Russia’s Use of Disinformation in the Ukraine Conflict

John R. Haines

February 2015

All warfare is based on deception...
To subdue the enemy without fighting is the acme of skill.
Sun Tzu

We will not forget!  We will not forgive!
CyberBerkut motto

In the vanguard of the non-linear war now raging in eastern Ukraine is an old weapon, disinformation, wielded by an unconventional force.  Exemplifying that force is the hacktivist group, CyberBerkut.  It recently issued an ultimatum to Ukrainian President Petro Poroshenko to end the war in eastern Ukraine that "has plunged the people of Ukraine into an abyss of war, poverty, unemployment and despair."[1]  It directed an additional threat to Prime Minister Arseniy Yatsenyuk:

"Mr. Yatsenyuk! We start the countdown. You have three days to stop what you started.  In the event our conditions are not met, we will open the world's eyes to all that is happening in the country. Personal correspondence top officials, telephone calls, secret documents — everything that we found by hacking the computers of employees of Ukraine's Security Service.  You decide: to stop the bloodshed in your own country and start over from scratch, or to commit public suicide in front of millions of people."[2]

The newest fulfillment of this threat is the release of a set of documents CyberBerkut alleges it obtained by "cracking"[3] Ukrainian Defense Ministry computers.[4]  The documents, published on CyberBerkut's website and the Russian portal LifeNews, purport to be correspondence between Ukraine's Deputy Defense Secretary, Peter Mehedi, and a senior Syrian commander, Brigadier General Talal Makhlouf.[5]   If the documents are to be believed, they suggest American arms shipments intended for frontline units in eastern Ukraine were diverted by Ukrainian government officials and sold illegally for private financial gain to the Assad regime.[6]

Risible as this claim may seem, it is impossible to disprove on the basis of open-source evidence, but then again, that misses the point.  The objective of disinformation, to borrow from Whitehead, is to impose a pattern on experience.  It is a lens used to distort and pervert our understanding of facts.  It is telling Ukrainians that their government is corrupt and has betrayed the forces fighting in eastern Ukraine.  It reinforces the narrative among the "Territorial Defense Battalion" paramilitaries — for example, the "cyborgs" of the Azov Battalion whose defense of the Donetsk Airport lasted longer than the siege or Stalingrad or Moscow — that they are being sacrificed in the war, a common and recurring social media theme.[7]  It provokes demoralizing backlashes — a 2 February protest on Kyev's Independence Square included calls for the imposition of martial law and the dismissal of senior defense and security officials — that are reported gleefully in Russian news portals.[8]

Americans and Western Europeans are not the intended audience for Russian disinformation about Ukraine.  Instead, Ukrainians are: the intent is, at the minimum, to demoralize; and at the maximum, to provoke a popular backlash against the Ukrainian government, even a putsch.  It is intended to sustain a narrative that the political leadership has abandoned the frontline forces fighting in eastern Ukraine, especially among army conscripts and nationalist paramilitary volunteer units.  The purported Mahedi-Makhlouf correspondence is a variation on the Dolchstoßlegende,[9] the mythical "stab-in-the-back" of the army by craven politicians, exemplifying the corrosive effect of even less-than-artful disinformation.

This, then, is the less-noticed side of the conflict in eastern Ukraine.  Bringing incidents of disinformation to light for discussion purposes can have risks since disinformation thrives on repetition.  It is nonetheless important to understand the instrumental effect of Russian disinformation on eroding Ukrainians' confidence in their civil institutions and creating fertile ground for extremist groups on all sides.

A Non-Linear War[10]

Vladimir Putin - Photo Credit Frederic Legrand - COMEO
Photo Credit: Frederic Legrand - COMEO

Vladislav Surkov's use of the term non-linear war[11] exemplifies how Russian theorists characterize 21st century warfare.  He wrote, "The old wars of the 19th and 20th centuries involved two sides.  Now, it is all against all." Valery Gerasimov expands the term with a distinctly Russian view of modern warfare (with echoes of eastern Ukraine):

"A perfectly thriving state can, in a matter of months and even days, be transformed into an arena of fierce armed conflict, become a victim of foreign intervention, and sink into a web of chaos, humanitarian catastrophe, and civil war."[12]

