NEWS 1.6 billion records. 51 seconds per hack. 357% increase in attacks on the promector. These are not anti-records – it is Russia in 2025

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,249
The CSB SOC has published the landscape of cyber threats 2025.
1780303871981.png
To attack a large company, attackers increasingly do not need a direct hack of the main infrastructure. A contractor becomes a weak point: an integrator, IT service provider or a partner with remote access. Through a trusted channel, hackers get logged in to the corporate network, and the victim does not see an invasion for a long time, but the usual work of the external performer.

The SCFR SOC presented at the CIPP conference a study “Langtaf of cyber threats 2025/2026: trends, attacks, vulnerabilities” and a forecast for Russian companies for 2026. According to analysts of Threat Intelligence, at least 30% of known cyber attacks in 2025 went through the compromising IT contractors. This channel has become one of the key trends: criminals use access of trusted partners, bypass some of the usual checks and stay invisible longer.

Attacks have become faster and more difficult. Attackers combine data encryption, information theft, publication threats and pressure through DDoS. The role of already known vulnerabilities has increased separately: the number of incidents where primary access was received through the CVE described increased by about 30% compared to 2024. For companies, the problem is especially unpleasant, because it is often not about unknown mistakes, but about spaces for which patches and public descriptions already exist.
1780303888382.png
The SCSC study identifies 65 vulnerabilities most critical of the Russian market. Operating systems and workstations accounted for 44%, network infrastructure and services - 27%, for application software and libraries - 23%, on corporate IT platforms - 6%. Microsoft products focus about 43% of vulnerabilities that were actively used in attacks. In Russian IT solutions, attackers more often used errors in video conferencing servers, postal systems and endpoint protection.

The activity of APT-groups against Russian organizations increased by 25-30%. The growth was provided mainly by well-known players who have intensified attacks on large and strategically important industries. The report also cite the CrowdStrike score: the path from primary penetration to targeted action on average reduced to 48 minutes, and in the fastest cases to 51 seconds.
1780303906566.png
DDoS attacks also ceased to be a simple overload of sites. The number of attacks at network levels increased by 24.18%, the most powerful attack reached 1.57 Tbps, and the share of the industrial sector increased by 357%. Among the most active groups of 2025, the SOC calls IT Army of Ukraine, CyberSec (adB), Himars DDOS and Cybercorpus. The main goal was Russian telecom providers.

In 2026, experts expect more powerful strikes on critical infrastructure with the expectation of not a short failure, but on the long degradation of services. A separate risk is associated with Ransom-DDoS, when infrastructure overload is combined with a ransom requirement. AI reinforces the threat: algorithms help generate adaptive malicious traffic and circumvent the typical filtering rules.

The average volume of one leak in Russia reached 3.27 million records, which is 26% more than in 2024. Personal data accounted for 74% of the total volume of leaked information. The main channel of the publication remained Telegram: it accounted for about 72% of reports of leaks, while the darknet and closed forums took 26%.

The most affected public sector, industry, finance, IT, transport and logistics, as well as retail. The public sector accounted for 22% of incidents, the industry - 21%, finance - 14%, IT - 12%, transport and logistics - 10%, retail - 9%. Over the past two years, the total volume of compromised data in these industries has exceeded 1.6 billion records, and the share of incidents with a leak of more than 10 million records has tripled.
1780303934549.png
In 2026, the MCSB expects the growth of attacks with several targets at once. Encryption will complement data theft, publishing threats and air accessibility strikes. Industrial control systems, IoT equipment and smart sensors will be at risk, because hacking industrial systems can lead to real production downtime.

The main protection measures are related to the control of entrance points. Companies are advised to tightly manage contractors’ access, use VPNs with MFA, segment the network, apply the principle of minimum privileges, keep unchanging backups, monitor the public perimeter, strengthen monitoring via SIEM and EDR/XDR, automate responses and conduct hardening critical systems.
 

