Security News

Hacktivist Group Admits Breaching Moscow Health Network and Staying Inside for Months

The Record · 10 Oct 2026
Key Takeaway Quiet intrusions can go unnoticed for years, so regularly review administrator accounts and connections to partner networks, and monitor for unusual access before an attacker's presence is discovered by someone else.

The Belarusian Cyber Partisans, an activist hacking group, say they broke into the Moscow Department of Health in 2023 and gained administrator-level access to its infrastructure, including systems connected to other government agencies. In a statement on Friday, the group said it spent months inside the network before abandoning the operation. It told Recorded Future News that it gained full access "relatively quickly and with little effort" and did not keep its access because the network was not a priority.

The admission follows a report from Russian cybersecurity firm Solar, a subsidiary of Rostelecom. Solar said it found the breach in December 2025 and traced the earliest signs of intrusion to early 2024, suggesting the attackers may have been inside for nearly two years. The Cyber Partisans say they got in a year earlier than that. Solar reported that the attackers accessed sensitive medical information but did not destroy data or disrupt operations. It also noted the victim's network was connected to many other healthcare institutions, potentially exposing further systems.

The group did not say what data it took, though it suggested medical information gathered in operations could help it assess Russian military casualties in the war in Ukraine. A representative also claimed access to hundreds of IT systems across Russia and Belarus, which could not be independently verified.

Summarised by CISO AI from The Record, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.