Ukraine's State Service of Special Communications and Information Protection (SSSCIP) warned this week that Russian operators are increasingly targeting the smartphones of military personnel, government officials and civilians. According to The Record's report on the SSSCIP findings, the toolset includes DarkSword, an iPhone exploit kit delivered through compromised news and government websites. Once a phone is infected, the operators can steal credentials, messages, contacts and call histories within minutes. On Android, the campaigns tracked as UAC-0244 (CamelSpy) and UAC-0263 (BTMOB) used decoy sites impersonating a Ukrainian army corps, air-raid alert apps and fuel-discount apps. CERT-UA logged 3,137 incidents in the first half of 2026, up 8% on the prior six months.
This is a data-flow story as much as a malware story. Every exfiltrated contact list is a cross-border transfer that no data subject consented to and no regulator authorised. It also exposes a gap in how Ukraine, and most countries, frame transfer policy.
The case for tighter borders
The strongest argument for restricting transfers or mandating residency runs as follows. Data held abroad is harder to protect and harder to recall, and a state at war has legitimate reason to keep sensitive records under its own jurisdiction. If adversaries are systematically pulling data off Ukrainian devices, a rule that keeps data at home looks like a sensible defence. That instinct deserves respect.
It also fails on the facts of this threat. DarkSword and CamelSpy do not go through any transfer channel that a residency law could regulate. They compromise the endpoint, and the data leaves the device regardless of where the organisation's servers sit. A residency mandate would not have stopped a single incident described in the SSSCIP warning. It would, however, add compliance cost to the companies and agencies least able to bear it.
Ukraine's own wartime record argues the other way
Ukraine's experience since 2022 points toward geographic diversification. After the full-scale invasion began, the government pushed its critical data into cloud infrastructure. The Cabinet's January 2024 decision expanding the Ministry of Digital Transformation's powers over cloud services states the rationale plainly: after the invasion, "the most important data is in cloud storage," and Russian attempts to destroy archives did not cause a collapse. The Ministry shapes cloud policy and the SSSCIP acts as regulator. The underlying law, signed in March 2022, was presented as letting state bodies store data in the cloud. The lesson is that resilience came from moving data beyond the reach of Russian missiles and intrusions, not from keeping it in one place.
A strict residency rule would put that lesson at risk. Data stored only on Ukrainian soil is exposed to kinetic strikes, physical seizure and the same network intrusions that CERT-UA tracks daily. Residency should remain a risk-based choice: sovereign or in-country hosting for a narrow class of data, and trusted foreign cloud regions for the rest.
The transfer regime that does need fixing
The more pressing problem is the legal framework for lawful transfers. Under the 2010 Law on Personal Data Protection, as summarised by DLA Piper, transfers are allowed to countries providing an "appropriate level of protection" and otherwise depend on grounds such as consent or contract necessity. Ukraine, in turn, is not on the European Commission's list of adequacy decisions. Adequacy is the mechanism in Article 45 of the GDPR that lets EU personal data flow freely to a recognised country. Without it, Ukrainian firms handling EU customer data face added friction, and the country's IT services sector pays for it.
Draft Law No. 8153, submitted on 25 October 2022 to align Ukraine with the GDPR and Convention 108+, was adopted as a basis on 20 November 2024 and was awaiting a second reading as of that summary. Ukraine should finish it. A modern law with clear transfer tools, an independent supervisor and enforceable accountability rules serves two purposes: it moves Ukraine toward EU adequacy, and it gives regulators a lawful basis for going after the actors who mishandle data.
What proportionate policy looks like
The SSSCIP findings suggest three priorities.
- Secure the endpoint first. Mandate patch and mobile-device-management baselines for government and military-adjacent users, and treat compromised official websites as a state-security failure. Watering-hole attacks work because trusted government and news sites are the delivery channel.
- Classify data instead of drawing borders. Keep a small tier of genuinely sensitive data under in-country or sovereign control, and permit transfers of everything else to jurisdictions with demonstrable safeguards. A blanket residency mandate treats a municipal permit record like a military roster.
- Complete the legislative work. Adopt Draft Law 8153 with proportionate transfer mechanisms such as standard contractual clauses, so that legitimate flows have a lawful path while illicit exfiltration is treated as a security matter.
The bottom line
Involuntary data flows are a real and growing cost of the war. But the data leaving Ukrainian phones is leaving through the endpoint, not through a policy gap in transfer law. Data localisation would cost Ukraine's economy and resilience while leaving the DarkSword problem untouched. A better response is to invest in device security, tier data by sensitivity, and pass the data protection law that would bring Ukraine closer to the EU's adequacy list. That protects citizens and preserves the open, cloud-enabled digital state that has served Ukraine well since 2022.