<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/schneier-on-security-zmbxixwkg" -->

---
title: Schneier on Security | daily.dev
description: Leaked training materials from Bauman Moscow State Technical University&#x27;s Department No. 4 reveal a formalized pipeline recruiting students into Russian...
canonical: https://daily.dev/posts/schneier-on-security-zmbxixwkg
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Schneier on Security | daily.dev
og:description: Leaked training materials from Bauman Moscow State Technical University&#x27;s Department No. 4 reveal a formalized pipeline recruiting students into Russian...
og:url: https://daily.dev/posts/schneier-on-security-zmbxixwkg
og:image: https://api.daily.dev/og/posts/zmbXIXwKg.png
og:image:alt: Schneier on Security
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Schneier on Security

**[Schneier on Security](https://daily.dev/sources/schneier)** · 2 min read · 0 upvotes · 0 comments

## Summary

Leaked training materials from Bauman Moscow State Technical University's Department No. 4 reveal a formalized pipeline recruiting students into Russian military and intelligence cyber roles, including GRU units like the 8th Directorate. The leak links a 2024 graduate to Military Unit 74455 (Sandworm), known for destructive attacks including 2017's NotPetya, though it does not prove individual operational involvement for all listed graduates. The material reframes Russian cyber capability as an institutionalized system rather than isolated threat groups like APT28 and Sandworm, suggesting defenders should track overlapping personnel pipelines across espionage, destructive activity, and influence operations.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.schneier.com/blog/archives/2026/09/leaked-russian-cyber-operations-training-materials.html>

## Questions this post answers

### What is Military Unit 74455 and how is it connected to Sandworm?

Military Unit 74455 is widely known as Sandworm, a group associated with destructive cyber activity against Ukraine and other targets, including the 2017 NotPetya attack. Leaked Russian training records linked a 2024 Department No. 4 graduate from Bauman Moscow State Technical University to this unit, though this does not prove that graduate personally participated in named operations.

_Security teams tracking state-sponsored threat actors like Sandworm can follow developments like this on daily.dev._

### What do the leaked Bauman University records reveal about Russian cyber operations training?

The leaked records describe a force-generation mechanism feeding several General Staff components, including the GRU, its Main Operational Directorate, and the 8th Directorate, which handles protected communications, cryptography, and information security. They reframe Russian cyber capability as an institutional system with a formalized recruitment pathway from university into intelligence, cyber, and security roles, rather than isolated well-known threat groups.

_Researchers studying nation-state threat pipelines can track analysis like this on daily.dev._

## Similar posts on daily.dev

- [CTI Research: Sandworm / APT44](https://daily.dev/posts/cti-research-sandworm-apt44-qhmgi2dli) · InfoSec Write-ups · 0 upvotes · 0 comments
- [Response to CISA Advisory \(AA25-343A\): Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure](https://daily.dev/posts/response-to-cisa-advisory-aa25-343a-pro-russia-hacktivists-conduct-opportunistic-attacks-against--etypghjmt) · Security Boulevard · 0 upvotes · 0 comments

---

[View this post on daily.dev](https://daily.dev/posts/schneier-on-security-zmbxixwkg)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Schneier on Security","url":"https://daily.dev/posts/schneier-on-security-zmbxixwkg","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/schneier-on-security-zmbxixwkg"},"datePublished":"2026-09-01T16:31:53.379Z","dateModified":"2026-09-01T16:47:12.570Z","description":"Leaked training materials from Bauman Moscow State Technical University's Department No. 4 reveal a formalized pipeline recruiting students into Russian...","image":"https://media.daily.dev/image/upload/s--ZrL_HSsR--/f_auto/v1722860399/public/Placeholder%2006","thumbnailUrl":"https://media.daily.dev/image/upload/s--ZrL_HSsR--/f_auto/v1722860399/public/Placeholder%2006","isAccessibleForFree":true,"articleSection":"Schneier on Security","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Schneier on Security","logo":"https://media.daily.dev/image/upload/s--0aZDA7eZ--/f_auto/v1758461069/logos/schneier","url":"https://daily.dev/sources/schneier"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/schneier-on-security-zmbxixwkg","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Schneier on Security","item":"https://daily.dev/sources/schneier"},{"@type":"ListItem","position":3,"name":"Schneier on Security"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/schneier-on-security-zmbxixwkg#faq","mainEntity":[{"@type":"Question","name":"What is Military Unit 74455 and how is it connected to Sandworm?","acceptedAnswer":{"@type":"Answer","text":"Military Unit 74455 is widely known as Sandworm, a group associated with destructive cyber activity against Ukraine and other targets, including the 2017 NotPetya attack. Leaked Russian training records linked a 2024 Department No. 4 graduate from Bauman Moscow State Technical University to this unit, though this does not prove that graduate personally participated in named operations. Security teams tracking state-sponsored threat actors like Sandworm can follow developments like this on daily.dev."}},{"@type":"Question","name":"What do the leaked Bauman University records reveal about Russian cyber operations training?","acceptedAnswer":{"@type":"Answer","text":"The leaked records describe a force-generation mechanism feeding several General Staff components, including the GRU, its Main Operational Directorate, and the 8th Directorate, which handles protected communications, cryptography, and information security. They reframe Russian cyber capability as an institutional system with a formalized recruitment pathway from university into intelligence, cyber, and security roles, rather than isolated well-known threat groups. Researchers studying nation-state threat pipelines can track analysis like this on daily.dev."}}]}
```

