Cyber Incident Victim: Sluzhba Vneshney Razvedki Rossiyskoy Federatsii
Date:
May 2022
Location:
Russia
Summary
A hacking group identified as AgainstTheWest leaked sensitive data belonging to leaders of Russia's GRU, the foreign military intelligence agency. The compromised information included hashed passwords, exposing credential details of high-ranking personnel within the organization. The breach was publicly promoted by the group alongside affiliations with broader hacktivist collectives, highlighting vulnerabilities in the security infrastructure of a critical Russian defense entity.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On May 26, 2022, the hacking group #AgainstTheWest (#ATW) publicly disclosed a data breach targeting leaders of Russia's GRU, the foreign military intelligence agency of the Russian Armed Forces. The leaked information included password hashes belonging to GRU personnel, though the specific number of affected individuals and the exact scope of compromised systems were not detailed in the disclosure. The group shared this information via social media platforms, including Twitter, using hashtags such as #OpRussia and #DataLeak to amplify visibility. The incident occurred amid heightened cyber activity related to the Russia-Ukraine conflict, with #ATW positioning the breach as part of broader operations against Russian entities. No technical specifics regarding intrusion methods, malware used, or duration of network access were provided in available reporting.

The exposure of password hashes represented a potential security risk for GRU operational security, as successful decryption could facilitate unauthorized access to sensitive systems. The breach marked one of several publicly announced cyber operations against Russian government entities during this period, with #ATW associating itself with the #Anonymous collective's anti-Russia campaigns. No official GRU acknowledgment of the incident or remediation actions was documented in the source material. The leak's operational impact on GRU activities remained unverified, though it underscored persistent targeting of Russian military intelligence infrastructure by hacktivist groups. Third-party accounts, including cybersecurity researchers monitoring the PuckArks Twitter handle, circulated the disclosure but did not provide independent validation of the data's authenticity or significance.
