The Cyberattack Was Part of the Strike Package: Ukraine Targeted Wildberries Online and Offline.
Ukraine’s military intelligence says a cyber operation against Wildberries was designed to amplify physical strikes on the retailer’s warehouses. The cyber effects have not been independently verified, but the claim is significant because it describes digital disruption as one component of a combined strike package against the same logistics network.
What Ukraine claims
On 15 August 2026, Ukraine’s Defence Intelligence, HUR, published a statement saying members of the Cyber Corps had attacked Wildberries’ digital infrastructure on 10 and 11 August.
HUR said the operation disrupted the retailer’s primary remote customer-service channel, increased pressure on contact centres and partially destabilised payment infrastructure. It reported customer complaints about failed payments and described the target as heavily protected.
The agency’s most important claim was about purpose. It said the cyber operation was intended to amplify the effect of physical strikes by Ukraine’s defence forces on Wildberries warehouses.
That is a Ukrainian government account of an operation carried out during an active war. It should not be presented as independently established fact.
What remains unverified
Recorded Future News reported on 17 August that it could not independently verify the claimed cyber effects. Wildberries had not publicly commented on the cyberattack or the alleged damage when the report was published.
The available public evidence does not identify the access method, the affected systems, the duration of individual outages or the volume of transactions that failed. It also does not establish whether the payment issues came from a compromise, a denial-of-service condition, defensive shutdowns or another cause.
Those gaps matter. The strongest accurate formulation is that HUR claims it disrupted customer service, contact centres and payment infrastructure, and that the operation was coordinated in purpose with physical strikes. The technical mechanism and scale remain unconfirmed.
The physical campaign is independently documented
The cyber claim sits alongside a well-documented physical campaign against Wildberries’ logistics estate.
On 23 July, Reuters reported through Euronext that Ukraine had struck four Wildberries warehouses since the previous weekend. Open-source analysis cited by Reuters estimated damage to about 552,000 square metres of warehouse space, roughly 10 per cent of the retailer’s logistics capacity at that point.
Recorded Future News said Russian-media estimates had since placed the affected warehouse area above 1.2 million square metres. It also cited a Ukrainian Defence Ministry claim that seven of the company’s ten largest logistics centres had been taken out of operation. Those later figures are estimates and belligerent-government claims, not audited damage totals.
The basis for targeting is also contested. Ukraine says Wildberries supports Russian logistics and the war effort. The Kremlin has denied that the company handles military supplies. Wildberries primarily serves the consumer economy, so the effects extend to sellers, workers and customers as well as any military-related activity alleged by Ukraine.
The significant development is the combination
Cyberattacks during armed conflict are not new. Neither are strikes on logistics infrastructure.
The operationally important feature here is that HUR explicitly described the cyber operation as an amplifier for physical attacks against the same organisation.
The two forms of disruption affect different recovery mechanisms. A damaged warehouse reduces storage, sorting and distribution capacity. Disrupted customer service makes it harder to explain delays and resolve seller or customer problems. Payment instability can interrupt orders, refunds and cash flow. Contact-centre overload consumes people precisely when the physical incident is creating more demand for support.
Each effect can therefore increase the cost of the others.
This is more useful to a planner than treating the cyber incident as a separate headline. The target is not merely a website or a building. It is the organisation’s ability to convert orders, inventory, payments, communications and transport into a functioning service.
Availability is a system property
Resilience programmes often divide responsibility by technology. Facilities teams protect warehouses. Security teams protect networks. Payments teams manage transaction providers. Customer-service leaders manage contact centres.
An adversary does not have to respect those boundaries.
For a marketplace, availability emerges from the whole chain:
- Customers must be able to place and pay for orders.
- Sellers need visibility of stock, settlement and returns.
- Warehouses must receive, locate, sort and dispatch goods.
- Transport systems must move parcels between facilities and pickup points.
- Support channels must absorb exceptions when the normal path fails.
- Finance operations must reconcile payments, refunds and seller balances.
If several of those functions degrade together, recovery is not the sum of separate technical fixes. The organisation can restore a website while remaining unable to fulfil what the website promises.
Support and payments are part of the strike surface
Customer service is sometimes treated as a secondary business function. During a logistics crisis it becomes part of operational continuity.
Every delayed parcel, damaged consignment, inaccessible pickup point and disputed seller balance creates a support interaction. If the primary digital channel fails while warehouses are unavailable, demand moves to telephone and other channels. Those channels can then fail through overload even without direct compromise.
Payment systems create a similar multiplier. A marketplace may still display goods while customers cannot complete purchases, sellers cannot predict settlement or refunds accumulate. The cyber effect does not need to destroy data to deepen the physical disruption. Timing and coordination can be enough.
