Standoff 14: the international cyberbattle
Cyber exercise
finished
Banking
Commercial Bank of Standoff First Partner Bank Global Digital Bank
Banks in State F long ago ceased to be simply a place where money is kept. Here, people pay for purchases by QR code, arrange loans in a matter of minutes, open accounts without visiting an office, and transfer digital rubles between organisations.
The financial landscape is shaped by three major players. Global Digital Bank develops digital services and serves clients entirely online. First Partner Bank bets on a partnership ecosystem, QR payments, and the digital ruble platform. And Commercial Bank of Standoff is responsible for the corporate segment, interbank settlements, and business lending.
Attackers have access both to the banks’ external services and to their internal infrastructure: web portals, Kubernetes clusters, interbank transfer systems, customer databases, operators’ workstations, and digital ruble interfaces. The compromise of a single vulnerable system here rarely remains a local problem. The takeover of a container can lead to an attack on the entire cluster; hacking an internal portal can halt the connection of partners to the instant payment system; and data tampering on the digital ruble platform can cause panic among businesses and regulators.
The consequences of successful attacks quickly extend beyond a single company. Leaks of passport data trigger a wave of fraud and lawsuits. Disruption of interbank transfers hits supplies, salaries, and settlements between enterprises. The compromise of digital ruble systems endangers trust in the state’s new financial infrastructure.
When financial services work invisibly, hardly anyone thinks about them. But the moment the ability to pay for a purchase, receive a salary, or transfer money to a supplier disappears, digital comfort instantly turns to chaos.
Attacker metrics
Critical events
82reports
submitted
submitted
52critical events
triggered
triggered
Loading data
Difficulty:
Low
Medium
High
Master
Vulnerabilities
0vulnerabilities
discovered
discovered
Severity:
Critical: undefined
High: undefined
Medium: undefined
Low: undefined
Defender metrics
0
incidents
recorded
recorded
0
critical events
investigated
investigated
Results
Rank
Team
Triggered events
Event points
Discovered vulnerabilities
Vulnerability points
Bonus and penalty points
Total points
1
PanBobr
10
44,848
2
600
45,448
2
DD0ST4R
10
42,786
3
600
43,386
3
Vantage Point Security
6
32,637
2
600
33,237
4
Baguette2Pain
6
22,929
1
300
23,229
5
mimicats
5
17,582
2
600
18,182
6
Redteam VNPT-VCI
4
16,904
1
300
17,204
7
ChiLL Chain
2
12,106
2
700
12,806
8
С2 (Chisto na Chili)
2
9,031
1
300
9,331
9
team1337
1
6,375
1
300
6,675
10
TeaTime
1
3,070
3
1,100
4,170
11
V-Blue
1
2,125
1
300
2,425
12
HCS
1
2,000
1
300
2,300
13
CyPeaceJutsu_R2
1
2,000
1
300
2,300
14
0xPTGS1337
1
2,000
0
0
2,000
15
Eth-RED
0
0
2
700
700
16
M53 Red
0
0
2
700
700
17
r3kapig
0
0
1
300
300
18
ByteRaider
0
0
1
300
300
19
R0N1N
0
0
1
300
300
20
B A N D I T S - V I I
0
0
1
300
300



