Новая атака на организации и гражданские институты со стороны государственных хакеров

Сеть организаций, по которой от одного узла распространяется компрометация Important

A new wave of targeted attacks against civil society organisations, independent media and civic institutions has been detected. Moldovan, Russian and international organisations working in the region are being hit. The damage is not limited to the direct targets — anyone who corresponds with them can be affected.

The attack is ongoing. Below is what is happening and what to do about it.


This has happened before

The technique is not new. In 2024–2025, Access Now and the Citizen Lab documented a campaign by COLDRIVER (also known as Star Blizzard and Callisto), a group that several governments have linked to Russia’s FSB. The targets included Russian and Belarusian organisations, independent media, international NGOs, donors, and even a former US ambassador.

It worked like a snowball. One mailbox is compromised — the attacker gets contacts, correspondence and context — writes to the next people in the chain as the person already compromised — compromises several more — and repeats. Every new mailbox opens a new circle of targets. From 2025 onwards, malware delivery was added to the credential theft.

What is happening now follows the same logic.


What the email looks like

The pretexts come straight out of your ordinary work:

  • a conference invitation or event registration;
  • a message from a donor, a query about your application, a contract, a report;
  • a request from a journalist or researcher;
  • an invitation to join a coalition or a consultation.

Much of this is assembled from public sources. If your website says your project is supported by EED (the European Endowment for Democracy), the email will arrive in EED’s name — with their logic, their terminology, and a reference to your project. The same works with any donor, partner, network or programme you list publicly. The “our partners” section of your website is a ready-made list of pretexts for an attacker.

Technically, three approaches are used, often together:

  • lookalike domains — addresses registered one letter or one top-level domain away from the real thing, visually almost indistinguishable;
  • compromising the representatives themselves — then the email arrives from a real person’s real address, and no domain check will catch it;
  • replying inside an existing thread — with the genuine message history quoted below.

How a state attack differs from ordinary fraud

An ordinary criminal wants money, moves fast and loudly, and you find out fairly soon that something happened. State-sponsored groups work differently.

1. You will never know what exactly they accessed

Unless the attackers are caught, or they choose to make themselves visible, you will not learn what they read, what they downloaded, or how long they were inside your mailbox.

There is no defaced page, no ransom demand, no missing files. The login looks like your own login. Data is not deleted, it is copied. The mailbox is not broken into — it is entered with your password.

As a result you do not know how long the access lasted, which correspondence was taken, or which of your contacts was compromised alongside you. You have to plan your response around the worst case, because you cannot verify it.

This also affects people. If your mailbox contained names, addresses, travel routes or personal circumstances of people in Belarus, Russia or Moldova, you will not be able to tell them whether they are at risk.

2. The stolen data is used for the next attacks

The mailbox is not taken for its contents. It is taken to be used further.

For the next compromises. Contacts, calendar, project names, deadlines, donor names, amounts and writing style are all extracted from your correspondence. After that the attacker knows which email your partner is expecting this week — and sends exactly that one. The sender is real, the subject is expected, the timing is right, and there is nothing to check against.

For disinformation campaigns. Genuine internal documents, stripped of context or edited, get published as a “leak”. The result is a ready-made storyline about foreign funding, instructions from abroad, hidden coordination. Rebutting this is very hard: the authentic part checks out, and the fabricated part disappears into the volume. For individuals named in the correspondence, it works as personal kompromat.

For pressure. Personal details, conflicts, drafts and informal discussions become material for blackmail, recruitment approaches and the discrediting of specific staff members.


What a single compromised mailbox can do: the Revolut case

In September 2026, Revolut handed customer personal data to fraudsters itself. The request came from an email address that genuinely belonged to a government body; the initial check confirmed the message was authentic, and the data was sent. Only afterwards did the bank contact the agency and learn that no such request had been made. The attackers obtained passports and driving licences, identity-verification selfies, names, dates of birth, home addresses, phone numbers, IBANs and account statements.

No one broke into Revolut’s systems. The weak link was the government body, not the bank: its mailbox was compromised, and from that point the request was entirely legitimate on paper, passed every technical authentication check, and was processed according to procedure.

Two lessons for us. First: one weak link in the chain surrenders everyone else’s data. Second: the sender can be one hundred per cent genuine and still not be the person writing.


Why this concerns those who were not attacked

Attackers do not break into the strong organisation. They break into whoever it trusts.

  1. They compromise the weak link: a coalition coordinator, a freelancer, a bookkeeper, a small partner organisation, sometimes a donor employee’s personal mailbox.
  2. They extract correspondence, Google Drive, contacts and calendar.
  3. They write to the next people — on topic, at the right moment, from a real person.
  4. They repeat. Every new mailbox opens a new circle of partners.

One compromised mailbox at a donor foundation enables attacks on dozens of grantees. One coalition means all of its members.

We share donors, regional programmes and partners. An email from a compromised colleague in Chișinău, from a Russian human rights organisation in exile, or from an international foundation will land in a Belarusian organisation’s inbox as an ordinary piece of work correspondence.


What to do now

1. Hardware security keys or Advanced Protection on work accounts. This is the only measure that fully closes off password theft: even if you give away your password and your code, you do not give away access. At minimum: the director, the bookkeeper, the mail administrator, and everyone who corresponds with donors. Two keys per person.

2. Never enter your password via a link in an email. If a document asks you to log in, open your mail or drive separately, by hand, and find the document there. If it is not there, it does not exist.

3. Confirm money and bank details by voice. Using a number you already had on record, not one taken from the email.

4. Check the sender’s domain character by character. Especially on messages from donors and international bodies. But remember: a matching domain guarantees nothing — the sender’s own mailbox may be compromised.

5. Clean up your cloud. Eight years of correspondence and a drive holding everything is a map of the entire sector. Archive locally, delete what you no longer need from the cloud. The less is stored there, the less is taken.

6. Agree on partner notification in advance. After a compromise, the first thing to do is warn your entire address book. Staying silent to protect your reputation is exactly what turns one breach into a chain. Write this into your organisational protocol.

7. Review active sessions. After a session is stolen, changing the password does not help — you need to terminate all sessions and review app passwords.


If you suspect a compromise

Do not write about it from the same mailbox.

Where to turn (alphabetically):

  • Access Now Digital Security Helpline — helpline@accessnow.org. 24/7, free, Russian supported, response usually within two hours. For urgent cases and confirmed compromise, this is the main address.
  • Digital Skills Coalition Belarus — info@digitalskills.lt. For Belarusian organisations: we will help work out what happened and escalate it where needed.
  • RESIDENT.ngo — help@resident.ngo. Digital security support for civil society in the region, Russian supported.

Before you write:

  • Save the suspicious email in full, with headers (in Gmail: “Show original” → save to file). Ordinary forwarding destroys the data needed for analysis.
  • Warn your partners through another channel — messenger or phone.
  • Do not delete the email or change anything in the mailbox before the state of it has been preserved.

Prepared by the Digital Skills Coalition Belarus. Free to share and republish.

Rate article
Digital Skills Coalition Belarus