VYPR
breachPublished Aug 21, 2026· 1 source

Russian Network Monitoring Firm Microolap Confirms Cyberattack by Pro-Ukraine Hackers

Russian firm Microolap confirmed a cyberattack, but disputes the scope claimed by pro-Ukraine hackers Black Spark, who allege access to sensitive customer data.

Russian software developer Microolap has confirmed a cyberattack on some of its systems, though it disputes the extent of the breach claimed by a pro-Ukraine hacking group. The company stated that hackers did not gain access to its core infrastructure or customer data, contrary to the assertions made by the group known as Black Spark.

Black Spark claimed to have spent over a month within Microolap's network, allegedly accessing its EtherSensor network traffic analysis platform and exfiltrating data from several high-profile Russian clients. These alleged victims include Russian Railways, Goznak (a state banknote and document producer), VTB Bank and its leasing subsidiary, and IT firm NEK.TECH. The group also released screenshots purportedly showing compromised systems and stolen data, though their authenticity remains unverified.

Microolap CEO Andrey Smirnov urged the public to disregard the attackers' claims, emphasizing that the company's cybersecurity measures detected the incident and protected critical data. "Our cybersecurity systems worked as intended: We detected the incident and kept critical data secure," Smirnov stated.

The company's investigation revealed that the attackers accessed less critical systems, including rarely used development environments hosted by a third-party provider, an outdated version of Microolap's website, and an old Bitrix24 customer management system containing limited data. Microolap stressed that these compromised systems were isolated from its main infrastructure.

Crucially, Microolap asserted that the breach did not grant attackers access to EtherSensor, its flagship network analysis platform, nor did it compromise any customer or partner data. The company confirmed that its production systems and components essential for EtherSensor's operation remained unaffected, with no impact on the platform's performance, data integrity, or availability.

In response to the incident, Microolap has taken its outdated website offline, implemented additional security measures, and is collaborating with an unnamed major Russian cybersecurity firm to investigate the breach. The company's statement aims to counter the narrative presented by Black Spark, which describes itself as a Russian "underground movement" engaged in "armed resistance."

This incident highlights the ongoing cyber conflict between Russia and Ukraine, with hacking groups on both sides targeting critical infrastructure and technology companies. While Black Spark sought to publicize a significant breach, Microolap's swift response and detailed rebuttal underscore the importance of independent verification and the complexities of attributing and assessing the true impact of cyberattacks in wartime.

Synthesized by Vypr AI