Russian software developer Microolap confirmed that hackers compromised several non-critical systems but denied that attackers gained access to its EtherSensor network monitoring platform or stole customer data.
Microolap Data Breach Claims Versus Corporate Denials
A hacking group calling itself Black Spark claimed it spent more than a month inside Microolap’s network. According to the group’s statements published on Telegram, the attackers gained access to internal systems, including the EtherSensor network traffic analysis platform. The cybercriminals stated they managed to steal and wipe information belonging to prominent Russian organizations, such as Russian Railways, the state banknote and document manufacturer Goznak, VTB Bank together with its leasing arm, and the Russian technology firm NEK.TECH. To support these claims, the group published several screenshots purporting to show compromised systems and obtained data, though the authenticity of these images could not be independently verified.
Microolap acknowledged that attackers compromised some peripheral systems but strongly rejected the threat group’s account of the breach. Based on the findings of the company’s internal probe, intruders managed to infiltrate a handful of infrequently utilized development environments managed by an external Russian vendor, a legacy iteration of its web portal, and a deprecated Bitrix24 customer relationship management database containing minimal information. Microolap CEO Andrey Smirnov urged the public not to treat the attackers’ claims as fact. “Our cybersecurity systems worked as intended: We detected the incident and kept critical data secure,” Smirnov stated.
Isolation of Core Infrastructure and EtherSensor Security
The affected systems were completely isolated from Microolap’s core infrastructure. According to the company, this separation prevented attackers from reaching EtherSensor or accessing proprietary partner and customer data. Microolap confirmed that none of its production systems or components critical to EtherSensor were affected by the intrusion.
Did you know? EtherSensor is a specialized network traffic analysis platform used for intercepting and examining digital data packets, making its security a primary target for advanced threat groups operating in the region.
Following the detection of the breach, Microolap took its outdated website offline and deployed additional security controls. The firm also partnered with one of Russia’s largest cybersecurity companies—which remains unnamed—to investigate the intrusion.
The Adversary: Black Spark’s Origin and Tactics
Black Spark describes itself as an underground movement operating inside Russia. In a manifesto posted on Telegram, members stated that they remain within the country and chose what they characterized as armed resistance. The group relies on publicizing partial screenshots and unverified data extracts to amplify the perceived impact of its network intrusions, a common tactic in politically or ideologically motivated cyberattacks.
Frequently Asked Questions
Did hackers access Microolap’s EtherSensor platform?
No. Microolap confirmed that its core infrastructure, production components, and the EtherSensor platform remained secure and unaffected by the breach.
Which organizations were allegedly targeted in the data leak?
The hacking group Black Spark claimed to have extracted data belonging to Russian Railways, Goznak, VTB Bank and its leasing subsidiary, and NEK.TECH, though Microolap denies any customer data was compromised.
What systems were actually compromised during the incident?
According to Microolap, attackers gained access to a few rarely used development systems hosted by an external provider, an outdated corporate website, and an old Bitrix24 customer management system.
What are your thoughts on how software developers handle legacy development systems? Share your insights in the comments below, explore our latest cybersecurity reports, or subscribe to our newsletter for real-time threat intelligence updates.
Related reading