MOONCLUBFORUMS

Well-known member
Member
Joined
Jul 12, 2026
Messages
120
Reaction score
0
Location
ABD
The CSB SOC has published the landscape of cyber threats 2025.
View attachment 267
To attack a large company, attackers increasingly do not need a direct hack of the main infrastructure. A contractor becomes a weak point: an integrator, IT service provider or a partner with remote access. Through a trusted channel, hackers get logged in to the corporate network, and the victim does not see an invasion for a long time, but the usual work of the external performer.

The SCFR SOC presented at the CIPP conference a study “Langtaf of cyber threats 2025/2026: trends, attacks, vulnerabilities” and a forecast for Russian companies for 2026. According to analysts of Threat Intelligence, at least 30% of known cyber attacks in 2025 went through the compromising IT contractors. This channel has become one of the key trends: criminals use access of trusted partners, bypass some of the usual checks and stay invisible longer.

Attacks have become faster and more difficult. Attackers combine data encryption, information theft, publication threats and pressure through DDoS. The role of already known vulnerabilities has increased separately: the number of incidents where primary access was received through the CVE described increased by about 30% compared to 2024. For companies, the problem is especially unpleasant, because it is often not about unknown mistakes, but about spaces for which patches and public descriptions already exist.
View attachment 268
The SCSC study identifies 65 vulnerabilities most critical of the Russian market. Operating systems and workstations accounted for 44%, network infrastructure and services - 27%, for application software and libraries - 23%, on corporate IT platforms - 6%. Microsoft products focus about 43% of vulnerabilities that were actively used in attacks. In Russian IT solutions, attackers more often used errors in video conferencing servers, postal systems and endpoint protection.

The activity of APT-groups against Russian organizations increased by 25-30%. The growth was provided mainly by well-known players who have intensified attacks on large and strategically important industries. The report also cite the CrowdStrike score: the path from primary penetration to targeted action on average reduced to 48 minutes, and in the fastest cases to 51 seconds.
View attachment 269
DDoS attacks also ceased to be a simple overload of sites. The number of attacks at network levels increased by 24.18%, the most powerful attack reached 1.57 Tbps, and the share of the industrial sector increased by 357%. Among the most active groups of 2025, the SOC calls IT Army of Ukraine, CyberSec (adB), Himars DDOS and Cybercorpus. The main goal was Russian telecom providers.

In 2026, experts expect more powerful strikes on critical infrastructure with the expectation of not a short failure, but on the long degradation of services. A separate risk is associated with Ransom-DDoS, when infrastructure overload is combined with a ransom requirement. AI reinforces the threat: algorithms help generate adaptive malicious traffic and circumvent the typical filtering rules.

The average volume of one leak in Russia reached 3.27 million records, which is 26% more than in 2024. Personal data accounted for 74% of the total volume of leaked information. The main channel of the publication remained Telegram: it accounted for about 72% of reports of leaks, while the darknet and closed forums took 26%.

The most affected public sector, industry, finance, IT, transport and logistics, as well as retail. The public sector accounted for 22% of incidents, the industry - 21%, finance - 14%, IT - 12%, transport and logistics - 10%, retail - 9%. Over the past two years, the total volume of compromised data in these industries has exceeded 1.6 billion records, and the share of incidents with a leak of more than 10 million records has tripled.
View attachment 270
In 2026, the MCSB expects the growth of attacks with several targets at once. Encryption will complement data theft, publishing threats and air accessibility strikes. Industrial control systems, IoT equipment and smart sensors will be at risk, because hacking industrial systems can lead to real production downtime.

