Russian Cyber-Criminals
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor is publicly identified as Russian cyber‑criminals, also referred to in German sources as russische Cyber‑Kriminelle, and is associated with operations originating from Russia. No additional aliases, organizational structure, or state sponsorship are mentioned in the available material. The actor’s known activity is limited to a single reported intrusion against a European retail conglomerate.
In early November 2023 the actor targeted the KaDeWe Group, a German luxury department‑store operator, affecting its flagship Berlin location as well as the Alsterhaus in Hamburg and the Oberpollinger in Munich. According to the company’s statement, the breach attempt began on the night of Thursday to Friday and was promptly detected by the organization’s security and warning systems, which enabled early containment. As a precaution, the IT infrastructure was placed into an offline emergency mode; systems were later restored with only minor operational disruptions. Investigators confirmed that no customer payment data, account information, or passwords were accessed or exfiltrated during the incident. The KaDeWe Group notified law enforcement, filed a criminal complaint, and indicated ongoing cooperation with the Berlin police Cyber Crime Unit.
Beyond this specific event, the supplied sources do not provide any further details about the actor’s typical tactics, techniques, or procedures, such as particular malware families, initial‑access vectors, or tooling preferences. No additional campaigns, affiliations with criminal consortia, or broader targeting patterns are documented in the provided information. Consequently, the profile reflects only the confirmed facts concerning the November 2023 intrusion against the KaDeWe Group, with all other aspects remaining unspecified in the available evidence.
Incidents
Attributed incidents are available to members.
1 incident