LiMP VPN
← All news

22% of Russian Companies Have Databases Exposed Online

22% of Russian Companies Have Databases Exposed Online

In short: On October 5, 2026, Russian cybersecurity firm BI.ZONE published research on the external attack surface of Russian organizations: 22% of the companies surveyed had databases exposed to direct internet access, 18% had the Windows Remote Desktop Protocol (RDP) open, 15% exposed the SMB file-sharing protocol, and 6% exposed LDAP directory services. BI.ZONE also counted roughly 90,000 systems in the Russian segment of the internet running active remote-access services between July and September 2026. An exposed service does not automatically mean a breach — but it is an open door if there is no reliable lock behind it.

What was actually found

BI.ZONE researchers analyzed the external perimeter of Russian organizations — the hosts and services visible to anyone on the internet, without a VPN or credentials. Among the companies surveyed, 22% had databases (systems such as MySQL, PostgreSQL, MongoDB, or MS SQL) reachable for a direct connection from outside, even though such databases should, in principle, live only on the internal network. 18% had RDP, the Windows remote-desktop protocol, exposed on the perimeter; 15% had SMB, the protocol for network file and folder access; and 6% had LDAP, the protocol used to access corporate employee directories and permissions.

The report separately cites a figure of roughly 90,000 systems with active remote-access services found in the Russian segment of the internet during the third quarter of 2026. That does not mean all of them are vulnerable — but each one is, in principle, reachable for a password-guessing attempt or exploitation of a known flaw in the protocol itself.

Why this matters beyond a routine finding

BI.ZONE stresses that an exposed service alone does not mean a company has already been breached. Some of these connections genuinely support remote employees, branch offices, or contractors. But in practice, an unprotected RDP endpoint or an open database is one of the most common entry points in real-world ransomware and data-theft attacks: automated scanners used by attackers typically start brute-forcing a password or exploiting an unpatched flaw within hours of a host appearing on the network.

Exposed databases carry a particular risk. If a database is directly reachable and protected only by a weak or default password, an attacker does not need to breach the internal network at all — they connect from outside and either exfiltrate the data wholesale or delete it and demand a ransom. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued standalone guidance on RDP specifically because an exposed protocol so often becomes the first step in an attack chain against organizations worldwide.

What this means for customers and partners of these companies

An individual company's exposed database is rarely visible to an ordinary user directly — but sources like this are exactly where personal-data leaks typically originate, leaks that customers later encounter firsthand: phone numbers, addresses, order history, sometimes payment details. The more organizations leave their perimeter exposed, the higher the odds that personal data you handed to a bank, a retailer, or a delivery service ends up in third-party hands — not through any fault of your own, but due to someone else's lapse in basic security hygiene.

If you administer your own infrastructure — a website, a personal server, a home NAS — it is worth checking the same list: is a database or RDP endpoint unnecessarily exposed to the internet? Even free scanners such as Shodan or Censys will show exactly what your infrastructure looks like from the outside.

How to protect yourself

CISA and BI.ZONE's recommendations for organizations boil down to a few clear principles: never expose RDP or databases directly to the internet, use a VPN or a bastion host for remote access, enable multi-factor authentication, restrict access by IP address, and log all connections. For databases specifically: change default credentials and keep the database engine patched.

For an individual, the practical takeaway is not to assume that services you trust with your data will automatically secure their own perimeter. It is reasonable to minimize the amount of data you share with any given service, use unique passwords with two-factor authentication everywhere, and encrypt your own traffic on networks you do not control. The LiMP VPN app encrypts the connection between your device and the network, hiding from your ISP and the Wi-Fi owner which sites and services you use — a separate, complementary layer of protection, not a substitute for the data hygiene of the companies you trust with your information.

Plans from 69 ₽/month, a verified no-logs policy: LiMP VPN pricing.

Sources