Full Report
In other news: NoName057 leaks data on Spanish police and military; China and South Korea detain vishing gang; AI malware is not that common.
Analysis Summary
# Industry News: Russia Tightens Digital Borders as Pro-Kremlin Hacktivists Target Spain
## Summary
Russia has escalated its internet censorship by beginning to block encrypted DNS protocols (DoH and DoT), targeting services from Google and Cloudflare to prevent citizens from bypassing state filters. Simultaneously, the pro-Russian hacktivist group NoName057 has leaked sensitive data on nearly 1,000 Spanish military and police personnel in retaliation for Spain’s support of Ukraine.
## Key Details
- **Date:** August 26, 2026
- **Companies Involved:** Google, Cloudflare, ReliaQuest, Digdir (Norway), Minimus.io
- **Category:** Government Regulation / Cybersecurity Incidents / Market Exit
## The Story
The Russian communications regulator, Roskomnadzor, has moved beyond simple website blocking to targeting the underlying infrastructure of internet privacy. By blocking **DNS-over-HTTPS (DoH)** and **DNS-over-TLS (DoT)**, the state is attempting to close a common loophole used by citizens to circumvent the "Sovereign Internet" filters. These protocols, offered primarily by Western giants Google and Cloudflare, hide a user's destination from local ISPs.
In the private sector, security firm **ReliaQuest** faced a publicized social engineering attempt by the **ShinyHunters** group. While the hackers claimed a major breach, ReliaQuest clarified that the incident was limited to "view-only" access of an Okta backend, highlighting a trend of attackers inflating breach claims for reputational damage. Meanwhile, the specialized container security firm **Minimus.io** announced its closure, giving clients 60 days to migrate, signaling a consolidation or failure in the niche hardened-infrastructure market.
## Business Impact
### For the Companies Involved
- **Google & Cloudflare:** Face diminished reach and utility of their privacy tools within the Russian market, potentially leading to a total loss of service availability for millions of users.
- **ReliaQuest:** Must manage a PR challenge following a social engineering incident, though their transparent response serves as a blueprint for modern incident disclosure.
### For Competitors
- **VPN Providers:** Will likely see a surge in demand as users look for even more robust ways to bypass Russian protocol blocks, though they face increased risk of being targeted by Roskomnadzor next.
### For Customers
- **Spanish Government Personnel:** Face significant personal security risks following the leak of their identities by NoName057.
- **Minimus.io Clients:** Are under immediate pressure to find alternative distroless and hardened container image providers within a tight 60-day window.
### For the Market
- The blocking of DoH/DoT marks a definitive shift toward **"Splinternet"** dynamics, where global internet protocols are no longer universally supported, complicating operations for multinational tech firms.
## Technical Implications
- **Protocol Interference:** Russia is likely using Deep Packet Inspection (DPI) to identify the specific handshakes of DoH and DoT, which typically run over port 443 and 853 respectively.
- **Tooling:** The release of **Fortitool** (FortiOS firmware decryption) and **WinFlesher** (attack surface assessment) provides new capabilities for security researchers to audit network infrastructure and Windows environments.
## Strategic Analysis
- **Market Positioning:** Russia's move reinforces its isolationist tech strategy, forcing domestic users toward state-monitored DNS resolvers.
- **Competitive Advantage:** Security firms that focus on **Identity Threat Detection and Response (ITDR)**, like ReliaQuest, are becoming the front line as attackers shift from software exploits to social engineering against identity providers (Okta).
- **Challenges:** The closure of Minimus.io suggests that while "security by default" in containers is in demand, standalone niche providers may struggle against integrated offerings from major cloud CSPs.
## Industry Reactions
- **Analyst Opinions:** Analysts view the DoH/DoT block as the "final nail in the coffin" for privacy in the Russian digital space.
- **Expert Commentary:** Cybersecurity experts note that the NoName057 leak is a classic example of **hybrid warfare**, using data exfiltrated via "insider" help (a former professor) to achieve political goals.
## Future Outlook
- **Predicting AI Malware:** Despite the hype, current data suggests AI-generated malware remains rare in the wild; however, watch for LLMs being used to refine **social engineering** scripts, making phishes harder to detect.
- **Consolidation:** Expect further consolidation in the container security space as smaller players like Minimus exit.
## For Security Professionals
- **Focus on Identity:** The ReliaQuest incident underscores that even high-tier security firms are vulnerable to social engineering. Prioritize hardware-based MFA and aggressive monitoring of identity provider (IdP) logs.
- **Infrastructure Auditing:** Practitioners using Fortinet devices should utilize the new **Fortitool** to verify firmware integrity against recent vulnerabilities.