Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

Belarusian Cyber Partisans claim 2023 breach of Moscow's health network

Belarusian Cyber Partisans say they took admin access to Moscow's health department network in 2023, including systems linked to other agencies. Solar, the Rostelecom unit that found the intrusion, puts the first trace a year later, so the two sides disagree on how long the attackers were inside.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Belarusian Cyber Partisans claim 2023 breach of Moscow's health network
Generated illustration

What happened

  • Solar said it discovered the intrusion in December 2025 and that the attackers may have stayed inside the network for nearly two years.
  • Solar's report named the Cyber Partisans as the likely perpetrator but described the victim only as an unnamed Russian healthcare organization.
  • According to Solar, the attackers accessed sensitive medical information but did not destroy data or disrupt the organization's operations.
  • A group representative claimed current access to hundreds of IT systems across Russia and Belarus; Recorded Future News could not verify it.
  • Russia's Supreme Court designated the group an extremist organization in July, the first time Russia has applied that label to a hacking group.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • contradiction The network's owner cannot yet tell whether its exposure ended in 2023, as the group says, or ran until Solar found it in December 2025.
  • decision Anyone scoping the incident has to pick a start date, and a review anchored to Solar's early-2024 trace would miss the year in which the group says it got in.
  • exposure Institutions and agencies connected to the health department's network sit inside the blast radius of an administrator-level compromise under either timeline.

The two timelines conflict at both ends. The Cyber Partisans say they got in during 2023, a year before Solar's first trace, and made no attempt to hold the access once they had what they wanted [1][17]. "The network was not a priority for us, so we did not maintain our access," the group told Recorded Future News [5]. Solar's dwell estimate points the other way [16]. If the group let go in 2023, the activity Solar dates from early 2024 needs another explanation. If Solar's dates are right, the group's account of walking away is incomplete.

"We gained full access to its entire infrastructure relatively quickly and with little effort," the group said [2]. The reporting does not describe how the group got in or what it ran once inside. For operators outside Russia and Belarus, that leaves nothing from this case to patch or hunt for [15].

The group says its administrator-level access reached systems connected to other government agencies [1]. Solar describes the victim's network as linked to numerous other healthcare institutions, potentially giving the attackers a path into more systems [7]. By the group's dates, roughly two to three years passed between entry and Solar's discovery [14].

The group gives an intelligence motive. It says medical information gathered in its operations could help it assess Russian military casualties in Ukraine [9]. It will not say what it took from the Moscow network, citing operational reasons, and says most of its current operations are secret [10].

That fits the group's record. It formed after protests over Belarus's disputed 2020 presidential election [11]. It has claimed attacks on Belarusian government institutions and the country's railway system, and after Russia's full-scale invasion of Ukraine in 2022 it widened to Russian targets, both to gather intelligence and to disrupt infrastructure [12]. Quiet access to a health network's medical data is the collection side of that campaign [8][12].

"We take this opportunity to acknowledge responsibility for the hack and agree with the report's authors on at least one point: No matter how hard the Russians try to defend their systems, the Cyber Partisans 'find and will continue to find ways around' their security measures," the hackers said in a statement [3].

What to watch

  • Technical detail from Solar on the early-2024 activity, enough to show whether the same actor stayed after 2023 or a second intruder arrived.
  • Confirmation from the Moscow Department of Health or a connected agency that it was the unnamed organization in Solar's report.
  • Any leak or disruptive operation that tests the group's claim of current access to hundreds of IT systems in Russia and Belarus.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence45
Adoption
Insufficient
Hype gap+25
Incentives70
Confidence50
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    In a statement on Friday, the Belarusian Cyber Partisans said they infiltrated the Moscow Department of Health in 2023 and obtained administrator-level access to its infrastructure, including systems connected to other government agencies.

  2. [2]

    "We gained full access to its entire infrastructure relatively quickly and with little effort."

    ReportedSupportedSource: Belarusian Cyber Partisans, to Recorded Future News3 sources— create a free account to open themView cited source
  3. [3]

    "We take this opportunity to acknowledge responsibility for the hack and agree with the report's authors on at least one point: No matter how hard the Russians try to defend their systems, the Cyber Partisans 'find and will continue to find ways around' their security measures."

    ReportedSupportedSource: Cyber Partisans statement3 sources— create a free account to open themView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. therecord.media

    1 article · October 9, 2026

    Belarusian hacktivists admit to 2023 breach of Russian state healthcare network

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories