Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

On May 21, 2025, the United States, United Kingdom and allied governments issued a joint cybersecurity advisory saying Russia’s military intelligence service had targeted Western logistics organizations and technology companies since at least February 2022. The agencies attributed the espionage campaign to GRU Unit 26165 and warned that similar targeting was expected to continue. Its strategic concern is what attackers can learn about assistance to Ukraine: what is moving, when, through which routes and organizations.

What governments warned

This was a technical and operational Joint Cybersecurity Advisory, accompanied by announcements from participating agencies—not a military attack warning, evacuation order or sanctions announcement. U.S. participants included the Cybersecurity and Infrastructure Security Agency, National Security Agency and FBI; the UK National Cyber Security Centre and allied agencies also participated. Czech authorities listed the United States, United Kingdom, Germany, Poland, Australia, Canada, Denmark, Estonia, France and the Netherlands among the countries joining the advisory. The agencies said the campaign had been active since at least February 2022 and expected the targeting and techniques to continue. Czech NÚKIB’s announcement also describes targeting in NATO member states, Ukraine and neighboring countries.

The advisory identifies targets and methods; it does not establish that every named organization or sector was successfully breached. It describes cyber-espionage, not a blanket claim of ransomware, sabotage or operational disruption. Attribution to the Russian military intelligence service is the issuing governments’ assessment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who the advisory identifies

The governments attributed the activity to Russia’s GRU Unit 26165, associated with the 85th Main Special Service Center. Public security reporting uses several overlapping names for activity attributed to this unit: APT28, Fancy Bear, Forest Blizzard, BlueDelta, Sofacy, Sednit and Pawn Storm. Naming conventions differ among governments and security vendors; these labels should not be read as a list of seven separate groups. The NSA announcement gives the attribution and aliases.

Why logistics and technology firms matter

Shipment information can reveal the wider operation

The advisory highlights organizations involved in coordinating, transporting and delivering foreign assistance to Ukraine. Shipping schedules, manifests, routing details and delivery changes can reveal what is moving, when it is expected, which carriers and facilities are involved, and where a supply chain may be delayed or vulnerable. That makes intelligence potentially valuable even if an organization does not transport weapons directly.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

The relevant network can include freight forwarders and brokers, warehouses, customs intermediaries, port and transport operators, and the software providers they use. A compromised mailbox, scheduling platform or camera feed can expose useful fragments of a larger movement picture. The agencies’ UK campaign summary describes the campaign’s focus on organizations supporting Ukraine.

Technology providers can be targets and pathways

IT companies may hold customer and supplier records, corporate email, cloud data or administrative access to client systems. A technology provider serving logistics, defense or government customers may therefore be valuable in its own right or as a route to connected organizations. The advisory covers technology companies alongside logistics entities, but that does not mean it found a universal software supply-chain compromise. Any particular compromise requires separate evidence. The CISA bulletin provides the U.S. agency summary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which organizations should assess their exposure

Risk depends more on access to relevant information or infrastructure than on company size. A small broker with access to sensitive schedules can be of interest; a company may also be exposed because it serves another targeted organization. Sectors identified or implicated in public government descriptions include:

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
  • Freight, logistics and transportation, including maritime, rail, airports and ports.
  • Defense, government and organizations supporting assistance to Ukraine.
  • IT services and technology providers connected to transport, defense or government customers.
  • Air-traffic-management systems and operators of internet-connected cameras near strategically important sites.

The advisory’s sector list is not a claim that every organization in those sectors was compromised. Companies should consider what data, systems and customer access they hold, including through vendors and contractors.

How the campaign’s techniques work

The advisory and government summaries identify several methods. The same activity can be quiet: monitoring communications or physical movements may produce intelligence without disrupting operations.

Password spraying and targeted phishing

Password spraying tests a small number of commonly used passwords against many accounts, rather than repeatedly trying passwords against one account. It can exploit reused or weak passwords, especially where authentication monitoring and lockout protections are inadequate. Spear-phishing uses messages tailored to a person’s role or current work. In logistics, a plausible lure might concern a delivery schedule, customs document, invoice or carrier coordination.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Email and identity access

The advisory describes credential theft and abuse or manipulation of Microsoft Exchange mailbox permissions. An attacker who adds forwarding, delegated access or other mailbox permissions may monitor business communications without taking over an entire organization. Freight, customs, procurement and scheduling mailboxes can disclose routes, relationships and timing.

