Russian-linked hackers targeted email systems used by US nuclear scientists, defense contractors and government staff over the past year. Security firms and allied agencies say the campaign focused on nuclear fusion research and used a rare exploit that can steal three months of emails and full organizational directories without requiring users to click links. The group reportedly tested techniques in Ukraine before expanding to NATO targets; one alleged member was arrested in Thailand and extradited to the US.
Russian Hackers Target Emails Of US Nuclear Scientists And Defense Contractors, Allies Warn

Private-sector researchers and allied intelligence agencies say a Russia-linked hacking group has spent the past year targeting email systems used by US nuclear scientists, defense contractors and government officials. The campaign appears focused on gathering intelligence related to nuclear fusion research and other materials that could aid Moscow in its war in Ukraine.
What investigators found
US email security firm Proofpoint examined parts of the operation and reported that the attackers targeted email servers supporting 'nuclear installations and the defense industrial base' in the United States. Proofpoint researcher Greg Lesnewich told CNN the activity suggested the group was 'targeting entities and users with an interest in nuclear fusion' to assess technological progress among Western peers.
How the attack worked
According to a federal advisory issued by the US and more than a dozen allied agencies, the hackers used a relatively uncommon software exploit that only requires a vulnerable email system to receive and open a message. The flaw does not depend on victims clicking links. The advisory says the exploit can exfiltrate roughly three months of a target's email content and extract an organization’s full email directory.
Pattern of testing in Ukraine
The advisory and security firms caution that the group repeatedly tested intrusive techniques on Ukrainian victims before applying them to NATO and other Western organizations. 'This demonstrates an increasing trend within Russian cyber threat groups to target Ukrainian users first — both as a priority target and as a testbench,' the notice said.
'The actor likely hoped to gain strategic insight into western military information, logistics, and policy decisions,' said Sherrod DeGrippo, vice president of threat intelligence at Palo Alto Networks' Unit 42.
Response and law enforcement actions
US agencies including the FBI and NSA helped issue the advisory; officials were not immediately available for comment when the advisory was released. The Department of Energy, which oversees several national research laboratories focused on nuclear energy, did not respond to requests for comment. The Russian Embassy in Washington, D.C., also did not reply to requests for comment.
Law enforcement actions are underway: Thai authorities arrested an alleged member of the group in November — a Russian national in his 30s — who was extradited to the United States and made an initial court appearance in Boston.
Why this matters
The combination of targeted victims, the type of exploit used, and the theft of months of communications and directories raises concerns about the potential depth of intelligence collected. UK Security Minister Dan Jarvis called the tactic 'particularly concerning' because the group reportedly refined its methods on Ukrainian victims before targeting NATO members.
What to watch next: US and allied agencies say the advisory is intended to help potential victims identify compromise and assess damage. If additional organizations come forward, authorities may be able to better determine what information the operatives exfiltrated and how broadly the campaign spread.
Help us improve.




























