Data Breaches

Russian Security Firm Doctor Web Hacked

Antimalware company Doctor Web was recently targeted in a cyberattack that prompted it to disconnect all resources from its networks.

Hacked

Russian antimalware company Doctor Web, the developer of Dr.Web cybersecurity products, on Tuesday said it was recently targeted in a cyberattack.

In an English-language statement posted on its website, the security firm said it had detected a targeted attack aimed at its resources on September 14. 

“The attempt to harm our infrastructure was prevented in a timely manner, and no user whose system was protected by Dr.Web was affected,” the company said.

The incident prompted the company to disconnect all resources from its network to check them for signs of compromise. Its Dr.Web virus databases were also temporarily suspended.

A post written in Russian reveals that the company had kept an eye on the attacker’s movements after detecting the breach. In the same post, the company said the virus databases have been brought back online. 

Doctor Web has not shared any information on who may be behind the attack. Cybersecurity companies may be targeted by any type of threat actor, including state-sponsored groups, hacktivists, and profit-driven cybercriminals. 

Advertisement. Scroll to continue reading.

The Russian cybersecurity firm Kaspersky, which is leaving the United States following a software sale ban, was targeted at least two times by what are believed to be state-sponsored threat actors: a decade ago in Duqu 2.0 attacks and more recently in Operation Triangulation

The Russian security firm Avanpost was recently targeted by pro-Ukrainian hackers, with the attackers claiming to have stolen and destroyed vast amounts of data belonging to the company. 

Western cybersecurity companies have also been targeted in recent months, including major firms such as Zscaler and Fortinet, both apparently targeted by profit-driven hackers.  

Related: North Korean Hackers Hijack Antivirus Updates for Malware Delivery

Related: Cybersecurity Firm FireEye Says Was Hacked by Nation State

Related: Dragos Says No Evidence of Breach After Ransomware Gang Claims Hack via Third Party

Related Content

Supply Chain Security

The hackers exfiltrated data from Salesforce instances of Klue customers, such as Huntress and Recorded Future.

Data Breaches

The cybersecurity firm’s investigation has not found any impact on its source code release or distribution process. 

Malware & Threats

Hackers compromised a MicroWorld Technologies update server and fed a malicious file to eScan customers.

Data Breaches

Proofpoint, SpyCloud, Tanium, and Tenable confirmed that hackers accessed information stored in their Salesforce instances.

Cybercrime

Check Point has responded to a hacker’s claims of sensitive data theft, confirming an incident but saying that it had limited impact.

Data Breaches

Doctor Web says no development or user data was compromised after pro-Ukraine hacktivists claimed the theft of 10 Tb of files.

Endpoint Security

Users continue to flame Kaspersky and Pango Group as the automatic, forced transition to UltraAV gradually progresses.

Endpoint Security

Many US users are voicing concerns over the silent, forced transition from Kaspersky’s security products to UltraAV.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version