Q&A with Ukraine's Cyberpolice Department chief Yevhenii Panchenko on his role after Russia's invasion, battling pro-Russian hacking groups, and more
Ukraine's cyber police talks crypto, ransomware and documenting war crimes after Russia's invasion — On February 24, 2022, Russian forces invaded Ukraine. X: @haje and @lorenzofb X: @haje : Such a great piece from @lorenzofb - the cybersecurity team at @TechCrunch just keeps on cranking out bangers. Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: We spoke to Yevhenii Panchenko, the chief of division of Ukraine's Cyberpolice, about how they are fighting Russian hackers, and about how their work has changed since the invasion. We also touched on crypto, ransomware and documenting war crimes. https://techcrunch.com/...
Context & Ripple Effects
Ukraine’s cyber response was initially framed around a government-backed “IT Army” and crypto-donation strategy, alongside support for digital public services and external pressure on Russia. This interview adds the law-enforcement layer: the Cyberpolice’s remit now reaches hostile hacking, financially motivated cybercrime and war-crime evidence.
It also follows reporting on Ukraine’s cyberdefense campaign against Russian wiper malware, showing that the response is not limited to network defense. Cyber policing connects incident response with investigations and evidentiary work.
First-order effects
- Ukraine’s Cyberpolice must divide its post-invasion capacity among pro-Russian hacking activity, ransomware and crypto-related cases, while also documenting alleged war crimes.
- The department’s role becomes more integrated with Ukraine’s wider wartime cyber effort: cyber incidents can be treated as both operational threats and potential investigative evidence.
Second-order effects
- Defenders, investigators and international partners have stronger incentives to preserve attack data and chain-of-custody records, rather than treating every intrusion solely as a remediation problem.
- Ransomware and crypto investigations compete with state-linked threat response for specialized staff and forensic resources, increasing the value of coordination across Ukraine’s cyber institutions.
Third-order effects
- If this division of labor persists, wartime cyber resilience will increasingly include law-enforcement and evidentiary capabilities alongside military and civilian network defense.
- The case points toward a more durable model in which cybercrime enforcement, attribution and conflict-related documentation converge, though the long-term institutional form remains uncertain.
The trend: Ukraine’s experience is part of a broader shift from treating cybersecurity as technical defense alone to treating it as an integrated function of public safety, financial-crime enforcement and conflict accountability.