Automatically translated version. May contain inaccuracies compared to the original.
A coordinated information attack on Ukrainian companies via anonymous resources deals a direct blow to the country’s economic resilience Ukrainian business during the war is one of the key elements of the state’s economic resilience. At the same time, coordinated information attacks on companies undermine trust in business and the country’s investment image. Anonymous Telegram channels and manipulative websites previously attacked Philip Morris, Meest China, Uklon, and other companies. In recent months a similar campaign has been underway against Ajax Systems and its founder, Oleksandr Konotopskyi. RBC-Ukraine examines how this market for media attacks operates and what threats it poses to business and the state. Key points The main platform for media attacks is anonymous Telegram channels. Discrediting campaigns have characteristic signs and mechanics. Information attacks use trigger topics for society. Reputational attacks on businesses can have consequences for the country’s economy. How the market for information attacks works Information campaigns targeting businesses have long ceased to be isolated incidents, and in the Ukrainian segment of Telegram a distinct market has formed for distributing commissioned content. According to media market researchers, the combined audience of the largest 14 Telegram channels that regularly and systematically post commissioned materials approaches 12 million readers. The mechanics of the attacks in most cases look similar. First a primary publication appears — often on a little-known resource or in a Telegram channel. After that it is almost simultaneously picked up by dozens of other channels repeating the same theses, and later some phrasings begin to be quoted by websites or even large media outlets. In some cases, which businesses have publicly reported before, the information pressure was accompanied by demands to stop the campaign in exchange for a fee. That is why some business representatives call such practices digital terrorism or reputational extortion. Media expert Oksana Moroz notes that today Telegram has become the main environment for launching such campaigns. As a rule, the same text or identical theses begin to appear almost simultaneously across a network of Telegram channels. It is enough to check a key phrase through search or a monitoring system — and you will see that the messages appeared practically synchronously. This is one of the clearest markers of a coordinated campaign, she explains. Next you need to analyze the content of the messages. If identical discrediting messages are spread, that is a sign of a black information campaign. If, in a similar way, positive messages are massively spread, that is also a campaign, but aimed at protecting or promoting a particular subject, Oksana Moroz says. According to the expert, a few years ago such campaigns often started on dubious websites and then moved to social networks. Today the situation has changed: in most cases Telegram is the primary platform, and only afterward is the information spread by other resources. A well-tested scheme Philip Morris Ukraine reported that it repeatedly faced waves of discrediting campaigns. In particular, it was reported that there were over 200 negative publications in 66 Telegram channels with a combined audience of about six million users, and the scale of the campaign was estimated at more than 100 thousand dollars. PMU links such campaigns to its consistent stance against the illegal tobacco market and its support for transparent and fair rules of the game. In fact, the mechanics of most information attacks are very similar to propaganda. It uses manipulative or deliberately false information that primarily appeals to emotions, shared Victoria Ilinska, head of communications at Philip Morris in Ukraine, describing common traits of such campaigns. In March 2024 the CEO of Uklon, Serhii Hryshkov, publicly accused a scandalously known Telegram channel of a disinformation attack that, he said, developed into real digital terrorism. Hryshkov reported more than 300 negative publications over two months and claimed the company was offered to stop the campaign for 200 thousand dollars. After that Uklon appealed to law enforcement. It should be noted that, according to RBC-Ukraine, Ajax Systems employees also received offers from intermediaries to settle the issue for a financial reward. A similar scenario of campaign deployment was described by Meest China co-owner Viacheslav Lysenko. In 2024 a number of Telegram channels spread information about his alleged involvement in organizing an underground casino that was exposed by the NABU. The businessman himself was not a subject of the related criminal proceedings and filed lawsuits to protect his honor, dignity, and business reputation. In April 2025 a wave of publications hit the Textile-Contact group of companies. The company was accused without evidence of monopolizing government procurements, cooperating with Russia, and supplying poor-quality products. Later, publicist Oleksandr Kochetkov, whose post was one of the sources of this information, said he had been misled, retracted his claims, and apologized. Similar information campaigns also affected dozens of other businesses. Despite differences between individual stories, they share common features: synchronous dissemination of identical messages, use of unverified or anonymous sources, appeals to the topics most sensitive to society, and the absence of any request to the company before publishing accusations. The Russian factor in campaigns against Ukrainian business Particular attention is drawn by the fact that most discrediting theses about Ajax Systems that are spread by Ukrainian resources are almost simultaneously duplicated in Russian social networks and public pages. That is, the attack on the company is actively amplified not only in Ukraine but also directly in the Russian information space. This case gains additional weight because it concerns a company that participated pro bono in creating and provides technical support for the national app “Air Alarm,” integrated with the alerting system — one of the key civil defense tools that daily helps warn the population about missile and aviation threats. Accordingly, amplification of such an attack from the Russian side is not just a hit to the reputation of a single business, but effectively a threat to Ukraine’s national security: this is a company that acts in the interests of that security. Experts note that such campaigns objectively align with Russia’s interests because they undermine trust in Ukrainian producers, weaken the country’s investment attractiveness, and create additional risks for the economy during wartime. How an information campaign works: the Ajax Systems case Recent publications about Ajax Systems and its founder Oleksandr Konotopskyi contain a number of signs of a coordinated information-media attack described above. Chain of dissemination The first publications about Ajax Systems began to appear en masse in early June. One of the most active platforms was a Telegram channel that positions itself as an international detective bureau. Over two months it published more than two dozen posts about the company and its founder. Screenshot At the same time, several other small Telegram channels published similar content, and later some theses began to appear in much larger