Your Business Is Already a Wartime Target. Here Is What to Do About It.

Nation-states attacking private companies is not a future risk. It happened at scale in 2017 and the conditions that made it possible have only grown more complicated since.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a dimly lit modern open-plan office at night, rows of dark computer screens glowing faintly blue, empty chairs
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Russian military hackers planted a hidden backdoor in a Ukrainian tax-software update in 2017, and the resulting attack caused tens of billions of dollars in damage to thousands of companies worldwide.
  • Ordinary businesses, not just defence contractors, can qualify as military targets under international humanitarian law.
  • The Trump administration's March 2026 "Cyber Strategy for America" document commits the US to offensive hacking operations, which could push other nations to hit private-sector companies harder in retaliation.
  • Practical steps exist that companies of all sizes can take to lower their profile as a target.

In 2017, a Ukrainian company called Intellect Services sold accounting software called M.E.Doc to businesses across the country. Unremarkable in every way that matters. Then Russian foreign military intelligence, through a hacking group known as Sandworm, buried a hidden backdoor (a secret entry point into a computer system) inside a routine M.E.Doc software update.

The result was NotPetya, malicious software that wiped data from any machine it touched. It escaped Ukraine almost immediately. Shipping giant Maersk, pharmaceutical company Merck, and hundreds of other firms with no interest in Eastern European politics found their systems destroyed. Damage estimates reached tens of billions of dollars.

Intellect Services never signed up for a war.

Why would any nation-state come after your company?

You might not need a government contract to look like a target. Jonathan Horowitz, a legal adviser at the International Committee of the Red Cross, points to the 1977 Geneva Conventions, which define a military objective as anything that makes "an effective contribution to military action" and whose destruction offers "a definite military advantage." That definition is broader than most business owners realise.

Allie Mellen, an analyst at Forrester Research and author of "Code War," spelled this out at the Zenith Live 2026 conference in Las Vegas. "If you have a contract with the military, you are a target," she said. But suppliers with no defence connection can find themselves in the line of fire too.

Medical equipment firm Stryker, which sells supplies to several US military branches, was targeted by Handala, an Iranian hacking group linked to Iran's Ministry of Intelligence and Security. Stryker doesn't build weapons or run intelligence operations. It sells hospital equipment, and that was enough to attract attention. Our 8 June piece on how Ukraine built resilience under sustained Russian attack showed exactly how fast civilian infrastructure becomes a military problem.

The Trump administration's March 2026 "Cyber Strategy for America" raises the stakes further. Its opening commits the US to deploying "offensive cyber operations," a pledge Mellen says will prompt other nations to ask how hard they can hit American private-sector companies before it triggers a response.

Should you worry if you're not a defence contractor?

Yes, and the Stryker case is the clearest illustration of why. Mellen recommends that companies avoid publicly listing military or government clients on their websites. Horowitz suggests separating the systems serving civilian customers from those serving public-sector clients, and keeping data centres physically away from military sites. For smaller businesses, partnering with a managed security vendor that provides threat monitoring adds visibility that's otherwise unaffordable in-house.

Geopolitical shifts create new targets fast. A company invisible to foreign governments last year may not be this year, and reviewing that exposure honestly is now basic operational sense.

© 2026 Threat Vectr