Kharkiv sits close enough to the Russian border that the thud of artillery is part of the newsroom's daily backdrop. For the reporters who refuse to leave, the danger has expanded well beyond rocket strikes and drone attacks. Their phones, laptops and cloud accounts have become a second battlefield, and a small cohort of trainers is teaching them to fight back. Backed by the Free Press Foundation, the programme focuses on practical digital security skills for a single afternoon.
Workshops gather local stringers, regional staff journalists and citizen contributors who document life under bombardment. Many arrived thinking they only needed to worry about physical safety, then realised their inboxes had been probed and their private Signal threads scraped.
Australia has watched these developments closely. Reporters from the ABC, The Guardian Australia and Crikey have filed from Ukraine since 2022, often relying on local fixers and stringers in cities like Kharkiv and Dnipro. Australian outlets have a stake in making sure those collaborators survive the digital threats that shadow them long after a foreign correspondent flies home.
What follows draws on conversations with trainers, participants and editors in both Ukraine and Australia, sketching how a fragile but promising programme is taking shape in one of Europe's most exposed cities.
Kharkiv's proximity to the border makes it a natural base for both Ukrainian and international media. It also makes it a hunting ground for hostile intelligence services, whose phishing campaigns and SIM-swap attempts have multiplied since the full-scale invasion. Trainers chose the city for its dense pool of working journalists, reliable internet and a sympathetic municipal administration willing to host sessions.
Local universities, some still operating partly online, have provided rooms that can be secured quickly. Editors who trained in the Soviet system before the 1990s are receptive to new technical ideas because they have seen what happens when state-aligned actors gain leverage over a newsroom.
Participants describe a routine that would alarm most Australian journalists. A reporter covering a strike might receive a text from a supposed colleague, asking for shared-drive credentials. Another might find their Telegram channel flooded with hostile comments designed to unmask anonymous sources. A third could open an email attachment that quietly installs spyware on a phone used to photograph military checkpoints.
The attackers are patient. They build profiles of individual journalists over months, piecing together personal details from social media, leaked databases and intercepted calls. Once they understand a target's daily rhythm, they can craft a message that feels routine, slipping past the usual caution.
These tactics echo patterns documented in research on what are the characteristics of an authoritarian government, where control of information flows is treated as a strategic priority rather than a byproduct of political ideology.
Sessions start with a candid conversation about mistakes. Trainers ask when attendees last reused a password, clicked an unfamiliar link or shared a draft over consumer messaging apps. The room typically goes quiet, then fills with laughter as journalists recognise themselves. That vulnerability is the foundation on which the rest of the curriculum is built.
Each participant leaves with a personalised setup: a password manager, two-factor authentication on every account that supports it, and a simple routine for wiping devices before crossing checkpoints. Trainers also walk them through encrypted cloud storage, secure file-sharing with editors abroad, and the basics of threat-modelling.
The curriculum borrows from guidance published by Australia's own cyber agencies, including the Australian Cyber Security Centre, whose advisories resonate as strongly in a Kharkiv kitchen as in a Canberra office. Journalists learn to segment their work across devices, keep personal accounts separate from sensitive ones, and treat every unsolicited message with the same suspicion.
Australian editors can back their Ukrainian colleagues by adopting similar habits. Using end-to-end encryption for source communication, rotating credentials after every assignment, and avoiding public Wi-Fi at conferences in Brisbane or Sydney are small steps that mirror the discipline being taught in eastern Ukraine.
Australia's media landscape is closely connected to events in Ukraine. Australian taxpayers have funded non-lethal military assistance, refugee support and information-warfare research, while Australian outlets continue to commission long-form features from the region. Protecting those local reporters is a direct investment in the integrity of stories that appear in Australian papers and broadcasts.
The work also offers lessons for homegrown newsrooms. The same phishing kits and spyware tools used against Ukrainian stringers have surfaced in reporting by journalists behind Mariupol's siege and in attacks on Australian public servants, health agencies and political campaigns. Treating digital security as core craft rather than a luxury for foreign correspondents helps everyone.