As Russians see it, all conflict is a means to a geopolitical end.  Nonmilitary instruments — in one embodiment, the purposeful distortion of an adversary's sensibilities[13] — can rival the power of weapons in their effectiveness.[14]  Peter Pomerantsev refers to this as "the weaponization of information."[15]  For Gerasimov, "The information space opens wide asymmetrical possibilities for reducing the enemy's fighting potential."[16]  The coordinated use of nonmilitary instruments to provoke civil unrest and instill fear to the point of panic last year in Crimea is a good illustration of the theory in action.  The information space is the main battlefield in this conception of information warfare, “a battle between states involving only the use of information weapons in the sphere of information models.”[17]  It is, simply put, "to wage war without ever announcing it officially."[18]

What is "Disinformation"?

The English word "disinformation" is a translation of a Russian one, dezinformatsia.  It involves a carefully constructed, intentionally deceptive message leaked by an operator who conceals his identity, either by hiding behind a cloak of anonymity or by acting indirectly through agent, witting or otherwise.[19]  

An element of the Soviet-era concept of maskirovka, disinformation is the deliberate use of misinformation or misleading information.[20]  In Shmuel Vaknin's deft description, it is "an open and authorized policy, a conscious decision to subvert language itself, to divert topology, to disinform, to transform reality into an inane hall of mirrors."[21]  A former deputy chief of the Czechoslovak ŠtB[22] analogized disinformation to poison, saying, "One drop may not be a problem, but together, a dose could be fatal."[23]

Active measures — a Soviet-era term for political warfare — were defined by a Russian naval officer term as:

"A means of eliminating, distorting or stealing information for the purpose of obtaining necessary data after penetrating the security system; blocking of access to information by its legitimate users; and in the final account, disorganization of all means of society’s life support, including the enemy military infrastructure."[24]

Naked active measures can come dangerously close to open war.  It would constitute an overt act of state aggression were the Russian government to admit openly to hacking Ukrainian government networks and stealing official documents.  The same would be true if the Russian government admitted openly to disseminating stolen or counterfeit documents.  Disinformation allows Russia to direct active measures aimed a destabilizing Ukraine without having to take public ownership of those measures.

Feliks Dzerzhinskii[25] established a "special disinformation office" within the Soviet Union's State Police Directorate in 1923.[26]  Dezinformatsiya first received institutional status in 1959 when the Soviet KGB established a special unit in its First Chief Directorate known as the "Department For Active Measures."  Using the cryptonym "Department D" and operating under the direct authority of the Communist Party Central Committee, Department D specialized in black propaganda and disinformation.[27]  It was from the start true to its description by Dzerzhinskii's deputy, Martin Latsis, as "a fighting organ...It does not judge, it strikes."[28]

Propagandistic disinformation strives to demoralize.  A classic if simple method of Soviet propagandistic disinformation was to disseminate forge documents[29] which for effect, however, contained at least some genuine information: "Every disinformation message," wrote Ladislav Bittman, "must at least partially correspond to reality or generally accepted views."[30]  The overall purpose is to damage the target — Ukraine's government — by playing on the audience's prejudices and biases — a widely held suspicion of corruption among public officials.  This allows propagandistic disinformation to be effective even when it comes from a source that the audience finds dubious or unreliable.


Suspicion often creates what it expects.
C.S. Lewis

Timothy Jordan conceptualizes technopower as a condition in which war no longer involves the conquest of new territory, but, rather, the destruction of the opponent's will to resist.[31]  In the conflict in eastern Ukraine, dezinformatsia is a potent instrument of Russian technopower.  It is a central component of what Russian theorists call information warfare (aka "information operations"), which is potentially one of the most damaging applications of force.  Gerasimov described information operations as "military means of a concealed nature."[32]  The aim is to manipulate information and exert psychological influences on another state's political and military leaders, soldiers, and civilian population.[33]  Applied in Russia's near abroad, it is "information warfare as domestic counterinsurgency,"[34] something "capable of shaping public opinion to mobilize political forces against the authorities in their state.’’[35]

