Microolap Confirms Cyberattack as Pro-Ukraine Hackers Claim Russian Data Theft
Russian network monitoring software developer Microolap confirmed that hackers compromised several of its systems this week, but pushed back against claims by a pro-Ukraine hacking group that attackers gained access to the company's flagship EtherSensor platform and stole data from major Russian organizations. CEO Andrey Smirnov said Thursday that the company's cybersecurity defenses detected the intrusion and kept critical infrastructure secure, urging the public not to treat the attackers' claims as fact.
The intrusion was claimed by Black Spark, a group that describes itself as an “underground movement in Russia” practicing what it calls “armed resistance” from within the country. According to a manifesto published on Telegram, the group said it spent more than a month inside Microolap's network and obtained access to EtherSensor, the company's network traffic analysis platform. Black Spark claimed it extracted and deleted data belonging to several high-profile Russian customers, including Russian Railways, state banknote and document producer Goznak, VTB Bank and its leasing subsidiary, and Russian IT firm NEK.TECH. The group published screenshots purporting to show compromised systems and stolen data, though their authenticity could not be independently verified. Organizations concerned about exposure can run their email domains through a breach checker to assess potential compromise.
Microolap acknowledged that some systems were breached but said these were limited to non-critical assets: several rarely used development systems hosted by a third-party Russian provider, an outdated version of the company's website, and an old Bitrix24 customer management system containing a limited amount of data. The company stressed that those systems were isolated from core infrastructure and that their compromise did not provide access to EtherSensor, customer data, or partner information. Microolap took its outdated website offline, deployed additional security measures, and is investigating with the help of an unnamed major Russian cybersecurity firm. Network administrators reviewing their own exposure can use a SSL/TLS checker to identify outdated certificates and a port scanner to verify exposed services.