Supply chain ⛓ Supply Chain

Local credit and financial businesses Third-Party Breach (February 2025)

📅 2025-02-01 🏢 LANIT Group
Primary Source ↗

Incident Details

Russian officials warn of potential compromise of major tech services provider. In an unusual public disclosure, the Russian government said that subsidiaries of LANIT, a major tech services provider, had potentially been breached. Russian cybersecurity authorities have warned local credit and financial businesses about a potential compromise involving subsidiaries of the country’s largest tech services provider, LANIT. In an unusual public disclosure issued late last week, Russia’s National Coordination Center for Computer Incidents (NCCCI) stated that the incident likely affected the information infrastructure of two LANIT companies specializing in payment services and supplying software for banking equipment and automated teller machines (ATMs). Third-party company: LANIT Group.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
LANIT Group
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2025-02-01 Breach occurred
  2. 2025-02-25 Publicly disclosed