Hundreds of pharmacies across Russia shut down this week after a cyberattack hit two of the country’s largest pharmacy chains, disrupting payments and access to medication reservations for patients. In addition to the pharmacy chains, Moscow’s Family Doctor clinic network also reported a cyber incident this week, which temporarily disabled its patient portal and online appointment system. Separately, a ransomware attack this month disrupted operations at Novabev Group, a major Russian alcohol producer, forcing more than 2,000 WineLab liquor stores to shut down for three days. Petersburg, also suspended operations, posting notices at storefronts citing “technical issues.” Online services for both chains, including drug reservations and loyalty programs, were disrupted, and employees were sent home. The Stolichki pharmacy chain, which operates about 1,000 stores across Russia confirmed that a technical failure that halted its operations on Tuesday was caused by a hack. Russia’s state internet watchdog, Roskomnadzor, said the disruptions were not caused by distributed denial-of-service (DDoS) attacks but did not elaborate on the method or origin of the hacks. The pro-Ukrainian hacker group Silent Crow and the Belarusian Cyber Partisans claimed responsibility for that breach, which targeted critical airline infrastructure. In 2022, after being targeted by Western sanctions over his support for Russia’s invasion of Ukraine, Nifantiev transferred his shares to an investment fund. Local media reported that many users in darknet forums condemned the targeting of medical services as unethical, suggesting the attacks may have geopolitical motivations. Stolichki and Neofarm are part of the same holding company, previously controlled by former State Duma lawmaker Yevgeny Nifantiev. Earlier this week, a cyberattack on Aeroflot, the country’s largest airline, caused widespread flight delays and cancellations. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. The company described the incident as “malicious activity” but has not attributed the attack to a specific group.
This Cyber News was published on therecord.media. Publication date: Wed, 30 Jul 2025 15:40:22 +0000