Data breach
Raychat
- Records
- 3,566,891
- Breach date
- 31 January 2021Estimated
- Added
- 1 December 2024
What was exposed
4 types of data · 2 more reported
- Email addresses3,566,513
- IP addresses3,561,492
- Names3,438,650
- Biographies2,452,735
- PasswordsReported, not counted
- Private messagesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In January 2021, Raychat, an Iranian messaging platform used by businesses to talk with customers, exposed its user database on the open internet. Security researcher Bob Diachenko found a misconfigured MongoDB database holding what he described as more than 267 million user accounts, and before it could be secured, a bot attack wiped its contents. Its index of the leaked material contains 3,566,891 records tied to Raychat users. The mismatch between the figures reported in 2021 and the volume in circulation since has never been fully resolved.
January 31, 2021: Researcher Bob Diachenko reported on Twitter that Raychat had exposed its entire database on a misconfigured server and that a bot attack had destroyed it.
February 1, 2021: Raychat published a statement confirming an intrusion into its database while denying that user data had leaked, according to Iranian tech outlet Zoomit.
May 3, 2021: A dataset of roughly 150 million Raychat user records appeared on a Russian hacking forum, with a user claiming to have downloaded the data before it was wiped, as reported by Hackread.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (3,566,513 records), IP addresses (3,561,492 records), names (3,438,650 records), and biographical information (2,452,735 records).
Not every individual is affected by every type of data listed here.
Contemporaneous reporting described a broader set of fields. Gizmodo reported that the exposed database contained names, emails, passwords, metadata, and encrypted chats. Mozilla Monitor lists passwords, IP addresses, email addresses, browser user agent details, and names among the compromised data for this breach. Whether passwords were stored in a form that could be read by outsiders was disputed at the time; Raychat said its data was stored in encrypted form.
What Are the Potential Risks for Affected Individuals?
Exposed email addresses and names are raw material for phishing: criminals can send messages that appear to come from Raychat or other services, asking recipients to log in or hand over details. IP addresses can reveal approximate locations and internet providers, and can be used to target people with tailored scams.
If passwords were captured in a usable form, the risk extends to account takeover. Many people reuse passwords across services, so credentials from one breach are often tried against email, banking, and social media accounts. Biographical details make phishing messages more convincing, because they let a sender appear to already know something about you.
What Is Raychat Doing in Response?
Raychat acknowledged the intrusion the day after Diachenko's report. In a statement quoted by Zoomit, chief executive Mojtaba Mahmoudzadeh apologized to users and said the database had been taken offline while security measures were reviewed. The company said its technical team had found no evidence that information had leaked, and that it had opened contact with the researcher under responsible-disclosure norms. Gizmodo reported that the company said it would restore user data from backups.
The later appearance of Raychat records on a hacking forum in May 2021 cuts against the company's position that no data had escaped. Hackread's analysis found the leaked data appeared authentic, but it noted that researchers could not confirm whether the records came directly from Raychat's servers or from the earlier exposed database. No claim of responsibility has been verified, and the investigation team lists no claimed actor for this breach.
What Should You Do If You Were Affected?
Change your Raychat password, and change it anywhere else you used the same one.
Turn on two-factor authentication for your email and other important accounts, since email access lets attackers reset many other passwords.
Be skeptical of unexpected emails referencing Raychat, your account, or your personal details, and avoid clicking links or attachments in them.
Watch for unfamiliar logins or password-reset notices on accounts tied to the same email address.
In the news
- Gizmodo: Iranian Chat App Gets Its Data Wiped Out in a Cyberattackgizmodo.com (opens in a new tab)
- Zoomit: Raychat confirms intrusion but denies data leakagezoomit.ir (opens in a new tab)
- Hackread: Hacker leaks 150 million user records from Iranian Raychat apphackread.com (opens in a new tab)
- Mozilla Monitor: Raychat Data Breachmonitor.mozilla.org (opens in a new tab)
