2PB is a lot, but it's not a crazy huge amount. It's only ~100 LTO tapes isn't it? Or a shelf or 2 of hard drives, perhaps backed up to one of their other sites?
I'd also heard it said that the Chinese clouds were really busy in the days around the invasion, suggesting the Russians were backing up out of country to them.
Maybe both Ukraine and Russia have weaponized their ransomware gangs?
They mostly weaponized themselves, in a sense. Before the 2022 invasion (yes, even after 2014), the entire post-Soviet cybercriminal space, including the Baltics, was tightly connected (not just ransomware which is a recent thing but also carders, DDoS-for-hire, scammers, etc) and everyone has been outsourcing parts of their "business" to everyone else. What media used to call Russian ransomware gangs were in most cases loose networks of criminals scattered all over the place. As the war started, they quickly separated and started attacking the legitimate infrastructure of the other side and also their former accomplices.
That's been ongoing ever since 2014. The famous Maersk hack, the most costly cyberattack in history was a Russian cyberattack that was intended to target Ukrainian banks and businesses.