Routers, other small-office devices and cameras

Compromised small-office/home-office (SOHO) networking devices can provide a way to route or conceal malicious traffic. Internet-connected cameras may reveal activity near border crossings, transport facilities or military installations; their value can be intelligence collection rather than access to corporate data. Routers, cameras and digital video recorders are easy to overlook when security teams focus on servers and employee devices.

Related but separate later activity: On April 7, 2026, the U.S. Department of Justice announced a court-authorized disruption of a DNS-hijacking network controlled by GRU Unit 26165 that had used compromised routers. That later operation is relevant context for the unit’s router activity, but it is not evidence that the router operation was part of the May 2025 logistics advisory. See the Justice Department announcement.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What organizations should do

Use the advisory’s technical indicators and mitigations alongside controls matched to your systems. The measures below address the identified attack paths and the operational information at risk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Strengthen identity and email defenses

  • Require phishing-resistant multifactor authentication where available, especially for administrators and remote access. MFA reduces password-based risk but does not stop session-token theft, weak account recovery, compromised administrators or vulnerable devices.
  • Review alerts for repeated failed logins across many accounts, unusual locations, impossible travel and password spraying. Disable legacy authentication where it remains enabled.
  • Audit Exchange mailbox permissions, delegated access, inbox and forwarding rules, application credentials and newly created OAuth applications or service principals.
  • Remove stale or excessive privileges, and alert on unusual access to shared mailboxes handling freight, customs, procurement and scheduling.

Harden internet-facing devices and networks

  • Inventory routers, firewalls, VPN appliances, cameras and remote-management interfaces exposed to the internet; patch them or replace end-of-life equipment.
  • Disable public administration unless operationally essential. Restrict management interfaces to approved networks or secure access paths, and replace default or reused credentials.
  • Monitor DNS settings and unexpected resolver changes. Segment cameras, warehouse systems, operational technology and corporate IT so access to one does not automatically expose the others.
  • Retain logs long enough to investigate activity that may be discovered well after initial access.

Reduce exposure in logistics and vendor relationships

  • Limit which users and vendors can see shipment details, export manifests or change delivery destinations. Use out-of-band verification for urgent routing, payment, customs or delivery changes.
  • Protect cameras and telematics systems as sensitive operational assets, and check that carriers and software providers apply appropriate security controls.
  • Technology vendors should map privileged access to customer environments, secure remote support and software-update channels, and monitor for anomalous customer-data access or bulk exports.
  • Give security teams the authority to investigate suspicious mailbox rules, authentication events and administrative changes. Prepare an incident plan that includes customers, suppliers, relevant technology providers and appropriate authorities.

Warning signs and response to suspected access

Investigate unexpected mailbox forwarding or delegated access, login attempts spread across many accounts, unrequested password resets, unfamiliar OAuth applications, router DNS changes, camera logins from unknown addresses, and unexplained access to shipment or manifest data. Messages unexpectedly referencing current shipments or aid deliveries also merit scrutiny.

If compromise is suspected, preserve evidence before destructive changes. Then contain affected systems, remove unauthorized access, investigate connected accounts and suppliers, and assess what information may have been exposed:

  1. Preserve logs, mailbox data, firewall records and device images.
  2. Isolate affected endpoints or network appliances, then disable or reset compromised accounts and revoke active sessions.
  3. Remove malicious mailbox rules, forwarding settings and unauthorized delegated permissions.
  4. Rotate credentials for administrators, service accounts, VPNs, routers and cloud applications.
  5. Patch or replace vulnerable internet-facing devices; check for persistence, new accounts, scheduled tasks and unauthorized applications.
  6. Determine whether shipment, customer, employee or government information was accessed.
  7. Notify affected customers, regulators, insurers, law enforcement and national cyber authorities as required.
  8. Hunt across connected suppliers and service providers, not only the system where suspicious activity was first found.

How to interpret the warning

The warning is dated May 21, 2025, and concerns a campaign reported active since at least February 2022. It is not a new 2026 advisory, and it should not be conflated with warnings about other Russian intelligence services, different GRU activity or pro-Russia hacktivists. The governments’ central operational concern is that access to communications, shipment data and connected devices can help an adversary understand and monitor a supply chain, even when no visible outage occurs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.