Bauman Leak Exposes GRU Cyber Pipeline

Leaked Bauman training records show a 2024 Department No. 4 graduate linked to Military Unit 74455, better known as Sandworm, and point to a formal GRU personnel pipeline rather than isolated operator placements. The files also describe training paths feeding several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate. The records suggest Moscow is grooming cyber talent through a structured path from university recruitment to supervised technical and ideological preparation, then into intelligence and cyber posts. That matters because it makes Russian cyber capacity look less like separate branded groups and more like a shared workforce that can be reused across espionage, destructive activity, reconnaissance, and influence work. For government, defense, and CTI teams, the leak shifts the unit of analysis from a single actor label to the institution that produces and routes personnel. It does not prove every named graduate took part in a specific operation, but it does show how Sandworm-style activity can sit inside a broader GRU system whose edges are still only partly visible.

Part of the PlainSec briefing for 2026-09-01

Editions

Sources