Donbas Post, the Russian state-owned postal operator serving the occupied territories of Donetsk and Luhansk, suffered a major cyberattack attributed to the Ukrainian Cyber Alliance (UCA). The attack resulted in the disruption of the operator's corporate network, email systems, and web platform, with UCA claiming to have wiped over 1,000 workstations, nearly 100 virtual machines, and several dozen terabytes of data. The incident forced Donbas Post to restrict access to several services and suspend operations at postal branches and its call center. The disruption coincided with a Ukrainian drone strike on the region's energy infrastructure, though it remains unclear if the two events were coordinated.
This attack is part of a broader pattern of persistent hacktivist and state-sponsored cyber operations targeting Russian-controlled Ukrainian territories. Previous campaigns have included the deployment of novel surveillance malware and cyberespionage attacks against high-profile organizations in Donetsk, Luhansk, and Crimea. The UCA, active since 2016, has intensified its operations since Russia's 2022 invasion, previously targeting Russian financial, telecom, and municipal entities. The Donbas Post incident underscores the ongoing cyber conflict in the region and the vulnerability of critical infrastructure to hacktivist campaigns.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Around the same time as the cyber incident, regional power outages attributed to a reported Ukrainian drone strike on energy infrastructure led Donbas Post to suspend work at postal branches and its call center. Reporting said it was unclear whether the physical and cyber disruptions were coordinated.
The pro-Ukraine hacktivist group Ukrainian Cyber Alliance claimed responsibility for the incident, alleging it wiped more than 1,000 workstations, about 100 virtual machines, and several dozen terabytes of data. The group also published screenshots it said were taken from Donbas Post internal systems.
Donbas Post, a Russian state-owned postal operator in Russian-controlled parts of Donetsk and Luhansk, said external interference disrupted its corporate network, web platform, and email systems. The operator restricted access to some services and began restoration efforts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.