Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ukrainian officials and researchers described intense cyber activity during the country’s June 2023 counteroffensive, with attacks and attempted intrusions aimed at service providers, media, critical infrastructure, and government networks. But activity and attackers’ public claims did not necessarily translate into verified disruption: contemporaneous reporting found no evidence that a Killnet claim against European financial institutions had interrupted their services, and a document published by Beregini was not authenticated.

This is a historical account of reporting published in June 2023, not evidence that the named groups remain active in September 2026.

What Ukrainian officials reported during the counteroffensive

In an interview published June 16, 2023, CyberScoop quoted Victor Zhora, then deputy chairman of Ukraine’s State Service of Special Communications and Information Protection, describing cyber activity as “still very high.” He said pro-Russian hackers were focusing on Ukrainian service providers, media, critical infrastructure, and collecting data from government networks. Zhora expected the pace to increase.

Those observations describe the tempo and targets officials were seeing; they do not, by themselves, establish that every attempted operation succeeded or had a measurable military effect. CyberScoop also quoted Sean Townsend, spokesperson for the Ukrainian Cyber Alliance, saying: “They apparently realize that their usual method of communication simply doesn’t work.” Both quotations were reported by CyberScoop.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

Did Killnet disrupt SWIFT or European banks?

Killnet claimed to have hit European financial institutions, including IBAN and Swift. CyberScoop’s June 2023 report said it found no indication of disruption: the European Central Bank said its systems were running normally, and Swift said it was operating without issue. The distinction matters: a group’s announcement is not proof that an institution was breached or that its services were affected. This describes the contemporaneous reporting, not the institutions’ status today.

Was Beregini’s purported Defense Department document real?

Beregini published what appeared to be a U.S. Defense Department document concerning coalition air-defense deliveries. CyberScoop said it could not verify the document’s authenticity, and a Defense Department spokesperson could not confirm it. The reporting therefore did not establish that the document was genuine or that it resulted from a successful breach.

Even unverified material can serve an information purpose: publishing an apparent leak can attract attention and shape perceptions whether or not the document is authentic. That possibility should not be confused with proof of the material’s origin.

What did researchers say about Russian-linked actors?

Microsoft’s assessment of Cadet Blizzard

On June 14, 2023, Microsoft Threat Intelligence identified Cadet Blizzard as a distinct Russian state-sponsored threat actor and assessed that its operations were associated with Russia’s General Staff Main Intelligence Directorate (GRU). Microsoft described it as separate from other known GRU-affiliated groups. This is Microsoft’s attribution assessment, not an independently established finding presented by CyberScoop.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft said Cadet Blizzard had operated in some capacity since at least 2020, was tracked after destructive events in Ukraine in January 2022, and re-emerged in January 2023 following an extended period of reduced activity. The company identified Ukrainian government organizations and IT providers as primary targets, and also noted activity against organizations in Europe and Latin America. It characterized the group’s objectives as disruption, destruction, and information collection, and described tactics ranging from exploiting web servers and collecting credentials to espionage and destructive activity.

Shuckworm activity reported by Symantec

CyberScoop separately reported findings from Symantec’s Threat Hunter Team about Shuckworm activity targeting Ukrainian security services, military, and government organizations, including efforts to steal sensitive information. These findings describe another reported set of operations; they should not be merged with Microsoft’s Cadet Blizzard attribution or treated as evidence that every pro-Russian group was part of one coordinated unit.

How to distinguish a cyber claim from a confirmed effect

The June 2023 accounts illustrate why reports of cyber operations need to be read with attention to source and evidence. A useful assessment separates:

  • Claim from corroboration: A group’s announcement, an official statement, and an independent technical finding are different kinds of evidence.
  • Activity from effect: An attempted intrusion or posted material does not establish service disruption, data theft, or a battlefield consequence.
  • Purpose: Espionage, destructive activity, and information operations can overlap, but they are not interchangeable.
  • Attribution: Preserve who made an attribution and how they qualified it; for example, Microsoft assessed Cadet Blizzard’s association with the GRU.
  • Time and geography: Targets and activity described in a 2023 report cannot be assumed to describe the same actors’ operations in 2026.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What this reporting does—and does not—establish

The June 2023 reporting documented Ukrainian officials’ concern about a high tempo of cyber activity during the counteroffensive, alongside research describing particular actors and targets. It also showed the limits of public claims: the Killnet announcement was not accompanied by evidence of financial-service disruption in CyberScoop’s account, and Beregini’s purported document remained unverified.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CyberScoop’s June 16, 2023 article and Microsoft Threat Intelligence’s June 14, 2023 assessment are historical sources. They do not establish whether the groups named remain active, what they are targeting, or what effects their operations may have in September 2026.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.