Russian broker sells stolen access, spies on Ukraine
CloudSEK said the Russian-speaking operator continued scanning exposed systems, stealing credentials, selling network access to multiple ransomware groups, and collecting from Ukrainian defense and aerospace targets. Organizations later named in the research included Greater Pittsburgh Orthopaedic Associates in the United States and MARTEC MARINE in Italy.
- Started
- Aug 3, 2026
- Latest activity
- Sep 9, 2026
- Attributed to
- Russian-speaking access broker (state-linked)Likely
- Where
- Worldwide, Ukraine, United States
- Sectors
- Government, Healthcare, Finance, Education, Telecom, Defence +2
- Scale
- Hundreds of thousands of internet-facing systems scanned worldwide
Current status
No credible incident-specific report or official statement dated after 2026-09-09 was found as of 2026-09-11.
Active: Confirmed and still going. Attacker activity or disruption is continuing.
Who is behind it
CloudSEK assesses the operator as a Russian-speaking access broker and says the Ukrainian collection had a likely state nexus, but names no specific Russian service.
Impact
The broker compromised exposed network appliances and, in some cases, entire Active Directory domains before selling access. CloudSEK linked several held networks to later ransomware claims by different groups. It also reported source-code theft and camera surveillance involving Ukrainian defense-related targets.
What to do
Patch and remove management interfaces from the internet. Rotate appliance, domain and service-account credentials. Check for unfamiliar admin accounts, SSH keys, web shells, forged login tickets and unusual internal connections. Change default camera passwords, update firmware and isolate cameras from the internet.
Timeline
-
Sep 9, 2026
CloudSEK publicly linked to its investigation and said the operator's held access later appeared in ransomware leak-site claims by several different groups. It also described the scanning setup as configured to continue.
Activelinkedin.com -
Aug 25, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Aug 4, 2026
GBHackers detailed CloudSEK research showing the same operator used Sliver C2 and compromised IP cameras to spy on Ukrainian defense and aerospace organizations, alongside selling access to ransomware gangs.
Activegbhackers.com -
Aug 3, 2026
Cyber Security News reported a Russian-speaking hacker linked to a broad access-sale operation breaching organizations across education, healthcare, finance, telecom and government worldwide.
Activecybersecuritynews.com
Sources
- Russian Access Broker Sells Network Access to Ransomware Gangs While Spying on Ukraine GBHackers Aug 4, 2026
- Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites Cyber Security News Aug 3, 2026
- CloudSEK's post on the Russian-speaking access broker investigation LinkedIn Sep 9, 2026