The main protection measures are related to the control of entrance points. Companies are advised to tightly manage contractors’ access, use VPNs with MFA, segment the network, apply the principle of minimum privileges, keep unchanging backups, monitor the public perimeter, strengthen monitoring via SIEM and EDR/XDR, automate responses and conduct hardening critical systems.
Credit Credit card Credit card counterfeit money Credit card counterfeit money bomb Credit card counterfeit money bomb trigger Credit card, counterfeit money, bomb, hitman, drugs Credit card, counterfeit money, bomb, hitman, drugs, weapon Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence. Credit card, counterfeit money, bomb, hitman, drugs, weapon, hacker, military weapons, spy, intelligence agent Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence agents, fake. Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence agents, counterfeit money. Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence agents, counterfeit money, flash Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence agents, counterfeit money, flash USDT Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence agents, counterfeit money, flash USDT, crypto software. Credit cards, counterfeit money, bombs, gunmen, drugs, weapons, hackers, military weapons, spies, intelligence agents, counterfeit money, flash USDT, crypto software, bank accounts, money. Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence agents, counterfeit money, flash USDT, crypto software, depositing money into bank accounts Credit card, counterfeit money, bomb, gunman, drugs, weapon, hacker, military weapons, spy, intelligence agents, counterfeit money, flash USDT, crypto software, depositing money into bank accounts Mercenary mercenary hitman mercenary hitman assassin mercenary hitman assassin magic books mercenary hitman assassin magic books credit card mercenary hitman assassin magic books credit card mercenary, hitman, assassin, magic books, credit card, card clone mercenary hitman assassin spell books credit card card clone card wars mercenary hitman assassin spell books credit card card clone card wars

Session

050bbbee83794febed3c001a153cf99f2474b71f0952ba019fc62a1b206401a819
 

FLASHUSDTTTT

Well-known member
Member
Joined
Aug 3, 2026
Messages
50
Reaction score
18
The CSB SOC has published the landscape of cyber threats 2025.
View attachment 267
To attack a large company, attackers increasingly do not need a direct hack of the main infrastructure. A contractor becomes a weak point: an integrator, IT service provider or a partner with remote access. Through a trusted channel, hackers get logged in to the corporate network, and the victim does not see an invasion for a long time, but the usual work of the external performer.

The SCFR SOC presented at the CIPP conference a study “Langtaf of cyber threats 2025/2026: trends, attacks, vulnerabilities” and a forecast for Russian companies for 2026. According to analysts of Threat Intelligence, at least 30% of known cyber attacks in 2025 went through the compromising IT contractors. This channel has become one of the key trends: criminals use access of trusted partners, bypass some of the usual checks and stay invisible longer.

Attacks have become faster and more difficult. Attackers combine data encryption, information theft, publication threats and pressure through DDoS. The role of already known vulnerabilities has increased separately: the number of incidents where primary access was received through the CVE described increased by about 30% compared to 2024. For companies, the problem is especially unpleasant, because it is often not about unknown mistakes, but about spaces for which patches and public descriptions already exist.
View attachment 268
The SCSC study identifies 65 vulnerabilities most critical of the Russian market. Operating systems and workstations accounted for 44%, network infrastructure and services - 27%, for application software and libraries - 23%, on corporate IT platforms - 6%. Microsoft products focus about 43% of vulnerabilities that were actively used in attacks. In Russian IT solutions, attackers more often used errors in video conferencing servers, postal systems and endpoint protection.

The activity of APT-groups against Russian organizations increased by 25-30%. The growth was provided mainly by well-known players who have intensified attacks on large and strategically important industries. The report also cite the CrowdStrike score: the path from primary penetration to targeted action on average reduced to 48 minutes, and in the fastest cases to 51 seconds.
View attachment 269
DDoS attacks also ceased to be a simple overload of sites. The number of attacks at network levels increased by 24.18%, the most powerful attack reached 1.57 Tbps, and the share of the industrial sector increased by 357%. Among the most active groups of 2025, the SOC calls IT Army of Ukraine, CyberSec (adB), Himars DDOS and Cybercorpus. The main goal was Russian telecom providers.

In 2026, experts expect more powerful strikes on critical infrastructure with the expectation of not a short failure, but on the long degradation of services. A separate risk is associated with Ransom-DDoS, when infrastructure overload is combined with a ransom requirement. AI reinforces the threat: algorithms help generate adaptive malicious traffic and circumvent the typical filtering rules.

The average volume of one leak in Russia reached 3.27 million records, which is 26% more than in 2024. Personal data accounted for 74% of the total volume of leaked information. The main channel of the publication remained Telegram: it accounted for about 72% of reports of leaks, while the darknet and closed forums took 26%.

