Перейти к содержанию

More than in all of 2025: a surge in cyberattacks on accounting departments via EDI and business correspondence

Once inside the system, attackers can not only substitute payment details in documents but also use the compromised company's infrastructure to attack its partners, initiating a chain of infections.

Ahead of the St. Petersburg International Economic Forum, Kaspersky Lab experts reported a sharp increase in attacks on Russian businesses through electronic document management (EDM) systems. In the first five months of 2026, 13,000 such incidents were recorded, which is already more than in all of 2025.

The main target of attackers is the accounting departments of companies working with large financial flows. At risk are enterprises in manufacturing, consulting, construction, as well as education and healthcare.

Experts attribute the increase in attacks to widespread digitalization. Accountants daily work with a large number of files, which hackers exploit by disguising malicious programs as familiar invoices, acts, and contracts.

The tactics of attackers have also changed. Banking Trojans, such as Buhtrap, have been replaced by more sophisticated tools. In 2026, there is a surge in activity of the DarkWatchman Trojan, which allows full control over a device, hidden surveillance, and spread across the corporate network. Sergey Golovanov, a leading expert at Kaspersky Lab, noted:

If a few years ago the main trend was mass fraud against private users, today more and more attacks are again directed at accounting and financial departments of companies. The reason is simple: a successful compromise of an organization can bring attackers significantly more income than an attack on an individual user.