• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Tech

How Hacked Kremlin Emails Could Signal a Turn in the U.S.-Russia Cyberwar

By
Simon Shuster
Simon Shuster
and
TIME
TIME
Down Arrow Button Icon
By
Simon Shuster
Simon Shuster
and
TIME
TIME
Down Arrow Button Icon
November 7, 2016, 12:44 PM ET
Eastern gate of moscow kremlin
The eastern gate of the Kremlin in Moscow, Russia.Photograph by Image Source Getty Images

Before they pulled off one of the most embarrassing cyber heists ever to hit the Kremlin, the hackers from the Ukrainian Cyber Alliance, who styled themselves as the online shock troops in Ukraine’s conflict with Russia, weren’t really on the radar. They had mostly spent the last two years on easy targets—the computers and cell phones of Russia-backed separatist rebels in eastern Ukraine, who are not known for their discipline when it comes to virus protection or, for that matter, anything else. Every once in a while, the hackers would also deface a Russian website, the cyber equivalent of spray-painting graffiti.

Victor Zhora, the head of Infosafe, one of Ukraine’s leading cyber security firms, had never met any of these hackers or heard much about them in the local tech community. “They just weren’t doing much,” he says—that is, until the past two weeks, during which they posted two troves of emails apparently stolen from the inboxes of Vladislav Surkov, the Kremlin’s former propaganda czar, who is now in charge of Russia’s shadow war in eastern Ukraine. Among the close aides to Russian President Vladimir Putin, Surkov is about as tough and consequential a hacking target as they come.

Read More: What’s Going On With Julian Assange and WikiLeaks? Here Are 4 Theories

Which is partly why the hack looked so suspicious to Zhora and other cyber experts. Its sophistication seemed well beyond the reach of amateurs, as did its presentation, which featured slickly produced video announcements and textual analysis translated into five languages, including flawless English and, for some reason, Bulgarian. Ukrainian hackers had never pulled off anything close to this level of operation. “This clearly involved top-level professionals,” Zhora says. And based on the resources that would have been required, he suspects the hackers may have had help from a foreign intelligence service—most likely a Western one.

Get Data Sheet, Fortune’s technology newsletter.

The timing would seem to support that theory. In a joint statement on Oct. 7, the U.S. Department of Homeland Security and the Director of National Intelligence formally accused “Russia’s senior-most officials” of authorizing the theft and disclosure of emails from Hillary Clinton’s presidential campaign and its allies in the Democratic Party, via WikiLeaks and other online conduits. A week later, Vice President Joe Biden said in an interview with NBC News that the U.S. would respond to these attacks “at the time of our choosing, and under the circumstances that have the greatest impact.” Pressed for details, Biden would only add that the U.S. was “sending a message” to Putin, and that he would know when that message arrives.

The following week, starting on Oct. 23, a group calling itself the CyberHunta, which is part of the Ukrainian Cyber Alliance, released the first batch of emails from a Russian government address that appeared to belong to Surkov’s office in the Kremlin. The documents showed in minute detail how Russia has micromanaged the separatist rebellion in eastern Ukraine over the past two years, picking its leaders, managing their finances and choreographing their propaganda.

Read More: Vladimir Putin Signs Order Making Steven Seagal a Russian Citizen

Asked to respond, the Kremlin’s chief spokesman, Dmitry Peskov, dismissed the documents as an elaborate forgery, pointing out that Surkov is so cautious with his digital affairs that he does not even use email. This appears to be true from the hack, at least: all of the messages taken from his accounts were handled by intermediaries and assistants; none came directly from him.

But in a detailed analysis of the leaked emails, the Atlantic Council’s Digital Forensic Research Lab concluded that they are almost certainly genuine—though not exactly rich in surprises: “The Surkov Leaks,” the analysts said, “show us a picture of the conflict in Eastern Ukraine that we have long suspected: the Kremlin had a guiding hand in orchestrating and funding the supposedly local and independent government.”

More striking than the actual contents of the documents, however, was the sudden reversal in what had previously been a fairly one-sided cyber conflict between Russia and its rivals. It appears the “message” Biden promised to send Putin may have been delivered through Ukraine. “From a technical and operational point of view, this does look like a message in reply to the attacks on the U.S. electoral system,” says Zhora.

Read More: The Future of Civilization Is a Battle Between Google and Wikileaks

Biden’s office, as well as the spokesman for the Director of National Intelligence, did not respond to requests for comment. But Zhora is not the only expert to voice suspicion of U.S. involvement in the hack. Mark Galeotti, a senior researcher at the Institute of International Relations in Prague, and an expert on Russian intelligence services, told USA Today that, “This kind of a leak is enough to warn the Russians [that] the USA has certain capabilities and is willing to use them.” But, as he was also careful to stress, “we are a long way from having any evidence of this—if we ever will.”

