The Ukrainian hacktivist community Ukrainian Militant has declared the completion of "Operation Poseidon," a claimed large-scale intrusion into Russian enterprises that design submarines, naval navigation systems, hydroacoustics and shipboard control systems. According to reporting by Ukrainian outlet UNN, the named victims include the Rubin and Malakhit Central Design Bureaus for Marine Engineering, the Elektropribor Central Research Institute, Okeanpribor, GNINGI and other organisations tied to Russia's defence-industrial complex and the Russian Ministry of Defence. The open-source intelligence community InformNapalm reviewed part of the released material but has explicitly declined to confirm the operation's full scale: investigators received only individual documents bearing the markings of a single Russian military entity, with the remainder withheld on operational security grounds. No record count, archive size or victim-confirmed breach statement exists at this time, and none of the named organisations has publicly responded.
What Happened
Ukrainian Militant announced Poseidon as a completed operation rather than an ongoing intrusion, publishing screenshots as proof of access. The material shown relates to Project 636.3 diesel-electric submarines, Project 955M ballistic missile submarines, Project 22350 frigates, and the Andoga-M2, Chardash, KAMA-NS-VK and Simfoniya-PM navigation systems. Some documents carry dates in the 2024 to 2026 range, which would indicate access to live engineering and programme documentation rather than a historical archive dump.
The corroboration picture is deliberately narrow. InformNapalm's volunteers state they did not receive the complete Poseidon data set and therefore cannot independently establish the volume of stolen information, the structure of the archives, or the actual depth of penetration into Russian systems. That is a meaningful limit: the claim covers a half-dozen named institutions, but the verified portion is document-level evidence tied to one of them. Accounts of the operation's true scope genuinely differ between the claimant and the analysts reviewing it, and readers should treat the wider target list as asserted rather than established.
Poseidon does not stand alone. UNN notes in the same reporting cycle that Ukrainian actors also claimed a breach of Russia's Central Election Commission systems ahead of the 17 September 2026 State Duma elections, another claim that remains unverified. Ten days before the Poseidon announcement, Ukraine's Main Directorate of Intelligence (HUR) publicly claimed a separate operation against the Moscow Institute of Thermal Technology (MIT), the design house behind the Yars (RS-24) and Topol-M intercontinental ballistic missiles, the Bulava (R-30) submarine-launched missile, the Iskander-M, and the Oreshnik/Kedr system. That operation is described across Militarnyi, UNITED24 Media and Censor.NET, all citing HUR's own 9 September statement, and all three report the same figure: personal data on 2,648 MIT employees, whom Kyiv says it will pursue for sanctions and prosecution. Censor.NET adds that MIT's structure includes the Prozhektor Design Bureau, the Vympel Machine-Building Plant, the Votkinsk Plant and Iskra.
What Was Taken
For Poseidon itself, the honest answer is that the volume is unknown. What is visible is documentation touching submarine and surface combatant programmes, hydroacoustic and navigation subsystems, and associated design bureau paperwork dated as recently as 2026. No claimed terabyte figure, file count or personnel total has been published for this operation, and InformNapalm's partial view makes independent quantification impossible.
The adjacent Ukrainian operations give a sense of the category of data now routinely moving out of the Russian defence sector:
- MIT (HUR, 9 September 2026): organisational structure, leadership and staff lists, current and prospective developments, plus personal details on 2,648 employees. HUR also describes documentation on rapid-deployment military satellite systems, the Start-1M conversion launch vehicle and the Tiporyad unified space platform.
- LLC NIK (Black Spark, 27 August 2026): The Defense News reports the Russian underground group Black Spark claimed hundreds of terabytes from NIK's internal database, including interceptor UAV designs. Black Spark says an insider supplied the access rather than a cyberattack, and that it subsequently erased the data from NIK's servers. The published specifications cover a swept-wing interceptor variant of the UBB-M loitering munition launched from a 160 mm canister, with a 15 to 16 kg launch mass, roughly 3 kg payload, 250 to 300 km/h speed, 20 km range and up to 10 minutes endurance. NIK has not responded publicly. These figures rest on a single lower-tier source and the group's own claims.
- Khrunichev Centre (August 2026): UNITED24 Media, citing an investigation by private firm Dallas Analytics, reports leaked internal procurement documents showing the Angara launch vehicle manufacturer sourcing restricted Taiwanese, Chinese and Japanese machine tools through rebranded "domestic" umbrella labels such as ProTech.
Taken together, the sensitivity profile is design documentation, subsystem specifications, procurement chains and named-individual personnel records. The last category is the most consequential for the people involved: these leaks are being used to build sanctions and prosecution target lists, not just to embarrass.
Why It Matters
Three patterns should concern defenders on any side of this conflict.
First, design bureaus and research institutes are now first-class targets, not peripheral ones. Rubin, Malakhit, Elektropribor and MIT are not operational military units; they are engineering organisations with commercial-grade IT estates, long supplier tails and document-heavy workflows. That combination produces enormous intelligence value at a fraction of the difficulty of attacking a hardened military network.
