Full Report
Russia's Rostelecom said that it was responding to a cyberattack on a contractor that helps to run its corporate website and procurement portal.
Analysis Summary
# Incident Report: Alleged Data Theft from Rostelecom Contractor
## Executive Summary
A major Russian telecommunications provider, Rostelecom, is investigating a suspected cyberattack after the hacker group Silent Crow claimed responsibility for leaking customer data, including emails and phone numbers, allegedly stolen from a contractor responsible for the corporate website and procurement portal. While Rostelecom stated that no highly sensitive personal data appears to have been compromised based on initial findings, users were advised to reset passwords and enable MFA as a precautionary measure.
## Incident Details
- Discovery Date: Tuesday (Date of publication of the data dump)
- Incident Date: Unknown prior to Tuesday
- Affected Organization: Rostelecom (via a third-party contractor)
- Sector: Telecommunications
- Geography: Russia
## Timeline of Events
### Initial Access
- Date/Time: Unknown prior to Tuesday
- Vector: Compromise of a contractor maintaining Rostelecom’s corporate website and procurement portal.
- Details: The attacker group Silent Crow published a data dump allegedly sourced from this contractor.
### Lateral Movement
- Details: Not explicitly detailed in the source, but the compromise targeted systems supporting Rostelecom's online presence and procurement functions.
### Data Exfiltration/Impact
- Details: Thousands of customer emails and phone numbers were published online by Silent Crow. Rostelecom is reviewing the database to confirm the scope of the leak, but claims initial findings suggest "no leak of highly sensitive personal data."
### Detection & Response
- Detection: The incident was detected when hacker group Silent Crow published the data dump on a Telegram channel.
- Response Actions: Rostelecom began reviewing its database to determine compromised data. The company advised affected website users to reset passwords and enable two-factor authentication (MFA). The Russian Ministry of Digital Development confirmed the breach did not affect the state services portal.
## Attack Methodology
- Initial Access: Exploitation or compromise of a third-party contractor’s environment (details of exact vector not provided, implied via web/portal access).
- Persistence: Not detailed.
- Privilege Escalation: Not detailed.
- Defense Evasion: Not detailed.
- Credential Access: Not detailed (likely related to database access).
- Discovery: Not detailed.
- Lateral Movement: Movement from the contractor's environment into the Rostelecom-related databases.
- Collection: Targeting customer email and phone number information.
- Exfiltration: Data dump published on a private Telegram channel.
- Impact: Unauthorized disclosure of customer contact information.
## Impact Assessment
- Financial: Not disclosed/Unknown.
- Data Breach: Thousands of customer emails and phone numbers allegedly exposed. Rostelecom suggests highly sensitive data was not impacted.
- Operational: Potential disruption to the contractor’s corporate website and procurement portal management.
- Reputational: Negative public exposure arising from the data leak claim against a major state-affiliated provider.
## Indicators of Compromise
- Network indicators: Not publicly provided (URLs/IPs associated with Silent Crow's Telegram channel are volatile and excluded).
- File indicators: Data dump containing customer emails and phone numbers.
- Behavioral indicators: Publication of data via the Silent Crow Telegram channel.
## Response Actions
- Containment: Investigation initiated into the compromised contractor systems.
- Eradication: Not publicly detailed, but essential steps would involve patching the vulnerability at the contractor level.
- Recovery: Advising affected users to reset passwords and enable MFA on associated platforms.
## Lessons Learned
- Third-party risk remains a critical vulnerability, as demonstrated by the compromise via a contractor responsible for essential corporate/procurement functions.
- The disclosure method (public leak via Telegram without ransom demand) utilized by Silent Crow bypasses traditional ransom negotiation response playbooks.
## Recommendations
- Immediate audit and hardening of security protocols, access controls, and data segmentation for all third-party contractors handling sensitive data or managing public-facing infrastructure for Rostelecom.
- Mandate universal MFA implementation across all access points related to corporate websites and vendor management portals.
- Enhance proactive monitoring around sensitive databases accessible by vendor accounts.