Sun 23 Aug 2026 / 18:20 ET
Kernel
Security 2 min read

Microolap confirms limited cyberattack, disputes Black Spark’s theft claims

Microolap says attackers reached isolated systems but not EtherSensor or customer data, countering unverified claims by Black Spark.

Dana Voss

By Dana Voss / Security Correspondent

Microolap confirms limited cyberattack, disputes Black Spark’s theft claims
img: The Record

Russian software developer Microolap has confirmed a Microolap cyberattack affected some of its systems, while rejecting a hacking group’s claim that it penetrated the company’s core network-monitoring platform or stole customer data. The company says the breach was limited to isolated, non-critical systems.

Microolap develops tools for intercepting and analyzing network traffic, including its EtherSensor platform. In a statement reported by The Record, the company said it identified an attempted intrusion involving several systems outside its main infrastructure.

Chief executive Andrey Smirnov said Microolap detected the incident and kept critical data secure. The company said it found no evidence that attackers entered its core infrastructure, reached EtherSensor, or obtained customer or partner data.

What did Microolap say hackers accessed?

Microolap said the affected assets included seldom-used development systems hosted by another Russian provider, an outdated version of its website and an older Bitrix24 customer-management system holding a limited amount of information.

According to Microolap, those systems were separated from the infrastructure used for production services. The company said the compromise did not provide a route into EtherSensor or its customers’ and partners’ data.

The company also said no production systems or EtherSensor-critical components were affected. EtherSensor remained available and its performance and data integrity were not affected, Microolap said.

What Black Spark claimed

The acknowledgment followed claims from a group calling itself Black Spark, which said it had been inside Microolap’s network for more than a month. The group alleged that it accessed internal systems, including EtherSensor, and extracted and deleted data tied to Russian Railways, state document and banknote producer Goznak, VTB Bank and its leasing unit, and IT company NEK.TECH.

Those claims remain unverified. Black Spark released screenshots it presented as evidence of access and stolen material, but The Record reported that their authenticity could not be independently confirmed. Microolap directly disputed the group’s description of the intrusion’s reach and consequences.

Black Spark describes itself as an underground movement in Russia. In a Telegram manifesto, the group said its members remained in the country and had chosen what it called armed resistance. The available reporting does not independently establish the group’s identity, how long it had access, or whether it took or deleted any customer data.

Microolap’s response

Microolap said it has removed the outdated website from service, added security controls and begun an investigation with help from an unnamed large Russian cybersecurity company. Its statement is a confirmation that a limited compromise occurred, not confirmation of Black Spark’s broader allegations.

This story draws on original reporting from The Record.

More Security/

view all ↗