MainNews -
Special feature

YouControl analyses how Russia obtains information on Ukraine’s defence industry from SBU open data

The organisation analysed more than 7,000 posts on the SBU’s official website from January 2020 to August 2026

YouControl analyses how Russia obtains information on Ukraine’s defence industry from SBU open data
Photo: defence ministry

Russia most often seeks to obtain sensitive information about Ukraine’s defence industry through people who have access to companies and government institutions. Other channels include agent networks, social media and cyberattacks. This is stated in a study by YouControl analysts.

The organisation analysed 7,362 reports published on the SBU’s official website between January 2020 and August 2026. Of these, 131 directly concerned threats to Ukraine’s defence industry.

Based on open data, the researchers identified seven main ways in which Russia attempts to obtain information about Ukrainian defence facilities:

  • Recruiting employees of strategic and defence companies. In 111 SBU reports directly related to the defence industry, the exposure of “moles” and spies was reported, including employees of companies, engineers, designers and officials who may have passed on data.

  • Using agent networks, intermediaries and personal contacts. The exposure of individual FSB agents and intermediaries was mentioned in 179 reports, including 115 reports in the defence industry sample.

  • Stealing classified technical documentation. This was recorded in 19 defence industry reports. The cases involved attempts to copy scientific and technical information onto storage devices and transfer it abroad.

  • Targeted collection of information about military facilities and visual reconnaissance. A total of 269 SBU reports concerned fire adjustment and the targeting of Russian strikes. At the same time, in 43 cases, agents physically collected information about facilities by photographing or filming their premises.

  • Remote recruitment through social media. Social media are used to identify potential spotters among local residents living near industrial areas. There were 90 such reports in the defence industry sample.

  • Bloggers, Telegram channels and photo/video recording. In 15 cases, bloggers, Telegram channel administrators and streamers were involved in the unauthorised recording of the results of strikes, air defence operations or the movement of military equipment.

  • Cyberattacks and technical data leaks. During the period studied, the SBU published 71 reports on hacker attacks and 45 reports on unauthorised actions involving computer information. The defence industry dataset also included four cases of unauthorised access by Russia to external IP cameras located near defence plants. At the same time, according to YouControl’s analysis, open data did not feature among the identified channels for leaking information about the defence industry. Across all 7,362 SBU reports, the researchers found no case in which obtaining information about defence facilities was linked specifically to the use of data from public government registers.

Photo: Youcontrol

The analysts also identified 14 SBU reports concerning 11 criminal proceedings over the unlawful disclosure of restricted information by employees of law enforcement and regulatory bodies. Tax and fiscal authorities were most frequently involved in such cases.

The researchers analysed only public posts from the SBU website, selected under articles of the Criminal Code of Ukraine on treason, espionage and disclosure of official information. A single post could fall into several categories, so the number of mentions does not equal the number of cases. YouControl cautions that the study does not cover non-public SBU materials and does not provide a complete picture of Russia’s attempts to obtain information about the defence-industrial complex.

Advertising
Advertising