US Cyber Command head Paul Nakasone confirms that US military hackers have conducted cyberattacks in support of Ukraine in response to Russia's invasion
In an exclusive interview with Sky News, General Paul Nakasone confirmed for the first time that the US had “conducted a series of operations” …
Context & Ripple Effects
This confirmation is the endpoint of a decade-long arc of disclosure. US officials had already told NBC in 2016 that military hackers had penetrated Russia's grid and telecom networks (reported grid and telecom access), and Nakasone had built the dedicated Russia Small Group task force in 2018 before publicly acknowledging actions against ransomware groups in December 2021 (first ransomware acknowledgment).
What changed by June 2022 is the shift from defense to acknowledged offense: in March, sources described US soldiers and cybersecurity experts bolstering Ukraine's cyber defenses, and now the Cyber Command chief confirms a series of offensive operations run in support of Ukraine — the first time the US has publicly claimed attacks, not just hardening, inside an active war.
First-order effects
- US Cyber Command's operations in the Russia-Ukraine war move from sourced reporting to official record, giving Russia formal grounds to treat US military hackers as a direct belligerent rather than a background presence.
- Nakasone's statement sets a disclosure precedent inside his own command: after the ransomware acknowledgment, offensive operations are now confirmed publicly when the command deems deterrence value worth the exposure.
Second-order effects
- Russia faces a named adversary in its cyber theater, raising the likelihood of retaliatory operations against US networks and forcing US defensive postures to price in that escalation.
- Other governments backing Ukraine now operate under a US template that treats confirmed offensive cyber support as declarable policy, pressuring allies to either match the acknowledgment or explain their restraint.
Third-order effects
- If confirmed offensive operations become a standing feature of US military practice — ransomware targets in 2021, Russia in 2022, a Mission Force deployed to 20 countries — cyber operations harden into an openly declared instrument of war, with disclosure itself becoming a deterrence tool.
- The pattern points toward codified norms for state-on-state cyber conflict, where the question shifts from whether military hackers act to which operations governments choose to confirm.
The trend: Military cyber operations are moving from deniable activity to publicly confirmed statecraft, with the US using acknowledgment itself as a deterrent signal.