TheCyberExpress

ARMA Cyberattack Hits Ukraine Asset Recovery Agency


A suspected ARMA cyberattack has targeted Ukraine’s Asset Recovery and Management Agency as it prepares to select a manager for assets linked to IDS Ukraine. ARMA said its servers experienced unauthorized interference ahead of the August 22 deadline for applications, prompting an investigation into whether the incident was part of a broader effort to disrupt its operations.

The Asset Recovery and Management Agency, known as ARMA, manages assets seized by Ukrainian authorities, including assets linked to sanctioned Russian individuals and alleged collaborators with Moscow.

ARMA Cyberattack Raises Questions Over IDS Ukraine Competition

ARMA said the attack occurred shortly before the August 22 deadline for applications to participate in the competition to select a manager for assets controlled by sanctioned Russian oligarch Mikhail Fridman.

The agency said its experts and law enforcement authorities are examining the cyberattack and the events surrounding the IDS Ukraine competition. The Security Service of Ukraine, or SBU, is investigating the recent attack, while a broader National Anti-Corruption Bureau of Ukraine, or NABU, investigation is examining earlier alleged interference.

According to ARMA, signs of illegal interference in processes connected to its work have been recorded since spring. These included unauthorized access to the agency’s officials’ register.

ARMA said the combination of cyber incidents, information activity and increased inquiries from some media outlets and members of parliament had raised concerns about a possible coordinated campaign. The agency said investigators must determine whether these events were intended to disrupt its work, create pressure or affect the competition.

ARMA has not identified those it believes may have organized or carried out the alleged campaign.

IDS Ukraine Selection Continues Despite Cyberattack

Despite the incident, ARMA said the competition to select the IDS Ukraine asset manager will proceed according to the procedures and timeframe established by law.

The deadline for applications is August 22, 2026, with the competition announcement published through Ukraine’s Prozorro public procurement system.

The agency said it has also started an audit of the financial indicators of seized IDS group assets to support the legality, objectivity and transparency of the transfer process.

ARMA said additional information concerning possible unauthorized access to officials’ email accounts and official information will be provided to law enforcement authorities for investigation and legal assessment.

Acting ARMA Head Yaroslava Maksymenko said the agency would continue the competition despite what it described as information pressure, political interference and attempts to gain unauthorized access to its resources.

Ukraine Investigates Possible Coordinated Interference

ARMA said the latest incident is not being viewed in isolation. The agency pointed to a similar episode earlier this year, when Reuters reported on a cyberattack involving attempts at interference and hacking alongside increased information activity and inquiries.

The agency said each event could have an individual explanation, but their timing and combination warranted further investigation.

The cyberattack comes as Ukraine continues efforts to prevent sanctioned Russian capital from retaining control over assets seized in the country. ARMA said this includes preventing control through management arrangements, intermediaries or influence groups.

Fridman has been sanctioned by Ukraine and several Western governments since Russia’s invasion.

ARMA said the final responsibility for determining the organizers, customers and perpetrators of the attack rests with the ongoing investigations. The agency said it will continue the IDS Ukraine competition and act within the law while law enforcement agencies examine the reported cyber incidents and possible attempts to interfere with its activities.



Source link