million-audience channels. Screenshot The next stage was the spread of these materials on a number of dubious websites. Some later publications in larger media already referred not to the original Telegram posts but to those sites, creating the effect of numerous independent confirmations. Screenshot That very scheme is characteristic of many information campaigns, Oksana Moroz says. According to her, today it often happens either that materials are launched simultaneously across a network of Telegram channels, or an expert opinion is used that is then massively replicated by different platforms. Campaign themes: from business to personal A separate point of interest is the evolution of the campaign’s messages. In the initial stage most publications that were identical in content and phrasing addressed state procurements, the defense sector, and interaction with government agencies. The publications began to include assumptions about the alleged connection of the company or related structures with military contracts, although no evidence for such claims was provided. Later the emphasis shifted to Ajax Systems’ international activities: its work in foreign markets, accusations of ties to Russia, the structure of the business, and production sites. This is one of the most sensitive techniques in such information special operations: creating a public impression of a business’s ties to Russia, which in wartime is the quickest way to demonize the attack target and destroy its reputation. Screenshot The next stage was placing Ajax Systems’ founder into a political context. In mid-July, when protests were ongoing over personnel changes in the government, Telegram channels began to massively spread claims that Oleksandr Konotopskyi was allegedly financing them. The authors of the publications provided no evidence for these accusations either, but posts of this type appeared daily at the peak of the protests. Screenshot Oksana Moroz considers the use of such storylines a typical technique in discrediting campaigns. During such campaigns a company or its owner is linked not so much to specific organizations as to topics that are most sensitive to society at that moment. If the trigger is Russia — they use the Russia theme. If society is discussing a political crisis or a corruption scandal — they try to integrate the business into that context, the expert explains. At the same time the business reputation was blurred by delving into the founder’s private life — discussions of purchases, family, household details, and so on — which is a standard psychological technique to demonize an object in the eyes of ordinary citizens. What was accused and how the company comments RBC-Ukraine analyzed the main theses circulated in the information space about Ajax Systems and its founder and compared them with the company’s public position. Most accusations related to topics most sensitive to Ukrainian society — ties to Russia, the defense sector, politics, and the personal reputation of the company’s owner. Participation in the group’s defense procurements Major accusations began with the thesis that Ajax Systems performs defense contracts and transfers funds abroad. Or that non‑Ukrainian companies in the group received money from the defense company Skyfall. Ajax Systems, however, assures that it never had any defense order and never received money from the companies named in the publications. This is confirmed by the company’s independent audit reports from a Big Four firm. Politics and control over media and political meetings During personnel reshuffles in the government and protests over Mykhailo Fedorov’s resignation as minister of defense of Ukraine, Telegram channels synchronously spread the thesis that Oleksandr Konotopskyi allegedly finances rallies with Russian money. The most posts about sponsorship without any evidence appeared precisely at the peak of the protests in mid-July. On this backdrop accusations also surfaced that Konotopskyi allegedly controls certain Ukrainian media and that he has ties to representatives of big business and politics. One likely goal of this campaign may have been to create the impression of a conflict between a Ukrainian entrepreneur and the authorities, presenting him as a sponsor of chaos without any evidence. Ajax Systems categorically denies these accusations, noting that the company has no political component to its activity and is not connected to any political movements or processes. Work on the Russian and Belarusian markets Another widespread thesis was the accusation that the company continued to operate via Kazakhstan with subsequent re-export of products to Russia. Ajax Systems rejects this. They reported that they ceased operations in the Russian and Belarusian markets in March 2022. The company provided the editorial office with independent audit conclusions from a Big Four firm and substantial evidence confirming the 2022 statement about exiting the market. It is also worth adding that one of Ajax Systems’ shareholders is the international fund Horizon Capital, whose rules and policies make any sales to EU- or US-sanctioned countries impossible. A factory in Vietnam is being built instead of Ukraine Another topic of discussion was opening production in Vietnam. In a number of publications this was presented as allegedly relocating production from Ukraine. The company explains that Ajax has long been a global company and the company’s main operations do not take place in Ukraine. But that does not mean Ajax has stopped investing in Ukraine. According to Ajax Systems, the Ukrainian team’s headcount has doubled since the full-scale war began. So creating jobs in Ukraine remains a major focus for the company. *** Over two months the information campaign against Ajax Systems evolved from manipulations about international activities to accusations of influence on the country’s socio-political situation. However, the Ajax case is not unique but another proof of the already formed industry of reputational extortion in Ukraine, through which other market leaders have previously passed. The experience of businesses that have already faced information attacks indicates the importance of comprehensive protection against them. In particular, Philip Morris Ukraine advises continuously monitoring the information field, having worked-out response scenarios, promptly communicating with key audiences while carefully assessing the necessity of a public reaction, taking into account the risk of unintentionally amplifying attention to false reports. In the conditions of a full‑scale war, large information attacks on systemic Ukrainian business go far beyond corporate conflicts. If they are based on manipulation or unreliable information, their consequences can be not only reputational harm to individual companies but also reduced trust in Ukrainian producers, deterioration of the country’s investment image, and additional pressure on the economy, which is one of the key elements of the state’s resilience. That is why countering coordinated discrediting campaigns is not only a matter of protecting the business reputation of individual companies but also a component of Ukraine’s economic and information security.
Document: PDF proof of the original version of the news item "Бізнес як мішень: як медійні атаки б'ють по економічній стійкості України". It records the publication content at the moment of the first scan, the preservation date and the source: RBC-Ukraine.