Cyberattack

One in every five Russian businesses has faced attacks

Published on October 3, 2026

At 24% of the companies that were attacked, information resources and hardware stopped working, while 15.5% had their data destroyed. The count of large and medium Russian organizations dealing with information security incidents rose by 8.7% in 2025, reaching 46.4 thousand. Their share grew by 1.5 percentage points to 17.8%, which means one in every five enterprises. These figures come from the analytical services of the FinExpertiza audit and consulting network, based on the Rosstat survey under form number 3, “Information on the use of digital technologies and the production of related goods and services.”

A year before, cybercriminals attacked 16.3% of Russian organizations. The study covers almost the entire range of medium and large organizations, whether commercial, state, or municipal. In 2025, over 260 thousand entities took part in it.

The sample leaves out correctional facilities, public order and security units, education below higher education, and personal service firms like laundries, dry cleaners, saunas, and hairdressers. Information security incidents cover computer attacks, unauthorized intrusions into information systems, and malware infections. In a few cases they caused blocking or failures of information resources and hardware, breaches of data confidentiality, and full or partial destruction or damage of records.

By industry, wholesale and retail trade has the largest share of organizations facing cyber threats, at 31.7%—about one in three enterprises. Hotels and catering rank second at 27.3%, or one in four enterprises. Higher education organizations are third at 23.5%, also one in four enterprises. The share topped the national level in information and communications at 21.5%, financial and insurance at 20.8% (one in five enterprises), and manufacturing at 19.9%. By region, Moscow leads, with 26.4% of organizations reporting incidents—one in four enterprises.

Perm territory and the Samara region follow at 21% each, the Udmurtia and Kemerovo regions at 20.2% each, and the Sverdlovsk region and Ingushetia at 20.1% each. In the Tyumen region the share of organizations with recorded incidents was 19.9%, in the Novosibirsk region 19.8%, and in the Tula region 19.7%. In ten more regions the figure ranged from 18.7% to 19.6%. In the Kaliningrad region it hit 19.6%, the Yaroslavl region 19.5%, and the Adygea and Tomsk regions 19.3% each, and the Vladimir and Pskov regions 19.1% each. In the Kursk region the share was 18.9%, Dagestan 18.8%, and the Rostov region and Khanty Mansi Autonomous Area 18.7% each. Industry trends varied.

The share of organizations reporting cyber threats grew notably in trade, from 22% to 32% (up 10 percentage points), and in information and communications, from 19% to 21% (up 2 points). In hotel and catering services, growth was minimal, at plus 0.2 percentage points. In other sectors the share of organizations with incidents fell. The biggest drop, about 2 percentage points, was in energy, from 18.8% to 16.7%, and in healthcare, from 12.6% to 10.9%.

FinExpertiza reports security tool data separately. About 78% of Russian organizations use them. Mainly, companies protect the network perimeter and access to information systems. Strong authentication tools are used by 79.2% of organizations with information security solutions, firewalls by 67.6%, encryption tools by 63.3%, and spam filters by 63.2%. More specialized tools are much rarer: intrusion detection systems by 52.9%, corporate virtual private networks by 44.9%, and biometric authentication tools by 9.3%. FinExpertiza President Elena Trubnikova notes that with 17.8% of organizations facing security incidents, many saw real consequences.

Among organizations hit by cyberattacks, unauthorized intrusions, and malware, 24% had blockages or interruptions of information resources and hardware, 15.5% had data destroyed or corrupted, and 11.9% had confidentiality breaches and data leaks. In 2025 the Russian cybersecurity industry created and launched a fundamentally new method for quantitative evaluation of corporate protection against cyberattacks. It involves moving from finding individual vulnerabilities to proving that unacceptable damage cannot be inflicted.

Continue Reading