Monday, August 31, 2026

Bauman university trained hundreds of hackers for Russia’s military intelligence

August 31, 2026
2 mins read
Bauman university trained hundreds of hackers for Russia’s military intelligence
Bauman university trained hundreds of hackers for Russia’s military intelligence

A six-year training programme at Moscow’s Bauman university prepared specialists in cyber-espionage, digital sabotage and information operations, according to reports based on leaked material.

Russia’s Bauman Moscow State Technical University trained about 250 specialists for the country’s military intelligence service over six years, preparing them for cyber-espionage, attacks on information systems and wider influence operations, according to Cyberpress and reporting by 24TV.

The reports, published on 28 August 2026, said the programme was run by department No 4 at the prestigious Moscow university and was linked to Russia’s Main Directorate of the General Staff of the Armed Forces, commonly known as the GRU. Students were divided into three tracks: special intelligence service, information-technical influence, and the protection of information technologies.

A university pipeline into cyber units

The most popular course was military speciality VUS 141600. About 120 students were enrolled in it in 2024, almost half the department’s total intake, according to the reports. Its curriculum went beyond defensive cybersecurity, covering password cracking, malware development, cryptography, steganography and disinformation.

The programme’s breadth points to a Russian approach in which technical intrusion and information manipulation are treated as connected tools of hybrid warfare. Graduates were not simply being prepared to secure systems. They were being equipped, according to the reported curriculum, to penetrate them, disrupt them and influence the public environment around an operation.

Graduates joined military unit 26165, identified with the Fancy Bear hacking group, also known as APT28, and military unit 74455, associated with Sandworm. Fancy Bear is known for cyber-espionage and intelligence collection, while Sandworm has carried out attacks against critical infrastructure. One of the department’s curators was Viktor Netiksho, a former commander of unit 26165.

Netiksho’s involvement illustrates the direct connection between Russia’s military intelligence structures, higher education and offensive cyber operations. The university was functioning not only as an academic institution but as part of a longer-term personnel system supplying specialists to military and intelligence formations.

European infrastructure already targeted

The disclosure matters because the groups linked to the graduates have repeatedly targeted European governments and essential services. In the winter of 2026, Fancy Bear used a vulnerability in Microsoft Office to compromise government systems in Poland, Slovenia, Turkey, Greece and Ukraine. The affected organisations included defence ministries, transport companies and diplomatic institutions.

Sandworm, meanwhile, has targeted energy and transport systems in European countries, creating risks for millions of people. In December 2025, the group carried out a large-scale attack on Poland’s energy system, affecting more than 30 sites, including solar and wind power stations and combined heat and power plants.

These operations show why the training system cannot be viewed as a narrow Russian military concern. A steady flow of personnel into espionage and sabotage units gives Moscow a continuing capacity to renew its cyber operations even when individual campaigns are exposed or particular tools are disabled.

From isolated attacks to a persistent threat

The preparation of about 250 specialists by one institution over six years suggests a sustained and organised effort to create a reserve of personnel for hacking operations. The figure does not represent the entire Russian cyber capability, but it demonstrates the scale of one university’s contribution to that system.

It also reinforces the warning for European universities and research institutions. Academic links with organisations connected to Russia’s military-intelligence sector could create risks involving sensitive technology, research networks and professional contacts. The Bauman programme shows how educational structures can be aligned with security-service requirements long before graduates enter operational units.

Europe therefore faces a challenge that cannot be addressed solely through responses to individual incidents. EU member states and their partners need stronger intelligence-sharing on Russian cyber groups, recruitment and training programmes, attack methods and emerging tools. Greater investment in the resilience of energy, transport, telecommunications and public-sector infrastructure is also required, alongside efforts to counter disinformation.

Where documentary evidence establishes that universities, officials, teachers or other individuals are directly involved in preparing personnel for offensive Russian cyber operations, they could become candidates for sanctions and other restrictions. The central issue is whether Europe will continue treating each attack as a separate emergency, or confront the institutional system that keeps producing the people capable of carrying them out.

How should European governments balance academic cooperation with stronger security checks on institutions linked to offensive cyber programmes?

Leave a Reply

Your email address will not be published.

Don't Miss

Nord Stream investigation points to possible Russian false-flag operation

Nord Stream investigation points to possible Russian false-flag operation

Evidence gathered by German investigators has raised the possibility that Russia planned
AfD politician dismisses controversy over Russian army mug in German constituency office

AfD politician dismisses controversy over Russian army mug in German constituency office

The row over a Russian military souvenir has renewed questions about the