CSIDB logo
Incident

Russian National Visa Bureau

Incident posture

Attack window
Dec 2016
Location
Netherlands
Status
Historical
CIA posture
Available to members
Updated
2026-01-10 21:42

Linked entities

Victim
Russian National Visa Bureau
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Dec 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Russian National Visa Bureau's website was compromised via a blind SQL injection attack, exposing personal data including names, phone numbers, email addresses, and login credentials with a hashed password from approximately 13,000 accounts. The attacker identified the same vulnerability in a related consular department website hosted on the same server but refrained from publishing the sensitive information. Administrators were notified and acknowledged the breach, planning remediation while keeping both sites operational until implementing fixes that caused intermittent downtime.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On December 15, 2016, security researcher Kapustkiy breached the official website of the Russian National Visa Bureau (RNVB) in the Netherlands, exposing personal data of thousands of users. The compromised information included names, phone numbers, and email addresses, with at least one account revealing login credentials containing a hashed password. Kapustkiy employed a blind injection attack to access the databases but refrained from publicly disclosing the data due to its sensitive nature, estimating approximately 13,000 accounts were affected. The RNVB website, operational since 2003 as a subsidiary of the PDC Foundation, provided visa services for Dutch businesses and private clients, handling information typically associated with visa applications. Kapustkiy notified website administrators of the breach immediately after discovery to facilitate remediation. During his investigation, he identified that the RNVB shared hosting infrastructure with the Consular Department of the Embassy of the Russian Federation in the Netherlands, which he had previously compromised using the same vulnerability.

Both the RNVB and Embassy Consular Department websites remained online despite Kapustkiy’s notifications, continuing to operate with unpatched security flaws. Administrators from ambru.nl acknowledged Kapustkiy’s report and indicated plans to deploy fixes within days, though no immediate downtime occurred. The Russian National Visa Bureau administrators subsequently confirmed they were investigating the breach and preparing vulnerability patches, anticipating temporary service interruptions during remediation. No evidence suggested unauthorized data misuse occurred between the breach discovery and administrator notifications. The incident highlighted risks associated with shared hosting environments and persistent vulnerabilities affecting government-affiliated visa processing platforms.

Sources

Sources available to members: 1 source.

CSIDB