Roseltorg confirms cyberattack on Russia's state procurement platform

Organization
Roseltorg
Exploit
Hacking
Industry
Government

Roseltorg, one of the federal electronic trading platforms authorized by the Russian government to run public procurement under laws 44-FZ and 223-FZ, went offline on January 9, 2025. For several days the platform attributed the outage to unplanned technical work.

On January 13 the operator acknowledged that the disruption stemmed from what it described as an external attempt to destroy its data and the entire infrastructure used to conduct electronic auctions. CNews noted that the admission came four days after the platform first became unreachable.

A previously unknown pro-Ukraine group calling itself Yellow Drift claimed responsibility on Telegram, saying it had deleted 550 terabytes of data including mailboxes, backups and certificates, and posting screenshots it presented as proof. Roseltorg did not confirm that figure.

The company said all affected data and infrastructure had been fully restored and that trading systems would resume shortly, adding that procurement deadlines would be extended automatically once service returned. Its public website stayed largely unavailable for more than a week, with ComNews reporting on January 21 that core site functions had been restored.

Roseltorg serves government agencies and large state-linked buyers including Lukoil, Rostelecom, Alrosa, Rosatom and the Moscow city government. Users complained publicly about procurement delays and potential financial losses while systems were down.

Sources