Data breach
gemotest.ru
- Records
- 30,183,800
- Breach date
- 1 January 2022Estimated
- Added
- 27 January 2025
What was exposed
6 types of data · 2 more reported · 1 puts you at serious risk
- Names30,173,204
- Home addresses15,613,444
- Passport numbers9,548,162
- Email addresses9,128,455
- Insurance providers1,185,811
- Phone numbers6,756
- Dates of birthReported, not counted
- Medical recordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Russian medical laboratory chain Gemotest lost a database containing information on more than 30 million customers after attackers exploited a vulnerability in the company's IT systems and pulled more than 300 gigabytes of records from its network. The stolen data was offered for sale on darknet forums in early May 2022, and Russia's media regulator, Roskomnadzor, later confirmed the leak. Our investigation team estimates the exposed dataset contains 30,183,800 rows, including names, passport numbers, home addresses, email addresses, and insurance provider details. Russian courts subsequently fined the company for the incident.
April 22, 2022: According to the leak-monitoring service DLBI, the database was extracted from Gemotest's systems no earlier than this date, following a vulnerability discovered by attackers.
May 1, 2022: The Telegram channel "Утечки информации" reported that a database of more than 30 million Gemotest customer records had been listed for sale on a darknet forum.
May 3, 2022: A second seller offered the order database, together with details of the vulnerability used to access it.
May 18, 2022: Gemotest confirmed that its database had been hacked.
July 8, 2022: A Moscow district court fined Gemotest 60,000 rubles under Russia's administrative code for violations in processing personal data.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Names: 30,173,204 records
Passport numbers: 9,548,162 records
Home addresses: 15,613,444 records
Email addresses: 9,128,455 records
Insurance provider details: 1,185,811 records
Phone numbers: 6,756 records
Reporting by Forbes Russia and RBC described additional material in the stolen trove, including dates of birth, mobile phone numbers, and roughly 554 million laboratory order records, some of which contained medical test results, including HIV tests.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Passport numbers combined with full names and home addresses are the raw material for identity fraud. In Russia, passport details are used to open bank accounts, take out loans, register SIM cards, and complete government transactions, so people whose passport data was exposed face a real risk of someone impersonating them for financial gain.
The possible exposure of laboratory results adds a medical privacy dimension. Health information, including test results, can be used for targeted scams, extortion, or discrimination if it falls into the wrong hands. Email addresses and phone numbers support ordinary phishing: attackers who know a person used a specific laboratory can craft convincing fake notifications about test results or billing to extract payment details or login credentials.
There is also a longer-term risk. Unlike a password, a passport number or date of birth cannot be changed. Once these details circulate on criminal markets, they can resurface in fraud schemes for years.
What Is gemotest.ru Doing in Response?
Gemotest's information security chief initially said the company could not confirm the leak but had opened an internal investigation, according to Meduza. The company confirmed the hack on May 18, 2022, and said it would tighten technical security measures and contact law enforcement if unauthorized access was substantiated.
Roskomnadzor requested a prosecutorial review despite a government moratorium on such inspections, and a later probe established that more than 300 GB of customer data had been downloaded, with access to a staff account reportedly involved. On July 8, 2022, a Moscow district court fined the laboratory 60,000 rubles, the minimum for the offense. Gemotest disputed the ruling and appealed, while stating it had strengthened its security after the intrusion was discovered.
What Should You Do If You Were Affected?
Watch for phishing messages that reference test results, invoices, or appointments, and do not click links or open attachments in unexpected emails or texts.
Be skeptical of callers who already know your name, address, or recent medical activity. Verify any claim by contacting the company directly through its official website.
Monitor your bank accounts and credit history for loans, accounts, or services opened in your name, and report anything unfamiliar immediately.
If your passport number was exposed, monitor for fraudulent use of your identity documents and consider reporting misuse to law enforcement.
Use unique passwords and two-factor authentication on any account linked to the compromised email addresses.
