Conversely, loud disruption may consume adversary resources without materially changing battlefield decisions.

Build an effects ledger with intended target, direct effect, duration, affected mission, civilian dependencies, cross-border propagation, recovery pathway, intelligence lost, adversary adaptation, and evidence confidence. Revisit it after hours, days, and weeks. A service outage restored in six hours may create a decisive window—or no meaningful operational advantage at all.

The enduring lesson from Ukraine is resilience as combat power. Manual operation, segmentation, distributed backups, cloud and partner capacity, practiced incident command, trusted communications, and public credibility deny the attacker persistence and amplification. The defender is also campaigning. Every recovery teaches the adversary, so defenders must decide what to reveal, what to preserve for intelligence, and when to force eviction.

Resources