Passport data leak: what can actually go wrong
Passport data leaks in Russia are a mass phenomenon. Large databases that appeared in open access in 2024–2025 included passport series and number, date of issue, issuing authority code, registered address and, in some cases, a photo of the page. This set is enough for several typical scenarios against the owner.
The main risks are microloans and credit cards issued using someone else’s data, SIM cards issued under a power of attorney or a forged notarized power of attorney, targeted phishing when a fraudster knows the victim’s passport data and therefore looks “legitimate,” and registration of individual entrepreneur status and accounts. We examine each scenario below, indicating what can be done immediately, within a week, and within a month.
This material is not a call to panic. Most consequences can be reversed if you act step by step and do not sign anything without checking. The tone is dry: the goal is to describe the practice and the procedure.
In short
- Main risks: microloans, fake SIM cards, targeted phishing, loans, individual entrepreneur registration in someone else’s name.
- The first step is to request your credit history from a credit bureau, free twice a year.
- File a report about the leak and possible fraud with the Ministry of Internal Affairs, at your place of residence.
- Set an SMS ban at the bank and subscribe to notifications for any transactions.
- Check for loans in personal accounts at banks and microfinance organizations.
- A passport can be replaced only if there are grounds: damage, loss, or change of personal data.
What exactly happens after a leak
A passport in Russia is the basic identifier for most financial and government operations. When passport data gets into an open database, access to it is obtained not only by organized fraud schemes, but also by individual operators: in 2025, taking out a loan from a microfinance organization online takes a few minutes and formally requires only passport data and a phone number.
Microloans and loans
This is the most common scenario. A fraudster takes out an online loan from a microfinance organization using someone else’s passport data, sometimes with a SIM issued under a forged power of attorney. The victim learns about the loan when debt collectors start calling or notifications arrive from a credit bureau. Such a loan can be removed, but the procedure takes months and requires a police report.
SIM swap and number takeover
If a fraudster has passport data, they can try to get a duplicate SIM card through an operator’s retail office using a power of attorney. This gives access to SMS confirmation codes for logging in to a bank, Gosuslugi (Госуслуги), and marketplaces. The protection is a PIN for SIM replacement in the operator’s personal account.
Targeted phishing
A caller who states your passport series and number, date of issue, and registered address looks more convincing than an ordinary fraudster. Scenarios such as a “safe Central Bank account,” a “Gosuslugi representative,” or an “investigator in a fraud case” are built on this. Knowledge of passport data does not mean that the caller has any connection to official bodies.
Registration of individual entrepreneur status and accounts
A rarer but real scenario is opening individual entrepreneur status using someone else’s data for subsequent financial operations, often connected with cash-out schemes or gray transfers. You can find out about this through an extract from EGRIP, the Unified State Register of Individual Entrepreneurs, using your taxpayer identification number.
What this means in practice
| Sign | What it may mean | What to check / do |
|---|---|---|
| Unknown call mentioning your passport series | Use of a leaked database for phishing | End the call, call the bank back using the number on your card |
| Entry in a credit bureau about a loan you did not take out | Microloan using someone else’s data | File a statement with the microfinance organization and the police, dispute it with the credit bureau |
| An expected confirmation code does not arrive | Possible SIM swap | Urgently go to the operator’s office with your passport, block the number |
| Notification about registration in a new service | Someone is registering an account using your data | Recover the password, link it to your own email |
| Letter from the Federal Tax Service about an unknown individual entrepreneur registration | Individual entrepreneur registration using your data | File a statement with the Federal Tax Service to close it, file a report with the Ministry of Internal Affairs |
| Request for documents “for verification” from unknown people | Social engineering using leaked data | Do not send anything, check the contact through the official website |
How to check right now
The basic sequence has three steps. First, request your credit history from a credit bureau through Gosuslugi or directly; two requests per year are free. Second, log in to the personal accounts of all banks and microfinance organizations where you have ever had an account and check for active loans. Third, check the EGRIP extract for your name.
At the same time, check whether your full name appears in public repressive registries. Wanted Radar shows data from the Russian Ministry of Internal Affairs wanted list; the search takes a few seconds.
Check full name in the Ministry of Internal Affairs wanted list
Warning signs vs false alarms
A real warning sign is an entry in a credit bureau about a loan you did not take out, an incoming call from a debt collection agency, a notification from the operator about a SIM change, or a letter from the Federal Tax Service about registration actions. These signs are documented and verifiable.
Anonymous messages saying “your data has been leaked, follow the link” are usually phishing based on leaked databases. There are no “safe Central Bank accounts,” and Gosuslugi never calls asking you to state a code from an SMS. A call mentioning passport data is a sign that the caller has the data from a leaked database, not from an official system.
What to do next
- Request your credit history from a credit bureau through Gosuslugi or the bureau’s website.
- Check active loans in the personal accounts of all banks and microfinance organizations.
- Set an SMS ban at banks and subscribe to notifications about any transactions.
- Set a PIN for SIM replacement in your mobile operator’s personal account.
- If you find a loan taken out using someone else’s data, file statements with the microfinance organization, the Ministry of Internal Affairs, and the credit bureau to dispute it.
- Never dictate codes from SMS to anyone, including “the bank,” “the police,” or “Gosuslugi.”
- Read current leak statistics on TASS and an international analysis of the probiv personal data search industry in The Guardian.
Disclaimer: this material is for informational purposes and is not legal advice. For a specific situation, contact a lawyer or a debt specialist. Information in registries is updated retroactively and may differ from the current situation.
Conclusion
A passport data leak does not mean automatic financial losses, but it creates a persistent risk: microloans, SIM swaps, and targeted phishing are not theory, but mass practice in 2024–2025. Risk reduction is based on regularly checking credit bureaus and personal accounts, setting a PIN in the operator’s personal account, and calmly refusing any “urgent” instructions by phone.
Wanted Radar helps close a related question: whether you appear in open state wanted registries. This does not replace dealing with the financial consequences of a leak, but it gives a picture of another layer of risk.