Cyber Incident Victim: Microolap
Timeline
Summary
Microolap confirmed that hackers had compromised some of its systems but denied that they accessed its core network monitoring platform or stole customer data. The attackers identifying as the pro‑Ukraine group Black Spark claimed they had spent over a month inside the network gained access to EtherSensor and extracted data from customers such as Russian Railways Goznak VTB Bank and its leasing arm and NEK.TECH. Microolap said its investigation showed the breach was limited to rarely used development systems hosted by a third party an outdated website version and an old Bitrix24 CRM containing only a small amount of data all isolated from critical infrastructure. The company added that EtherSensor continued to operate normally and the incident had no effect on performance data integrity or availability. Black Spark describes itself as an underground movement in Russia and has posted a manifesto on Telegram advocating armed resistance.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 0 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On August 20, 2026, Microolap announced that its cybersecurity systems had detected an attempted breach of several non‑critical systems within its environment. The company stated that the intrusion was identified promptly and that no evidence was found indicating that the attackers had accessed its core infrastructure, customer data or other sensitive information. Microolap’s chief executive, Andrey Smirnov, urged the public not to accept the attackers’ claims as fact and emphasized that the firm’s defenses had functioned as intended by keeping critical data secure. The announcement came one day after a hacking group called Black Spark claimed to have infiltrated Microolap’s network for more than a month.

Microolap acknowledged that some of its systems had indeed been compromised but contested the scope described by Black Spark. According to the company’s internal investigation, the attackers gained access only to a set of rarely used development systems that were hosted by a third‑party Russian provider, to an outdated version of the firm’s public website, and to an old Bitrix24 customer‑management system that contained a limited amount of data. These affected environments were isolated from Microolap’s core infrastructure, meaning that the breach did not provide the intruders with a pathway to EtherSensor, the company’s network traffic analysis platform, nor to any customer or partner data. Microolap affirmed that none of its production systems or components essential to EtherSensor were affected and that the platform continued to operate normally without any impact on performance, data integrity or availability.
Black Spark asserted that it had extracted and deleted data belonging to several Microolap customers, including Russian Railways, the state banknote and document producer Goznak, VTB Bank and its leasing subsidiary, and the Russian IT firm NEK.TECH, and it published screenshots purporting to show the compromised systems and the data taken; the authenticity of those images could not be independently verified. The group describes itself as an underground movement in Russia and, in a manifesto posted on Telegram, stated that its members had remained in the country and chosen what it termed armed resistance. Microolap’s statement concluded that, despite the attackers’ claims, the incident had not resulted in any loss of critical data or disruption to its services.