The creation and dissemination of disinformation in cyberspace is an important tactic in modern conflicts.  Unlike the classic domains of military conflict (i.e., land, air, sea & space), cyberspace is not strictly speaking a domain.  Rather, it is a built environment, which means it can be un-built and remodeled (and in the extreme, destroyed).[36]  In the cyber frame of a broader cybered conflict, defensive information operations protect the integrity of electronic data.  Their main function is to prevent "cracking" and other cyber attacks from successfully accessing, changing, and/or destroying electronic data, which might includes efforts to alter its context or otherwise manipulating it for purposes of deception.[37]

Cyberspace confers some distinct advantages on dezinformatsia: when dealing with electronic data or documents, neither style nor provenance (how it was obtained) is a reliable signal to indicate deception, unlike handwritten or typewritten material.  An effective way to create disinformation with electronic data is to begin with a genuine message and then change some critical element (e.g., time, place, name) in a systematic way.[38]  Disinformation created this way is easily disseminated through defaced governmental websites, which has the added benefit of confounding the adversary's information flows.[39]

Disinformation based on forged or altered electronic data is an important tool since governments rely on information and reputation to exercise moral influence and to model public opinion.  Comingling strategic content (information that is genuine but compromising) and disinformation can alter a political balance and/or legitimate a broader conflict.  It is an effective way to intervene in a target state's domestic affairs[40]  that skirts the principle of international law that foreign agents cannot carry out activities within the territory of another state without its permission.  As a practical matter, most states engaged in systematic campaigns to disseminate dezinformatsia do so in ways that makes its attribution difficult to prove.

From Asymmetric Warfare to Dissymmetric Warfare

Asymmetric warfare is a concept that is broad, inclusive, and as often as not, misapplied.  It denotes where two sides in a conflict have such divergent strengths and weaknesses that they resort to drastically different — thus asymmetric — tactics to achieve relative advantage.  The superior force in an asymmetric conflict will attempt to limit operations in order to keep its costs low.  The inferior force will attempt to inflict the highest possible costs on its more powerful adversary, and to draw it into a war of attrition in which asymmetry favors the inferior force.  One aim of asymmetric warfare is to make any countermove by the stronger force look like a significant and unwarranted escalation, which in the current conflict might be a pretense for deploying Russian "peacekeepers" into the territory. 

Asymmetrical actions, Gerasimov wrote, include informational ones: "The information space opens wide asymmetrical opportunities to reduce the enemy's fighting potential."[41]  It is primarily a figurative war of narratives in which favorable ones are reinforced and multiplied while “foreign” interpretations are neutralized and pushed to the margins where they pose no threat.[42]  Rastorguyev has long argued that defensive tactics in this kind of war would lead to defeat.  Russia has accordingly reframed how it defines the threat in eastern Ukraine to fit an offensive war: the focus of Russian dezinformatsia is a purported rising anarchy in eastern Ukraine and the right of separatists to self-determination.

The opposite of asymmetric warfare is dissymmetric warfare, which results from the application of massive force against a weaker opponent in a military conflict.  Ukraine confronts both asymmetric and dissymmetric dimensions in the war in eastern Ukraine.  Pro-Russian separatists wage asymmetric warfare against the Ukrainian government — information warfare shares many features with classic guerrilla warfare, for example, the absence of a single frontline or a formal declaration of war — while Russia prosecutes a parallel, dissymmetric one.[43]  The Ukrainian government has been unable to transform the asymmetric war against pro-Russian separatists into a dissymmetric one in which Ukraine could exploit its advantages.  This reflects several factors.  The separatist forces have demonstrated considerably higher esprit de corps than Ukraine's, whose regular army units are increasingly dependent upon conscripts[44] (thus Ukraine's risky gambit to "stiffen" army units by deploying ultra-nationalist paramilitary units to front line positions).   Separatist forces also have limited their actions to waging a genuine asymmetric conflict that makes optimal use of terrain and keeps to guerrilla warfare tactics.

The dissymmetric war in eastern Ukraine (for the most part so far) is a cybered conflict. [45]   Ukraine faces a determined, capable adversary — the Russian government — that is highly skilled in the use of dezinformatsia to impose virtual costs and virtual collateral damage, in this case on Ukraine.  The hostile use of information and communication technologies (ICTs) is a Russian conceptualization meant to influence or damage an adversary-state's information resources and telecommunication systems.  It includes disseminating disinformation and creating virtual depictions in cyberspace that misrepresents reality, all geared toward disorienting, destabilizing and demoralizing a civilian population.[46]  Properly used, disinformation has an outsized "shock and awe" effect that saps an adversary's will to fight, largely by distorting how its civilians perceive and understand the conflict.[47]  In the current one, cyberspace has becomes Ukraine's second ungovernable badland, one in which it is fighting an unconventional cybered war alongside the conventional one in the physical space of eastern Ukraine.

