LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › mail.ru Dump Data Breach (2014)

CRITICAL severityConfirmedHow we verify

mail.ru Dump Data Breach (2014): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·September 10, 2014

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

mail.ru Dump Data Breach (2014)

Reported September 10, 2014. Approximately 16.6M people affected.

CRITICAL
Severity
16.6M
People affected
2
Data types exposed
September 10, 2014
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The mail.ru Dump Data Breach (2014) (reported September 10, 2014) exposed Email addresses and Passwords belonging to roughly 16.6M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Plaintext passwords exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the mail.ru Dump Data Breach (2014) breach?
16.6M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In September 2014, a collection of user credentials surfaced on the Russian Bitcoin Security Forum. One portion contained nearly 5 million email addresses and passwords, predominantly linked to the mail.ru domain. Additional records said to contain mail.ru addresses and plain-text passwords were later added, bringing the combined total above 16 million. The incident was subsequently marked unverified. The appearance of these records matters because email addresses paired with passwords can be tested against many online services. Individuals whose details match the dump may encounter attempts to access accounts where the same credentials were reused.

What happened

The records first appeared in September 2014. Public reporting at the time described several large credential collections posted to the forum, one of which focused on mail.ru addresses. Further material was added in January 2018. No official statement from mail.ru confirming or denying a direct intrusion has been recorded in the available information. The source of the credentials remains undisclosed, and the overall incident carries an unverified designation.

How a breach like this happens

Credential collections of this kind often originate from compromises at third-party websites or services rather than from the email provider itself. Attackers may obtain usernames and passwords through malware, phishing, or exploitation of unrelated platforms, then test the same combinations against popular email domains. Once assembled, the lists circulate on forums or file-sharing sites. In some cases the data are aggregated from multiple earlier incidents, which can make the exact origin difficult to trace.

mail.ru Dump and its sector

Mail.ru operates one of the largest email services in Russia and the surrounding region. Providers in this sector maintain user accounts that include login details, message archives, and linked services such as calendars or storage. A large set of credentials tied to such an account base draws attention because many people continue to rely on the same email address across multiple platforms over long periods.

What was likely exposed

The named data types are email addresses and passwords. The initial 2014 portion was described as containing nearly 5 million such pairs focused on the mail.ru domain, with later additions increasing the total beyond 16 million. Whether every record corresponds to an active mail.ru account, and whether the passwords were stored or transmitted in plain text by mail.ru itself, has not been confirmed. Public information does not include further categories of data.

What's at stake

For individuals, the primary concern is password reuse. When the same password protects other accounts, an exposed credential set can be used to attempt access elsewhere. For the organization, the circulation of a large credential list can prompt users to change passwords or migrate to competing services, even if the provider itself was not directly breached. The unverified status of the dump means the precise scope and accuracy of the records remain unclear.

What to do if you're exposed

Change the password for the affected email account and for any other service that used the same password. Enable two-factor authentication wherever available. Review recent login activity on important accounts. Readers can run a free exposure scan of their email address against known breach data to determine whether their information appears in public compilations.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

Companymail.ru Dump security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See mail.ru Dump’s full breach history →

More recent breaches

Team SoloMid Data Breach (2014)December 22, 2014Acne.org Data Breach (2014)November 25, 2014Malwarebytes Data Breach (2014)November 15, 2014Bot of Legends Data Breach (2014)November 13, 2014

Latest breaches

Read GalaxyWarden’s full analysis of the mail.ru Dump Data Breach (2014) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram