
On September 26, 2026, Ukraine’s Defense Forces carried out a large-scale strike on the Azov Optical and Mechanical Plant (AOMZ) in Russia’s Rostov region. The enterprise, part of Russia’s missile-industrial complex, has been under sanctions since 2022, while its military specialization has been known for years. Why, then, was significant damage to its production capacity inflicted only in the fifth year of the full-scale war?
According to the General Staff of the Armed Forces of Ukraine, the strike caused a fire in AOMZ’s foundry and damaged equipment in five production buildings.
Analysis of satellite imagery also indicates damage to several production buildings at once.
This differs significantly from the attack on the plant on July 4, 2025, the first that InformNapalm was able to identify in open sources. At the time, reports said unmanned aerial vehicles had struck two buildings, but the scale of the damage was considerably smaller.
After July 2025, AOMZ did not appear in open-source reporting on further large-scale damage to its production facilities for more than a year.
AOMZ’s military importance had long been known
AOMZ is part of Russia’s Tactical Missiles Corporation, KTRV [Rus.: Корпорация «Тактическое ракетное вооружение»]. According to the company profile on War&Sanctions, the Ukrainian Defense Intelligence portal, the plant produces electronic systems for precision-guided artillery, missile and anti-tank weapons, radar seekers for tactical guided missiles, thermal-imaging equipment, and electro-optical systems.
The company has been under US sanctions since March 2022 and was subsequently subjected to restrictions by a number of other countries.
AOMZ’s military significance was therefore no revelation in September 2026. Its specialization, location, and affiliation with KTRV had been known for years.
At the same time, distance from Ukraine does not mean that the plant was an equally accessible target throughout the war. Ukraine’s long-range strike capabilities, their availability, and the list of priority targets have changed significantly since 2022.
Against that background, another aspect of the AOMZ case becomes particularly important: the body of internal documentation linked to the plant.
71 line items and 44 suppliers
On the day of the strike, September 26, Dallas Analytics published an investigation based on internal correspondence, government contracts, and production-cooperation documents involving AOMZ and related enterprises.
The material covers the period from April 2023 to March 2025 and includes documents from AOMZ itself, KTRV, the Michurinsk Progress Plant [Rus.: Мичуринский завод «Прогресс»], and SKTB Kurganpribor [Rus.: СКТБ «Курганприбор»].
One of the key documents is dated September 9, 2024. It concerns provisioning for the 2025 production program under seven government contracts.
Its appendix contains 71 line items linking AOMZ products to specific suppliers of electronic components, the quantities required, installation rates, and financing.
We took a closer look at the #documents published by @dallas_analytic and spotted another interesting lead.
The leaked AOMZ supply-chain table contains a large 65-SNL component cluster, followed by BA-65 and 65ML assemblies.
Open sources link 65-SNL / 65ML to the Kh-38ML… https://t.co/oSXylZtuns pic.twitter.com/DMG6jCSRVb
— InformNapalm (@InformNapalm) September 26, 2026
Dallas Analytics identified 44 supplier companies. The total value of the component base for the 2025 program was RUB 583.6 million, of which RUB 497.6 million had already been paid in advances.
According to Dallas Analytics, the documents make it possible to trace AOMZ’s involvement in at least seven Russian missile programs, including the Kh-101, R-37M, and systems associated with the Oreshnik program.
A separate KTRV letter dated March 4, 2025, also indicates the planned scale of production. Beginning in 2026, AOMZ was asked whether it could supply annually 500 switching units, power-supply units, battery activation units, several types of cable harnesses and assembled circuit boards, as well as 1,000 housings for products from the 610M line.
In open sources, the designation “Product 610M” is associated with the K-37M/R-37M missile. The document itself does not name the missile.
The value of this dataset is not limited to identifying individual missile programs. The documents offer a partial view of the internal architecture of Russia’s defense industry: manufacturer — product — component — supplier — quantity — financing.
AOMZ, the Su-57 and a trail familiar to InformNapalm
AOMZ’s connection to the Su-57 program also deserves attention.
Dallas Analytics cites correspondence indicating that AOMZ acts as an assembler and supplier of components for Product 760K(L). The researchers associate it with a modification of the R-74 family of air-to-air missiles and the Su-57 weapons suite.
For InformNapalm, this is not the first case in which internal documentation from a Russian defense enterprise reveals far more than the company’s official presentations.
In 2025, as part of the OKBMLeaks investigation, InformNapalm published internal documents from Russia’s OKBM — an enterprise involved in producing components for the Su-57 fighter and the prospective PAK DA Poslannik strategic bomber.
In the OKBMLeaks case, the origin of the information was known. Access to the company’s internal documentation was obtained through a CYBINT operation, and the acquired material was used for several months in the interests of Ukraine’s Defense Forces and partners before being made public.
