Mezha SBU and FBI Expose Russian Cyber Campaign Targeting Messaging Accounts
Article Content
- •Russian intelligence is targeting messaging accounts of officials and civilians in multiple countries.
- •Phishing attacks use SMS disguised as official support messages, exploiting user vulnerability.
- •SBU and FBI recommend strict cybersecurity practices to mitigate risks.
On June 25, 2026, Ukraine's Security Service (SBU) and the FBI announced a coordinated cyber campaign by Russian intelligence targeting messaging accounts of officials, military personnel, politicians, and activists in Ukraine, Europe, and the U.S. The campaign aims to access sensitive military, political, and economic information, as well as personal data. Russian operatives employ phishing techniques, primarily through SMS messages disguised as official support communications, often sent during early morning hours to exploit user vulnerability. The SBU emphasized that both public officials and ordinary citizens are at risk, urging enhanced cybersecurity measures such as two-factor authentication and cautious handling of suspicious links and QR codes. This warning follows a previous operation that disrupted a large-scale cyber espionage campaign linked to Russian military intelligence, which involved compromising Wi-Fi routers to intercept sensitive communications.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (18)
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…