Cyber · Wed, 05 Aug 2026 05:17:00 GMT

Hackers Pose as Russian Federal Officials to Steal Drone-Defence Plans From Factories: Espionage Disguised as Workplace Safety

Russian cybersecurity firm F6 says attackers are sending industrial companies fake government emails about employee safety during air-raid alerts, attempting to obtain sensitive information on how facilities protect themselves from drones and missile attacks.

Hackers Pose as Russian Federal Officials to Steal Drone-Defence Plans From Factories: Espionage Disguised as Workplace Safety

Cybercriminals are exploiting Russia’s growing fear of Ukrainian drone attacks by posing as federal officials and sending industrial companies messages about workplace safety and air-raid procedures.

Russian cybersecurity firm F6 has reported a broader pattern of attackers impersonating government departments and targeting companies through carefully written phishing emails.

The latest reported scenario is particularly sensitive because the attackers allegedly seek information about how factories and industrial sites defend themselves against drones and missile threats.

The emails are said to arrive from public or spoofed addresses while using reply addresses designed to resemble official government domains.

Messages may carry bureaucratic subject lines about measures to ensure safe working conditions for employees.

Some reportedly tell workers they may refuse shifts or leave during air-raid alerts without fear of dismissal.

The administrative language creates credibility.

A recipient may believe the message concerns emergency regulation and forward internal documents, defence diagrams or contact information to the supposed agency.

That can expose much more than normal corporate data.

Russian industrial facilities increasingly use radar detectors, electronic warfare systems, physical barriers, mobile gun teams and emergency procedures to survive Ukrainian long-range drone attacks.

The government has expanded legal authority for certain civilian institutions and companies to defend their own facilities.

Businesses have also been allowed or encouraged to finance anti-drone equipment.

This creates a large new category of sensitive information outside traditional military networks.

A refinery security manager may possess maps showing radar positions, blind zones, electronic-warfare equipment and evacuation shelters.

A logistics company may know which routes remain operational during air alerts.

An attacker who acquires those details could theoretically help plan a physical strike.

The cyber campaign therefore sits between financial crime and military intelligence.

F6 has documented several active criminal and espionage groups targeting Russian organisations through email.

Some campaigns steal money from accounting departments.

Others deploy malware to gather documents and credentials.

Attribution is difficult.

A phishing email asking for drone-defence information may be sent by Ukrainian intelligence, pro-Ukrainian hackers, ordinary criminals hoping to sell data or another state service.

The fact that the material could help Ukraine does not prove Kyiv ordered the campaign.

Russian authorities have a strong incentive to describe cyberattacks as foreign intelligence operations.

Security companies also have incentives to emphasise the seriousness of threats they are paid to defend against.

The technical indicators matter more than political assumptions.

Investigators should examine malware families, command-and-control servers, language patterns, infrastructure reuse and stolen-data destinations.

The social-engineering method is effective because Russian wartime regulation changes rapidly.

Managers receive genuine government instructions about air alerts, mobilisation, civil defence and drone protection.

A fake message can look plausible simply because unusual official requests have become normal.

The best defence is procedural.

Companies should verify sensitive requests through a known government contact rather than replying to an email.

Defence diagrams should not be transmitted through ordinary mail.

Government agencies should use digitally signed correspondence and predictable official portals.

Employees should be trained to recognise domain impersonation and homograph attacks using characters that visually resemble legitimate addresses.

The campaign also shows how distributed air defence creates distributed intelligence risk.

Russia is asking private companies to protect themselves because the state cannot place military units at every refinery, warehouse and factory.

That expands resilience.

It also spreads information about defensive systems across thousands of civilian computers and employees.

The open question is whether these emails are mainly another profitable phishing scheme—or whether someone is systematically mapping the gaps in Russia’s industrial drone defences before choosing where the next wave of physical attacks should strike.

The stolen information could be valuable even if the attackers never penetrate an industrial control system. Maps of shelters, interceptor positions, drone-detection equipment, evacuation procedures and hardened production areas can reveal which facilities Russia considers vulnerable and how they intend to survive Ukrainian strikes. That makes the phishing campaign relevant to both ordinary cybercrime and military intelligence. Companies should verify unusual federal requests through independent official contacts before sending any security plans or opening attachments.