Cyber review · Q2 2026

Cyber threats to Ukraine: quarterly review

Key events, trends and recommendations of Q2 2026 — based on the Software Ukraine newsroom and open CERT-UA data.

// quarter in numbers

Context: the pressure is not easing

According to open data from the governmental CERT-UA team, almost 6,000 cyber incidents were processed in 2025 — 37.4% more than a year earlier. Q2 2026 confirmed the trend: attacks increasingly target state institutions, critical infrastructure and software supply chains, while phishing toolkits are constantly updated.

// key events

What happened this quarter

  • CERT-UA warned about the updated toolkit of the UAC-0057 group — new malware in phishing campaigns against state institutions.
  • New attack tactics against critical infrastructure — and why passive defence no longer works.
  • Microsoft 365 token theft on Android — mobile devices as the weak link of the corporate perimeter.
  • The Oracle PeopleSoft vulnerability in universities — a lesson for owners of legacy systems.
  • Protecting your own AI services from prompt injection — a new attack surface businesses are only learning to close.
  • Offboarding as the weakest link — insider risks when staff leave.
// trends

Three trends of the quarter

  • AI security became a discipline of its own. Prompt injection, data leakage through LLMs and semantic DLP filters are now part of corporate defence.
  • Zero Trust moves beyond IT companies. Zero-trust architecture is increasingly required for ERP systems, hybrid infrastructure and the public sector.
  • Compliance is being automated. ISO/IEC 27001 and SOC 2 audits and NIS2 requirements are increasingly handled with AI tools.
// recommendations

What organisations should do

  • Check your infrastructure for Russian software — start with our Replacement Navigator.
  • Make multi-factor authentication and network segmentation the minimum standard.
  • Run a phishing simulation for staff — phishing remains attack vector No. 1.
  • Formalise offboarding and access-revocation procedures.

Prepared by the Software Ukraine editorial team based on its newsroom and open CERT-UA data. The next issue will cover Q3 2026.