The most affected public sector, industry, finance, IT, transport and logistics, as well as retail. The public sector accounted for 22% of incidents, the industry - 21%, finance - 14%, IT - 12%, transport and logistics - 10%, retail - 9%. Over the past two years, the total volume of compromised data in these industries has exceeded 1.6 billion records, and the share of incidents with a leak of more than 10 million records has tripled.
View attachment 270
In 2026, the MCSB expects the growth of attacks with several targets at once. Encryption will complement data theft, publishing threats and air accessibility strikes. Industrial control systems, IoT equipment and smart sensors will be at risk, because hacking industrial systems can lead to real production downtime.

The main protection measures are related to the control of entrance points. Companies are advised to tightly manage contractors’ access, use VPNs with MFA, segment the network, apply the principle of minimum privileges, keep unchanging backups, monitor the public perimeter, strengthen monitoring via SIEM and EDR/XDR, automate responses and conduct hardening critical systems.
 

MATRİXELİTES

Well-known member
Member
Joined
Aug 4, 2026
Messages
443
Reaction score
53
The CSB SOC has published the landscape of cyber threats 2025.
View attachment 267
To attack a large company, attackers increasingly do not need a direct hack of the main infrastructure. A contractor becomes a weak point: an integrator, IT service provider or a partner with remote access. Through a trusted channel, hackers get logged in to the corporate network, and the victim does not see an invasion for a long time, but the usual work of the external performer.

The SCFR SOC presented at the CIPP conference a study “Langtaf of cyber threats 2025/2026: trends, attacks, vulnerabilities” and a forecast for Russian companies for 2026. According to analysts of Threat Intelligence, at least 30% of known cyber attacks in 2025 went through the compromising IT contractors. This channel has become one of the key trends: criminals use access of trusted partners, bypass some of the usual checks and stay invisible longer.

Attacks have become faster and more difficult. Attackers combine data encryption, information theft, publication threats and pressure through DDoS. The role of already known vulnerabilities has increased separately: the number of incidents where primary access was received through the CVE described increased by about 30% compared to 2024. For companies, the problem is especially unpleasant, because it is often not about unknown mistakes, but about spaces for which patches and public descriptions already exist.
View attachment 268
The SCSC study identifies 65 vulnerabilities most critical of the Russian market. Operating systems and workstations accounted for 44%, network infrastructure and services - 27%, for application software and libraries - 23%, on corporate IT platforms - 6%. Microsoft products focus about 43% of vulnerabilities that were actively used in attacks. In Russian IT solutions, attackers more often used errors in video conferencing servers, postal systems and endpoint protection.

The activity of APT-groups against Russian organizations increased by 25-30%. The growth was provided mainly by well-known players who have intensified attacks on large and strategically important industries. The report also cite the CrowdStrike score: the path from primary penetration to targeted action on average reduced to 48 minutes, and in the fastest cases to 51 seconds.
View attachment 269
DDoS attacks also ceased to be a simple overload of sites. The number of attacks at network levels increased by 24.18%, the most powerful attack reached 1.57 Tbps, and the share of the industrial sector increased by 357%. Among the most active groups of 2025, the SOC calls IT Army of Ukraine, CyberSec (adB), Himars DDOS and Cybercorpus. The main goal was Russian telecom providers.

In 2026, experts expect more powerful strikes on critical infrastructure with the expectation of not a short failure, but on the long degradation of services. A separate risk is associated with Ransom-DDoS, when infrastructure overload is combined with a ransom requirement. AI reinforces the threat: algorithms help generate adaptive malicious traffic and circumvent the typical filtering rules.

The average volume of one leak in Russia reached 3.27 million records, which is 26% more than in 2024. Personal data accounted for 74% of the total volume of leaked information. The main channel of the publication remained Telegram: it accounted for about 72% of reports of leaks, while the darknet and closed forums took 26%.

