Security1 distinct publisher2 min readUpdated
The Russian traffic-interception vendor confirms an intrusion while denying attackers reached EtherSensor or customer data. The one checkable claim belongs to customers who have not spoken.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The two accounts touch at one point, which is that someone was inside Microolap's estate [14]. Everything a buyer would need to know sits on the far side of the disagreement. Black Spark says more than a month of access and reach into EtherSensor [6]. Microolap says rarely used development systems hosted by another Russian provider, an outdated copy of its website, and an old Bitrix24 install [9].
Read the denial by its nouns. The company denies that the compromise gave attackers access to EtherSensor or to data belonging to customers and partners [10]. It also confirms that one of the systems reached was a customer management platform holding what it describes as a limited amount of data [9]. Both statements can hold at once only if "customer data" means something narrower inside the vendor than it does to the customer whose records were in that Bitrix24 [16]. The vendor's account also does not engage the claimed month of access, or say when the intrusion began [17], while chief executive Andrey Smirnov says the company's systems "worked as intended" and that it detected the incident [5].
The deletion claim is the part that can actually be settled, and not by Microolap. The attackers said they extracted and deleted data belonging to Russian Railways, the banknote and document producer Goznak, VTB Bank and its leasing subsidiary, and NEK.TECH [7]. Missing records are visible to the party that owns them. Five named organisations, and not one of them appears in the report saying anything [15].
Evidence on the attacker side is no stronger. The screenshots have not been independently verified [8], and the group publishing them describes itself as an underground movement in Russia whose members have chosen what a Telegram manifesto calls "armed resistance" [13]. That is a political posture, and political postures have an interest in a large number. Smirnov's request that people not treat the attackers' claims as fact is reasonable [4]; it is also an argument that applies in both directions.
What lifts this above a routine denial is what the company sells. Microolap builds software for intercepting and analysing network traffic [1]. A vendor in that business accumulates the paperwork of the job, meaning the record of which networks are watched and how the watching is set up. A customer buying visibility hands over a description of where it cannot see. A stale website and a forgotten CRM at such a supplier are not the same class of asset as the same two systems at a company that sells office furniture, and the customer's exposure is not settled by the supplier's assessment being correct.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Microolap said none of its production systems or components critical to EtherSensor were affected, that the platform continued to operate normally, and that the incident had no impact on its performance, data integrity or availability.
Microolap is a Russian software developer that develops software for intercepting and analyzing network traffic.
Microolap confirmed that hackers had compromised some of its systems but denied claims that they gained access to its network monitoring platform or stole data belonging to major Russian companies.
Microolap said Thursday that it had detected an attempted breach of several non-critical systems and found no evidence that hackers accessed its core infrastructure, customer data or other sensitive information.
Microolap CEO Andrey Smirnov said: "We urge people not to treat the attackers' claims as fact."
Smirnov said: "Our cybersecurity systems worked as intended: We detected the incident and kept critical data secure."
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet, two self-interested accounts
Everything traces to a single trade-press report relaying a vendor statement and a hacktivist claim. The vendor's scope findings come from its own investigation; the attackers' proof is screenshots the reporter says could not be independently verified. No forensic third party is named, no customer confirms or denies, and no intrusion timeline is on the record. What is solidly established is that each side said what it said, and that both agree attackers got in.
Deployment footprint asserted only by attackers
The supplied material contains no verified information about who runs EtherSensor or at what scale. The five customer names come from the attackers and are neither confirmed by Microolap nor by the organizations themselves, and the vendor's statement that the platform continued operating normally is self-reported. There is no basis to score real-world adoption without inferring facts the source does not provide.
Both accounts outrun their proof
Positive because assertion exceeds demonstration on both sides, though the reporting itself stays cautious. The attackers claim a month inside the network, access to the interception platform and destruction of data at five major Russian institutions, supported only by unverifiable screenshots. The vendor claims its defenses 'worked as intended' and that critical data stayed secure, in the same statement that concedes attackers reached a live-data CRM and a public website, and without addressing how long the intruders were present. The gap is in the competing claims, not in the article, which flags the verification limits.
Every speaker has a stake in the scope
Both primary sources are maximally interested parties. Microolap sells network interception software to large Russian state-linked customers, so minimizing scope and asserting containment is commercially and politically necessary; its CEO's quotes do exactly that, and the investigating security firm is left unnamed. Black Spark is a self-declared underground movement pursuing 'armed resistance' whose objective is impact perception, giving it reason to inflate dwell time, platform access and victim prominence. The reporting outlet covers the Russia-Ukraine cyberwar from Ukraine, an orientation visible in the framing of the actors.
Confident about the dispute, not the facts
Confidence is high that the two accounts exist as described and that they conflict on every material point, since both are quoted in a single competent trade report. Confidence is low on the substance: no independent forensics, unverified artifacts, silent customers, no timeline, and no second publisher. Adoption cannot be scored at all, which caps overall certainty.
security
The aim point was a peripheral: how US operators blinded Iran's air defenses1 distinct publisher
security
U.S. Bank's answer to LockBit: the breach happened two tiers out1 distinct publisher
security
One vendor, 19 million patients: the MyDr breach is a lesson in whose perimeter matters1 distinct publisher
security
TikTok's own review says the safety fix was withheld "by design," and that phrase is now evidence1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026