That precedent matters in the AOMZ context for one reason: the moment a dataset is published is not necessarily the moment it was obtained, and the public effect is not necessarily the first result produced by the data.
It would be incorrect to project the OKBMLeaks scenario onto AOMZ. We know neither the source of the AOMZ documents, nor when they were obtained, nor whether any access was sustained over time. But InformNapalm’s own experience illustrates how long internal information from Russia’s defense industry may be exploited before it is made public.
Where did the AOMZ documents come from?
The source may have been a compromised IT system or corporate email, HUMINT, or another channel of information acquisition. It is also unknown whether the material represents a one-time archive or prolonged access to the company’s internal data.
The fact that the dataset contains documents from 2023 to 2025 does not prove continuous access throughout that period. Nor is there open-source evidence that these documents were used in preparing strikes against AOMZ.
But the case raises a broader question: what should happen after a dataset of this kind is obtained?
From access to operational effect
A hypothetical exploitation cycle for intelligence of this kind could look as follows: gain access — accumulate information — analyze production cooperation — identify critical dependencies — apply non-kinetic effects — conduct physical strikes.
Internal documentation reveals what cannot be seen from a satellite: who supplies a specific component, how many units are required, what production volumes are planned, who receives funding, and which enterprises are critical to fulfilling state defense orders.
This transforms a list of companies into a map of production dependencies.
In some cases, information on dozens of suppliers to a single plant may have greater intelligence value than the coordinates of the plant itself. It can support sanctions and export-control work, the identification of intermediaries and import channels, financial intelligence, OSINT, and CYBINT.
A physical strike is only one possible outcome of such work.
This also helps explain why a significant period of time may pass between acquiring information and seeing a visible effect. Maintaining covert access may be more valuable than exposing it immediately. In other cases, delays may result from limited strike capabilities, competing operational priorities, the need for additional verification, or problems with information-sharing between institutions.
Open sources do not establish which, if any, of these factors played a role in the AOMZ case.
Where do Ukraine’s Cyber Forces fit in?
The AOMZ case brings InformNapalm back to an issue we have raised before: the need for a systematic military cyber capability integrated with other intelligence disciplines.
We do not know whether the AOMZ documents were obtained through a cyber operation, but the dataset itself demonstrates the potential value of access to the internal information environment of a defense-industry enterprise.
Corporate correspondence, contracts, specifications, and production plans can be used to reconstruct relationships between companies, identify critical suppliers, and estimate production volumes.
The ability to acquire such data is therefore only part of the requirement. A system is also needed to verify the information, integrate it with other intelligence disciplines, and pass the resulting intelligence to structures capable of turning it into practical effects.
OKBMLeaks already demonstrated one possible version of such a cycle. AOMZ raises the question of how systematically Ukraine is able to scale this approach.
Sometimes the most valuable result of a cyber operation is neither a destroyed server nor a published data dump, but a breach the adversary does not know about.
“AOMZ. Creating the future”
There is one more symbolic OSINT detail in this story.
On September 21, 2026, just five days before the strike, the Azov Museum-Reserve ceremonially opened an exhibition marking AOMZ’s 80th anniversary. The ceremony was attended by plant executives and employees, company veterans, and representatives of the local authorities.
The exhibition was titled “AOMZ. Creating the future” [Rus.: «АОМЗ. Создавая будущее»] and was scheduled to run until January 20, 2027.
Five days later, the future of at least part of AOMZ’s production capacity became considerably less certain.
This publication was prepared by Andriy Lisitsyn especially for readers of InformNapalm volunteer intelligence community. Distribution and reprint with reference to the source is welcome! (Creative Commons — Attribution 4.0 International — CC BY 4.0). Subscribe to InformNapalm social media pages.
InformNapalm does not receive any financial support from any country’s government or large donors. Only community volunteers and our readers help us to maintain the site. You can also become one of the community volunteers or support InformNapalm with your donations.
Read more related material from InformNapalm
- Walking the Path of Fire: Twelve Years of InformNapalm’s War Against the Kremlin
- Ukrainian hackers uncover how Russian drone operators are using Belarus
- CYBINT operation against the Gonets satellite system, dubbed “Russia’s equivalent of Starlink”
- Hacktivists uncovered new classified documents from STC, Russian manufacturer of Orlan-10 drones
- CYBINT. Hacking Russian UAV manufacturer. Part 1: who assembles Geran-2?
- AlabugaLeaks. Part 2: Kaspersky Lab and neural networks for Russian military drones
- AlabugaLeaks. Part 3: Albatross, war, NVIDIA, Sony and Saito
- The Russian drone threat 2026–2027: Ukraine’s lessons for NATO
- Russian generals’ funeral march 2.0: confirmed casualties in the war against Ukraine















No Responses to “From intelligence to impact: what the AOMZ case reveals about operations against Russia’s defense industry”