Such plausible deniability seems to be the nature of cyber conflict going forward. In hacking the Clinton campaign and the Democratic National Committee, Russia appears to have used a series of intermediaries and decoys in order to maintain deniability and keep the state’s fingerprints as far from the hack as possible. According to the Oct. 7 statement from U.S intelligence agencies, these Kremlin fronts have included WikiLeaks and an “online persona” known as Guccifer 2.0, who claimed to be a lone Romanian hacker after he posted emails from the DNC.

For their part, the members of the Ukrainian Cyber Alliance, appearing in video interviews this week with Halloween masks over their faces, have denied being anybody’s sock puppet. “Ukrainian hacking groups have fairly high technical skills,” one of them told Reuters on Nov. 3. “And so there is no need for the U.S. or any other NATO country to support us. What’s more, it would be quite an extreme foreign policy move from the U.S.” But probably not extreme enough to make Russian hackers back off in the cyberwars to come.

This article originally appeared on Time.com.

About the Authors
By Simon Shuster
See full bioRight Arrow Button Icon
By TIME
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

$12 billion crypto company boss says Gen Z ‘create an absurd amount of chaos’ and make him want to pull his hair out—but he’s betting on them anyway
SuccessGen Z
$12 billion crypto company boss says Gen Z ‘create an absurd amount of chaos’ and make him want to pull his hair out—but he’s betting on them anyway
By Orianna Rosa RoyleApril 12, 2026
3 hours ago
mueller
CommentaryEntrepreneurship
I grew up in a family of entrepreneurs. Here’s what I had to unlearn to build a $1 billion business
By Samuel MuellerApril 12, 2026
4 hours ago
grantham
Investingbubble
Legendary investor says the AI boom masks a deeper crisis: Falling sperm counts, shrinking populations, and vanishing resources
By Nick LichtenbergApril 12, 2026
4 hours ago
Wemimo Abbey and Samir Goel, the cofounders of fintech company Esusu
SuccessCareers
These cofounders quit corporate jobs, took on $100K in credit card debt, and slept in a Denny’s—now their $1.2B company is backed by Serena Williams
By Emma BurleighApril 12, 2026
5 hours ago
Born in Soviet Union, Grindr CEO was told he had two career options: Learn English or how to shoot a gun
SuccessThe Promotion Playbook
Born in Soviet Union, Grindr CEO was told he had two career options: Learn English or how to shoot a gun
By Orianna Rosa RoyleApril 12, 2026
5 hours ago
These startups are racing to make AI safe for the Pentagon’s most closely guarded secrets
AIDefense
These startups are racing to make AI safe for the Pentagon’s most closely guarded secrets
By Erik GermanApril 11, 2026
1 day ago

Most Popular

'This is the last warning.' Iran threatens U.S. warships after they throw down the gauntlet for winner-take-all Strait of Hormuz
Politics
'This is the last warning.' Iran threatens U.S. warships after they throw down the gauntlet for winner-take-all Strait of Hormuz
By Fortune EditorsApril 11, 2026
16 hours ago
Palantir CEO says AI ‘will destroy’ humanities jobs but there will be ‘more than enough jobs’ for people with vocational training
Future of Work
Palantir CEO says AI ‘will destroy’ humanities jobs but there will be ‘more than enough jobs’ for people with vocational training
By Fortune EditorsApril 11, 2026
1 day ago
The 'affordability economy' has created a housing market nobody predicted: Prices collapsing in the Sun Belt, soaring in the Rust Belt
Real Estate
The 'affordability economy' has created a housing market nobody predicted: Prices collapsing in the Sun Belt, soaring in the Rust Belt
By Fortune EditorsApril 11, 2026
1 day ago
Warren Buffett says 'accumulating great amounts of money' doesn’t achieve greatness—He still lives in a $31,500 Nebraska home and clipped coupons
Success
Warren Buffett says 'accumulating great amounts of money' doesn’t achieve greatness—He still lives in a $31,500 Nebraska home and clipped coupons
By Fortune EditorsApril 11, 2026
1 day ago
Navy tests Hormuz blockade as expert says U.S. military prepares for round 2 and could degrade Iran's hold over the strait to a 'manageable level'
Politics
Navy tests Hormuz blockade as expert says U.S. military prepares for round 2 and could degrade Iran's hold over the strait to a 'manageable level'
By Fortune EditorsApril 11, 2026
22 hours ago
2 years ago, Saudi Arabia quietly canceled the ‘petrodollar’ deal with America that wired the world economy for 50 years. Then war broke out in Iran
Energy
2 years ago, Saudi Arabia quietly canceled the ‘petrodollar’ deal with America that wired the world economy for 50 years. Then war broke out in Iran
By Fortune EditorsApril 7, 2026
5 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.