The most affected public sector, industry, finance, IT, transport and logistics, as well as retail. The public sector accounted for 22% of incidents, the industry - 21%, finance - 14%, IT - 12%, transport and logistics - 10%, retail - 9%. Over the past two years, the total volume of compromised data in these industries has exceeded 1.6 billion records, and the share of incidents with a leak of more than 10 million records has tripled.
View attachment 270
In 2026, the MCSB expects the growth of attacks with several targets at once. Encryption will complement data theft, publishing threats and air accessibility strikes. Industrial control systems, IoT equipment and smart sensors will be at risk, because hacking industrial systems can lead to real production downtime.

The main protection measures are related to the control of entrance points. Companies are advised to tightly manage contractors’ access, use VPNs with MFA, segment the network, apply the principle of minimum privileges, keep unchanging backups, monitor the public perimeter, strengthen monitoring via SIEM and EDR/XDR, automate responses and conduct hardening critical systems.
 

Get Monie🎒

Well-known member
Member
Joined
Jul 27, 2026
Messages
199
Reaction score
1
𝙷𝚎𝚕𝚕𝚘 𝙸’𝚟𝚎 𝙷𝚒𝚐𝚑 𝚀𝚞𝚊𝚕𝚒𝚝𝚢 🥇𝙲𝚊𝚛𝚍𝚜 💳𝚆𝚑𝚒𝚌𝚑 𝙻𝚒𝚗𝚔𝚜 𝙰𝚞𝚝𝚘𝚖𝚊𝚝𝚒𝚌 𝚆𝚒𝚝𝚑𝚘𝚞𝚝 𝙾𝚃𝙿 𝚟𝚎𝚛𝚒𝚏𝚒𝚌𝚊𝚝𝚒𝚘𝚗: 𝙲𝚊𝚛𝚍 𝙲𝚊𝚗 𝙱𝚎 𝙻𝚒𝚗𝚔𝚎𝚍 𝚝𝚘
🧬⬇️
🅒🅗🅘🅜🅔 > 🅟🅐🅨🅟🅐🅛 > 🅥🅔🅝🅜🅞 🅐🅟🅟🅛🅔 🅟🅐🅨 > 🅒🅐🅢🅗🅐🅟🅟 > 🅖🅟🅐🅨 🅕🅞🅡 🅘🅝🅢🅣🅐🅝🅣 🅒🅐🅢🅗 🅞🅤🅣

ℂ𝕒𝕣𝕕 ℂ𝕒𝕟 𝕓𝕖 𝕦𝕤𝕖𝕕 𝔽𝕠𝕣 𝕆𝕟𝕝𝕚𝕟𝕖 ℙ𝕦𝕣𝕔𝕙𝕒𝕤𝕖𝕤, 𝕊𝕙𝕚𝕡𝕡𝕚𝕟𝕘,ℙ𝕙𝕠𝕟𝕖 𝕆𝕣𝕕𝕖𝕣𝕤,𝕊𝕚𝕥𝕖 𝕍𝕖𝕣𝕚𝕗𝕚𝕔𝕒𝕥𝕚𝕠𝕟 💻📲

𝔸𝕝𝕤𝕠 ℍ𝕒𝕧𝕖 𝔸𝕔𝕥𝕚𝕧𝕖 𝔻𝕦𝕞𝕡𝕤 + ℙ𝕚𝕟 , 𝕆𝕡𝕖𝕟 𝕌𝕡𝕤 , 𝔼𝕓𝕥 𝕔𝕒𝕣𝕕𝕤 , 𝔽𝕦𝕝𝕝𝕫 , 𝔹𝕒𝕟𝕜 𝕃𝕠𝕘𝕤 , 𝔹𝕒𝕟𝕜 𝕤𝕥𝕒𝕥𝕖𝕞𝕖𝕟𝕥𝕤 …

*Also Got clone cards with good hitting balance just hit me up 👇*

ℙ𝕄 @Wgtpayd 𝔽𝕆ℝ 𝕄𝕆ℝ𝔼 𝕀ℕ𝔽𝕆𝕊✅```_ ON TELEGRAM_```

WhatsApp:+44 7735 020263
 
5,612Threads
75,265Messages
5,817Members
SkibidiuwusigmaLatest member
Top Bottom