CSIDB logo
Incident

Sluzhba Vneshney Razvedki Rossiyskoy Federatsii

Incident posture

Attack window
May 2022
Location
Russia
Status
Historical
CIA posture
Available to members
Updated
2025-11-20 00:00

Linked entities

Victim
Sluzhba Vneshney Razvedki Rossiyskoy Federatsii
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
May 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A hacking group identified as AgainstTheWest leaked sensitive data belonging to leaders of Russia's GRU, the foreign military intelligence agency. The compromised information included hashed passwords, exposing credential details of high-ranking personnel within the organization. The breach was publicly promoted by the group alongside affiliations with broader hacktivist collectives, highlighting vulnerabilities in the security infrastructure of a critical Russian defense entity.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 26, 2022, the hacking group #AgainstTheWest (#ATW) publicly disclosed a data breach targeting leaders of Russia's GRU, the foreign military intelligence agency of the Russian Armed Forces. The leaked information included password hashes belonging to GRU personnel, though the specific number of affected individuals and the exact scope of compromised systems were not detailed in the disclosure. The group shared this information via social media platforms, including Twitter, using hashtags such as #OpRussia and #DataLeak to amplify visibility. The incident occurred amid heightened cyber activity related to the Russia-Ukraine conflict, with #ATW positioning the breach as part of broader operations against Russian entities. No technical specifics regarding intrusion methods, malware used, or duration of network access were provided in available reporting.

The exposure of password hashes represented a potential security risk for GRU operational security, as successful decryption could facilitate unauthorized access to sensitive systems. The breach marked one of several publicly announced cyber operations against Russian government entities during this period, with #ATW associating itself with the #Anonymous collective's anti-Russia campaigns. No official GRU acknowledgment of the incident or remediation actions was documented in the source material. The leak's operational impact on GRU activities remained unverified, though it underscored persistent targeting of Russian military intelligence infrastructure by hacktivist groups. Third-party accounts, including cybersecurity researchers monitoring the PuckArks Twitter handle, circulated the disclosure but did not provide independent validation of the data's authenticity or significance.

Sources

Sources available to members: 1 source.

CSIDB