Supply chain
⛓ Supply Chain
Local credit and financial businesses Third-Party Breach (February 2025)
Primary Source ↗Incident Details
Russian officials warn of potential compromise of major tech services provider. In an unusual public disclosure, the Russian government said that subsidiaries of LANIT, a major tech services provider, had potentially been breached. Russian cybersecurity authorities have warned local credit and financial businesses about a potential compromise involving subsidiaries of the country’s largest tech services provider, LANIT. In an unusual public disclosure issued late last week, Russia’s National Coordination Center for Computer Incidents (NCCCI) stated that the incident likely affected the information infrastructure of two LANIT companies specializing in payment services and supplying software for banking equipment and automated teller machines (ATMs). Third-party company: LANIT Group.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- LANIT Group
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2025-02-01 Breach occurred
- 2025-02-25 Publicly disclosed