Ukraine’s military intelligence agency, HUR, said it carried out a cyberattack against Wildberries, Russia’s largest online marketplace, in coordination with the hacker group Cyber Corps. According to the claim, the operation disrupted customer service, contact centers, and payment infrastructure, with customers reportedly encountering failed payments and service outages.
Ukrainian officials said the cyber operation was timed to amplify the effects of drone strikes on Wildberries’ logistics infrastructure, portraying the company as a strategic target because of its role in Russia’s logistics network and alleged support for the war effort, including sales of military-related goods. The reported impact and extent of damage had not been independently verified, and Wildberries had not publicly commented at the time of reporting.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
In September 2025, HUR said it hacked Russian election systems and other government services in response to voting held in occupied Ukrainian territories.
In June 2025, Ukraine's military intelligence agency HUR said it breached the internal systems of Russian state-owned aircraft manufacturer Tupolev following Ukrainian drone attacks on Russian air bases.
Ukraine's Main Intelligence Directorate, working with the Cyber Corps hacker group, claimed it conducted a cyberattack against Russian e-commerce giant Wildberries. HUR said the operation disrupted customer service, contact centers, and payment infrastructure, with customers reportedly unable to complete payments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.