Ukraine's Asset Management Agency Hit by Cyberattack Amidst High-Stakes Seizure Dispute
Ukraine's **Asset Recovery and Management Agency** (**ARMA**) has reported a cyberattack, coinciding with its efforts to appoint a manager for the seized assets of **IDS Ukraine**, a major bottled water producer. The incident is under investigation by the **SBU**, Ukraineβs security service, as **ARMA** suspects a coordinated effort to disrupt its operations and influence the high-profile asset management process.
# Ukraine's Asset Management Agency Hit by Cyberattack Amidst High-Stakes Seizure Dispute
**Kyiv, Ukraine** β The **Asset Recovery and Management Agency** (**ARMA**), Ukraineβs key body for managing seized criminal and sanctioned assets, announced a cyberattack on its systems this Tuesday. The incident comes as **ARMA** investigates a potential coordinated campaign to undermine its operations, particularly concerning the management of **IDS Ukraine**.
## Targeting Critical Infrastructure
**ARMA** is responsible for overseeing assets confiscated by Ukrainian authorities, including those linked to sanctioned Russian individuals and alleged collaborators. The agency stated that this latest attack occurred during preparations to select a manager for the corporate rights of **IDS Ukraine**, one of the nation's largest producers of bottled mineral water and beverages.
**Yaroslava Maksymenko**, **ARMA**'s acting head, commented on the broader context: βOver the years that the Russian oligarchic capital has operated in Ukraine, it has built up a network of people willing to serve its interests from within our country.β
## Unspecified Attack Details and Ongoing Investigation
While **ARMA** has not disclosed the perpetrators or provided technical specifics of the cyberattack, the **SBU** is actively investigating. The agency has also reported other suspicious activities since spring, including unauthorized access to an internal database containing information on **ARMA** officials.
**ARMA** is examining whether these incidents are part of a concerted effort to compromise the competitive process for the **IDS Ukraine** assets. However, no public evidence has yet linked the cyberattack to specific groups or individuals. Despite the disruption, **ARMA** confirmed that the selection process for an **IDS Ukraine** manager will proceed as planned.
## The IDS Ukraine Controversy
Ukraine seized the corporate rights of Russian shareholders in **IDS Ukraine** in late 2022, following Russiaβs full-scale invasion. Among the company's shareholders is **Mikhail Fridman**, a Russian billionaire and co-founder of **Alfa-Bank**, who has been sanctioned by Ukraine and several Western governments.
**ARMA** has firmly stated: βSanctioned Russian capital must not be allowed to retain control over assets seized in Ukraine.β The agency claims to have faced resistance in transferring **IDS Ukraine** to independent management but has not identified those allegedly attempting to influence the process.
## A History of Cyber Threats
This is not the first time **ARMA** has faced suspected Russia-linked cyber threats. In April, Ukrainian officials reported that **ARMA** employees were targeted in a cyberespionage campaign attributed to **APT28**, also known as **Fancy Bear**, **BlueDelta**, or **Forest Blizzard**. This Russian state-linked hacking group is notorious for its sophisticated operations. While **Maksymenko** confirmed that **APT28** failed to breach **ARMA**'s internal systems at that time, the recurring nature of these incidents underscores the persistent threat landscape faced by Ukrainian agencies managing sensitive assets.