[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2jceltmrcciz2":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":33,"isSensitive":33,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda4882513a","CDEK","CDEK Unverified Breach Dataset (2022)","cdek","cdek.ru","2022-03-09T00:00:00.000Z","2022-03-17T06:19:02.000Z","2026-07-19T22:33:08.252Z","Unknown","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fukraine-recruits-it-army-to-hack-russian-entities-lists-31-targets\u002F",[15,17,18],"https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20220121085729id_\u002Fhttps:\u002F\u002Fwww.cdek.ru\u002Fabout\u002Findex.html","https:\u002F\u002Fwww.cdek.ru\u002Fru\u002Fabout\u002F",19218203,"known",null,"email_identifiers","Critical",[25,26,27],"Email addresses","Names","Phone numbers","\u003Cp>The \u003Cstrong>unverified dataset attributed to CDEK\u003C\u002Fstrong> was published in March 2022 with 19,218,203 unique email addresses.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The data classes that can be safely limited for this record are email addresses, names and phone numbers. The tracked measure is \u003Cstrong>19,218,203 unique email addresses\u003C\u002Fstrong>; it must not be interpreted as a confirmed count of CDEK customer accounts, delivery records or individual people. One person may have multiple contact details, and the claim that the source was CDEK's systems has not been independently established. Email addresses can support phishing and account discovery, phone numbers enable fraudulent texts and calls, and names make messages more personal. Association with a courier brand can make delivery, customs-fee, address-update or return scams more convincing. Passwords, physical addresses, passport details, payment data, shipment history and package contents are not verified classes in this record; adding them would go beyond the available evidence.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>In March 2022, a hacktivist collective published more than 30 GB of data that it claimed came from Russian courier and logistics brand CDEK. The record date of 9 March 2022 refers to the published dataset; it does not prove that CDEK's network was entered or that data was extracted on that day. The material was indexed on 17 March and its authenticity assessment remained “unverified.” Independent public evidence has not established whether it came directly from CDEK, through a third party, or from a combination of other sources. The initial access method, affected systems, time spent in a network and creation dates of the records were not reliably disclosed. The event therefore cannot be classified as a confirmed internal company breach, supplier incident or exploitation of a particular vulnerability. The “Unknown” source value expresses this evidence boundary rather than assigning an unsupported technical cause.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People whose email, name or phone appears in the dataset may face social-engineering risk, but a match does not prove they were a CDEK customer or that the information came from CDEK. Attackers can combine contact details to create messages about delayed parcels, failed delivery, missing addresses, returns, customs charges or customer-service calls. A phone enables targeting through text, voice and messaging apps; email supports fake sign-in pages, malicious attachments and account discovery. Since no password class is verified, a match does not mean that a password was exposed or an account was taken over. The 19.2 million measure also does not establish that every row contains all three classes or that each detail remains current. Potential exposure, successful fraud and confirmed compromise are separate outcomes.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>Before following a link in an unexpected parcel message, check the shipment through the carrier's app or by typing its address and \u003Cstrong>verify it through an official channel\u003C\u002Fstrong>. Use contact details on the company site rather than a number inside the message. Reject requests for card details, passwords or one-time codes framed as an address correction, customs charge, redelivery or return. Enable multi-factor authentication on email, review recovery details and sessions, and remove unfamiliar forwarding rules or app passwords. Since passwords are not verified here, this match alone does not show that a CDEK password leaked; change passwords reused across other incidents. Report suspicious texts and fraudulent pages, and contact your bank immediately for an unauthorized payment.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Separate email aliases for shopping and delivery can reveal which registration a message relates to and make fraud easier to identify. A different password for every service, stored in a password manager, limits takeover from other incidents even though none is verified here. Use multi-factor authentication on email and important accounts, preferably through an authenticator app or hardware key. Add a mobile-carrier PIN and number-transfer alerts to reduce SIM-swap risk. Remove obsolete addresses and phones from courier profiles, disable unnecessary marketing permissions and consider deleting unused accounts. Check the real sender domain instead of trusting the displayed name because filtering cannot stop every scam. Contact details remain useful for years, so continue periodic exposure and account-security reviews.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>A matching email means it appeared in the unverified dataset published in March 2022 and attributed to CDEK. It does not prove that the person was a CDEK customer, that data left company systems, that an account was compromised or that a password was exposed. Treat it as a warning: inspect delivery-themed email and phone messages carefully, and review sessions and recovery options on important accounts. No match is an absolute safety guarantee because you may have used another address, appeared only through a phone or name field, or faced another unverified dataset. Checking services cover only indexed material. Preserve the terms “attributed to CDEK” and “unverified”; do not share the result as a confirmed company breach. For suspicious messages, assess the real sender domain, link destination, pressure to act and requests for payment or verification codes together.\u003C\u002Fp>","","CDEK Unverified Breach Dataset (2022) (19.2 Million Email Identifiers)","CDEK Unverified Breach Dataset (2022). 19.2 Million email identifiers were reported. Reported data: Email addresses, Names, Phone numbers. Review the scope…","\u002Fuploads\u002Flogo\u002Fcdek_ru.webp",false,{"name":35,"sector":36,"country":37,"website":10,"websiteArchiveUrl":29,"websiteStatus":29,"websiteCheckedAt":21},"CDEK-attributed unverified dataset","Other","Russia"]