International Standoff 16 Cyberbattle

Cyber exercise finished

Banking

Commercial Bank of Standoff First Partner Bank Global Digital Bank

Banks in State F long ago ceased to be simply a place where money is kept. Here, people pay for purchases by QR code, arrange loans in a matter of minutes, open accounts without visiting an office, and transfer digital rubles between organisations.
The financial landscape is shaped by three major players. Global Digital Bank develops digital services and serves clients entirely online. First Partner Bank bets on a partnership ecosystem, QR payments, and the digital ruble platform. And Commercial Bank of Standoff is responsible for the corporate segment, interbank settlements, and business lending.
Attackers have access both to the banks’ external services and to their internal infrastructure: web portals, Kubernetes clusters, interbank transfer systems, customer databases, operators’ workstations, and digital ruble interfaces. The compromise of a single vulnerable system here rarely remains a local problem. The takeover of a container can lead to an attack on the entire cluster; hacking an internal portal can halt the connection of partners to the instant payment system; and data tampering on the digital ruble platform can cause panic among businesses and regulators.
The consequences of successful attacks quickly extend beyond a single company. Leaks of passport data trigger a wave of fraud and lawsuits. Disruption of interbank transfers hits supplies, salaries, and settlements between enterprises. The compromise of digital ruble systems endangers trust in the state’s new financial infrastructure.
When financial services work invisibly, hardly anyone thinks about them. But the moment the ability to pay for a purchase, receive a salary, or transfer money to a supplier disappears, digital comfort instantly turns to chaos.

Attacker metrics

Critical events
71reports
submitted
54critical events
triggered
Loading data
Difficulty:
Low
Medium
High
Master
Vulnerabilities
0vulnerabilities
discovered
Severity:
Critical: undefined
High: undefined
Medium: undefined
Low: undefined

Defender metrics

D0br03 utr0
Monitoring
Error: Success!
Monitoring
0
incidents
recorded
0
critical events
investigated

Results

Rank
Team
Triggered events
Event points
Discovered vulnerabilities
Vulnerability points
Bonus and penalty points
Total points
1

KiberS

12
67,500
4
1,400
68,900
2

SITON

10
57,500
2
600
58,100
3

r3kapig

10
50,000
2
500
50,500
4

HUST RED

5
27,500
1
400
27,900
5

Pentester Negeri Sipil

4
22,500
2
600
23,100
6

Cascroot

3
12,500
8
3,100
15,600
7

SecurePulse

3
15,000
1
300
15,300
8

Odoohondoo

3
12,500
0
0
12,500
9

Redmops

2
5,000
4
1,500
6,500
10

APHC.exe

1
5,000
1
300
5,300
11

TeaTime

1
2,500
0
0
2,500
12

NILADIC

0
0
1
300
300
13

TLP:R3D

0
0
1
300
300
14

tempest

0
0
1
300
300