Ukraine Cyber Operation May Have Turned Russian Air Defense Against Its Own Su-57 Fighter Jet

A Russian Sukhoi Su-57 fifth-generation fighter jet crashed near Moscow on July 23, and the circumstances surrounding its loss have become the focus of an extraordinary claim: that Ukrainian cyber operatives manipulated a Russian air defense system into shooting down one of its own aircraft.

The crash occurred shortly after the Su-57, likely a two-seat Su-57D variant, took off from Kubinka airfield in the Zvenigorod area. Moscow confirmed the loss of a fifth-generation fighter but attributed it to a technical malfunction. Unofficial Russian sources, however, immediately linked the incident to friendly fire by the BARS Moscow detachment, a reserve unit equipped with anti-aircraft drones, machine guns, and man-portable air defense systems.

The Ukrainian intelligence community InformNapalm subsequently reported that Ukrainian cyber units had conducted a combined HUMINT and CYBINT operation that successfully turned Russian air defense systems against their own aircraft.

If confirmed, the incident would mark the first known instance of a combat aircraft being destroyed as a result of a cyberattack, a threshold in the evolution of electronic warfare that defense analysts have warned about for years but which has never been documented in operational combat.

Your support allows us to spend more time verifying facts and less time chasing page views.

Keep quality journalism alive

Two possible technical scenarios

Defense analysts have outlined two plausible mechanisms for how such an attack could work, both relying on the integration of Russian air defense networks with digital command-and-control systems.

The first scenario involves unauthorized access to the Citadel autonomous air defense system, a 30-millimeter autocannon capable of detecting and engaging low-altitude targets without human intervention. The Su-57 crashed shortly after takeoff, meaning it was at low altitude and within the engagement envelope of such systems. Compromising the Citadel’s target identification protocols could cause it to classify the fighter as hostile.

The second scenario involves manipulation of the broader airspace situational awareness system. By feeding false tracking data into the network, an attacker could designate the Su-57 as an enemy aircraft, triggering engagement by longer-range missile systems under the 1st Moscow Special Purpose Air and Missile Defense Army. No visual confirmation of surface-to-air missile launches in the Moscow area has been reported.

The timing of drone threat warnings issued for the Moscow region between 11:20 a.m. and 11:40 a.m., before the crash at approximately 1:20 p.m., has led some analysts to suggest the warnings may have been coordinated with or used as cover for the operation.

Operational implications

The BARS Moscow unit’s equipment normally requires visual contact to engage a target, making accidental friendly fire unlikely without electronic intervention. The unit’s personnel are reservists with varying levels of training, a factor that InformNapalm said was specifically analyzed as part of the pre-operation intelligence gathering.

The operation, if verified, demonstrates that integrated air defense networks, which combine radar, tracking data, automated targeting, and human operators into a single kill chain, create a vulnerability surface that did not exist with earlier generation, manually operated systems. A sufficiently sophisticated adversary may not need to defeat the air defense system kinetically; manipulating the data it trusts may be enough.

Sources: “How Ukrainian Cyber Operation May Have Led to Downing of russian Su-57 Near Moscow” (Defense Express, Jul 25, 2026); “Ukrainian cyber experts forced Russian air defense to shoot down its own Su-57” (dev.ua, Jul 2026); “Pro-Ukraine group claims it helped hack Russian drone air defense” (Tom’s Hardware, Jul 2026)

Scroll to Top