Russian data centers face new security requirements amid Ukraine's drone threats
A new Russian decree tightens critical-infrastructure security requirements, forcing data center operators to boost physical and digital defenses amid Ukrainian drone attacks.
A decree signed by President Putin in late August lets the Russian government temporarily take control of critical infrastructure, including data centers, if operators fail to protect facilities from drone attacks. Russia hosts 181 data centers, many concentrated around Moscow and St. Petersburg, areas increasingly exposed to Ukrainian long-range drone operations. Operators report higher capital expenditures for physical defenses and cybersecurity, costs likely passed to customers. Ukraine has also struck data centers in Kyiv, and Russia has expanded anti-drone measures such as netting and metal barriers.
Risky Bulletin: Russia tells data centers to deploy drone defenses
Russia ordered data center operators to deploy drone strike defenses under a Putin decree allowing temporary state takeover of unprotected critical infrastructure.
The Russian government instructed data center operators to deploy protections against drone strikes under a presidential decree signed by Putin that allows temporary state administration of critical infrastructure operators failing to defend against Ukrainian hacks and drone strikes. Although data centers are not formally critical infrastructure in Russia, the decree applies to them because other sectors depend heavily on cloud services; Russia has more than 180 data centers, over 80% in the European region within range of Ukrainian strikes. The digest also reports a Dropbox breach affecting nearly 5,000 accounts via the Lenovo ID integration, spyware attacks on at least 14 Serbians using NoviSpy or Pegasus, and a password recovery attack targeting hundreds of thousands of X accounts tied to the new X Money service. Other items include a 14-hour compromise of Coder's Cloudflare infrastructure delivering malicious Terraform modules, donor data breaches at Davayte and You Are Not Alone via the Stripe/WooCommerce integration, a $2.5M Aquifer crypto heist, and a TVING breach exposing data of almost 40 million accounts.