CyberBerkut & the Conflict in in Eastern Ukraine

The hacktivist group CyberBerkut[48] is the vanguard of a sophisticated dezinformatsia campaign in Ukraine.  Since first emerging in March 2014, it has been implicated in multiple incidents of cyber espionage, including direct denial of service (DDoS) attacks against NATO as well as Ukrainian and German government websites.[49]  More recently, it has focused on the online publication of "cracked" or maliciously hacked electronic documents obtained from the computers of Ukrainian governmental and political figures. 

The membership of CyberBerkut is anonymous, but reportedly includes former officers in the Crimean Berkut. That unit was part of Ukraine's Interior Ministry until Crimea's March 2014 annexation, upon which the Crimean Berkut was incorporated into Russia's Interior Ministry.[50]  CyberBerkut's "Ukrainian identity" is vigorously asserted, however, as it postures as an internal opposition group.  This, too, is consistent with the Russian playbook, for as Gerasimov wrote, "Asymmetrical actions...[include] internal opposition to create a permanently operating front through the entire territory of the enemy state, as well as informational actions..."[51] 

In the past several days, CyberBerkut published several sets of documents online that it claims were obtained from electronic records the group purportedly "cracked" from the Ukrainian Security Service, known as the SBU.[52]   The first set of documents purport to show SBU complicity in a 13 January rocket attack in Volnovakha in which a civilian passenger bus was destroyed, killing 10 persons and injuring 17 (it is important to note that the circumstances of the rocket attack conflict with much of the "evidence" produced by CyberBerkut and others).  One key document in this set purports to be a confidential letter from Vasili Gritsak to Hennadiy Kuznetsov[53] dated 13 January 2014.  Gritsak is the SBU's First Deputy Chairman and the head of its Anti-Terrorism Center.[54]  Kuznetsov, an SBU Colonel, at the time was head of Special Operations Center "A", a unit responsible for special anti-terrorist operations.  The document contains what appear to be written directions from Gritsak directing Kuznetsov to carry out so-called "false flag"[55] attacks in eastern Ukraine's Donetsk and Lugansk regions.  The objective, according to the document, is to produce civilian deaths that can be blamed on pro-Russian separatists.  A companion document purports to be a report from the SBU Donetsk Regional Unit regarding its implementation of a propaganda campaign citing several media reports of the Volnovakha rocket attack.

Not surprisingly, similar documents have surfaced before.  In December 2014, the online portal Russiya Vesna[56] ("Russian Spring") published a document on its website that it purported to be a 25 November order signed by Gritsak.  In it, he directs SBU units to execute false flag artillery attacks against several villages north of Donetsk, an area in which separatist units were known to operate.  Afterwards, the document reads, the SBU will "organize visits to the villages by Ukrainian and foreign correspondents, who will be provided with evidence that 'terrorists' launched the artillery attacks."

On 28 January, CyberBerkut published another set of documents the group claimed are cracked electronic files belonging to Anatoly Matios, Ukraine's Deputy Prosecutor General and Chief Military Prosecutor.[57]   The document that received the most attention orders an end to public reporting of the number of casualties suffered by Ukrainian forces "in the area of the ATO" (anti-terrorist operations) by hospitals under the jurisdiction of the Ukrainian Defense Ministry.

However, the most scandalous purports to be an order dated 25 January 2015 from Lieutenant-General Serhiy N. Popko,[58] who commands Ukrainian ATO forces in the Donetsk and Lugansk regions (and who currently is in the Debaltseve area).  In it, he orders the formation of "protective detachments" comprised of members of "the volunteer corps," a reference to the Ukraine Volunteer Corps aka DUK-Right Sector, a paramilitary force organized by the ultra-nationalist political party Right Sector.  The formation of protective detachments is intended "to prevent mass defections soldiers from the battlefield near Debaltseve."[59]  The geographic reference is to a salient centered on the town of Debaltseve — a strategic railway hub connecting Donetsk and Lugansk — in which separatist forces are attempting to trap a force of several thousand Ukrainian soldiers and paramilitary.  In a related document, Matios purportedly orders all personnel rotating out of the combat zone to first surrender their weapons.

