Image Credentials: Image Title: Major Cyber Breach Hits Romanian Air Force as Russian-Linked Hackers Target NATO-Linked Systems Source: (chatgpt.com) Date: April 2026. Attribution: This image was created using AI-generated imagery (chatgpt.com) and does not depict a real-world scene.
Open Chronicle | with Agencies
Bucharest — A significant cybersecurity breach has compromised multiple accounts within the Romanian Air Force, raising alarm across European defense circles and highlighting the expanding scope of hybrid warfare linked to Russia.
According to investigations cited by Reuters, at least 67 email accounts were targeted in a prolonged cyber campaign attributed to the hacker group Fancy Bear, widely associated with Russia’s military intelligence service, the GRU. Romanian authorities confirmed that 30 of those accounts were successfully compromised, while the remainder of the attacks were repelled.
Operațiune rusă de spionaj. Ținta: emailuri ale unor entităţi militare, inclusiv din România. Cel puțin 67 de conturi ale Forțelor Aeriene Române, compromise https://t.co/NvmJaS2Xck pic.twitter.com/1HmPYql9S2
— TVR Info (@StirileTVR) April 15, 2026
NATO-Linked Infrastructure Raises Stakes
The breach is particularly sensitive due to the involvement of accounts linked to NATO air bases, placing the incident within a broader alliance security context. The Romanian Air Force plays a central role in protecting national airspace and coordinating regional defense, especially amid ongoing tensions tied to the war in Ukraine and instability in the Black Sea region.
Romania’s Ministry of National Defense stated that the compromised accounts were used for administrative purposes and did not handle classified information. Nonetheless, the incident has prompted a restructuring of cybersecurity protocols, with centralized oversight now placed directly under the ministry.
A Coordinated Regional Campaign
The Romanian breach appears to be part of a wider and highly coordinated campaign across Europe. Investigations indicate that similar attacks have targeted military and governmental systems in Greece, Bulgaria, Serbia, and Ukraine.
In Greece, dozens of email accounts tied to the country’s defense command structure were compromised, including those of military attachés abroad. Bulgaria reported intrusions affecting officials in the strategically important Plovdiv region, while Serbia saw targeting of academic and military figures despite its traditionally close ties with Moscow.
Ukraine has been the hardest hit, with more than 170 accounts belonging to prosecutors and investigators compromised. Many of those targeted were involved in anti-corruption efforts and the identification of pro-Russian collaborators, suggesting a deliberate attempt to disrupt internal security mechanisms.
Exploiting Everyday Technology
Cybersecurity analysts say the operation relied on exploiting vulnerabilities in widely used devices such as routers, turning them into covert surveillance tools. This method allowed attackers to gather sensitive data while avoiding detection, demonstrating a high level of sophistication and persistence.
In total, researchers estimate that at least 284 accounts were compromised between September 2024 and March 2026, revealing the scale of what appears to be a sustained espionage effort.
Rising Warnings of Hybrid Warfare
Romanian President Nicușor Dan recently warned that Russia is intensifying hybrid warfare tactics against Western nations, combining cyberattacks, disinformation, and strategic pressure to destabilize institutions.
He also revealed that Romanian intelligence services, working alongside the FBI and partners from multiple countries, had successfully prevented a major cyberattack linked to Moscow.
“Romania must strengthen its cybersecurity and continue cooperation with Western partners,” he said, underscoring the urgency of the threat.
A New Front in European Security
The revelations point to a broader pattern, one that extends beyond isolated breaches into a coordinated effort targeting Europe’s security architecture.
From Bucharest to Athens, and from Kyiv to Belgrade, the same digital footprint suggests a campaign designed not only to gather intelligence, but to test defenses, exploit weaknesses, and exert influence in a region already under geopolitical strain.
In this evolving landscape, cyber warfare is no longer a secondary domain. It has become a central battlefield, where even a single compromised account can open the door to far-reaching strategic consequences.