INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Belarusian hacktivists breach Russian state healthcare network in 2023 incident
| 2026-10-09 14:40 CRITICAL LOW DATA BREACH CRITICAL INFRASTRUCTURE & OT DDOS & DISRUPTION
Executive Summary
AI-generated
In 2023, Belarusian hacktivists known as the Cyber Partisans claimed responsibility for breaching Moscow's healthcare network, gaining administrator-level access to its infrastructure and systems connected to other government agencies. The group spent months inside the network before abandoning it due to lack of priority from their end. Currently, they claim to have access to hundreds of IT systems across Russia and Belarus. According to a recent report by Russian cybersecurity firm Solar, the hackers accessed sensitive medical information but did not disrupt operations or destroy data. The Cyber Partisans stated that the breach was for operational reasons, allowing them to assess Russian military casualties in the war in Ukraine, although they have since expanded their operations against Russian targets and claimed responsibility for major cyberattacks on Belarusian government institutions and its railway system.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SolarSolar
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
CIS
CIS
NORDICS
NORDICS
manufacturingmanufacturing
governmentgovernment
healthhealth
Incident Timeline
early 2024
Threat actors remained inside Solar's network for nearly two years after the earliest signs of intrusion were detected in early 2024.
Click on any entity below to view its context and source!
malware
Solar
Solar said it discovered the breach in December 2025 and traced the earliest signs of the intrusion to early 2024, suggesting the hackers may have remained inside the network for nearly two years.
December 2025
Solar discovered a breach in December 2025, tracing the earliest signs of intrusion to early 2024.
Click on any entity below to view its context and source!
malware
Solar
Solar said it discovered the breach in December 2025 and traced the earliest signs of the intrusion to early 2024, suggesting the hackers may have remained inside the network for nearly two years.
2026/10/02
The Cyber Partisans' statement acknowledged their involvement in a long-running medical data cyberattack.
Click on any entity below to view its context and source!
source_region
Russian Federation
The Cyber Partisans' statement follows a report published last week by Russian cybersecurity firm Solar, a subsidiary of state-controlled telecom giant Rostelecom, which identified the group as the likely perpetrator of a long-running intrusion into an unnamed Russian healthcare organization.
organisation
The Cyber Partisans'
The Cyber Partisans' statement follows a report published last week by Russian cybersecurity firm Solar, a subsidiary of state-controlled telecom giant Rostelecom, which identified the group as the likely perpetrator of a long-running intrusion into an unnamed Russian healthcare organization.
malware
Solar
The Cyber Partisans' statement follows a report published last week by Russian cybersecurity firm Solar, a subsidiary of state-controlled telecom giant Rostelecom, which identified the group as the likely perpetrator of a long-running intrusion into an unnamed Russian healthcare organization.
organisation
Rostelecom
The Cyber Partisans' statement follows a report published last week by Russian cybersecurity firm Solar, a subsidiary of state-controlled telecom giant Rostelecom, which identified the group as the likely perpetrator of a long-running intrusion into an unnamed Russian healthcare organization.
5 October
Threat actors exploited a vulnerability in the Danish company's access to the Central Person Register system, allowing them to gain unauthorized access to the CPR on 5 October.
Click on any entity below to view its context and source!
target_region
Denmark
Hackers accessed the Central Person Register (CPR) by taking advantage of a Danish company's access to the system, the government admitted in a
statement
on 5 October.
organisation
the Central Person Register
Hackers accessed the Central Person Register (CPR) by taking advantage of a Danish company's access to the system, the government admitted in a
statement
on 5 October.
2026/10/06
The 2026 Future Focus organization sent a promotional email to users, which was intercepted by threat actors.
Click on any entity below to view its context and source!
general_metric
2026 Future Focus
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
2026/10/09
The Belarusian Cyber Partisans claimed responsibility for a recent cyberattack on Qbusoft, the company behind Medyc software used by Polish healthcare providers to manage patient records and other medical information.
Click on any entity below to view its context and source!
organisation
Supreme Court
In July, Russia's Supreme Court designated the Cyber Partisans an “
extremist organization
,” accusing the group of seeking to destabilize Russia and Belarus and overthrow Lukashenko's government.
organisation
Recorded Future News
"The network was not a priority for us, so we did not maintain our access," the group said in a comment to Recorded Future News.
organisation
Google News
"
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News
and
add us as a preferred source
to keep tabs on all our latest news, analysis, views, and reviews.
organisation
the Moscow Department of Health
In a
statement
on Friday, the Belarusian Cyber Partisans said they infiltrated the Moscow Department of Health in 2023 and obtained administrator-level access to its infrastructure, including systems connected to other government agencies.
organisation
The Cyber Partisans
The Cyber Partisans said they had gained access a year earlier and had not attempted to maintain it after completing their objectives.
“We take this opportunity to acknowledge responsibility for the hack and agree with the report's authors on at least one point: No matter how hard the Russians try to defend their systems, the Cyber Partisans ‘find and will continue to find ways around’ their security measures,” the hackers said in a statement.
organisation
CyberSmart
Jamie Akhtar, CEO and co-founder of CyberSmart, agreed that Danes should be on the alert for
phishing
emails, texts and calls that claim to come from banks or public authorities.
organisation
CPR
The attack was spotted on Friday night, with CPR staff observing irregular behavior on systems during September.
organisation
Nathan Davies-Webb
Nathan Davies-Webb, principal consultant at Acumen Cyber, said this discovery gap is a highly concerning aspect of the breach.
organisation
Huntress
Dray Agha, senior manager of security operations at Huntress, said the incident shows the risk of developing a centralized national database that offers direct access to third parties.
organisation
Danes
In light of the breach, Egelund warned Danes to "be aware now and in the future," with a government statement warning citizens against giving out passwords or other confidential information over the phone or email to an unknown person, even if they have personal details like your address or CPR number.
organisation
BlueSky
You can also
follow ITPro on LinkedIn
,
X
,
Facebook
, and
BlueSky
.
organisation
MyDr
First, it was the
MyDr
system.
organisation
Inowrocław
The Rehabilitation and Psychiatric Treatment Center in the central city of Inowrocław said Thursday that
the attack had breached
the confidentiality of patients’ personal data.
organisation
Digital Affairs
Commenting online, Digital Affairs Minister Krzysztof Gawkowski said the Central Office for Combating Cybercrime was looking into the “potential cybersecurity incident” as part of “a broader investigation”.
organisation
the Central Office for Combating Cybercrime
Commenting online, Digital Affairs Minister Krzysztof Gawkowski said the Central Office for Combating Cybercrime was looking into the “potential cybersecurity incident” as part of “a broader investigation”.
Intelligence Sources
Data Breaches
2026-09-26
TheRecord
2026-10-09
IT Pro
2026-10-06
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-10T12:15
Comprehensive Tactical Telemetry
Highly Correlated Entities
18x
organisation
Identified Entity
Recorded Future News
entity
8x
timeline
Temporal Reference
2026/10/02
date
6x
target region
Target Country
Russian Federation
country
3x
industry
Targeted Sector
Health
sector
3x
general metric
People
8,800,000
people
2x
source region
Origin Country
Russian Federation
country
2x
tactic
Cyber Operation Type
Data Breach
tactic
Contextual Telemetry
Context Block
3 METRICS
general metric
Breach
2,023
breach
malware
Malware Payload
Solar
tool
general metric
Future Focus
2,026
future focus
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.