Data breach
VKontakte
- Records
- 181,991,735
- Breach date
- 1 January 2012Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses181,991,735
- Passwords77,116,055
- NamesReported, not counted
- Phone numbersReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In or around 2012, a large trove of user credentials from VKontakte, Russia's largest social network, was taken in what appears to have been a credential theft operation that stayed quiet for years. Our investigation team estimates the dataset behind this listing contains 181,991,735 rows, including 181,991,735 email addresses and 77,116,055 passwords, with an estimated breach date of January 1, 2012. The data surfaced publicly in June 2016, when a hacker using the alias "Peace" offered roughly 100 million VK.com accounts for sale on a dark web marketplace for one bitcoin, then worth around $570 to $580. Breach notification site LeakedSource received a copy of the data and published an analysis, and the hacker told Business Insider that the underlying hack dated back to 2012 or 2013. No actor has claimed responsibility for the original intrusion in this listing.
Early June 2016: A hacker known as "Peace" begins selling roughly 100 million VK.com account records on a dark web marketplace, and Motherboard and LeakedSource report on the dataset, which includes names, email addresses, phone numbers, and passwords.
June 6, 2016: A VK spokesperson denies the site was breached, telling Motherboard the data consisted of "old logins/passwords that had been collected by fraudsters in 2011-2012," while urging users to reset passwords and enable two-step verification.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and passwords.
Reporting on the leaked files, which came from a dataset of about 100.5 million records, described additional fields: Infosecurity Magazine, citing LeakedSource, said each record contained an email address, a first and last name, a location (usually a city), a phone number, a password, and sometimes a second email address.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The main danger is password reuse. If you used the same password on VK and on other services, criminals can try those credentials against email providers, banks, shopping sites, and other platforms, a technique known as credential stuffing. Reporting that followed the leak noted credential-stuffing attempts against other major services after the data began circulating.
Even people who no longer use VK face risks. Exposed email addresses and phone numbers can be used for targeted phishing, spam, and scam messages that reference personal details to appear convincing. Because this dataset has circulated on underground forums since 2016, it may be combined with newer leaks to build more complete profiles of victims.
What Is VKontakte Doing in Response?
VK has disputed that its systems were hacked. In a statement to Motherboard in June 2016, a spokesperson said the "VK database hasn't been hacked" and that the data consisted of old logins and passwords collected by fraudsters in 2011 and 2012, adding that affected credentials had been forcibly changed. The company still recommended that users enable two-step verification and use strong passwords. The company has not publicly explained how the data was obtained.
What Should You Do If You Were Affected?
Change your VK password, and change it anywhere else you reused that password.
Use a unique, strong password for every account, ideally generated and stored with a password manager.
Turn on two-factor authentication for VK and your most important accounts, especially email.
Be cautious with unexpected emails or messages referencing your VK account, since your address is likely known to attackers.
Watch for unfamiliar login attempts on other services and reset those credentials if anything looks wrong.
