EN

Database leaks in Russia: why your data has long been online

· · The Ateo Digital editorial team

Over the last three years, databases containing data on most adult residents of Russia have become publicly available: full names, phone numbers, passport data, SNILS, delivery addresses, account balances. According to Roskomnadzor, several hundred major incidents were recorded in 2024 alone, and the total volume of leaked records is measured in billions of rows.

This does not mean that “everything is lost.” It means that a single leaked password or phone number is no longer a catastrophe — the catastrophe is the habit of treating any database as “closed.” Understanding the scale helps choose reasonable protection measures instead of going to extremes.

Below: what exactly leaked, where leaked databases come from, and how this affects risks for an ordinary person.

In short

  • According to RKN and TASS, billions of rows of Russians’ personal data leaked online in 2023–2025.
  • The most common data in public access: full name, phone number, email, date of birth, passport, delivery address.
  • Sources fall into three groups: business CRMs (delivery, marketplaces, banks), government databases, and extracts leaked by employees.
  • Most “fresh” databases are old leaks combined with one new field, for example phone number → bank.
  • It is impossible to fully “remove yourself” from these databases. You can reduce risks: 2FA, separate emails for different services, and calling back through an official channel.

What exactly leaked: types of data

Most leaks in recent years follow the same pattern — exports of customer databases from services with mass audiences. According to publications by TASS and independent researchers, the field structure repeats.

Identification data

Full name, date of birth, gender, passport data (series/number, sometimes a scan), SNILS, INN. These most often come from exports by banks, insurers, telecom operators, and delivery services.

Contact data

Phone number, email, delivery address (including entry intercom code), geolocation of recent orders. This is the most “traded” segment — it is what scammers use to build a plausible call scenario.

Financial markers

Not card details themselves (those leaks are relatively rare), but indirect signals: which bank the client uses, average order value, the fact of an active loan, balance on a brokerage account. This is enough for social engineering “from the bank security service.”

Behavioral traces

History of marketplace orders, taxi rides, medical visits, ordered medicines. These traces are used to build a “digital double” — a profile that lets the caller convincingly appear informed.

Where databases usually come from

SourceWhat gets exposedHow it usually leaks
CRMs of delivery services and marketplacesFull name, phone number, address, order historyCloud hack, insider, unsecured API
Banks and insurersPassport, INN, SNILS, fact of loansAn employee downloaded an extract, contractor leak
Telecom operatorsPhone number, passport, billing, geolocationBribed employee at a mobile phone shop
Government databasesPassport, SNILS, registration, relativesLeaks from the Federal Tax Service/MVD/Rosreestr, custom exports
Medical servicesMandatory medical insurance policy, diagnoses, visitsUnprotected clinic CRMs, laboratory leaks
Old leaks in compilationsResale of merged databasesA “fresh” database is often old × old with one new field

How to check right now

Wanted Radar does not work with leaked databases — we search the MVD wanted register (source: Mediazona (Медиазона)). But if you came here after a “strange” call from scammers and want to make sure you are not in public repressive registries, you can do that here.

For the leaks themselves, use separate tools — we cover this in detail in our guide “How to check a data leak”.

Check a full name in the MVD wanted register

What this means in practice

The mere fact that a phone number or passport has leaked usually does not give a scammer an immediate way to steal money. Most attacks rely on social engineering: a plausible call + knowledge of context + urgency. If you remove the urgency and call back through an official channel, most schemes fall apart.

Passport data and SNILS leaks are more serious: they are used to take out microloans and create forged powers of attorney. Here, protection is not about a password, but about legal procedure: a ban on transactions without personal presence at an MFC (МФЦ), and a self-ban on loans at credit bureaus.

What to do next

  • Enable two-factor authentication in all important services — preferably not SMS, but an authenticator app.
  • Set up a self-ban on loans through Gosuslugi (Госуслуги) (available from 2025) — this closes the risk of microloans being issued using a leaked passport.
  • Use different emails for financial, communication, and entertainment services.
  • For any unexpected call “from the bank” / “from an investigator,” end the call and call back using the number on the back of the card or on the official website.
  • Regularly check email through services like Have I Been Pwned.
  • Do not leave your phone number and address in surveys, loyalty programs, or “promotions.”
  • More about the state’s digital trace is in the article “What the FSB knows about us”.

Conclusion

Database leaks in Russia have stopped being a rare incident — they are now the background state of the internet. Both government sources (TASS) and foreign investigations (The Guardian (blocked in Russia)) say this openly. Full protection is impossible, but basic digital hygiene closes most risks.

Check through Wanted Radar