INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Belarusian hacktivists breach Russian state healthcare network in 2023 incident

| 2026-10-09 14:40 CRITICAL LOW DATA BREACH CRITICAL INFRASTRUCTURE & OT DDOS & DISRUPTION
Executive Summary
AI-generated
In 2023, Belarusian hacktivists known as the Cyber Partisans claimed responsibility for breaching Moscow's healthcare network, gaining administrator-level access to its infrastructure and systems connected to other government agencies. The group spent months inside the network before abandoning it due to lack of priority from their end. Currently, they claim to have access to hundreds of IT systems across Russia and Belarus. According to a recent report by Russian cybersecurity firm Solar, the hackers accessed sensitive medical information but did not disrupt operations or destroy data. The Cyber Partisans stated that the breach was for operational reasons, allowing them to assess Russian military casualties in the war in Ukraine, although they have since expanded their operations against Russian targets and claimed responsibility for major cyberattacks on Belarusian government institutions and its railway system.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SolarSolar
Target & Sectors
NORTH_AMERICA NORTH_AMERICA CIS CIS NORDICS NORDICS manufacturingmanufacturing governmentgovernment healthhealth
Incident Timeline
‎early 2024
Threat actors remained inside Solar's network for nearly two years after the earliest signs of intrusion were detected in early 2024.
malware Solar
‎December 2025
Solar discovered a breach in December 2025, tracing the earliest signs of intrusion to early 2024.
malware Solar
‎2026/10/02
The Cyber Partisans' statement acknowledged their involvement in a long-running medical data cyberattack.
source_region Russian Federation
organisation The Cyber Partisans'
malware Solar
organisation Rostelecom
‎5 October
Threat actors exploited a vulnerability in the Danish company's access to the Central Person Register system, allowing them to gain unauthorized access to the CPR on 5 October.
target_region Denmark
organisation the Central Person Register
‎2026/10/06
The 2026 Future Focus organization sent a promotional email to users, which was intercepted by threat actors.
general_metric 2026 Future Focus
‎2026/10/09
The Belarusian Cyber Partisans claimed responsibility for a recent cyberattack on Qbusoft, the company behind Medyc software used by Polish healthcare providers to manage patient records and other medical information.
organisation Supreme Court
organisation Recorded Future News
organisation Google News
organisation the Moscow Department of Health
organisation The Cyber Partisans
organisation CyberSmart
organisation CPR
organisation Nathan Davies-Webb
organisation Huntress
organisation Danes
organisation BlueSky
organisation MyDr
organisation Inowrocław
organisation Digital Affairs
organisation the Central Office for Combating Cybercrime