On February 18, 2026, the President of Ukraine, Volodymyr Zelensky, announced the imposition of sanctions against Belarusian leader Alexander Lukashenko for his role in expanding and prolonging Russia’s war against Ukraine. The explanation noted that the actions were related to the second half of 2025, when a system of relay transmitters for controlling attack drones appeared on Belarusian territory. Such technologies significantly increased the Russian army’s ability to strike the northern regions of Ukraine, notably from the Kyiv region to Volyn. Without Belarus’s involvement, parts of the strikes, particularly against energy infrastructure and rail transport, would have been impossible.
These sanctions became the culmination of a prolonged cyber operation conducted by Ukrainian hackers from the Fenix Analytical Cyber Center with the support of volunteers from the international intelligence community. It has become one example of how cyberspace can influence real actions on the front and the international security landscape.
Details of the cyber operation and its impact on defense
As part of the operation, the hackers managed to break into the accounts of dozens of Russian servicemen and gain access to monitoring systems used by Russian drone operators. A round-the-clock covert surveillance of these accounts was organized, resulting in the Ukrainian defense forces receiving operational data to counter drone attacks and to collect intelligence on drone movement routes and flight tasks.
The operations lasted at least since mid-2025, and by the end of February 2026 their operational reconnaissance capabilities had been exhausted. A significant role in this was played by the successful strikes by Ukraine’s Defense Forces on Russian command posts and the destruction of individual drone locations.
Use of Belarusian infrastructure and testing of new tactics
In September 2025, during the analysis of intercepted chats of Russian drone operators, it was established that Russia actively used Belarusian civilian infrastructure, notably cellular towers, to route their drones. In doing so they maintained a stable signal and attempted to reach targets in the northern and western regions of Ukraine. Some routes even flew over the territory of certain NATO countries – which was not a coincidence.
In the chats of Russian operators there appeared messages such as transmitting onboard data and routing commands. There were also discussions about specific location designations and flight regimes, revealing the systematic nature of Russian drone operations.
Hidden threat monitoring and real assistance to the Armed Forces
For months, Ukrainian IT specialists worked in the shadows, not revealing their presence, and listened around the clock to and analyzed the correspondence of dozens of Russian strike drone operators. They transmitted important information to the relevant defense units, which significantly increased situational awareness and allowed the successful downing and suppression of Russian drones. Although this did not mean direct drone control, such a level of access allowed a better understanding of the aggressor’s actions and increased the effectiveness of countermeasures.
The operation lasted more than six months, during which Ukrainian forces carried out a number of significant cyberattacks: precise strikes on command posts and drone launch sites on Russian territory and in temporarily occupied parts of Ukraine, as well as the destruction of locations of certain units, which allowed thwarting the enemy’s plans.
Joint actions with NATO and implications for defense strategies
In September 2025 Ukrainian sources also indicated the transmission of operational information to NATO allies: the landing of dozens of Russian drones into Poland on the night of September 9–10, 2025 was considered as a test of new tactics and the capabilities of Belarusian civilian communications infrastructure. This allowed better understanding of risks and planning of further operations to counter drone attacks both on Ukrainian territory and in the region.
There was also a focus on the YY-series UAVs in data collection, which appeared both in the software of Russian operators and in their correspondence. Such aircraft were subsequently recorded not only on Russian territory, but also in the Baltic region and Poland after Russian strikes.
Legal framework and the future of Cyber Forces in Ukraine
The experience of this and other cyber operations shows: deep penetration into communications systems, planning and coordination of the adversary can significantly influence the course of combat operations. Ukrainian cyber specialists, both state and civilian, demonstrate high effectiveness, but the legislative formalization of such actions remains an issue. As of early 2026, legislation on creating the Cyber Forces is moving slowly: Parliament approved in principle Bill No. 12349 in October 2025, but its further progress is indirectly delayed. If a Cyber Forces Command and a cyber-reserve of civilian specialists had been established, this would enable systematic coordination between the state and civilian sectors, scale up successful operations, formalize interagency cooperation, and boost strategic planning in cyberspace.
Despite concrete successes, cyber operations prove: cyberspace is not a minor tool but a full-fledged theatre of war. It requires not only specialists but also a clear state position and legislative formalization. As a result of the latest events, prospects for closer cooperation between government bodies, the civilian sector, and united defense allies are demonstrated, which could significantly enhance Ukraine’s capacity to respond to modern threats.
Conclusion
Changes in the cyber sphere as illustrated by sanctions against Lukashenko and the months-long cyber operation against Russian drone systems show that modern warfare has not only a physical but also a deep digital dimension. The importance of formalizing cyber forces, developing interagency cooperation, and international support grows with each day. Ultimately, defense effectiveness depends on how quickly the government can formalize and scale such actions, ensuring the state’s defense in real time while accounting for new technological challenges.