Full Report
Wildberries told several Russian media outlets earlier this week that payments to some sellers were delayed by security measures introduced after a distributed denial-of-service (DDoS) attack targeted systems used to track and withdraw their earnings.
Analysis Summary
# Incident Report: Wildberries DDoS and Payment Disruption
## Executive Summary
Russian e-commerce giant Wildberries experienced a large-scale Distributed Denial-of-Service (DDoS) attack that targeted its financial tracking and withdrawal systems. The attack triggered automated security protocols that suspended payment processing, resulting in approximately 20 billion rubles ($240 million) in unpaid earnings to sellers. While the company claims funds are safe, the incident has caused significant operational disruption and sparked government-level inquiries into the marketplace's stability.
## Incident Details
- **Discovery Date:** Late July/Early August 2026
- **Incident Date:** Late July 2026 (Ongoing impact through September)
- **Affected Organization:** Wildberries
- **Sector:** E-commerce / Retail
- **Geography:** Russia
## Timeline of Events
### Initial Access
- **Date/Time:** Final week of July 2026
- **Vector:** Distributed Denial-of-Service (DDoS)
- **Details:** High-volume traffic targeted digital infrastructure, specifically systems managing merchant earnings and withdrawals.
### Lateral Movement
- **Details:** Not applicable/disclosed. As a DDoS attack, the primary movement was external traffic flooding internal service endpoints.
### Data Exfiltration/Impact
- **Details:** No data exfiltration reported. Impact centered on the availability of the payment gateway and customer service portals. Roughly 95.6% of surveyed sellers reported missing payments for the last week of July.
### Detection & Response
- **Detection:** Automated security systems identified the surge in traffic and flagged withdrawal requests as high-risk.
- **Response Actions:** Wildberries implemented "technical procedures" and security measures that temporarily suspended the processing of outgoing transfers to prevent fraudulent withdrawals during the period of instability.
## Attack Methodology
- **Initial Access:** Network Layer/Application Layer DDoS.
- **Persistence:** Not disclosed (attributed to ongoing disruptive operations).
- **Defense Evasion:** Use of distributed botnets to bypass standard rate-limiting.
- **Impact:** Resource exhaustion of financial tracking systems and subsequent triggering of automated security lockdowns to prevent cash outflow during the attack.
## Impact Assessment
- **Financial:** Estimated 20 billion rubles ($240 million) in delayed payments to merchants.
- **Data Breach:** None reported; funds are stated to be secure.
- **Operational:** Widespread disruption to customer service centers, contact centers, and payment processing for nearly 2,000 surveyed sellers.
- **Reputational:** Significant; the Russian Union of Marketplace Sellers petitioned the Prime Minister and antitrust authorities to investigate the company's reliability.
## Indicators of Compromise
- **Behavioral indicators:** Massive spikes in inbound traffic to `wildberries[.]ru` payment and withdrawal APIs; increased latency in database queries related to merchant accounts.
## Response Actions
- **Containment measures:** Temporary suspension of the payment processing engine to ensure transaction integrity.
- **Eradication steps:** Implementation of DDoS mitigation filters (details proprietary).
- **Recovery actions:** Gradual restoration of payments; manual verification of "technical procedures" to resume transfers.
## Lessons Learned
- **Key takeaways:** High-volume DDoS attacks can be used as a smokescreen or a direct trigger for automated safety shutdowns that result in massive financial gridlock.
- **What could have been done better:** Communication with the seller community was insufficient, leading to panic and government intervention. Redundant payment processing paths could have prevented a total halt of transfers.
## Recommendations
- **Anti-DDoS Scrubbing:** Enhance capacity for scrubbing malicious traffic at the edge before it reaches internal financial tracking modules.
- **Graceful Degradation:** Design security protocols that allow for limited, verified payment processing during an incident rather than a total suspension of the financial ecosystem.
- **Transparency Protocols:** Develop a clear communication plan for stakeholders (merchants) to mitigate reputational damage and legal scrutiny during technical outages.