Data breach
LovePlanet
- Records
- 20,077,733
- Breach date
- 1 January 2015Estimated
- Added
- 4 February 2025
What was exposed
3 types of data · 1 puts you at serious risk
- Usernames20,071,647
- Passwords19,650,754
- Email addresses19,279,753
About this breach
The Russian dating site LovePlanet (loveplanet.ru) is at the center of a large data breach that our investigation team estimates occurred around January 2015. According to our investigation team, the dataset contains 20,077,733 records tied to the platform's user accounts. The records sat largely out of public view for years before resurfacing: our team indexed the dataset on February 4, 2025, and Russian-language reporting has described a file with roughly 20 million LovePlanet entries circulating openly after being unavailable for years.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Researchers who have cataloged the dataset, including the breach tracker Synscan, report that the passwords in the file were stored in plaintext rather than in hashed or encrypted form. Some third-party indexes have linked the breach to GnosticPlayers, a hacker known for selling large caches of stolen records from dozens of companies in 2019, and Wikipedia's entry on the group lists LovePlanet among the companies it has claimed responsibility for. Our investigation team's catalog, however, attributes the breach to no confirmed actor, so the question of who took the data remains open.
Researchers have also noted that 2015 saw two leaks affecting major Russian-language dating services, LovePlanet and Mamba (mamba.ru), according to reporting by the Russian news agency Rossa Primavera.
What Information Was Compromised?
Our analysis found the following data types in this breach:
User nicknames: 20,071,647 records
Passwords: 19,650,754 records
Email addresses: 19,279,753 records
Not every individual is affected by every type of data listed here.
The combination matters. Because the passwords appear in plaintext, anyone holding the file can read them directly. Email addresses paired with those passwords give a direct path into other accounts where people reused the same credentials.
What Are the Potential Risks for Affected Individuals?
The most immediate risk is credential stuffing and account takeover. Many people reuse the same password across services. If you used a password on LovePlanet that you also used for email, banking, social media, or shopping accounts, attackers can try those same pairs elsewhere until one works.
Because the data is a dating-site dataset, there is also a targeted phishing angle. Attackers who hold a list of LovePlanet users can send convincing emails or messages referencing dating activity, exploiting the embarrassment or secrecy some people associate with dating accounts to pressure victims into clicking links or handing over more information.
If the data is circulating publicly, as Russian reporting suggests it eventually did, exposure to spammers, scammers, and data brokers grows over time.
What Should You Do If You Were Affected?
Change your password on LovePlanet if you still have an account, and on any account where you reused it.
Check whether your email address appears in this breach using the search tool.
Turn on two-factor authentication wherever it is offered, especially for email, which often controls password resets for everything else.
Be cautious with unexpected emails or messages that reference dating sites, account problems, or password resets, and do not click links in them.
Consider using a password manager so that every account has a unique password going forward.
