Security News

Russian FSB-Linked Hackers Ramp Up Phishing Campaigns Targeting Ukraine Supporters

The Record · 30 Sept 2026
Key Takeaway Businesses and staff involved with Ukraine-related advocacy, NGOs, or international affairs should treat unsolicited emails about fines, audits, or event invitations with caution and verify sender authenticity before clicking links or providing information.

Microsoft has revealed that Star Blizzard, a Russian hacking group linked to the FSB, has significantly expanded its phishing operations in 2026. Previously known for narrow, highly targeted spear-phishing, the group now sends bulk phishing campaigns of tens or hundreds of emails at once, affecting more than 100 organisations, mostly in the US and UK. Targets include Ukrainian individuals and institutions, along with NGOs, think tanks, governments and financial institutions that support Ukraine.

The shift appears to stem from the group adopting a mass-mailing phishing platform that automates attacks, with at least 13 large-scale campaigns identified since January. The hackers have also changed their infrastructure, using accounts on compromised websites rather than free email services to contact victims. Early campaigns impersonated Ukrainian authorities with fake tax audit or fine notices, while later ones used fraudulent conference or event invitations supposedly from legitimate think tanks and NGOs, sometimes disguised as internal staff communications.

Microsoft suggests Star Blizzard may have initially tested its new tactics on Ukrainian targets before expanding globally, indicating the campaign could continue to grow in scale and reach beyond its current victims.

phishing Star Blizzard Russia FSB Ukraine cyberespionage

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.