Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Russia has not stopped targeting Ukraine. The clearest picture is continuity with a widening horizon: UK assessments say Russia’s most disruptive cyber activity remains focused on Ukraine, while Google Cloud’s 2026 forecast anticipates broader global intelligence collection and strategic positioning alongside continued espionage against Ukrainian targets. That forecast describes an expected direction, not proof that a completed strategic shift has already occurred.
What Russia seeks to achieve with cyber operations
A UK government profile of Russian military intelligence (GRU) activity describes several aims in Ukraine: gathering information and battlefield advantage, coordinating cyber effects with military operations, creating fear and disruption, developing capabilities, and outsourcing some intelligence collection to cybercriminals. These aims can overlap, but they do not make every operation destructive or directly tied to an immediate battlefield event.
- Intelligence: Gain access to information about Ukrainian targets, military activity, or foreign support.
- Operational coordination: Use cyber activity in conjunction with military operations.
- Psychological pressure: Cause fear, uncertainty, or disruption among people and institutions.
- Capability development: Develop or exercise technologies and methods.
- Collection through others: Use cybercriminals for some intelligence-gathering tasks, according to the UK profile.
This range helps explain why a quieter period for disruptive attacks would not, by itself, mean that Russian cyber activity had ended: espionage and access-building can continue without a visible outage or destructive payload.
How different GRU units illustrate the operational picture
The UK profile, updated 13 July 2026, identifies three GRU units with known cyber capabilities. Its examples show distinct activity, rather than a single operation or one uniform target set.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
| GRU unit | Example in the UK profile | What the example shows |
|---|---|---|
| 29155 | The profile says the Whispergate wiper targeted more than 70 Ukrainian government systems before Russia’s full-scale invasion. | A destructive operation aimed at government systems. |
| 26165 | The profile attributes reconnaissance on civilian shelters in Mariupol and Kharkiv to the unit on 15 March 2022. It also says the unit used private IP cameras near military facilities, ports, train stations, and border crossings to monitor foreign assistance routes through Ukraine, Moldova, and NATO countries. | Intelligence gathering that could support battlefield awareness and monitoring of assistance routes without requiring a destructive attack. |
| 74455 | The profile reports that Ukraine’s Security Service (SBU) attributed the December 2023 Kyivstar operation to the unit. | A disruptive incident attributed by Ukrainian authorities, as reported by the UK government. |
The more-than-70 figure is the UK profile’s count of Ukrainian government systems targeted by Whispergate; it is not a measure of systems successfully disabled. For Kyivstar, the profile says the provider served 24 million customers at the time of the December 2023 incident. That customer figure indicates the scale of the affected service, not the number of people whose service was necessarily interrupted for the same duration or in the same way.
Disruption remains part of the record
The long-term emphasis on intelligence should not be mistaken for an absence of disruptive operations. The Kyivstar case is one reported example: the UK profile records the SBU’s attribution to GRU Unit 74455. That is an attributed claim, not an independently adjudicated finding presented here as settled fact.
Rank #2
The same UK profile reports that a BlackEnergy incident disrupted power for 230,000 people, with outages lasting between one and six hours. These figures describe that reported incident; they should not be combined with the Kyivstar customer count or the Whispergate target count to infer a trend across the war. They measure different things in separate incidents.
What “the long haul” means—and what it does not establish
Two recent assessments describe different aspects of the picture. The UK government’s National Cyber Security Centre (NCSC) annual review covers 1 September 2024 to 31 August 2025 and says Russia’s most disruptive threat activity continues to focus on Ukraine. Google Cloud’s Cybersecurity Forecast 2026, drawing on Mandiant assessment, looks ahead: it expects Russia to move beyond a singular focus on short-term tactical support for the conflict toward longer-term global strategic goals.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
| Source and time frame | What it says | How to read it |
|---|---|---|
| NCSC annual review, covering 1 September 2024–31 August 2025 | Russia’s most disruptive threat activity remains focused on Ukraine. | A UK government assessment of activity during the review period. |
| Google Cloud Cybersecurity Forecast 2026 | Expects continued espionage against Ukrainian government and defense targets, broader intelligence collection, and efforts to establish strategic footholds in international critical infrastructure. It also says disruptive and destructive attacks have declined since 2022. | A forecast of expected developments, not confirmation that the shift is complete. A reported decline in disruptive attacks does not mean Russian activity has ended. |
The two statements are not contradictory. One describes the continuing concentration of the most disruptive activity; the other forecasts a broader strategic agenda that includes persistent espionage against Ukraine. The available evidence does not establish exactly when a wider focus began, how large it is, or whether all the forecast positioning has already happened.
The NCSC also notes that pro-Russia hacktivist groups have targeted the UK, Europe, the United States, and other NATO countries. It describes their association with the state as varying. Their activity should therefore not automatically be described as directly controlled by the Russian government.
Rank #4
Why attack counts do not settle the question of success
A 2024 paper by Kott, Dubynskyi, Paziuk, Galaitsi, Trump, and Linkov argues that Ukrainian cyber resilience was a major reason Russian attacks were blunted, rather than security measures alone. That is the authors’ conclusion, not a settled consensus. The sources discussed here do not provide a common, audited measure of strategic effect across the war, so the number of attacks alone cannot show whether Russian cyber operations achieved their broader goals.
For readers assessing claims about a strategic change, keep five distinctions in view: espionage versus disruption; battlefield targets versus foreign governments or infrastructure; intelligence gathering versus psychological or operational effects; state-attributed units versus groups with varying state association; and observed activity versus forecasts.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

