Cyber Incident Victim: VTB Bank
Date:
May 2017
Location:
Russia
Summary
The WannaCry ransomware attack compromised systems at several Russian financial institutions, with the central bank confirming isolated incidents among credit organizations that were promptly addressed. VTB Bank was identified as a target by security researchers, though the extent of any system damage remained unclear; the institution maintained that its operations were unaffected and asserted its systems lacked the vulnerabilities exploited by the malware. The global attack particularly impacted Russian entities, highlighting security flaws in critical infrastructure, while the central bank pledged enhanced transparency regarding future cyber threats and countermeasures.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 4 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 3 actors | Available to members | Available to members |
Description
The WannaCry ransomware attack impacted Russian banking institutions in May 2017, with the Central Bank of Russia confirming on May 12 that isolated compromises had occurred despite earlier assertions of unsuccessful targeting. This marked the first official acknowledgment of operational disruptions within Russia's financial sector from the global cyber extortion campaign. The central bank stated that consequences were swiftly addressed but did not specify technical details regarding breached systems or data. Prior to this admission, the institution had maintained that Russian banks repelled the attacks when initially targeted in late April or early May. Following the incident, the central bank reissued cybersecurity recommendations to financial institutions and announced plans to publicly document future cyber incidents and security reinforcement measures.

Security researchers identified VTB Bank as an attack target, though the extent of system compromise remained unverified. VTB declined to confirm whether its infrastructure was breached but asserted normal operations across its retail banking division (VTB24) and corporate systems, claiming its systems lacked the vulnerabilities exploited by WannaCry. Sberbank, Russia’s largest bank, reported repelling a virus attack without infection. Kaspersky Lab researchers noted "a couple" of unnamed Russian banks encountered WannaCry, typically affecting employee workstations or non-critical systems rather than core banking infrastructure. The incident highlighted vulnerabilities in outdated operating systems within embedded devices across Russian institutions. Globally, while ATM ransom screens were reported in Asia, Reuters found no verified bank compromises outside Russia. The central bank’s revised transparency measures reflected heightened institutional awareness of cyber threats following an attack that exposed systemic security gaps in critical sectors.
