Standoff 14: the international cyberbattle

Cyber exercise finished

Banking

Commercial Bank of Standoff First Partner Bank Global Digital Bank

Banks in State F long ago ceased to be simply a place where money is kept. Here, people pay for purchases by QR code, arrange loans in a matter of minutes, open accounts without visiting an office, and transfer digital rubles between organisations.
The financial landscape is shaped by three major players. Global Digital Bank develops digital services and serves clients entirely online. First Partner Bank bets on a partnership ecosystem, QR payments, and the digital ruble platform. And Commercial Bank of Standoff is responsible for the corporate segment, interbank settlements, and business lending.
Attackers have access both to the banks’ external services and to their internal infrastructure: web portals, Kubernetes clusters, interbank transfer systems, customer databases, operators’ workstations, and digital ruble interfaces. The compromise of a single vulnerable system here rarely remains a local problem. The takeover of a container can lead to an attack on the entire cluster; hacking an internal portal can halt the connection of partners to the instant payment system; and data tampering on the digital ruble platform can cause panic among businesses and regulators.
The consequences of successful attacks quickly extend beyond a single company. Leaks of passport data trigger a wave of fraud and lawsuits. Disruption of interbank transfers hits supplies, salaries, and settlements between enterprises. The compromise of digital ruble systems endangers trust in the state’s new financial infrastructure.
When financial services work invisibly, hardly anyone thinks about them. But the moment the ability to pay for a purchase, receive a salary, or transfer money to a supplier disappears, digital comfort instantly turns to chaos.

Attacker metrics

Critical events
82reports
submitted
52critical events
triggered
Loading data
Difficulty:
Low
Medium
High
Master
Vulnerabilities
0vulnerabilities
discovered
Severity:
Critical: undefined
High: undefined
Medium: undefined
Low: undefined

Defender metrics

KARL?!
Monitoring
0
incidents
recorded
0
critical events
investigated

Results

Rank
Team
Triggered events
Event points
Discovered vulnerabilities
Vulnerability points
Bonus and penalty points
Total points
1

PanBobr

10
44,848
2
600
45,448
2

DD0ST4R

10
42,786
3
600
43,386
3

Vantage Point Security

6
32,637
2
600
33,237
4

Baguette2Pain

6
22,929
1
300
23,229
5

mimicats

5
17,582
2
600
18,182
6

Redteam VNPT-VCI

4
16,904
1
300
17,204
7

ChiLL Chain

2
12,106
2
700
12,806
8

С2 (Chisto na Chili)

2
9,031
1
300
9,331
9

team1337

1
6,375
1
300
6,675
10

TeaTime

1
3,070
3
1,100
4,170
11

V-Blue

1
2,125
1
300
2,425
12

HCS

1
2,000
1
300
2,300
13

CyPeaceJutsu_R2

1
2,000
1
300
2,300
14

0xPTGS1337

1
2,000
0
0
2,000
15

Eth-RED

0
0
2
700
700
16

M53 Red

0
0
2
700
700
17

r3kapig

0
0
1
300
300
18

ByteRaider

0
0
1
300
300
19

R0N1N

0
0
1
300
300
20

B A N D I T S - V I I

0
0
1
300
300