Russian companies logged 326 public data breaches in the past 18 months, exposing about 1.175 billion lines of user data and underscoring how the country’s geopolitical confrontation is translating into a persistent economic and operational cost for business.
Russian companies report 326 data breaches

The scale matters because cyber incidents have moved beyond a compliance headache and into a measurable drag on corporate balance sheets, customer trust and insurance pricing. F6, a cyberthreat specialist, said the number of public database leaks in Russia in 2025 and the first half of 2026 was roughly twice that recorded across Latin America, the Middle East and Africa, Asia-Pacific and other CIS states combined. That puts Russia at the center of a breach cycle that is larger than many peer regions even though its economy is far smaller than the global bloc it is being compared with.

Analysts cited a surge in attacks on businesses and institutions during the geopolitical conflict, with the objective not just of stealing data but of inflicting maximum damage on companies and their customers. F6’s technical chief, Elena Shamshina, said the intensity of attacks against Russian organizations remained “unprecedentedly high,” and argued that losses would be materially worse without modern security tools and professional incident-response teams.
For investors, the immediate implication is that cyber risk in Russia has become a structural operating expense rather than a one-off event. Higher breach frequency tends to lift spending on security software, monitoring and recovery services, while also increasing demand for cyber insurance. Russian cyber insurance premiums were estimated at 1.5 billion to 3 billion rubles and could double by year-end, according to earlier reporting cited in the material, with insurers already seeing higher take-up after a string of major incidents in 2025.
That creates a clear split in winners and losers. Security vendors, insurers and firms with stronger response capabilities stand to benefit from the escalation. Companies with weaker defenses face greater downtime risk, legal exposure and reputational damage, while customers and counterparties bear the cost of compromised data. The broader macro effect is a widening tax on Russian corporate activity at a time when geopolitical risk is already constraining capital allocation and raising the cost of doing business.
The pattern also matters because it suggests the breach problem is not easing as firms adapt. Rather, attack sophistication appears to be rising alongside the conflict, making it harder for organizations to treat security as a box-ticking exercise. For investors looking at Russian exposure, the key question is no longer whether cyber incidents will occur, but whether companies have the scale, controls and insurance to absorb them without lasting damage to earnings and valuations.
| Entity | Gains | Losses |
|---|---|---|
| Cybersecurity firms | ▲Higher demand | ▼Less urgency to spend |
| Cyber insurers | ▲Premium growth | ▼Lower claims frequency |
| Russian companies | ▲Better defenses if prepared | ▼Data loss, disruption |
| Customers | ▲Stronger protections over time | ▼Exposure of personal data |



