Convex Data Breach (2023): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The Convex Data Breach (2023) (reported February 1, 2023) exposed Email addresses, IP addresses, Names and Phone numbers belonging to roughly 150K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Telecommunications providers sit at a sensitive intersection of everyday connectivity and large stores of customer identity data, making them recurring targets in a threat landscape where both criminal and politically motivated actors seek bulk personal records. In early 2023 one such incident involving the Russian provider Convex brought roughly 150,000 individuals’ details into public view, underscoring how quickly subscriber information can move from internal systems into open circulation.
According to contemporaneous reports, the breach was disclosed in February 2023 after a large volume of data was released online. The episode matters because the exposed fields—names, email addresses, phone numbers, IP addresses and physical addresses—are the building blocks of phishing, account takeover and real-world harassment, even when no financial credentials are included.
Breaking down the breach
Public reporting dated 1 February 2023 states that Convex, a Russian telecommunications provider, suffered a compromise in which approximately 128 GB of data were subsequently released. The material was said to contain 150,000 unique combinations of email addresses, IP addresses, physical addresses, names and phone numbers. The release was accompanied by claims, attributed to the group identifying itself as “Anonymous,” that the data illustrated illegal government surveillance; those claims remain assertions rather than independently verified findings in the available record.
No further technical detail—such as the precise intrusion vector, the duration of unauthorized access, or whether encryption or other controls were bypassed—has been disclosed in the summarized facts. The scale figure of 150,000 affected people and the 128 GB volume are the only quantitative markers provided. Beyond the listed data types and the public dump itself, the incident timeline and containment steps remain undisclosed.
How a breach like this happens
Incidents that end with large customer databases appearing online typically follow a recognizable pattern, though the exact path in any single case is often never fully published. Attackers commonly obtain an initial foothold through stolen or guessed remote-access credentials, unpatched internet-facing services, or social-engineering messages that trick an employee into running malware. Once inside, they move laterally, locate database or billing systems that hold subscriber records, and package the data for exfiltration.
In many telecommunications environments the same systems that manage service provisioning also store contact details, device identifiers and usage metadata. If access controls or network segmentation are incomplete, a single compromised account can reach far more records than intended. After the data leave the network they may be posted to public forums or file-sharing sites, sometimes accompanied by political or ideological statements. The absence of a named, confirmed threat actor in the public summary of this case means only the general pattern—not a specific group’s tactics—can be described.
Who is Convex?
Convex operates as a telecommunications provider in Russia, supplying connectivity and related services to residential and business customers. Organizations in this sector routinely maintain account records that link real-world identities to network resources: names and postal addresses for billing, email addresses and phone numbers for service notifications, and IP address assignments for network management. Because telephone and internet service is foundational infrastructure, a breach at such a provider can affect a broad cross-section of the local population and can raise additional questions about the security of any ancillary data the company may process.
The consequential nature of the incident therefore stems less from the company’s global brand recognition and more from the sensitivity of the subscriber data it necessarily holds and from the public allegation—unverified in the available facts—that the material related to surveillance practices.
What was likely exposed
The reported release explicitly listed email addresses, IP addresses, names, phone numbers and physical addresses, totaling approximately 150,000 unique records inside a 128 GB archive. These categories match the core identity and contact fields that telecommunications operators normally retain for account administration and network operations.
No public confirmation has been given that passwords, financial account numbers, government identity documents or call-detail records were included. While providers of this type often possess additional technical logs or billing histories, the facts supplied for this incident do not confirm their presence in the leaked set. Readers should therefore treat only the named fields as established and regard any further contents as unconfirmed.
Why it matters
For the individuals whose records appeared, the practical risks are concrete. Email addresses and phone numbers enable targeted phishing or smishing campaigns that reference a real service relationship. Names paired with physical addresses can support impersonation or unwanted contact. IP addresses, especially if tied to residential assignments, may reveal approximate location patterns. Even without passwords or payment-card data, the combination lowers the barrier for social-engineering attacks against the same people at other services.
For the organization, the release creates regulatory, reputational and operational consequences. Customer trust is eroded, notification and support costs rise, and any allegation of improper data handling—whether or not ultimately substantiated—invites scrutiny from authorities and the public. Because the data were posted openly, the exposure cannot be fully reversed; copies can persist indefinitely on third-party sites.
Were you affected?
If you held an account or service with Convex around the time of the incident, assume your contact details may be among those released and take basic precautions. Change passwords on any accounts that used the same email address, enable multi-factor authentication wherever it is offered, and treat unsolicited calls or messages that reference your telecom service with skepticism. Monitor financial and email accounts for unusual activity.
You can also run a free exposure scan of your email address to check whether it has appeared in known breach datasets, which provides an additional signal beyond this single incident. Remain alert to phishing attempts that reuse personal details, and consider placing fraud alerts with relevant credit or identity services if you believe your physical address or phone number could be misused.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
GLAMIRA Data Breach (2023)Welhof Data Breach (2023)Zadig & Voltaire Data Breach (2023)Blooms Today Data Breach (2023)Latest breaches
Read GalaxyWarden’s full analysis of the Convex Data Breach (2023) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.