CSIDB logo
Incident

CDEK

Incident posture

Attack window
May 2024
Location
Russia
Status
Historical
CIA posture
Available to members
Updated
2025-12-31 13:09

Linked entities

Victim
CDEK
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
May 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A major Russian delivery service experienced a multi-day operational disruption following a ransomware attack by the hacker group Head Mare, which encrypted servers and destroyed backups. The company initially attributed the outage to technical failures but later faced internal and governmental acknowledgments of a cyberattack, leading to suspended parcel shipments, website and mobile app malfunctions, and widespread customer delivery delays—some causing significant financial losses. The attackers, who criticized the firm's security measures and service quality, have previously targeted other Russian entities. The company worked to restore operations while assuring customers of parcel safety.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 28-29, 2024, CDEK Express, one of Russia’s largest delivery companies, experienced a severe service disruption lasting at least three days. The company initially attributed the outage to a "massive technical failure" affecting its website, mobile application functionality, and parcel processing systems. CDEK suspended shipments to prevent errors during manual operations, assuring customers their parcels remained secure. By May 1, CDEK’s communications director stated significant restoration progress had been made but confirmed operations were not fully restored, with a target resumption date of May 29. Customers across Russia reported delivery delays, including a Novosibirsk resident whose package intended for children remained undelivered five days after its expected arrival and another individual facing a 40,000-ruble ($450) financial loss due to the delay.

The hacker group Head Mare claimed responsibility for the incident on May 1 via X (formerly Twitter), alleging they encrypted CDEK’s servers with ransomware and destroyed backup copies of corporate systems. They criticized CDEK’s system administrators as "too weak" and declared the company’s security policies ineffective. An anonymous CDEK employee told Vedomosti the disruption resulted from a ransomware attack, while the head of the Russian State Duma’s information policy committee publicly confirmed a cyberattack caused the outage. Head Mare, active since December 2023, has previously targeted Russian internet providers, government agencies, and industrial firms but provided no motive beyond calling CDEK "one of the worst delivery services in Russia." Independent outlet Meduza noted CDEK’s prior use by Russian soldiers to send packages from the Ukrainian border early in the invasion. CDEK operates over 4,300 pickup points across 31 countries, with a 2021 valuation of $200 million. The company maintained public assurances about parcel safety and backup recovery plans but did not formally acknowledge the cyberattack.

Sources

Sources available to members: 1 source.

CSIDB