Experts assess Russia-Ukraine information war
Atlantic Council experts discuss how cyber, influence operations, and private-sector support have shaped the information environment during the Russia-Ukraine war.
This is an expert roundtable, not an incident report, examining how the Russia-Ukraine war has played out across cyber and information domains over its first year. Contributors from the Atlantic Council's DFRLab, IST, and Carnegie Endowment discuss Russia's information influence operations (noted as unprofessional and low-engagement on Meta and Telegram), the resilience of Ukrainian communications infrastructure, and the unprecedented mobilization of private-sector technology companies (Microsoft, SentinelOne, Cloudflare, Google) in defending Ukrainian networks and countering disinformation.
Key themes include the risks private companies face when supporting a state in active conflict—becoming targets of retaliatory operations from state-aligned actors or hacktivist groups such as Killnet, and facing scrutiny for continued business ties with Russia. Panelists reference the AcidRain wiper attack on Viasat's satellite network as a notable example of cyber operations preceding kinetic action, and discuss Ukraine's volunteer IT_Army as an example of civil society mobilization in cyber operations. The piece also explores whether cyber/information operations have met pre-war expectations, generally concluding that no WannaCry/NotPetya-scale disruptive event occurred, but that combined cyber-kinetic-information operations have been a persistent feature of the conflict.
Overall, this is an analytical/policy piece reflecting on lessons learned for the US and allies regarding public-private cooperation, norms around private sector involvement in conflict, and the difficulty of generalizing this war's information dynamics to future conflicts.
Mentioned in this report
Source reporting: https://www.atlanticcouncil.org/content-series/the-5x5/the-5x5-conflict-in-ukraines-information-environment
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free