Article

How insiders became Ukraine’s biggest cybersecurity threat 

Illustration


Writer: Roman Bebeshko, Sales Engineer, Bakotech.

Ukraine's cyber battlefield has revealed a painful truth: even the strongest perimeter defenses become useless when the attacker walks through the front door. The concept of the impenetrable fortress no longer applies. Russian intelligence agencies (FSB, GRU, and SVR) are increasingly bypassing sophisticated technical exploits by targeting people. 
According to CERT-UA, the number of cybersecurity incidents in Ukraine increased by 37.4% in 2025, reaching 5,927 recorded cases. At least 425 attacks began with compromised user accounts. 
Not because of a software vulnerability. Not because of a zero-day exploit. But because someone had legitimate access. The biggest challenge is that most organizations simply have no visibility into what happens after a user logs in. 
Attackers need less than an hour to establish persistence, escalate privileges, and begin exfiltrating sensitive data. For businesses, this is no longer a hypothetical risk. According to the Ponemon Institute, the average cost of a single insider-related security incident reaches $779,000.

Three faces of the insider threat in Ukraine

An analysis of Ukraine's most significant cyberattacks, along with reports published by the Security Service of Ukraine (SBU), reveals three primary categories of insider threats affecting both public and private organizations. 

  • 1. The deliberate collaborator (ideologically or financially motivated)

These individuals possess legitimate access to critical infrastructure and intentionally use it to assist the enemy. Their technical expertise makes them highly effective accomplices.
The Ukrenergo case. Last autumn, the SBU detained a senior security executive at NEC Ukrenergo. With access to classified information, he systematically shared intelligence about the actual impact of Russian missile and drone strikes on Ukraine's energy infrastructure, which allowed the enemy to assess the effectiveness of its attacks.
The Kupiansk IT administrator. A system administrator voluntarily helped deploy the network infrastructure of the occupation authorities. After being recruited by Russia's GRU, he used his technical expertise to collect and transmit precise coordinates of Ukrainian military positions.

  • 2. The compromised user (victim of social engineering) 

This is by far the most common insider threat. The user has no malicious intent, but their digital identity is stolen and exploited by hostile APT groups.   
The Kyivstar attack. The devastating disruption of Ukraine's largest telecom operator in December 2023 resulted from a long-running operation conducted by the Sandworm group (GRU). The attackers gained initial access through a compromised employee account. From there, they remained inside the network for months, escalated privileges, and ultimately destroyed core parts of the company's infrastructure.
Espionage through messaging apps. Gamaredon (UAC-0010)—a threat group consisting of former Crimean SBU officers who defected to Russia—actively targets Ukrainian military personnel via Signal, WhatsApp, and Telegram. Using phishing campaigns and malicious QR codes, the attackers link victims' devices to their own infrastructure. Once access is obtained, stealing sensitive documents takes as little as 30 to 50 minutes.

3. The coerced insider (under occupation)

This unique threat emerged as a direct consequence of Russia's occupation of Ukrainian territories. 
The Ukrtelecom case. In March 2022, Ukrtelecom's Internet connectivity dropped to just 13% of its pre-war capacity. The attackers did not exploit a software vulnerability. Instead, they used legitimate credentials belonging to an employee located in a temporarily occupied territory. Because the login appeared legitimate, security systems allowed the attackers to proceed, enabling a rapid and large-scale attack.

Why traditional security approaches are blind

All of these scenarios share the same weakness. Traditional security controls—and even many basic Zero Trust implementations—focus almost exclusively on verifying identity before authentication. If Gamaredon possesses the correct password and a valid 2FA token, or if a collaborator legitimately logs into a database, the firewall allows them through. This creates what is known as the post-authentication visibility gap.  
This creates what is known as the post-authentication visibility gap.

The system verified who logged in. But it stopped monitoring what they did next. 

The same problem already exists throughout the private sector—it simply doesn't make the headlines. 

User Activity Monitoring closes the visibility gap

How can organizations address this gap? To effectively defend against insider threats and APT groups during wartime, a Zero Trust architecture must continuously verify user behavior throughout the entire session. This is precisely the role of User Activity Monitoring (UAM) and Privileged Access Management (PAM) solutions. 
A strong example of this approach is the Syteca platform. Rather than simply recording user activity through logs and session captures Syteca can automatically respond to risky behavior by terminating sessions, blocking suspicious processes, or alerting security teams before an attack spreads. 
In espionage campaigns such as those carried out by Gamaredon, attackers who compromise military or government accounts typically begin copying documents, archiving files, or transferring sensitive information to external resources as quickly as possible. In this case, a User Activity Monitoring system helps detect abnormal patterns: mass copying of sensitive data, connecting removable media, launching unusual applications, accessing critical documents outside normal working hours. 
The Ukrtelecom incident illustrates another common challenge. The login from an occupied territory appeared legitimate, which meant that conventional authentication controls could not detect anything suspicious. Behavior analytics provides an additional layer of protection by evaluating factors such as login location, activity timing, and user behavior throughout the session. If anomalies are detected, access can be automatically restricted.  
Protecting privileged administrator accounts is equally critical. If an administrator's password is compromised through phishing or malware, the consequences can be catastrophic. Syteca addresses this risk through centralized password vaulting. Administrators never see the actual credentials—the platform injects them automatically when connecting to servers. This significantly reduces the risk of compromising critical infrastructure, even if an employee's account is stolen.  
Syteca addresses this risk through centralized password vaulting. Administrators never see the actual credentials—the platform injects them automatically when connecting to servers. This significantly reduces the risk of compromising critical infrastructure, even if an employee's account is stolen.

Conclusion

Ukraine's cyber war has demonstrated one fundamental reality: Trust is the weakest link in cybersecurity.  
By integrating comprehensive User Activity Monitoring (UAM) and Privileged Access Management (PAM) platforms such as Syteca into a Zero Trust architecture, organizations transform Zero Trust from a theoretical concept into a practical survival strategy—capable of detecting and stopping both recruited insiders and sophisticated nation-state threat actors. 
Want to learn how to build an effective insider threat protection strategy for your organization? Contact the BAKOTECH experts at moc.hcetokab%40acetys. We'll help you assess your current risks and design the security architecture that best fits your environment.