The Vulkan Files
Verified: Documented in primary records or confirmed by reputable inquiry/reporting.
Documents dated 2016 to 2021 from a Moscow IT contractor described tools for cyber operations, disinformation and control of critical infrastructure. Five Western intelligence agencies told the reporters the files appeared authentic.
Confirmed
The Guardian reported the five agencies' view; Der Spiegel said the material was verified with ten media partners; Mandiant published its own analysis. Named projects included Scan-V, Amezit and Crystal-2V.
Claimed, disputed or not established
The Guardian reported that a unit commonly tracked as Sandworm (GRU unit 74455) appears as an approval party in a document. The contractor and the Kremlin did not respond. The documents describe plans and tools, not what was done in every case.
Reported impact
Governments and researchers cited the files in assessments of Russian cyber capabilities.
Sources (opened in a new tab)
- The Guardian: Vulkan files leak reveals Putin's cyberwarfare tactics ↗https://www.theguardian.com/technology/2023/mar/30/vulkan-files-leak-reveals-putins-global-and-domestic-cyberwarfare-tactics
- Der Spiegel: a look inside Putin's secret plans for cyber warfare ↗https://www.spiegel.de/international/world/the-vulkan-files-a-look-inside-putin-s-secret-plans-for-cyber-warfare-a-4324e76f-cb20-4312-96c8-1101c5655236
- Google Cloud / Mandiant: cyber operations at a Russian contractor ↗https://cloud.google.com/blog/topics/threat-intelligence/cyber-operations-russian-vulkan
Connected
- Agencies: FSB, GRU
- Related case files: GRU Unit 29155 officers charged over WhisperGate · NotPetya: government attribution to the Russian military
- Case board · Timeline (2023) · Document vault · How we verify leaks
This page describes and cites public reporting. It does not host or link to leaked files, and it names no private individuals.