Combined-effect planning should be explicit
Organisations operating critical logistics, retail, energy or public services should exercise incidents that cross physical and digital domains at the same time.
Useful controls include:
- Map the minimum set of facilities, applications, identities, payment services and communications channels required to deliver the core service.
- Identify common dependencies that can disable several recovery paths at once, including power, connectivity, cloud control planes and identity providers.
- Maintain an independently reachable status channel that does not depend on the primary customer platform.
- Design contact-centre overflow and seller communications for a sudden increase in exceptions.
- Test payment, refund and reconciliation procedures when the normal order system is partially unavailable.
- Segment warehouse operational technology and corporate services so disruption in one domain does not automatically spread to the other.
- Preserve offline or degraded-mode workflows for inventory, dispatch and pickup where safety permits.
- Exercise decision-making with incomplete attribution and conflicting public claims.
- Include physical damage, disinformation and cyber disruption in the same crisis simulation.
The last point matters in wartime and in ordinary crisis management. Public statements may come from attackers, governments, vendors, local officials and affected customers before forensic teams can establish a common picture.
Attribution language is an operational control
Overstating an unverified cyber claim can mislead decision-makers. Understating it because the mechanism is unknown can also leave them unprepared for the combined effect.
Good reporting should separate four conditions:
- The physical strikes and their observed consequences.
- HUR’s claim of responsibility and stated intent for the cyber operation.
- Customer or seller reports of service disruption.
- Technical findings independently confirmed by Wildberries or external investigators.
At present, the first category has substantial independent reporting. The second is clear as a Ukrainian claim. The third appears in reporting but lacks a complete denominator. The fourth remains largely absent from the public record.
That structure allows leaders to plan against a credible operational pattern without pretending that every technical detail has been proven.
The organisation was the target
The Wildberries story is not significant merely because a large retailer may have suffered a cyberattack during a drone campaign.
It is significant because Ukraine presented digital disruption as part of the same operational design as the physical strikes. Customer service, payments and contact centres were described as ways to increase pressure on a logistics network already losing warehouse capacity.
Defenders should take the same organisation-wide view. Protecting each system in isolation is necessary, but resilience depends on whether the business can continue when several trusted functions fail at once.
The cyber effects remain a claim that requires verification. The combined-effect strategy is already visible in the way HUR described the operation.
Sources and further reading
- Ukraine’s Defence Intelligence: statement on the Wildberries cyber operation
- Recorded Future News: Ukraine says cyberattack hit Wildberries amid drone strikes
- Reuters via Euronext: widening physical attacks on Wildberries warehouses
Update: the physical campaign has become a state-backed rebuilding problem
Reporting on 19 August shows the warehouse campaign continuing to expand. At least two dozen Wildberries warehouse or logistics sites have been struck since attacks began on 18 July, according to the latest reporting. The exact number and level of damage vary across sources, and some sites were hit more severely than others.
The Russian response now extends beyond company recovery. President Vladimir Putin has publicly acknowledged the damage and called for affected logistics and warehouse facilities to be rebuilt with state support at a higher technological level. That turns the strikes into a national capacity and resilience issue rather than a series of isolated commercial fires.
Broader loss figures require care. Independent estimates based on satellite imagery and reported warehouse capacity have placed damaged or destroyed space at more than one million square metres and around one fifth of Wildberries’ logistics capacity during earlier stages of the campaign. Ukrainian sources and officials have claimed larger economic losses and operational effects. Those figures are estimates and claims, not a final audited statement from Wildberries, and the cumulative position continues to change as new sites are attacked and partially damaged facilities return to service.
The physical evidence is much stronger than the cyber evidence. Drone strikes, fires and warehouse damage have been documented by independent reporting, satellite imagery and Russian officials. Ukraine’s Defence Intelligence has described online disruption as part of the same pressure campaign, but no independent forensic report has yet established the mechanism, duration or full business impact of the claimed cyberattack.
That distinction should remain visible in the article. The combined-effect strategy is credible because Ukraine explicitly described digital and physical pressure against the same organisation. It does not follow that every website outage, payment problem or customer-service delay was caused by the claimed cyber operation. Some disruption may result directly from lost warehouse capacity, emergency procedures, network congestion or defensive action.
The new development strengthens the resilience argument without proving the cyber component. A retailer with a concentrated logistics model can become a strategic target when repeated physical damage forces state-backed reconstruction, while simultaneous digital claims increase uncertainty for customers, sellers and operators. Defenders should plan for that combined pressure, but report the independently verified physical campaign separately from the still-unverified cyber effects.
Additional sources
- Associated Press: Ukraine’s campaign against Wildberries warehouses
- Associated Press: continuing strikes and warehouse damage
Continue the series: European National Cyber & Digital Law Series index


