For ten years, the Moscow-based company NTC "Vulkan" developed cyberwarfare tools for the FSB, GRU, and SVR in complete secrecy — operating with state clearances for classified information, closed contracts, and contractors who were former military personnel.

This secrecy was not broken by a foreign intelligence hacker, but by the company's own engineer, who was outraged by the war.

An Ordinary Office on the Outskirts of Moscow

NTC "Vulkan" is a medium-sized company registered as a regular cybersecurity contractor. It was founded in 2010 by Anton Markov and Alexander Irzhavsky — both graduates of a St. Petersburg military academy, who served in the army, reaching the ranks of captain and major, respectively. Since 2011, the company has held state licenses to work on classified military projects and materials containing state secrets.

Outwardly, it's an unremarkable business center on the northeastern outskirts of Moscow, next to residential buildings and an old cemetery. Inside, however, it developed hacking and disinformation tools commissioned by Russian special services.

Scan-V: Digital Intelligence for "Sandworm"

One of Vulkan's key products is the Scan-V system, commissioned in May 2018. This is a continuously operating scanner that scours the internet for software and hardware vulnerabilities, storing its findings for subsequent use in hacking operations.

In one of the leaked technical documents, military unit 74455 is listed as the "approving party" for the data exchange system — this is Sandworm, a special GRU unit responsible for some of the most high-profile cyberattacks of the last decade. Scan-V tests involving the GRU took place in 2020.

Amezit: The Internet as a Weapon

Vulkan received the contract for the Amezit system back in 2016. This is a far more ambitious tool: it allows for the interception and modification of internet traffic, wireless, and mobile communications within a limited geographical area, as well as blocking the use of Tor and VPN.

Amezit also manages over a hundred fake social media profiles to conduct large-scale disinformation campaigns — distributing content via social networks, email, fake websites, and telephone networks. Among the documents related to the system are lists of target servers in the USA and other countries, including, according to the investigation, a nuclear power plant in Switzerland. In 2018, Vulkan employees traveled to Rostov-on-Don in connection with their work on Amezit — specifically to the Radio Engineering Institute, which is linked to the FSB.

Kristall-2V: A Simulator for Saboteurs

The third major project is the "top secret" classified training platform "Kristall-2V" (contracts from 2018–2020). It is designed for up to 30 operators to work simultaneously and simulates attacks on railways, power plants, airports, waterways, ports, and industrial control systems — effectively training cyber saboteurs specifically for strikes against civilian infrastructure.

The Informant Outraged by the War

A few days after Russia's full-scale invasion of Ukraine began in February 2022, an anonymous informant contacted the German newspaper Süddeutsche Zeitung, stating that the GRU and FSB were "hiding behind Vulkan." This marked the beginning of work on the material, which took over a year.

Journalists obtained over 5,000 pages of the company's internal documents from 2016–2021: correspondence, contracts, estimates, technical specifications, and training materials. The investigation was coordinated by Munich-based Paper Trail Media, with The Guardian, The Washington Post, Le Monde, Der Spiegel, and several other publications joining the effort to analyze the data. In total, eleven media outlets worldwide simultaneously published the leaked materials on March 30, 2023.

Connections That Surfaced

Beyond the direct link to "Sandworm," the leaked documents, according to journalists, also indicate the company's connection to the Cozy Bear (APT29) group — another hacking entity that Western intelligence agencies associate with Russian intelligence. Journalists were unable to confirm whether Vulkan's specific developments were used in attacks on the territory of occupied Ukraine — this remains an undocumented fact, not a proven assertion.

The Outcome

Vulkan is a precise mirror image of Russia's system of secrecy itself: a closed company working for closed special services, hiring people from closed military academies, protected by state secrecy laws. For ten years, this system operated without a single public leak.

It was not a foreign intrusion into the company's protected servers that brought it down, but one engineer who, apparently, ran out of patience after February 24, 2022. Such a leak could not have been foreseen by any information security protocol — because it occurred not in the code, but in the mind of the person who was obligated to maintain that secrecy.