Stolichki
Incident posture
Timeline
Summary
Stolichki suspended operations across several regions after a cyberattack disrupted its digital infrastructure, affecting over 1,100 pharmacy locations in more than 80 cities and preventing access to prescriptions, medication reservations, loyalty programs and point‑of‑sale systems. The chain reported that cash registers and accounting were taken offline, some staff were placed on unpaid leave and IT teams worked to restore services, while a second pharmacy chain, Neopharm, experienced comparable outages that sent employees home as its systems remained nonfunctional.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Tuesday, two of Russia’s largest pharmacy chains, Neopharm and Stolichki, suspended operations across several regions after cyberattacks disrupted their digital infrastructure and brought their nationwide networks offline. The closures began on that day and quickly affected over 1,100 pharmacy locations in more than 80 cities across central Russia, preventing customers from accessing prescriptions, medication reservations, loyalty programs, and point‑of‑sale systems. Stolichki, the larger chain with more than 1,000 locations operating in Moscow, St. Petersburg, and the Leningrad, Tula, and Vladimir regions, initially cited “technical reasons” for the outages before later confirming that a cyberattack was the cause and stating that restoration efforts were underway. Notices posted to Stolichki’s website apologized for the disruption and assured customers that unavailable features would be restored soon.
The impact on Stolichki’s operations was extensive: according to the Telegram news channel Mash, all Stolichki locations in the Moscow area were forced to close entirely, with cash registers and accounting systems taken offline. Employees at affected stores were sent home as IT systems remained nonfunctional, and some staff were placed on unpaid leave while the company assessed the damage. Sources cited by Mash indicated that the outages could last up to two days, reflecting the severity of the disruption to the chain’s internal systems. Neopharm, which operates over 110 pharmacies in Moscow and St. Petersburg, experienced similar shutdowns, with its employees also sent home pending IT recovery.
Beyond the immediate incident, the pharmacy outages followed closely on the heels of a major cyberattack against Aeroflot, where Ukrainian hacking group Silent Crow and Belarusian group Cyber Partisans claimed responsibility for destroying 7,000 servers, crippling airport operations and prompting a confirmation from Russia’s Prosecutor General’s Office that the failures stemmed from unauthorized access. Prior to mid‑2022, both Stolichki and Neopharm were controlled almost entirely by businessman and former State Duma deputy Yevgeny Nifantiev, who transferred his stake to a closed‑end mutual investment fund called Zdravinvest after being sanctioned for his support of Russia’s invasion of Ukraine; Sergei Shulyak, CEO of DSM Group, noted that such fund structures can serve as protective mechanisms against secondary sanctions, allowing sanctioned individuals to maintain indirect control while providing legal separation from direct ownership. These factual details frame the Stolichki cyberattack within the broader context of recent cyber events affecting Russian enterprises.
Sources
Sources available to members: 1 source.