Microolap Confirms Breach, Downplays Scope of Black Spark Hacking Claims
Russian software developer **Microolap** has acknowledged a compromise of some of its systems, but vehemently denies claims by the hacking group **Black Spark** that they accessed core network monitoring platforms or exfiltrated sensitive data from major Russian entities. The incident highlights the ongoing challenges of verifying cyberattack claims and the critical importance of robust network segmentation.
Russian software developer **Microolap**, known for its network traffic interception and analysis software, has confirmed that some of its systems were compromised. However, the company strongly disputes the extent of the breach asserted by the hacking group **Black Spark**.
**Microolap** stated on Thursday that it detected an attempted breach of several non-critical systems. Crucially, the company found no evidence that attackers accessed its core infrastructure, customer data, or other sensitive information.
"We urge people not to treat the attackers' claims as fact," said **Microolap** CEO **Andrey Smirnov**. "Our cybersecurity systems worked as intended: We detected the incident and kept critical data secure."
### Black Spark's Claims
The company's statement follows claims by **Black Spark**, a group describing itself as an "underground movement in Russia," which asserted it had maintained access to **Microolap's** network for over a month. **Black Spark** claimed to have accessed internal systems, including **EtherSensor**, the company's network traffic analysis platform.
Furthermore, the hackers alleged they extracted and deleted data belonging to several high-profile **Microolap** customers. These reportedly included **Russian Railways**, state banknote and document producer **Goznak**, **VTB Bank** and its leasing subsidiary, and Russian IT company **NEK.TECH**.
**Black Spark** published several screenshots as purported evidence of compromised systems and exfiltrated data. The authenticity of these images has not been independently verified.
### Microolap's Investigation Findings
While acknowledging a compromise, **Microolap** has rejected **Black Spark's** account of the attack's scope. The company's investigation revealed that the hackers accessed several rarely used development systems hosted by a third-party Russian provider, an outdated version of its website, and an old **Bitrix24** customer management system containing a limited amount of data.
Crucially, **Microolap** emphasized that the affected systems were isolated from its core infrastructure. This segmentation prevented attackers from gaining access to **EtherSensor** or sensitive data belonging to customers and partners.
The company confirmed that none of its production systems or components critical to **EtherSensor** were affected. The platform continues to operate normally, with no impact on its performance, data integrity, or availability.
### Remediation Efforts
In response to the incident, **Microolap** has taken its outdated website offline and implemented additional security measures. The company is actively investigating the incident with the assistance of an unnamed "one of Russia's largest cybersecurity companies."
**Black Spark**, in a manifesto published on Telegram, states its members have remained in Russia and chosen what it terms "armed resistance."