Russia's National Coordination Center for Computer Incidents (NKTsKI) is warning organizations in the country's credit and financial sector about a breach at LANIT, a major Russian IT service and software provider. According to the bulletin, which was also published on the website of GosSOPKA (State System for Detection, Prevention, and Elimination of Consequences of Computer Attacks), the attack took place on February 21, 2025, and potentially impacted LLC LANTER and LLC LAN ATMservice, both part of the LANIT Group of Companies. "NKTsKI recommends that all organizations immediately change passwords and access keys for their systems hosted in LANIT's data centers," reads the bulletin. LLC LANTER and LLC LAN ATMservice are Russian companies specializing in banking technology and services, specializing in software for banking equipment, payment systems, and Automated Teller Machines (ATMs). At this time, NKTsKI did not specify how attackers gained access to the LANIT network, when the compromise occurred, what data might have been stolen, and who could be behind the attack. Due to the breach at these two entities, NKTsKI recommends all potentially impacted organizations rotate passwords and access keys and change remote access credentials. However, the latest notice from the Russian authorities indicates that there has been infiltration into a central service provider's systems, creating the potential for broad supply chain compromises. Bill Toulas Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks. Russian ATM operators and banks have been the target of Ukrainian hackers multiple times in recent months, who oftentimes employ distributed denial of service (DDoS) tactics to cause disruption. LANIT Group is a significant and influential company in Russia's information technology sector, considered the country's largest system integrator. Its clientele includes prominent entities such as the Russian Ministry of Defense and major players in the military-industrial complex, including Rostec, which is why it got sanctioned by the U.S. Department of the Treasury in May 2024.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Mon, 24 Feb 2025 20:50:15 +0000