Novabev Group
Incident posture
Linked entities
- Victim
- Novabev Group
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
A large-scale, coordinated cyberattack temporarily disrupted part of the IT infrastructure of the alcohol retail group and its ВинЛаб store network, affecting the availability of certain services and tools. The attackers contacted the company and demanded a monetary ransom, which the organization firmly refused, citing a policy of not engaging with cybercriminals. Internal IT teams worked around the clock to restore operations, supported by external forensic experts brought in to accelerate the investigation. Based on the information available at the time of the statement, no customer personal data was reported to be compromised, though the inquiry remained ongoing. The incident prompted the company to acknowledge the growing aggressiveness of cybercrime and to commit to strengthening its existing defensive measures.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 14, 2025, Novabev Group, the parent company of the Russian retail chain Winelab (ВинЛаб), was targeted by what the company officially characterized as an unprecedented cyberattack. According to the official statement issued by the group on July 16, 2025, the incident was described as a large-scale and coordinated action carried out by hackers. The attack succeeded in temporarily disrupting the operation of a portion of the company's IT infrastructure, which in turn affected the availability of certain services and tools used both by Novabev Group and by the Winelab retail network. Prior to this event, Novabev Group stated that it had placed significant emphasis on cybersecurity, citing regular improvements to its infrastructure protections, daily monitoring, vulnerability remediation, and employee training, which had previously allowed the company to repel earlier attacks. The July 14 incident, however, was portrayed as exceptional in both scale and coordination, representing a successful breach despite these prior defenses.
Following the cyberattack, the perpetrators contacted the company and issued a demand for a monetary payment, effectively attempting to extort the organization. Novabev Group publicly stated its principled position of rejecting any form of interaction with cybercriminals and categorically refused to comply with their demands. The company's IT team was reported to be working around the clock to address the situation, and external experts were engaged to assist in accelerating the investigation. The official communications emphasized that all efforts were being directed toward restoring services as quickly as possible. As of the statement dated July 16, 2025, the investigation was still ongoing, though the available information at that time indicated that customer personal data had not been affected. The company acknowledged the growing aggressiveness of cybercrime and expressed its intent to draw lessons from the incident in order to strengthen its defensive mechanisms and minimize the risk of similar attacks in the future.
The consequences of the attack centered on the partial disruption of IT infrastructure, which manifested as reduced availability of certain services and operational tools for both the corporate group and the Winelab store network. The company did not specify in its public statement which specific systems, applications, or business processes were affected, nor did it disclose technical indicators such as the attack vector, the type of malicious activity involved, or the identity or affiliation of the threat actors. There was no mention of data encryption, ransomware deployment, data theft, or any specific tactic, technique, or procedure associated with the incident. Likewise, the duration of the disruption, the number of stores or services impacted, and any potential financial consequences were not detailed in the available source material. The company's official communications focused instead on confirming the occurrence of the attack, the ransom demand, the refusal to negotiate, the ongoing recovery efforts, and the preliminary assessment that customer personal data remained unaffected.
Novabev Group apologized to its customers and partners for the inconvenience caused by the incident and expressed gratitude for the support and understanding received during the disruption. The two available source documents are identical in content, consisting of the same official statement published on the company's press room, with the second instance being an archived version of the same page. No additional follow-up statements, technical analyses, or updates regarding the resolution of the incident, the identification of the attackers, or any subsequent regulatory or legal actions were present in the provided evidence. Based solely on the information available, the incident is documented as a coordinated external cyberattack on July 14, 2025, resulting in temporary partial IT service disruption, an extortion demand that was publicly rejected, and an ongoing internal and external investigation into the full scope and impact of the breach.
Sources
Sources available to members: 2 sources.