A Ukrainian hacker group identified as CyberJunta/CyberHunta published more than 2,300 emails and documents it said were taken from the mailbox of Vladislav Surkov, a senior aide to Russian President Vladimir Putin. The leaked cache reportedly included email exchanges, passport scans of Surkov and his family, and documents describing efforts to influence Ukrainian politics, support nationalist and separatist figures, and push for early parliamentary elections. A later tranche of material also allegedly outlined a 2015 plan to destabilize Kharkiv and showed attempts to use influence over Ukrainian politicians to introduce legislation in Kyiv.
The disclosures were treated as at least partly credible by several reviewers, with Ukraine’s SBU saying the files appeared authentic and Digital Forensic Research Lab analyst Aric Toler reportedly finding the Outlook data likely genuine after checking headers and matching contents to real events, though both cautioned some released documents may have been altered after exfiltration. The Kremlin rejected the allegations and denied the authenticity of the material, with spokesman Dmitry Peskov saying Surkov did not use email and dismissing claims that he was involved in any destabilization campaign in Ukraine.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
By early November 2016, reporting described a newly disclosed cache of hacked emails allegedly from Surkov's office that pointed to a 2015 plan to destabilize Kharkiv in eastern Ukraine. The material also allegedly showed Russian influence being used to get legislation introduced in Ukraine's parliament.
After the leak became public, Kremlin spokesman Dmitry Peskov rejected the authenticity of the documents and denied Surkov's involvement in any destabilization plot described in them. Russian officials also argued that Surkov did not use email, disputing the premise of the hack.
Following the publication of the leak, Ukraine's SBU said experts believed the released documents appeared authentic, while cautioning that some files could have been altered after exfiltration. Independent analysis cited by media, including DFRLab review of headers and corroboration with real-world events, also judged at least part of the cache likely genuine.
On 2016-10-25, a Ukrainian hacker group variously identified as CyberJunta/CyberHunta claimed it had hacked Kremlin aide Vladislav Surkov and released more than 2,330 emails and related documents. The leaked material reportedly included correspondence, planning documents, and passport scans tied to Surkov and his family.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
11 references tracked. Mallory keeps watching after this page renders.
web.archive.org
Open sourcetheguardian.com
Open sourcesmh.com.au
Open sourcerferl.org
Open sourceweb.archive.org
Open sourceru.bellingcat.com
Open sourceforeignpolicy.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.