Перейти к содержанию

The Leak Reached a Percentage: Hackers Increased Pressure on Russian Businesses, Threatening to Disclose Information to Regulators and the Public

Attackers offer to save companies from multi-million dollar turnover fines

Hackers have taken advantage of the tightening of personal data protection laws in Russia. Now they offer hacked companies to pay a ransom for not disclosing information about a data leak. This is confirmed by a study conducted by the IT company "Urals Center for System Security" (UTSSB).

Image source: Grok Imagine

Attackers steal a significant amount of data — from corporate correspondence to backups and source code, UTSSB explained.

Hackers demand payment for not reporting the leak to the regulator, saving businesses from turnover fines.
UTSSB Press Service

Analysts note that in 2026, criminals began to organize combined attacks: encryption, data theft, and DDoS. At the same time, hackers use neural networks to proliferate phishing emails. Industrial enterprises are most often affected by their actions.

Konstantin Mushovets, Director of UTSSB SOC (a cyber incident monitoring and response center created by UTSSB), stated that implementing IT infrastructure protection measures would be cheaper than restoring it after an attack. The expert recommended reviewing the procedure for creating and using passwords, strengthening the protection of remote workstations, and implementing multi-factor authentication.

The law on turnover fines for companies (No. 420-FZ) for repeated data leaks came into force in May 2025. Legal entities must pay from 0.1% to 3% of the company's revenue for the calendar year, but not less than 25 million rubles.

Read more on the topic: