HabrJuly 26, 2026🇷🇺Translated from Russian

Measuring Data Leak Risk by Days of Silence Rather Than Megabytes in Cloud Environments

A financial professional with experience in risk assessment argues that the primary metric for evaluating data leaks should be the number of days an incident remains unknown internally, rather than the sheer volume of documents or database records that have escaped.

In cloud-based office environments, the most damaging events often occur without any audible warning. An employee may make an internal document publicly accessible, forward a batch of emails with attachments to an external address, or have a password changed in their mailbox, and the system registers none of these actions as suspicious.

Each of these operations is entirely legitimate and necessary for daily work, yet context determines whether they represent routine activity or a serious exposure. Only a human reviewer can properly interpret that context when notified promptly.

Why blanket restrictions often backfire

When executives first learn about these silent risks, their initial impulse is to disable public links, block external forwarding, and tighten all controls. The author consistently advises against this approach because it drives legitimate workflows into invisible channels such as personal email accounts, messengers, or USB drives.

Once activity moves outside monitored systems, visibility drops from partial to complete zero, converting a manageable risk into an uncontrollable one.

Core requirements for effective monitoring tools

The recommended evaluation checklist for any detection solution, whether commercial or custom-built, includes the following priorities:

  • Event-driven alerts instead of scheduled scans, because daily log reviews are always too late and suffer from alert fatigue.
  • Automated first response, such as automatically revoking public access when an alert fires, so that an unread notification at 3 a.m. on a weekend still results in the exposure being closed.
  • Periodic overview reports that provide a high-level view of access permissions and open resources without generating urgent noise.
  • Health verification mechanisms, including detailed execution logs, test runs before production activation, and failure notifications, to ensure the monitoring system itself has not silently stopped working.

Additional mandatory questions before deployment concern the integration method and data location. The tool must connect through standard OAuth for Yandex 360, operate with administrator-level rights only, and keep all processed data within the required jurisdiction for Russian organizations.

The author notes that tools meeting these criteria already exist for the Yandex 360 ecosystem and encourages readers to apply the same checklist regardless of platform. The central message remains that employees are rarely malicious; they are usually rushing and taking shortcuts. Punitive restrictions simply move the problem out of sight, while shortening the time between risky action and detection directly reduces potential damage.

Related articles

AntiMalwareData Breaches & Leaks

Russian Interior Ministry Opens Five Criminal Cases Against 'Glaz Boga' Analog Platforms Selling Personal Data of Russian Citizens

The Russian Ministry of Internal Affairs (MVD) has initiated five criminal investigations following the discovery of online platforms that sold personal data of Russian citizens, operating on the same model as the notorious 'Glaz Boga' service. These platforms allowed users to pay for access to detailed biographies and confidential information compiled into multiple files, including passport details, bank account records, and other sensitive personal information. The cases are being investigated under Article 272.1 of the Russian Criminal Code, which addresses the illegal use, transfer, collection, and storage of computer information containing personal data. Authorities have seized the servers of the implicated services and are currently analyzing their contents to gather evidence, although the specific names of the platforms, the number of clients, and the volume of data sold remain undisclosed. The developments highlight how repeated data leaks have transformed personal information into a marketable commodity traded on underground marketplaces, prompting law enforcement action against the operators responsible for distributing such data.

AntiMalwareData Breaches & Leaks

Solar inRights 3.11 Automatically Blocks Corporate Accounts Whose Passwords Appear in Dark Web Leaks

GC Solar has released Solar inRights 3.11, a major update to its identity and access management platform that integrates directly with the Solar AURA threat monitoring service. The new version automatically detects corporate credentials exposed in open sources and dark web dumps, validates whether the same login-password pairs remain active inside the organization, and instantly revokes access while alerting the security team. The feature addresses the common scenario in which employees reuse work email addresses and passwords on third-party websites, allowing attackers to test stolen credentials against corporate systems in what appears to be legitimate login attempts. Research cited by Solar shows that a single large Russian company typically has more than 600 unique corporate accounts circulating in public and underground sources, although only about 4 percent directly indicate infrastructure compromise. Yandex Cloud data further reveals that valid account abuse featured in 54 percent of over 25,000 attacks on cloud and hybrid environments during the first half of 2025. In addition to the leak-response capability, version 3.11 introduces improved search, request filtering, and integration templates for Active Directory, Exchange, and 1C.

securitylab_nData Breaches & Leaks

Hacker Leaks Suno Source Code Exposing Massive Scraping of 2 Million YouTube Music Tracks and Customer Data Breach

A hacker known as ellie.191 has leaked the internal source code of Suno, one of the largest AI music generation services, to 404 Media, revealing extensive unauthorized scraping of copyrighted material from YouTube Music, Deezer, Genius, and other platforms. The leaked files, believed to date from 2023 and 2024, detail how Suno collected over 2 million music tracks and hundreds of thousands of hours of audio, including 152,000 hours from YouTube Music alone, along with 420,000 podcasts totaling nearly 1 million hours. Additional datasets came from Pond5, Jamendo, Freesound, MuseScore, and other libraries, with the company using Bright Data proxies to bypass restrictions and tools to isolate vocals from instrumental tracks. The breach also exposed hundreds of thousands of customer records, including emails, phone numbers, and partial Stripe payment data, which multiple users have already confirmed as accurate. Suno claims the incident was limited, occurred in November 2025, and involved only outdated code, while denying any leak of sensitive payment information. The hacker gained access via an employee account compromised by the Shai-Hulud worm, which stole GitHub and cloud credentials, and stated the attack was driven purely by curiosity rather than a specific motive. This disclosure lends support to ongoing lawsuits from the Recording Industry Association of America alleging direct copyright infringement by Suno.

AntiMalwareData Breaches & Leaks

Over 600 Leaked Corporate Accounts Found Per Major Russian Company, with Half Exposing Plaintext Passwords

A study by Solar AURA examined nearly 19,300 records tied to the ten largest Russian companies from the RBC500 ranking and uncovered 6,194 unique corporate accounts. More than half of these credentials — 3,739 — were circulating on the dark web with passwords in plaintext. Only 4% of cases showed evidence of direct compromise of corporate infrastructure, indicating that the majority stemmed from employees reusing work emails and passwords on external platforms such as marketplaces, forums, and SaaS services. Researchers also identified over 12,600 additional records containing employee personal data that can be leveraged for targeted social-engineering attacks. The findings highlight how credential-stuffing, phishing, and password-reset abuse become trivial once external leaks occur, especially when short or reused passwords are involved. Experts recommend continuous leak monitoring, mandatory multi-factor authentication, and rapid blocking of exposed accounts to reduce risk.