
What was exposed, when it happened, and which databases confirm it.
- accounts
- 83,752,620
- Breached
- September 10, 2014
- Last Update
- January 9, 2018
Were you caught in this breach?
Search your email, phone number or username against every record CheckLeaked indexes.
What happened
In September 2014, several large dumps of user accounts appeared on the Russian Bitcoin Security Forum including one with nearly 5M email addresses and passwords, predominantly on the mail.ru domain. Whilst unlikely to be the result of a direct attack against mail.ru, the credentials were confirmed by many as legitimate for other services they had subscribed to. Further data allegedly valid for mail.ru and containing email addresses and plain text passwords was added in January 2018 bringing to total to more than 16M records. The incident was also then flagged as "unverified", a concept that was introduced after the initial data load in 2014.
Compromised Info
- Email addresses
- Passwords
Attestation
Four independent databases catalog this breach and they do not always agree. Each lane below is one source’s own count.
Sources & Link Methods
- LeakCheck— linked via automatic string matching
- Dehashed— linked via domain matching
- HIBP
FAQ
What was leaked in the MailRu breach?
The MailRu breach exposed: Email addresses and Passwords.
When did the MailRu breach happen?
The MailRu breach was disclosed on September 10, 2014 and affected 16,630,988 records.
Am I affected by the MailRu breach?
Search your email, phone or username at checkleaked.cc to find out whether your data appears in the MailRu leak.