October 2, 2026 | Policy Brief
Russian Cyberespionage Campaign Signals U.S. Should Fast-Track Lessons Learned From Ukraine
October 2, 2026 | Policy Brief
Russian Cyberespionage Campaign Signals U.S. Should Fast-Track Lessons Learned From Ukraine
Russia is testing its cyber weapons in Ukraine before turning them against the United States and its allies.
Microsoft has disclosed that the Russian intelligence-linked hacking group Star Blizzard breached more than 100 organizations across the United States and the United Kingdom.
But the research points to something more consequential than a single espionage campaign: Russian intelligence services are using the war in Ukraine as a proving ground for capabilities — and the United States has largely failed to recognize the value of this early-warning system.
Russian Cyber Tradecraft Is Evolving
Since January, Microsoft has uncovered at least 13 large-scale Star Blizzard campaigns aimed at government bodies, think tanks, and nongovernmental organizations. The group historically embarked on patient, personalized spear-phishing of officials, academics, and defense experts. Now it favors scale, deploying mass-mailing campaigns reaching hundreds of targets per operation.
Star Blizzard’s campaigns in January and February hit users of the Ukrainian email provider Ukr[.]net with fake tax-audit and fine notices designed to compromise victims with a single click. By spring, the group was using the same delivery technique against Western governments and financial institutions that support Kyiv — a progression that suggests deliberate capability testing.
No Replacement for Government-Led Assistance
Washington’s best window into Russian cyber tactics came from working inside Ukrainian networks. In December 2021, U.S. Cyber Command (CYBERCOM) deployed a team to help Ukraine evict malicious actors from its systems. CYBERCOM was able to share indicators of compromise with U.S. government and private-sector partners. Since then, no military cyber teams have been in-country, and government support has thinned amid the Trump administration’s cuts to foreign assistance programs.
Private companies have filled much of the gap, and their help has been substantial. But they cannot replace government channels. Government teams collect malware directly from partner networks. They then feed it into channels that protect classified systems, the defense industrial base, and private industry.
Washington Must Treat Ukraine as an Early-Warning System
Ukraine will continue to face Russia’s newest cyber weapons first. The question is whether Washington is positioned to learn from them in time. Congress should direct the Government Accountability Office to assess how and whether the Department of Defense, the Intelligence Community, and government-led critical infrastructure resilience efforts are absorbing Ukraine’s wartime lessons. Lawmakers should also require the Pentagon and the Office of the Director of National Intelligence to report on how Ukrainian threat intelligence is integrated into American military networks and the defense industrial base and then shared with private industry. Washington must learn from Ukraine now or risk losing valuable intelligence that could prevent the next major breach.
Johanna “Jo” Yang is a policy analyst at the Center on Cyber and Technology Innovation (CCTI) at the Foundation for Defense of Democracies (FDD), where she works on issues related to nation-state cyber threats, critical infrastructure protection, and U.S. cybersecurity policy. For more analysis from the author and CCTI, please subscribe HERE. Follow Jo on X @JohannaYang_. Follow FDD on X @FDD and @FDD_CCTI. FDD is a Washington, DC-based, nonpartisan research institute focusing on national security and foreign policy.