CSIDB logo
Incident

Myrotvorets

Incident posture

Attack window
Sep 2016
Location
Ukraine
Status
Historical
CIA posture
Available to members
Updated
2025-12-09 00:00

Linked entities

Victim
Myrotvorets
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Pro-Ukraine hackers associated with Myrotvorets leaked personally identifiable information of numerous Ukrainian and foreign journalists, primarily targeting those accused of pro-Russian sympathies due to obtaining press accreditation in conflict zones held by Russian-backed forces. The leak impacted reporters from over 30 international media outlets, exposing victims to financial risks and physical danger, including death threats, amid heightened tensions in the war-torn region. Ukrainian authorities reportedly did not intervene, with indications suggesting tacit approval to discourage reporting from frontline areas, while critics emphasized that journalistic access to conflict regions does not imply support for local factions.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On September 3, 2016, the pro-Ukrainian hacker group Myrotvorets publicly leaked the personal details of Ukrainian and foreign journalists they accused of holding pro-Russian sympathies. This marked the group’s second such action within four months, following an August 2016 leak targeting journalists who had obtained press accreditation in Russian-occupied eastern Ukraine. The data breach compromised individuals affiliated with over 30 international media organizations, including CNN, Al Jazeera, Radio Free Europe, The Daily Beast, BBC, and the Associated Press. Myrotvorets justified the leak by asserting that journalists securing accreditation in pro-Russian territories inherently supported Russian interests, a rationale characterized in reporting as simplistic given journalists’ professional obligation to report from conflict zones regardless of personal political alignment. The leak exposed personally identifiable information (PPI), though specific data types were not enumerated in available sources.

The disclosure placed affected journalists at heightened physical risk within Ukraine’s wartime environment, where nationalist sentiments were inflamed. Multiple journalists reported receiving death threats via telephone and social media following both the August and September leaks. Ukrainian authorities neither condemned the breaches nor initiated visible countermeasures against Myrotvorets, with reports indicating tacit approval or celebration within some government circles. Observers interpreted this inaction as a deliberate strategy to intimidate journalists and discourage reporting from conflict areas, particularly frontline regions under Russian control. The incident underscored the operational dangers facing media personnel in conflict zones beyond immediate battlefield risks, extending to targeted harassment by non-state actors exploiting wartime divisions.

Sources

Sources available to members: 1 source.

CSIDB