Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Risk»Threatscape»Do the Wildberries attacks expand the threatscape for global retailers? (Page 2)
Threatscape

Do the Wildberries attacks expand the threatscape for global retailers?

July 30, 20264 Mins Read
Signage on a Wildberries building.

Ukraine’s repeated drone attacks on warehouses operated by Wildberries, Russia’s largest online retailer, represent a potentially important development in the targeting of commercial infrastructure.

The attacks have reportedly damaged around 10% of the company’s warehousing capacity, destroyed substantial quantities of stock and affected tens of thousands of independent merchants. The consequences have spread beyond Wildberries: Russian banks are considering support for borrowers affected by the losses, while the Kremlin may have to help stabilise a business regarded as important to Russia’s consumer economy.

Ukraine says Wildberries supports the Russian military by transporting sanctioned electronics, drone components and other potentially military goods. The marketplace also sells equipment such as body armour, drone accessories, and field supplies, although most of its business remains ordinary consumer retail. A Ukrainian defence industry executive has additionally highlighted the company’s relationship with state-controlled VTB and its wider importance to Russia’s banking system.

The significance therefore lies less in the fact that a retailer was attacked than in why it was selected. Wildberries is simultaneously a marketplace, fulfilment network, payments platform, and financial ecosystem. Damaging a relatively small number of major warehouses can affect merchants, lenders, consumers, tax revenues, and public confidence. This case suggests retail infrastructure can be considered according to its systemic function rather than simply its commercial classification – though it is one case, not yet evidence of a settled doctrine shift.

For Western retailers, this does not mean that shops and warehouses automatically become military targets. Economic importance alone is not sufficient to make a civilian facility a legitimate military objective under international humanitarian law. Nor is there public evidence that global retailers operating in Ukraine have been placed on Russian target lists.

Nevertheless, the Wildberries campaign could strengthen Russian narratives that retailers operating in or supporting Ukraine are part of the conflict’s logistics infrastructure. Russian state media has already attempted to use the attacks to justify strikes on Ukrainian supermarkets, despite producing no evidence of military activity at those sites.

Outside Ukraine, the most plausible retaliation would remain below the threshold of conventional military action. Russian-linked actors have already been implicated in an arson attack on an IKEA store in Vilnius, the burning of a London warehouse holding aid for Ukraine, and incendiary devices introduced into DHL and DPD parcel networks. Separately, on the cyber side, the UK’s National Cyber Security Centre has previously warned of a GRU campaign targeting Western logistics and technology organizations involved in supplying Ukraine – an espionage operation rather than physical sabotage, but evidence of the same strategic interest in the sector.

On this precedent, exposure falls into two categories rather than one. The first is operational: retailers that transport aid, supply Ukrainian state or military bodies, operate regional distribution centres in countries such as Poland or the Baltic states, or connect their Ukrainian operations directly to global identity, ERP, and logistics systems. The second is symbolic: as the IKEA case shows, a retailer can become a target simply by virtue of having exited Russia or being publicly associated with Ukraine, regardless of any operational link to the supply chain.

Retailers should map these connections, review the separation of Ukrainian and group-wide systems, review security at warehouses and parcel interfaces, and exercise compound scenarios involving physical damage, cyber disruption, and disinformation. Insurance exclusions, force majeure clauses, and liabilities to marketplace sellers also require attention.

Wildberries does not turn Western retail into a new battlefield. It does, however, demonstrate that a sufficiently interconnected retailer may now be viewed as strategic infrastructure – and targeted for the cascading disruption its failure could produce.

The author

David Honour – editor of Resilience Forward

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleCyber security can’t scale with humans anymore
Next Article UK Resilience Academy publishes new standards for resilient leadership

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
AI enabled business processes concept.

Operational resilience in an AI-dependent enterprise

August 26, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?