Menu
Browse

Cyber Incident Victim: Microolap

Date

Aug 2026

Location

Russia

Status

Unknown

Updated

2026-08-21 16:59

Timeline
Occurred
Jul 2026
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending
Summary

Microolap confirmed that hackers had compromised some of its systems but denied that they accessed its core network monitoring platform or stole customer data. The attackers identifying as the pro‑Ukraine group Black Spark claimed they had spent over a month inside the network gained access to EtherSensor and extracted data from customers such as Russian Railways Goznak VTB Bank and its leasing arm and NEK.TECH. Microolap said its investigation showed the breach was limited to rarely used development systems hosted by a third party an outdated website version and an old Bitrix24 CRM containing only a small amount of data all isolated from critical infrastructure. The company added that EtherSensor continued to operate normally and the incident had no effect on performance data integrity or availability. Black Spark describes itself as an underground movement in Russia and has posted a manifesto on Telegram advocating armed resistance.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 0 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

On August 20, 2026, Microolap announced that its cybersecurity systems had detected an attempted breach of several non‑critical systems within its environment. The company stated that the intrusion was identified promptly and that no evidence was found indicating that the attackers had accessed its core infrastructure, customer data or other sensitive information. Microolap’s chief executive, Andrey Smirnov, urged the public not to accept the attackers’ claims as fact and emphasized that the firm’s defenses had functioned as intended by keeping critical data secure. The announcement came one day after a hacking group called Black Spark claimed to have infiltrated Microolap’s network for more than a month.

Cyber Incident Image

Microolap acknowledged that some of its systems had indeed been compromised but contested the scope described by Black Spark. According to the company’s internal investigation, the attackers gained access only to a set of rarely used development systems that were hosted by a third‑party Russian provider, to an outdated version of the firm’s public website, and to an old Bitrix24 customer‑management system that contained a limited amount of data. These affected environments were isolated from Microolap’s core infrastructure, meaning that the breach did not provide the intruders with a pathway to EtherSensor, the company’s network traffic analysis platform, nor to any customer or partner data. Microolap affirmed that none of its production systems or components essential to EtherSensor were affected and that the platform continued to operate normally without any impact on performance, data integrity or availability.

Black Spark asserted that it had extracted and deleted data belonging to several Microolap customers, including Russian Railways, the state banknote and document producer Goznak, VTB Bank and its leasing subsidiary, and the Russian IT firm NEK.TECH, and it published screenshots purporting to show the compromised systems and the data taken; the authenticity of those images could not be independently verified. The group describes itself as an underground movement in Russia and, in a manifesto posted on Telegram, stated that its members had remained in the country and chosen what it termed armed resistance. Microolap’s statement concluded that, despite the attackers’ claims, the incident had not resulted in any loss of critical data or disruption to its services.

Sources
Sources available to members
1 source