Russian Software Firm Microolap Denies Major Breach After Hacker Claims
Russian software developer Microolap has confirmed a cybersecurity incident but refuted claims by the hacking group Black Spark that it breached its core systems or stole sensitive customer data. The company, which specializes in network traffic analysis tools like EtherSensor, acknowledged that hackers compromised several non-critical systems but insisted its primary infrastructure and customer data remained secure.
The breach was first reported on Wednesday when Black Spark claimed to have spent over a month inside Microolap’s network, accessing internal systems and exfiltrating data from high-profile clients, including Russian Railways, state banknote producer Goznak, VTB Bank, and IT firm NEK.TECH. The group shared screenshots allegedly proving the intrusion, though their authenticity could not be independently verified.
Microolap countered these claims in a statement on Thursday, stating that the affected systems an outdated website, a rarely used development environment, and an old Bitrix24 customer management instance were isolated from its main operations. The company confirmed that EtherSensor and production systems remained unaffected, with no disruption to performance or data integrity.
While Black Spark described itself as an "underground movement" engaged in "armed resistance" within Russia, Microolap maintained that its cybersecurity measures successfully contained the incident. The firm has since taken the compromised systems offline, implemented additional security protocols, and engaged an unnamed major Russian cybersecurity firm to assist in its investigation.
Goznak TPRM report: https://www.rankiteo.com/company/goznak
VTB Bank TPRM report: https://www.rankiteo.com/company/vtb
Microolap TPRM report: https://www.rankiteo.com/company/microolap-technologies
"id": "vtbmicgoz1787322302",
"linkid": "vtb, microolap-technologies, goznak",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Network Traffic Analysis Tools',
'location': 'Russia',
'name': 'Microolap',
'type': 'Software Developer'},
{'industry': 'Transportation',
'location': 'Russia',
'name': 'Russian Railways',
'type': 'State-owned Enterprise'},
{'industry': 'Banking/Finance',
'location': 'Russia',
'name': 'Goznak',
'type': 'State Banknote Producer'},
{'industry': 'Banking/Finance',
'location': 'Russia',
'name': 'VTB Bank',
'type': 'Bank'},
{'industry': 'Information Technology',
'location': 'Russia',
'name': 'NEK.TECH',
'type': 'IT Firm'}],
'data_breach': {'data_exfiltration': 'Alleged (unverified)'},
'description': 'Russian software developer Microolap confirmed a '
'cybersecurity incident but refuted claims by the hacking '
'group *Black Spark* that it breached its core systems or '
'stole sensitive customer data. The company acknowledged that '
'hackers compromised several non-critical systems but insisted '
'its primary infrastructure and customer data remained secure.',
'impact': {'data_compromised': 'Non-critical systems data (allegedly)',
'operational_impact': 'Minimal (isolated non-critical systems)',
'systems_affected': 'Outdated website, rarely used development '
'environment, old Bitrix24 customer management '
'instance'},
'initial_access_broker': {'high_value_targets': 'Russian Railways, Goznak, '
'VTB Bank, NEK.TECH (alleged)',
'reconnaissance_period': 'Over a month (claimed by '
'threat actor)'},
'investigation_status': 'Ongoing',
'motivation': 'Armed resistance (claimed by threat actor)',
'references': [{'source': 'Microolap Statement'},
{'source': 'Black Spark Claims'}],
'response': {'communication_strategy': 'Public statement refuting breach '
'claims',
'containment_measures': 'Compromised systems taken offline',
'remediation_measures': 'Additional security protocols '
'implemented',
'third_party_assistance': 'Unnamed major Russian cybersecurity '
'firm'},
'threat_actor': 'Black Spark',
'title': 'Microolap Cybersecurity Incident',
'type': 'Data Breach'}