Ukraine’s Security Service says Russian intelligence services are using fake websites, social media accounts and messenger channels to impersonate government agencies, officials and media organisations. The campaign is intended to spread disinformation, collect personal data and obtain information about Ukraine’s defence and security forces.
The warning, published on 5 October 2026, highlights the growing security risks linked to online impersonation during Russia’s war against Ukraine. Ukrainian authorities are urging users to check web addresses, account names and verification badges before trusting or sharing information.
Ukraine identifies more than 50 fake SBU resources
The Security Service of Ukraine, known as the SBU, said it had identified and blocked more than 50 online resources designed to imitate the agency. The fake pages reportedly reproduce official names, logos, photographs and visual branding to make them appear authentic.
The impersonation effort is not limited to institutional websites. Ukrainian authorities say fake Telegram accounts and other social media profiles have also been created using the names and images of senior officials and public figures.
Previous examples cited by Ukrainian officials included accounts impersonating President Volodymyr Zelenskyy, First Lady Olena Zelenska, former presidential office chief Andriy Yermak and former SBU head Vasyl Maliuk.
How fake accounts are made to look credible
According to Ukraine’s Centre for Countering Disinformation, operators may use photographs of security officials and claim to publish exclusive or insider information. Some older Telegram channels, including channels previously associated with cryptocurrency content, can be renamed and given new branding to create the appearance of an official source.
Small details may reveal the deception. A fake profile may use a slightly different username, while an imitation website may copy the design of an official page but operate from a different web address. These differences can be difficult to notice, particularly when users encounter a post through a forwarded message or social media recommendation.
What the operation is designed to achieve
The SBU says the fake resources serve two connected purposes: information manipulation and intelligence gathering.
- Disinformation: False or misleading claims can be presented as if they came from a legitimate Ukrainian institution or media outlet.
- Political and social disruption: Authorities say the campaigns seek to undermine confidence inside Ukraine and weaken the country’s international position.
- Personal-data collection: Users may be encouraged to click links, send messages, follow accounts or provide identifying information.
- Account compromise: Interaction with fraudulent pages can expose users to attempts to take control of their accounts.
- Military intelligence gathering: Ukrainian officials say Russian intelligence is particularly interested in information about the operations of Ukraine’s defence and security forces.
A single fake channel can therefore be used to attract an audience, distribute misleading content and direct users towards links or conversations that support further collection of information.
Why the warning matters beyond Ukraine
The warning is part of a wider European security concern about hybrid threats, foreign interference and online disinformation. Fake government accounts can be used to exploit public trust during wartime, but similar techniques can also affect audiences in other European countries during elections, emergencies or periods of political tension.
For governments, the challenge is not only removing fraudulent pages. Authorities must also help the public distinguish between official information and convincing imitations. This is particularly important on messaging platforms, where content can spread rapidly without the editorial checks associated with established news organisations.
The issue also has a direct cybersecurity dimension. A misleading post may be designed to influence public opinion, while the link attached to it may attempt to harvest passwords, contact details or other sensitive information. Users should not assume that a familiar logo or a photograph of a senior official proves that an account is genuine.
How users can verify official information
Ukrainian authorities are advising the public to take several precautions when encountering government or security-related content online:
- Check the full web address rather than relying only on the page’s design or logo.
- Compare the account name and username with the details listed on the institution’s verified website.
- Look for official verification indicators, while remembering that visual badges or symbols can also be copied.
- Avoid clicking suspicious links or downloading files from unfamiliar channels.
- Do not share passwords, identification details or other personal information through unofficial accounts.
- Confirm dramatic claims through the institution’s established website or verified social media pages.
These steps cannot eliminate every risk, but they can reduce the chance of being misled or exposed to a phishing attempt.
What happens next
The SBU and Ukraine’s Centre for Countering Disinformation are expected to continue monitoring and reporting fraudulent online resources. Blocking identified websites and accounts may limit their reach, but operators can recreate channels, change names or move to new platforms.
That means online vigilance remains an ongoing part of Ukraine’s national security response. The central message from Ukrainian authorities is clear: users should treat unexpected claims, urgent requests and supposed insider information with caution, and verify them through official sources before taking action.
The broader lesson from this EU news development is that digital impersonation can combine influence operations with personal-data theft. Checking the source before clicking or sharing is a practical security measure for users in Ukraine and across Europe.



