Database leaks in Russia: why your data has long been online
Over the last three years, databases containing data on most adult residents of Russia have become publicly available: full names, phone numbers, passport data, SNILS, delivery addresses, account balances. According to Roskomnadzor, several hundred major incidents were recorded in 2024 alone, and the total volume of leaked records is measured in billions of rows.
This does not mean that “everything is lost.” It means that a single leaked password or phone number is no longer a catastrophe — the catastrophe is the habit of treating any database as “closed.” Understanding the scale helps choose reasonable protection measures instead of going to extremes.
Below: what exactly leaked, where leaked databases come from, and how this affects risks for an ordinary person.
In short
- According to RKN and TASS, billions of rows of Russians’ personal data leaked online in 2023–2025.
- The most common data in public access: full name, phone number, email, date of birth, passport, delivery address.
- Sources fall into three groups: business CRMs (delivery, marketplaces, banks), government databases, and extracts leaked by employees.
- Most “fresh” databases are old leaks combined with one new field, for example phone number → bank.
- It is impossible to fully “remove yourself” from these databases. You can reduce risks: 2FA, separate emails for different services, and calling back through an official channel.
What exactly leaked: types of data
Most leaks in recent years follow the same pattern — exports of customer databases from services with mass audiences. According to publications by TASS and independent researchers, the field structure repeats.
Identification data
Full name, date of birth, gender, passport data (series/number, sometimes a scan), SNILS, INN. These most often come from exports by banks, insurers, telecom operators, and delivery services.
Contact data
Phone number, email, delivery address (including entry intercom code), geolocation of recent orders. This is the most “traded” segment — it is what scammers use to build a plausible call scenario.
Financial markers
Not card details themselves (those leaks are relatively rare), but indirect signals: which bank the client uses, average order value, the fact of an active loan, balance on a brokerage account. This is enough for social engineering “from the bank security service.”
Behavioral traces
History of marketplace orders, taxi rides, medical visits, ordered medicines. These traces are used to build a “digital double” — a profile that lets the caller convincingly appear informed.
Where databases usually come from
| Source | What gets exposed | How it usually leaks |
|---|---|---|
| CRMs of delivery services and marketplaces | Full name, phone number, address, order history | Cloud hack, insider, unsecured API |
| Banks and insurers | Passport, INN, SNILS, fact of loans | An employee downloaded an extract, contractor leak |
| Telecom operators | Phone number, passport, billing, geolocation | Bribed employee at a mobile phone shop |
| Government databases | Passport, SNILS, registration, relatives | Leaks from the Federal Tax Service/MVD/Rosreestr, custom exports |
| Medical services | Mandatory medical insurance policy, diagnoses, visits | Unprotected clinic CRMs, laboratory leaks |
| Old leaks in compilations | Resale of merged databases | A “fresh” database is often old × old with one new field |
How to check right now
Wanted Radar does not work with leaked databases — we search the MVD wanted register (source: Mediazona (Медиазона)). But if you came here after a “strange” call from scammers and want to make sure you are not in public repressive registries, you can do that here.
For the leaks themselves, use separate tools — we cover this in detail in our guide “How to check a data leak”.
What this means in practice
The mere fact that a phone number or passport has leaked usually does not give a scammer an immediate way to steal money. Most attacks rely on social engineering: a plausible call + knowledge of context + urgency. If you remove the urgency and call back through an official channel, most schemes fall apart.
Passport data and SNILS leaks are more serious: they are used to take out microloans and create forged powers of attorney. Here, protection is not about a password, but about legal procedure: a ban on transactions without personal presence at an MFC (МФЦ), and a self-ban on loans at credit bureaus.
What to do next
- Enable two-factor authentication in all important services — preferably not SMS, but an authenticator app.
- Set up a self-ban on loans through Gosuslugi (Госуслуги) (available from 2025) — this closes the risk of microloans being issued using a leaked passport.
- Use different emails for financial, communication, and entertainment services.
- For any unexpected call “from the bank” / “from an investigator,” end the call and call back using the number on the back of the card or on the official website.
- Regularly check email through services like Have I Been Pwned.
- Do not leave your phone number and address in surveys, loyalty programs, or “promotions.”
- More about the state’s digital trace is in the article “What the FSB knows about us”.
Disclaimer: this material is for information only and is not legal advice. For questions about the processing of personal data by a specific operator, contact Roskomnadzor or a lawyer.
Conclusion
Database leaks in Russia have stopped being a rare incident — they are now the background state of the internet. Both government sources (TASS) and foreign investigations (The Guardian (blocked in Russia)) say this openly. Full protection is impossible, but basic digital hygiene closes most risks.