On August 15, 2026, Ukraine's Main Intelligence Directorate (HUR) announced that its cyber warfare unit conducted a successful, large-scale cyberattack against Wildberries, Russia's largest online retailer. The attack, executed by the affiliated Cyber Corps community on August 10-11, targeted the company's digital infrastructure, causing significant disruption to its payment systems and customer service channels. This digital operation was part of a broader hybrid warfare strategy, synchronized with a sustained campaign of drone strikes against Wildberries' physical warehouses. Ukraine has justified the attacks by accusing the e-commerce giant of being complicit in Russia's war effort.
The attack represents a clear example of coordinated hybrid warfare, where cyber operations are used to amplify the effects of kinetic military actions. The HUR's cyber specialists targeted Wildberries' core business functions, aiming to cause financial and operational chaos. The cyberattack reportedly destabilized the company's payment infrastructure, leading to widespread user complaints about failed transactions. This was timed with ongoing physical attacks, including a major drone strike on Wildberries' largest warehouse in Koledino, south of Moscow, on August 15-16. Analysts estimate these combined attacks have destroyed a significant portion of the company's logistics capacity, with potential losses in the billions of dollars. Wildberries acknowledged "technical problems" following the incident.
The operation combined cyber and physical attack vectors to maximize disruption.
Cyber Attack Phase:
T1499 - Endpoint Denial of Service (by disrupting payment software) and T1498 - Network Denial of Service (by overwhelming service channels).Physical Attack Phase:
This hybrid approach creates a compounding crisis for the target: the cyberattack disrupts immediate cash flow and erodes customer trust, while the physical attacks destroy long-term capital assets and operational capability.
The impact on Wildberries is severe. The cyberattack caused immediate financial disruption and reputational damage, while the physical destruction of warehouses results in massive capital losses and long-term logistical nightmares. The combined effect is designed to cripple a major component of the Russian consumer economy, which Ukraine alleges is also part of the military supply chain. For the broader cyber landscape, this incident serves as a powerful case study in modern state-backed hybrid warfare, where the lines between digital and physical battlefields are completely blurred. It demonstrates that critical civilian infrastructure, especially in the e-commerce and logistics sectors, is considered a legitimate target in contemporary conflicts.
No specific Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were mentioned in the source articles.
Security teams at organizations in conflict zones may want to hunt for the following patterns:
network_traffic_patternAnomalous traffic to payment gateway APIslog_sourceCustomer Support Systems (e.g., Zendesk, Intercom)otherGeopolitical Threat Intelligence FeedsUtilize DDoS mitigation services to absorb and filter malicious traffic aimed at disrupting online services.
Architect systems for resilience, with redundant and geographically distributed infrastructure to prevent a single point of failure.
Mapped D3FEND Techniques:
HUR's Cyber Corps conducts a cyberattack against Wildberries' infrastructure on August 10-11.
HUR publicly claims responsibility for the cyber operation.
Reports emerge of a major drone strike on Wildberries' Koledino warehouse overnight.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.