CDEK Data Breach (2022): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The CDEK Data Breach (2022) (reported March 9, 2022) exposed Email addresses, Names and Phone numbers belonging to roughly 19.2M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
What happened
The reported incident centers on a March 2022 claim by a group identifying itself as IT Army. The group stated that it had released over 30GB of data allegedly taken from CDEK and containing more than 19 million unique email addresses together with associated names and phone numbers. The collective described its broader objective as de-anonymising Russian users through large-scale database disclosures. No official confirmation of the source, method of acquisition or exact contents has been established, and independent verification of the data’s origin remains unavailable.
How a breach like this happens
Incidents involving the publication of large customer datasets often begin with unauthorised access to an organisation’s systems. Attackers may exploit vulnerabilities in web applications, compromised credentials or misconfigured databases to reach stored records. Once obtained, the data can be copied and later posted on public leak sites or forums. In some cases the material is presented by groups that frame the release as part of a stated campaign rather than a conventional financial motive. The precise sequence in any single case is rarely disclosed by the affected organisation or confirmed by investigators at the time of initial reporting.
About CDEK
CDEK operates as a courier and logistics provider primarily serving customers in Russia and neighbouring regions. Like other delivery services, it routinely collects contact and identification details from individuals who ship or receive parcels. Such information enables order processing, delivery notifications and customer support. A dataset of this nature, if authentic, would therefore reflect the scale of a mid-sized national logistics operator handling millions of shipments.
What was likely exposed
The only data types named in the reported disclosure are email addresses, names and phone numbers. The exact scope and completeness of any records remain unconfirmed because the incident itself has not been verified. Organisations in the courier sector commonly store additional fields such as delivery addresses, order histories and payment references, yet no public statement has specified whether those categories were included. Readers should treat any list of exposed fields as provisional until corroborated by CDEK or an independent investigation.
Why it matters
Contact details at this volume can be used for targeted phishing, unsolicited marketing or attempts to link individuals across other online services. When names and phone numbers accompany email addresses, the data becomes more useful for social-engineering campaigns or account-recovery abuse. For the organisation, even an unverified claim can prompt regulatory scrutiny, customer inquiries and the need to review access controls. The absence of Reported Details does not eliminate the possibility that the records are genuine; it simply leaves the practical consequences uncertain for those potentially affected.
If your data was in this breach
Individuals who suspect their information may have been included should monitor their email accounts for unusual login attempts and consider changing passwords on any services that reuse the same credentials. Enabling multi-factor authentication where available adds a further layer of protection. A free exposure scan of an email address against known breach datasets can indicate whether the address has appeared in previously published collections, though such scans cannot confirm participation in any single unverified incident.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
RailYatri Data Breach (2022)Gemini Data Breach (2022)SevenRooms Data Breach (2022)Activision Data Breach (2022)Latest breaches
Read GalaxyWarden’s full analysis of the CDEK Data Breach (2022) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.