Second, the insider channel is live and being advertised. Black Spark's explicit statement that it "didn't even have to break anything" because someone inside NIK chose to help is a recruitment message as much as a claim. Wartime and politically polarised environments turn cleared staff into a recruitment pool, and no perimeter control addresses that.
Third, disclosure has become the weapon. Poseidon's operators withheld the bulk of the data even from friendly analysts, releasing curated screenshots instead. The effect is to maximise psychological and signalling value while preserving the access, the sourcing, or both. Defenders should assume that a public leak represents a fraction of what was taken, and that silence about scope is a choice rather than an absence of material.
There is also a verification lesson. Hacktivist claims in this theatre consistently outrun what independent analysts can confirm, and InformNapalm's willingness to say plainly that it cannot corroborate the full scale is the exception that proves the rule. Intelligence consumers should log Poseidon as a credible but unquantified claim.
The Attack Technique
Ukrainian Militant has not disclosed initial access, persistence or exfiltration methods for Poseidon, and InformNapalm's limited view does not permit reconstruction. Any technical account of this specific operation would be speculation.
What is documented is the broader tradecraft currently succeeding against Russian enterprise networks. Kaspersky's Global Emergency Response Team published findings on 16 September 2026 covering the NightEagle group (also tracked as APT-Q-95), active since at least 2023 and newly focused on Russian businesses. This is a separate actor with no reported connection to Ukrainian Militant, but the intrusion chain is representative of what works against exactly this class of victim:
- Initial access via valid credentials on corporate VPNs. Kaspersky observed connections originating from Russian-segment IP addresses linked to Cloudflare WARP tunnels and from European virtual infrastructure providers, blending inbound access with plausible-looking traffic.
- GhostContainer backdoor on Microsoft Exchange, assembled from publicly available components: the Neo-reGeorg tunnel, an exploit for CVE-2020-0688, and the
GhostWebShellclass from ysoserial. - Suspected in-memory deployment by extracting Exchange cryptographic keys from the ASP.NET configuration, overwriting the
VIEWSTATEparameter and injecting a payload that launches the .NET backdoor in memory. Kaspersky assesses this with high confidence but could not confirm the exact delivery method. - Traffic redirection and lateral movement following the Exchange foothold.
Separately, The Defense News reports insider-supplied access at NIK, and informedclearly.com reports that Ukrainian prankster Yevhen Volnov, using the alias "Major Chernobaev," joined a closed Russian Defence Ministry video conference in August 2026 attended by 24 officials and industry representatives, accessing discussion of military production finances before revealing himself. The method of entry to that call was never established. Stolen credentials, an unpatched Exchange server, a disaffected employee and an unauthenticated conference link are all the same failure in different clothing.
What Organizations Should Do
- Treat design and engineering documentation as crown jewels with matching controls. Apply rights management, watermarking and per-document access logging to CAD files, specifications and programme paperwork. If a leak occurs, embedded markings are what let you scope it, as InformNapalm's document-level analysis demonstrates.
- Eliminate password-only VPN access. NightEagle's entry point was valid credentials. Enforce phishing-resistant MFA on every remote access path, and alert on authentications arriving from consumer VPN and WARP-style tunnel egress ranges or unexpected hosting providers.
- Audit internet-facing Exchange immediately. Confirm CVE-2020-0688 is patched, rotate ASP.NET machine keys if there is any suspicion of exposure, and hunt for anomalous
VIEWSTATEpayloads, unexpected .NET assemblies loaded in the Exchange worker process and Neo-reGeorg tunnel signatures. Kaspersky has published indicators of compromise for this campaign. - Build an insider risk programme that assumes motivated volunteers. Combine data loss monitoring on bulk database and file share access with a realistic escalation path. The NIK case, as reported, involved no exploitation at all.
- Lock down collaboration platforms. Require authenticated, individually issued invitations with waiting rooms and host admission for any meeting touching production, budget or programme content. Unlisted links are not access control.
- Map and monitor your supplier and procurement records. The Khrunichev material was procurement paperwork, not weapons designs, and it still exposed a sanctions evasion chain. Vendor lists, purchase orders and shipping documents deserve the same classification review as technical files.
- Plan for personnel exposure. Where staff rosters are compromised, assume named individuals face doxxing, targeted phishing and legal or sanctions consequences. Have a notification, monitoring and support process ready before it is needed.
Sources: Ukrainian hackers claimed a large-scale hack of Russian submarine a... | NightEagle APT targets Russian organizations Securelist | Ukrainian Intelligence Hacks Corporation Linked to Oreshnik System... | Why Ukraine's Hur Targeted Russia's Top Intercontinental Ballistic... | Secrets of Russia’s ballistic missiles and 2,600 suspects: Defence... | Russian Rebel Group "Black Spark" Leaks Classified Interceptor Dron... | The “Import Substitution” Myth: How Russia’s Khrunichev Centre Obta... | Ukrainian Prankster Infiltrates Russian Defense Ministry Video Meet...