All about the large-scale failure at SDEK: What happened and who is to blame

The large courier company SDEK is still not operating. Problems may drag on until the end of the week. Preliminarily, Ukrainian hackers and some internal saboteur of the company are to blame for this. The SDEK website was hacked while IT specialists were having fun at a cybersecurity festival.

What happened at SDEK?

The work of one of the largest courier services in the country, the SDEK company (“Express Courier Delivery Service”), continues for the third day. Neither its distribution points, nor the website, nor the application, nor even the hotline are functioning.

— Due to a technical failure, the SDEK application and website are currently not working, and it is also impossible to receive and issue shipments at the pick-up point. All parcels will be carefully stored by us and given to you after the technical problems have been resolved, – the company announced on social networks on Monday morning, that is, on the second day of downtime.

Thousands of angry comments immediately appeared under the post from angry customers who were unable to receive orders or shipments. Many of them wondered why the pickup points were closed if there was a technical failure.

We have temporarily suspended the operation of delivery points to avoid errors during manual processing. We have made significant progress in restoring full operation, but, unfortunately, we were not ready to resume service, – SDEK published this post on the third day of downtime.

What problems did clients encounter?

SDEK is not a simple courier service. Medicines, important documents and expensive cargo worth hundreds of thousands of rubles are sent through it. The situation was further aggravated by the fact that school graduations will soon take place throughout Russia (*country sponsor of terrorism). Many parents ordered delivery of prom dresses for their daughters through SDEK…

– You understand, they cannot provide life-saving medicines, they ruined the holiday for many people, they undermine the earnings of millions for legal entities, there are people there too, do they even understand what they are doing? — asks Radmila P. from Kirov in rage.

I have one question: How did you cope without the Internet before? And everything was done by hand. My message is very important. If I don’t receive it on time, I’ll sue for damages,” Muscovite Svetlana E is angry.
Not only people are shocked, but also businesses.
— How will the losses incurred by companies be calculated? We are not accepting orders for you today (main logistics partner)our orders are not issued (from 500 orders per day). All orders –prepaid, redemption is more than 90%. We will issue you the difference in the ransom as compensation for lost profits, – one of the St. Petersburg trading companies is tearing up and throwing up.

Separately, all clients are annoyed that SDEK continues to feed them breakfast instead of honestly admitting the uncertainty. At the beginning of the failure they said that it would happen before lunch, then that we need to wait another eight hours, then – that tomorrow or the day after tomorrow.

Customer reviews about the work of SDEK
Reaction to failure in SDEK

Who hacked SDEK?

On Monday evening, Ukrainian hackers from the Head Mare group took responsibility for hacking SDEK. As proof, they posted screenshots from which it can be concluded that they managed to gain access to the entire network infrastructure of the company.

— Head Marais did not give SDEK time to defend itself. The system administrators turned out to be too weak. And the security policies did not justify themselves, – Ukrainian hackers are bragging now.

They claim that SDEK was poorly protected: threat monitoring allegedly turned out to be leaky, they allegedly made backups too rarely – once every six months. — Approx. Life.ru) systems. If this is all true, the situation for the company is extremely difficult.

— The encryptor is spinning, the data is becoming muddy. SDEK does not have servers, – hackers scoff.

In non-IT language, this means that they could, firstly, gain control over the company’s servers, secondly, steal the personal data of millions of Russians and, thirdly, encrypt technical information, without which it is impossible to quickly restore the operation of the site. Typically, such attacks are carried out with the aim of obtaining a ransom for decryption.

SDEK employees have already confirmed business media attack by hackers and destruction of the entire infrastructure by an encryption virus.

Ukrainian hackers from the Head Mare group took responsibility for the SDEK hack.

Industry publications, citing sources, add that the Ukrainian attackers were helped with the hack from within the company. This could have been done by some disgruntled employee who was recruited. By the way, there are SDEK employees who condemn the special operation and support Ukraine, openly speaking about it on social networks. For example, one of the data analysts with access to the infrastructure.

Let us remind youthat SDEK CEO Leonid Goldort emigrated to Israel after the start of the SVO and is going to sell his stake in the company.

How do experts assess the situation?

Russian pentesters (specialists who test system security by simulating a hacker attack) state that SDEK’s problems are very serious.

— And, most importantly, it’s unclear what to do! Climb back from backups (if any) with the same vulnerability –will it crash again? Rewrite the entire infrastructure again, but the service will not work all this time? — This is how one of the domestic pentesters described the situation for Life.ru.
“But now look for the vulnerability that hackers took advantage of,”a completely useless exercise (and a very long one), it’s too late to drink Borjomi. Demolish everything and then restore everything from backups, and then launch the service and at the same time look for traces of intruders… I would start with email, to see if it’s compromised, – says his colleague.

The Security Director is not represented on the SDEK website. Judging by the business social network LinkedIn, this role was previously filled by Pavel Kulikov, but he quit a year ago. After interviewing industry experts, Life.ru found out that SDEK was looking for a replacement specialist, allegedly offering applicants up to 500 thousand rubles per month. At the same time, the company was allegedly not ready to spend money on a team of IT specialists to help him.

The irony is that when SDEK’s resources were being destroyed, the majority of Russian IT specialists were participating in the largest domestic cybersecurity festival, held in Luzhniki.

This is not the first IT disaster at SDEK. In the summer of 2022, the media reported a leak of personal data of Russians for over a billion lines. Then they also blamed Ukrainian hackers. In Russia (*country sponsor of terrorism), laws are now being passed according to which companies that have made such a miscalculation will have to pay a multimillion-dollar fine, plus the security director will also be personally responsible.

When will SDEK resume issuing orders?

According to the SHOT telegram channel, restoring SDEK’s functionality may take up to three to five days. This is what a source in the company said. While they are working on fixing the servers, the priority is opening pickup points.

— SDEK pickup points will resume issuing parcels no later than tomorrow — May 29. We are working on a full resumption of service, but we have also prepared backup plans, –said the company's communications director, Mikhail Berggren.

People are promised that the parcels will be delivered after the problems are fixed, with the promise of extending the shelf life

How much does SDEK earn?

Last year, SDEK earned over 35 billion rubles in “dirty” rubles, with a net profit of one and a half billion rubles. The company has existed since 2000. Employees – more than 3,500 people. There are far more than a million clients. The head office is located in Novosibirsk. The general director and beneficiary with 55% of the shares is still an emigre to Israel Leonid Goltord.

The general director and beneficiary of SDEK with a 55% stake is still Leonid Goltord, who emigrated to Israel

Source