While the Ukrainian Defense Forces are striking Wildberries’ logistics infrastructure, several independent cyber operations are simultaneously targeting Russia’s largest online marketplace.
On August 16, the Ukrainian Ministry of Defense reported that Ukrainian strikes had disabled seven of Wildberries’ ten largest logistics centers. In particular, following a UAV attack, the logistics hub in the Koledino industrial park in Moscow Oblast ceased operations. It is the company’s largest warehouse, covering approximately 250,000 m².
Several days earlier, the Main Directorate of Intelligence of the Ministry of Defense of Ukraine (HUR) reported that Cyber Corps specialists had attacked Wildberries’ digital infrastructure on August 10–11. Ukrainian intelligence describes the company as an important component of Russia’s logistics and economy supporting the war against Ukraine.
Wildberries databases
On August 7, InformNapalm international intelligence community received data from another group of cybersecurity specialists containing the results of a separate cyber intelligence (CYBINT) operation against Wildberries. The materials included several interconnected databases of marketplace sellers.
The initial dataset contained over 850,000 records. After cross-referencing and deduplicating the data, more than 352,000 unique Wildberries seller profiles were identified. The databases contain seller IDs and store pages, seller names, brands, and product categories, as well as extensive information on associated legal entities and individual entrepreneurs: tax identification numbers (INN), primary state registration numbers (OGRN/OGRNIP), full names, addresses, regions, business activities, telephone numbers, email addresses, websites, and, in some cases, financial and other registry data.
Here is a sample of one of the MS Excel pivot tables containing telephone numbers and email addresses, which may be useful for further work by other cyber groups:
Wildberries caught in the crossfire
Thus, Wildberries has come under pressure in both the physical and cyber domains: Ukrainian forces are striking the company’s key logistics hubs, while different units and groups are independently targeting its digital infrastructure and data holdings in cyberspace.
At the same time, this case once again highlights a systemic problem. Different structures of Ukrainian Defense Forces and independent cyber groups conduct cyber operations against Russia in parallel. Their activities cannot always be synchronized becaause or the high level of secrecy ingrained in the nature of such operations. Moreover, the capabilities they independently develop cannot always be integrated into a unified strategic effort.
As InformNapalm previously noted in an article on the prospects for developing Ukraine’s cyber capabilities based on the U.S. experience, establishing a Ukrainian Cyber Forces structure could provide strategic planning, coordination, and scaling of capabilities that are already working today.
The Wildberries case clearly demonstrates that the relevant capabilities already exist in Ukraine and are being applied in practice. The next question is how effectively the state will be able to bring these capabilities together into a coherent system, ensure coordination, and scale the impact of such operations.
Read more:
- “We can smuggle even nukes”: Russian officers from the 291st Regiment and Vostok-Akhmat establish weapons smuggling channel through Crimea
- Ukrainian hackers uncover how Russian drone operators are using Belarus
- OKBMLeaks: classified documents from a Russian components manufacturer for Su-57 fighter and PAK DA Poslannik next-gen bomber
- CYBINT operation against the Gonets satellite system, dubbed “Russia’s equivalent of Starlink”
