Since the beginning of 2026, BI.ZONE EASM specialists have discovered database services directly accessible from the internet in 22% of Russian companies. Such placement increases the attack surface and creates an additional risk of corporate information leakage, especially when using outdated or vulnerable software.
In another 18% of organizations, remote access services via RDP protocol are available from the external network. Attackers may attempt to guess credentials or use previously compromised passwords to penetrate the infrastructure.
The presence of such services does not in itself indicate a company breach, but it increases the likelihood of a successful attack. In July–September, experts discovered about 90,000 systems in the Russian segment of the internet with active remote access services amid a vulnerability in Microsoft Remote Desktop Services that allows remote code execution.
In addition, SMB was accessible in 15% of companies, and LDAP in 6%. These protocols can provide attackers with information about the internal network structure, accounts, and available resources.