Cyberwarfare

Secret US Documents on Ukraine War Plan Spill Onto Internet: Report

Secret documents that reportedly provide details of US and NATO plans to help prepare Ukraine for a spring offensive against Russia have spilled onto social media platforms.

Russia attack on Ukraine

Secret documents that provide details of US and NATO plans to help prepare Ukraine for a spring offensive against Russia have spilled onto social media platforms, the New York Times reported on Thursday.

The Pentagon said it is assessing the reported security breach. “We are aware of the reports of social media posts, and the Department is reviewing the matter,” Deputy Press Secretary Sabrina Singh said.

The documents were spread on Twitter and Telegram, and reportedly contain charts and details about weapons deliveries, battalion strengths and other sensitive information, the Times said.

Information in the documents is at least five weeks old, with the most recent dated March 1, the report said.

One of the documents summarized the training schedules of 12 Ukraine combat brigades, and said nine of them were being trained by US and NATO forces, and needed 250 tanks and more than 350 mechanized vehicles, the newspaper said.

The documents — at least one of which carried a “top secret” label — were circulated on pro-Russian government channels, it said. Information in the documents also details expenditure rates for munitions under Ukraine military control, including for the HIMARS rocket systems, the US-made artillery rocket systems that have proven highly effective against Russian forces, it added.

Advertisement. Scroll to continue reading.

The report quoted military analysts who warned that some documents appear to have been altered in a disinformation campaign by Russia, in one document inflating Ukrainian troop deaths and minimizing Russian battlefield losses.

—

Industry Commentary Received by SecurityWeek: “Russia has tried to undermine confidence in the Ukrainian military with disinformation delivered through a variety of schemes. They regularly leak realistic, but fake disinformation, like documents. On several occasions they have planted fabricated disinformation in real leaked data. In all cases, the goal is to launder their disinformation through careless intermediaries. We are very fortunate that this leak has received such a skeptical reception.” – John Hultquist, Head of Mandiant Intelligence Analysis – Google Cloud

Related Content

Malware & Threats

The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor.

Artificial Intelligence

Anthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model.

Cybercrime

The pro-Russian hacker group Server Killers claimed responsibility for the attack.

IoT Security

Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks.

Artificial Intelligence

Atalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network.

Cyberwarfare

CrowdStrike co-founder Dmitri Alperovitch discusses how cyber operations support kinetic warfare, signal coming conflicts, and reshape the global battlefield.

Mobile & Wireless

Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations.

Cybercrime

The suspects and their companies were previously sanctioned by the United States and its allies.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version