Russian data centers face new security requirements amid Ukraine's drone threats
A new Russian decree tightens critical-infrastructure security requirements, forcing data center operators to boost physical and digital defenses amid Ukrainian drone attacks.
A decree signed by President Putin in late August lets the Russian government temporarily take control of critical infrastructure, including data centers, if operators fail to protect facilities from drone attacks. Russia hosts 181 data centers, many concentrated around Moscow and St. Petersburg, areas increasingly exposed to Ukrainian long-range drone operations. Operators report higher capital expenditures for physical defenses and cybersecurity, costs likely passed to customers. Ukraine has also struck data centers in Kyiv, and Russia has expanded anti-drone measures such as netting and metal barriers.
Russian e-commerce giant Wildberries says DDoS attack delayed payments to sellers
Russian e-commerce giant Wildberries says a DDoS attack and subsequent security measures delayed seller payments, leaving roughly $240 million unpaid.
Wildberries, one of Russia's largest online marketplaces, said a distributed denial-of-service attack on systems used to track and withdraw seller earnings delayed payments, with funds to be transferred after technical procedures complete. The Russian Union of Marketplace Sellers reported about 20 billion rubles ($240 million) unpaid, and 95.6% of nearly 2,000 surveyed sellers had not received expected payments. Ukraine's military intelligence (HUR) previously claimed an operation with the hacker group Cyber Corps disrupted Wildberries' payment and customer service systems, though the company has not confirmed whether the DDoS attacks were connected.
Risky Bulletin: Russia tells data centers to deploy drone defenses
Russia ordered data center operators to deploy drone strike defenses under a Putin decree allowing temporary state takeover of unprotected critical infrastructure.
The Russian government instructed data center operators to deploy protections against drone strikes under a presidential decree signed by Putin that allows temporary state administration of critical infrastructure operators failing to defend against Ukrainian hacks and drone strikes. Although data centers are not formally critical infrastructure in Russia, the decree applies to them because other sectors depend heavily on cloud services; Russia has more than 180 data centers, over 80% in the European region within range of Ukrainian strikes. The digest also reports a Dropbox breach affecting nearly 5,000 accounts via the Lenovo ID integration, spyware attacks on at least 14 Serbians using NoviSpy or Pegasus, and a password recovery attack targeting hundreds of thousands of X accounts tied to the new X Money service. Other items include a 14-hour compromise of Coder's Cloudflare infrastructure delivering malicious Terraform modules, donor data breaches at Davayte and You Are Not Alone via the Stripe/WooCommerce integration, a $2.5M Aquifer crypto heist, and a TVING breach exposing data of almost 40 million accounts.