A Man-in-the-Middle (MitM) attack was discovered on the XMPP messaging service jabber.ru, targeting its encrypted traffic on Hetzner and Linode hosting providers. The attack involved issuing fake TLS certificates using Let's Encrypt, allowing the interception of encrypted communications. The attack is believed to have lasted for up to 6 months and may have been a lawful interception. The service's administrators detected the attack due to an expired certificate and have taken steps to mitigate it.