Cyber Incident Victim: Petrovsky Fort
Timeline
Summary
A significant data breach impacted Petrovsky Fort and two other Russian firms, resulting in the leak of over 437,500 emails totaling approximately 400 GB. The incident, attributed to hacktivist groups including Anonymous, targeted entities linked to Russia's commercial and industrial sectors amid geopolitical tensions following the invasion of Ukraine. Distributed Denial of Secrets (DDoSecrets) facilitated the publication, which contained internal communications from the victim—a major Saint-Petersburg office complex owner—alongside an engineering firm serving oil/gas industries and a logging company. This leak formed part of a broader wave of cyberattacks against Russian state-affiliated organizations, with hacktivist collectives explicitly aligning their actions with opposition to the military conflict. The compromised data added to over 2 million emails previously exposed through similar campaigns targeting Kremlin-aligned entities.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On or around April 8, 2022, Distributed Denial of Secrets (DDoSecrets) published a data leak containing approximately 437,500 emails totaling over 400 GB from three Russian companies: Petrovsky Fort, Aerogas, and Forest. The leak included 300,000 emails (244 GB) from Petrovsky Fort, a Saint Petersburg-based owner of one of Russia's largest office complexes. Aerogas, an engineering firm serving Russia's oil and gas sector, contributed 100,000 emails (145 GB), while Forest, a logging company, accounted for 37,500 emails (35.7 GB). DDoSecrets attributed the data to the Anonymous hacktivist collective, which had exfiltrated the information from the companies. This incident formed part of a broader wave of cyberattacks against Russian entities following the country's February 24 invasion of Ukraine, with DDoSecrets having published over 2 million emails from Russian targets since the war began. The operation exemplified what analysts described as 'smash and grab' attacks targeting Russian commercial and state interests.

The Petrovsky Fort breach occurred within a geopolitical context marked by widespread hacktivist activity against Russian targets, including Anonymous, Ukraine's IT Army, and Hacker Forces. Prior incidents included an 800 GB data leak from VGTRK (Russia's state broadcaster) and a separate release of 5,500 emails from investment firm Thozis Corp. Other compromised entities included state nuclear agency Rosatom, space agency Roscosmos, and energy giant Gazprom. The United Nations reported over 10 million people displaced by the conflict, with 4.3 million fleeing Ukraine, while allegations of human rights violations led to Russia's suspension from the UN Human Rights Council. Hacktivist groups framed their actions as retaliation for both the invasion and associated humanitarian consequences, though the specific operational impact of the Petrovsky Fort email leak remained unquantified in available reporting.
