- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,243
The CSB SOC has published the landscape of cyber threats 2025.

To attack a large company, attackers increasingly do not need a direct hack of the main infrastructure. A contractor becomes a weak point: an integrator, IT service provider or a partner with remote access. Through a trusted channel, hackers get logged in to the corporate network, and the victim does not see an invasion for a long time, but the usual work of the external performer.
The SCFR SOC presented at the CIPP conference a study “Langtaf of cyber threats 2025/2026: trends, attacks, vulnerabilities” and a forecast for Russian companies for 2026. According to analysts of Threat Intelligence, at least 30% of known cyber attacks in 2025 went through the compromising IT contractors. This channel has become one of the key trends: criminals use access of trusted partners, bypass some of the usual checks and stay invisible longer.
Attacks have become faster and more difficult. Attackers combine data encryption, information theft, publication threats and pressure through DDoS. The role of already known vulnerabilities has increased separately: the number of incidents where primary access was received through the CVE described increased by about 30% compared to 2024. For companies, the problem is especially unpleasant, because it is often not about unknown mistakes, but about spaces for which patches and public descriptions already exist.

The SCSC study identifies 65 vulnerabilities most critical of the Russian market. Operating systems and workstations accounted for 44%, network infrastructure and services - 27%, for application software and libraries - 23%, on corporate IT platforms - 6%. Microsoft products focus about 43% of vulnerabilities that were actively used in attacks. In Russian IT solutions, attackers more often used errors in video conferencing servers, postal systems and endpoint protection.
The activity of APT-groups against Russian organizations increased by 25-30%. The growth was provided mainly by well-known players who have intensified attacks on large and strategically important industries. The report also cite the CrowdStrike score: the path from primary penetration to targeted action on average reduced to 48 minutes, and in the fastest cases to 51 seconds.

DDoS attacks also ceased to be a simple overload of sites. The number of attacks at network levels increased by 24.18%, the most powerful attack reached 1.57 Tbps, and the share of the industrial sector increased by 357%. Among the most active groups of 2025, the SOC calls IT Army of Ukraine, CyberSec (adB), Himars DDOS and Cybercorpus. The main goal was Russian telecom providers.
In 2026, experts expect more powerful strikes on critical infrastructure with the expectation of not a short failure, but on the long degradation of services. A separate risk is associated with Ransom-DDoS, when infrastructure overload is combined with a ransom requirement. AI reinforces the threat: algorithms help generate adaptive malicious traffic and circumvent the typical filtering rules.
The average volume of one leak in Russia reached 3.27 million records, which is 26% more than in 2024. Personal data accounted for 74% of the total volume of leaked information. The main channel of the publication remained Telegram: it accounted for about 72% of reports of leaks, while the darknet and closed forums took 26%.
The most affected public sector, industry, finance, IT, transport and logistics, as well as retail. The public sector accounted for 22% of incidents, the industry - 21%, finance - 14%, IT - 12%, transport and logistics - 10%, retail - 9%. Over the past two years, the total volume of compromised data in these industries has exceeded 1.6 billion records, and the share of incidents with a leak of more than 10 million records has tripled.

In 2026, the MCSB expects the growth of attacks with several targets at once. Encryption will complement data theft, publishing threats and air accessibility strikes. Industrial control systems, IoT equipment and smart sensors will be at risk, because hacking industrial systems can lead to real production downtime.
The main protection measures are related to the control of entrance points. Companies are advised to tightly manage contractors’ access, use VPNs with MFA, segment the network, apply the principle of minimum privileges, keep unchanging backups, monitor the public perimeter, strengthen monitoring via SIEM and EDR/XDR, automate responses and conduct hardening critical systems.

To attack a large company, attackers increasingly do not need a direct hack of the main infrastructure. A contractor becomes a weak point: an integrator, IT service provider or a partner with remote access. Through a trusted channel, hackers get logged in to the corporate network, and the victim does not see an invasion for a long time, but the usual work of the external performer.
The SCFR SOC presented at the CIPP conference a study “Langtaf of cyber threats 2025/2026: trends, attacks, vulnerabilities” and a forecast for Russian companies for 2026. According to analysts of Threat Intelligence, at least 30% of known cyber attacks in 2025 went through the compromising IT contractors. This channel has become one of the key trends: criminals use access of trusted partners, bypass some of the usual checks and stay invisible longer.
Attacks have become faster and more difficult. Attackers combine data encryption, information theft, publication threats and pressure through DDoS. The role of already known vulnerabilities has increased separately: the number of incidents where primary access was received through the CVE described increased by about 30% compared to 2024. For companies, the problem is especially unpleasant, because it is often not about unknown mistakes, but about spaces for which patches and public descriptions already exist.

The SCSC study identifies 65 vulnerabilities most critical of the Russian market. Operating systems and workstations accounted for 44%, network infrastructure and services - 27%, for application software and libraries - 23%, on corporate IT platforms - 6%. Microsoft products focus about 43% of vulnerabilities that were actively used in attacks. In Russian IT solutions, attackers more often used errors in video conferencing servers, postal systems and endpoint protection.
The activity of APT-groups against Russian organizations increased by 25-30%. The growth was provided mainly by well-known players who have intensified attacks on large and strategically important industries. The report also cite the CrowdStrike score: the path from primary penetration to targeted action on average reduced to 48 minutes, and in the fastest cases to 51 seconds.

DDoS attacks also ceased to be a simple overload of sites. The number of attacks at network levels increased by 24.18%, the most powerful attack reached 1.57 Tbps, and the share of the industrial sector increased by 357%. Among the most active groups of 2025, the SOC calls IT Army of Ukraine, CyberSec (adB), Himars DDOS and Cybercorpus. The main goal was Russian telecom providers.
In 2026, experts expect more powerful strikes on critical infrastructure with the expectation of not a short failure, but on the long degradation of services. A separate risk is associated with Ransom-DDoS, when infrastructure overload is combined with a ransom requirement. AI reinforces the threat: algorithms help generate adaptive malicious traffic and circumvent the typical filtering rules.
The average volume of one leak in Russia reached 3.27 million records, which is 26% more than in 2024. Personal data accounted for 74% of the total volume of leaked information. The main channel of the publication remained Telegram: it accounted for about 72% of reports of leaks, while the darknet and closed forums took 26%.
The most affected public sector, industry, finance, IT, transport and logistics, as well as retail. The public sector accounted for 22% of incidents, the industry - 21%, finance - 14%, IT - 12%, transport and logistics - 10%, retail - 9%. Over the past two years, the total volume of compromised data in these industries has exceeded 1.6 billion records, and the share of incidents with a leak of more than 10 million records has tripled.

In 2026, the MCSB expects the growth of attacks with several targets at once. Encryption will complement data theft, publishing threats and air accessibility strikes. Industrial control systems, IoT equipment and smart sensors will be at risk, because hacking industrial systems can lead to real production downtime.
The main protection measures are related to the control of entrance points. Companies are advised to tightly manage contractors’ access, use VPNs with MFA, segment the network, apply the principle of minimum privileges, keep unchanging backups, monitor the public perimeter, strengthen monitoring via SIEM and EDR/XDR, automate responses and conduct hardening critical systems.