A clear objective of the current dezinformatsia campaign being waged against the Ukrainian government is to exploit fissures: within Ukraine's coalition government; between the government and combatants in the field, especially the DUK-Right Sector and Azov Brigade paramilitaries; and between the Ukraine's regular army and paramilitaries.  DUK-Right Sector leader Dmytro Yarosh[60] in late January threatened to split Ukraine's armed force by creating "a parallel General Staff...that would receive the support of many military units, both regular and volunteer.”  Shortly after Yarosh leveled the threat, the Ukrainian army's general staff announced its intention to disband all so-called "volunteer organizations" including the Aydar Battalion[61] and to "merge" them into other army units.

Within the past few days, the dezinformatsia campaign has taken direct aim at Yaros when CyberBerkut released documents that purportedly implicate him in a host of economic crimes:

“Today we are publishing documents that expose the criminal activities of the head of Ukrainian neo-Nazis, which confirm multiple incidences of extortion – the illegal and cynical seizure of properties and businesses belonging to Ukrainian citizens by Yarosh and his associates. The stolen money is then taken out of the country through fronts and deposited in offshore accounts in Cyprus.  Now everyone will know that the Ukrainian neo-Nazis led by Yarosh are common gangsters, and have used policies of the Maidan to cover up criminal activities and self-enrichment at the expense of the citizens of Ukraine.”[62]

All this seems oriented toward driving a deeper wedge between Yarosh's Right Sector political allies — and the DUK-Right Sector paramilitary — and Ukrainians in and out of government who have long harbored suspicions about the proper place of far right ultranationalists in Ukraine's civil society.    

A Potent Fifth Column

War in general is not declared. It simply begins.
Georgii Samoilovich Isserson

It is a dubious suggestion that a field commander would commit an order to writing directing subordinates to commit what indisputably constitutes a war crime.  That alone casts doubt on documents purporting to order false flag incidents against civilian populations.  It is not, however, probative regarding all of the documents in question.  It is certainly conceivable that military commanders would be reluctant to disclose casualty numbers in the midst of a mobilization and might direct that these statistics be withheld.  As to alleged criminal acts committed by individuals associated with political parties that are part of the Ukrainian governing coalition (or regarding government-aligned paramilitaries), those claims are impossible to assess from the outside.   Suffice it to say, however, that the bar should be high — far higher than allegedly cracked documents of dubious content and provenance — to seriously entertain taking such documents at face value.  At the end of the day it is up to the Ukrainian people to decide.

There is no independent way to assess the status of the allegedly cracked documents released by groups like CyberBerkut or Russiya Vesna.  It is possible some are genuine and mean what they say, but at the same time, genuine documents can be placed in a misleading context when bundled with altered or forged ones.  It is also possible that some may be sourced from genuine documents but altered to create false meaning and to deceive.  As to whether either is probable, the reader is left to decide.

There is no expectation that Russian dezinformatsia will lead to a groundswell of support for the pro-Russia separatists in eastern Ukraine.  That is not the intent.  It is to shape Ukrainian perceptions that the Maidan movement of just a year ago is a revolution betrayed.  The intent is not to mobilize; it is to demoralize.

Vladislav Surkov's short story "Without Sky" concludes on a powerful note:

"We organized a rebellion of the simple, the two-dimensional people against the complex and cunning. We are against those who never say ‘yes’ or ‘no’.  Who say neither 'black' nor 'white.'  Who know the third word.  There are many, many third words.  Empty, false, confusing ways that darken the truth.  These ways are the house of Satan.  There, they make money and bombs, saying 'Here's money for the benefit of the honest, here's a bomb for the protection of love.'  We begin tomorrow. We will win. Or lose. There is no third option."

The siren song of Russian disinformation notwithstanding, there is indeed no third option for Ukraine: it is either a sovereign nation or it is not.  What is unresolved is whether a sovereign Ukraine will remain territorially intact, and whether democratic government will wither or flourish there.  That is a struggle in which Russian dezinformatsia poses a potent fifth column.


