Probiv, Russian-style: how the leaked data market became everyday infrastructure
“Probiv” (пробив) is a paid search for a specific person’s personal data using a fragment of information: full name, phone number, or a car’s license plate number. Over the past ten years, this kind of search has turned from a shadow service into everyday infrastructure: prices fall to hundreds of roubles, and Telegram bots serve as the interface.
This does not concern only public figures. Any Telegram user can order probiv on an ex-partner, a colleague, or a potential tenant — without knowing the darknet and without cryptocurrency. Understanding how the market works helps assess the real risks and avoid believing the myth “there is nothing to find about me.”
Below: what probiv is, where the data comes from, how the law responds, and what it means for an ordinary person.
In brief
- Probiv is a search for personal data for money. The bill is usually from 300 to 30,000 ₽ per item.
- Today’s interface is Telegram bots and closed chats, not the darknet.
- Sources: insiders in the MVD/FNS/banks/mobile operators + public leaks.
- In 2024, Law 137-FZ tightened fines for the “circulation” of personal data, but the market continues to operate.
- You cannot protect yourself completely, but you can reduce the value of your profile for a probiv operator and reduce social engineering risks.
How the probiv market works
The market is described in publications by TASS and independent media (for example, The Guardian (resource blocked in Russia)). The structure is roughly the same for all “providers.”
Who sells it
There are several types of participants: owners of Telegram bots with automatic replies from leaked databases; “manual” operators who have a contact in the MVD (МВД)/FNS (ФНС)/a bank; and resellers aggregating other people’s sources. Large “providers” have a price list, ratings, and arbitration.
What they offer
A typical range includes: identifying a person by phone number/license plate/bank card; history of moves and registrations; circle of relatives; bank statement for a period; border crossings; place of work; child’s data. The price correlates with the source: automatic replies from old databases are cheap, while a “fresh” request to a current IVD/FNS database costs thousands of roubles.
Where the data comes from
There are three sources. The first is old leaks and their “compilations” (mass automatic replies come through this channel). The second is current employees of law enforcement agencies, banks, mobile operators, and insurance companies who sell access to work databases. The third is hacks of corporate CRMs. According to publications, the share of “insider” data has grown in recent years.
Law 137-FZ and why it has not stopped the market so far
The law adopted in 2024 increased administrative fines for violations of the procedure for processing personal data and introduced criminal liability for the illegal use of large data sets. In practice, the market continues to operate: sellers move to new channels, use pseudonyms, and proving “circulation” in court in a specific case is difficult.
What is usually sold on the probiv market
| Service | What is provided | Where the data comes from |
|---|---|---|
| “Who is this” by phone number | Full name + date of birth + city | Old leaks from operators and services |
| Finding a phone number by full name | Current number | Fresh exports from services, insider |
| Bank by phone number | Which bank the client uses | Leaks from bank CRMs, insider |
| Card statement | Transactions for a period | Bank employee / debt collector |
| Border crossings | Dates of entry to/exit from Russia | Insider in the border service |
| Address and family composition | Registration, relatives | FNS / MVD / Rosreestr (Росреестр) through an employee |
How to check right now
If you suspect that someone has run probiv on you, this generally cannot be established technically: the request leaves no visible trace in your Gosuslugi (Госуслуги) or bank account. An indirect sign is a scammer’s call where the caller knows exactly which bank you use, your address, and your recent purchases.
What you can do right now: check whether you are listed in public repressive registries and on the MVD wanted list (this is a separate scenario, not connected to probiv, but useful for a general assessment of visibility).
What this means for an ordinary person
Most probiv is not done by “the state against you,” but by private customers: former partners, relatives in disputes, investigative journalists, creditors, and scammers. This changes the protection priority — the focus is not on “fooling SORM,” but on reducing everyday risks (plausible phone calls, phishing, doxxing).
Prevention does not mean “removing yourself from the internet” (that is impossible), but making your profile less valuable: different email addresses for different services, 2FA, caution when publishing your address and geotags, and a separate number for registration in unimportant services.
What to do next
- Do not publish your date of birth, passport details, or address in public — even in contest forms.
- Close your social media profiles to non-followers, and hide your friends list.
- Enable two-factor authentication in your bank, on Gosuslugi, in email, and in messengers.
- Use a virtual number to register in marketplaces and delivery services.
- If you suspect probiv by a bank employee, file a complaint with the bank and the Central Bank.
- More about scam schemes that use probiv is in our article “Why scammers know your bank and address”.
Disclaimer: this material is for informational purposes only. Ordering probiv is an offense (137-FZ, Article 137 of the Russian Criminal Code under certain conditions). We do not provide or recommend such services.
Conclusion
Probiv in Russia has become everyday infrastructure — it is no longer a “shadow service for criminals,” but a mass service available through messengers. The law is being tightened, but the market adapts faster. You cannot protect yourself completely, but basic digital hygiene sharply reduces the value of a profile for an attacker.