[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3t3onl16qz3da":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":26,"seoTitle":14,"seoTitleEn":27,"seoDescription":14,"seoDescriptionEn":28,"logoUrl":29,"isVerified":4,"isSensitive":4,"isSpamList":30,"isMalware":30,"company":31},"68e3266eda11adda4882515d","convex","Convex Data Breach","convex.ru","2023-02-01T00:00:00.000Z","2023-02-26T06:51:44.000Z","2026-07-18T23:48:15.721Z","Third party breach","",[],150129,"known",null,"unknown","High",[22,23,24,25],"Email addresses","IP addresses","Names","Phone numbers","\u003Cp>The Convex data breach is a significant security incident that occurred in February 2023 and affected approximately 150,000 accounts. In the event related to a Russia-based telecommunications provider, customer communication and network areas were exposed. This page has been prepared to clearly explain the scope of the incident, the listed data fields, user risks, and applicable security measures.\u003C\u002Fp>\u003Cp>The presence of name, phone, email, and IP information together in telecommunications records makes the user targetable both online and through communication channels. The text relies only on verifiable data categories; other services with similar names, unverified additional claims, or areas where technical details are unclear are not presented to the user as definite information. Thus, the record remains both consistent with search intent and non-misleading.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this incident are as follows: email addresses, IP addresses, names, and phone numbers. IP addresses and phone numbers can associate a person with specific service usage and communication channels. The presence of these fields together can create a broader attack surface than a standalone email address leak; attackers can combine contact information, identity markers, account behavior, and industry context to craft more convincing messages.\u003C\u002Fp>\u003Cp>In this record, the password field is not listed; the risk is more concentrated in communication, network identity, and targeted social engineering areas. In records that have a password field, using the same or similar password on other services directly creates the risk of account takeover. In records without a password, permanent fields such as address, phone, device, school, purchase, or official ID can strengthen social engineering and fraud scenarios.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record covers approximately 150,000 unique email addresses within telecommunications data associated with the domain convex.ru. The incident falls under the verified record class. Therefore, the disclosure has not been expanded to make the incident appear larger than it is; the listed data types and account numbers have been preserved. The scope limit is especially important for sensitive records, as a user's real risk should be distinguished from hypothetical risk.\u003C\u002Fp>\u003Cp>Due to the context of the network provider, the sector has been protected as telecommunications and internet service provision. The title, domain name, country, sector, and sensitivity class have been corrected in line with this scope. Similar names that could create duplicate records have not been merged under a single event; each record has been evaluated with its own domain name and data class.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Convex customers who use the same phone and email combination on public, bank, or business accounts are at risk. The main risk for these users is that leaked data can be matched with information used on other accounts. If an email address, phone number, username, or device information remains the same across different services, attackers can use these common identifiers to make new attempts.\u003C\u002Fp>\u003Cp>The telecom context can be abused through fake invoices, line verification, modem updates, or customer service messages. Targeted business messages may appear more convincing for individuals using corporate email, while fake account alerts, refund notifications, or school- or subscription-themed messages may be more credible for individual users. Data related to children, students, employees, or sensitive membership contexts should also be handled with care.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should verify incoming account verification requests received by phone through a second channel and examine suspicious logins in their email accounts. If a password or password-like field is listed, users should change all accounts where they use the same password, use a unique password, and enable multi-factor authentication wherever possible. Performing actions only on the relevant platform may not be sufficient; the same email-password pair could also be tried on other services.\u003C\u002Fp>\u003Cp>Users should check account recovery options, logged-in sessions, routing rules, and suspicious notifications in records that contain phone numbers, addresses, birth dates, school classes, official IDs, financial information, or device areas. For corporate accounts, this information should be conveyed to the information security team, while for individual accounts, additional verification should be carried out against unexpected links received via email and phone.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Account PIN codes, customer service verification information, and email security for telecom users should be regularly updated. In the long term, a password manager, different passwords for different services, multi-factor authentication, closing old accounts, and deleting unnecessary profile information are basic defense steps. Once data breaches occur, fields such as date of birth, address, phone, or device information cannot be recovered; therefore, account behavior and verification processes should be strengthened.\u003C\u002Fp>\u003Cp>For companies and institutions, such incidents are not only a technical security issue; they also affect areas such as data minimization, employee access, retention periods of old records, children's data, customer notification processes, and post-incident transparency. On the user side, reducing old accounts and not using the same identity information everywhere permanently lowers risk.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user sees a match with this record, they should be more cautious against fake service messages that may come via phone and email. If a match is seen, the first thing to do is to read which data fields are listed and prioritize steps accordingly. If there is a password, password change should be prioritized; if there is official ID or financial data, identity and account monitoring should be prioritized; if there is student data, parent and school account checks should be prioritized.\u003C\u002Fp>\u003Cp>Final assessment: This record is a sensitive communication data incident because it contains phone and IP data in the context of telecommunications. The user should compare this record with their own account history; they should individually check the services where they have used the same combinations of email, phone, password, address, or username. Suspicious calls, messages, emails, or account recovery notifications should be considered higher risk after the incident.\u003C\u002Fp>","Convex Data Breach (150.1 Thousand Reported Records)","Convex Data Breach. 150.1 Thousand reported records were reported. Reported data: Email addresses, IP addresses, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fconvex_ru.webp",false,{"name":32,"sector":33,"country":34,"website":9,"websiteArchiveUrl":14,"websiteStatus":14,"websiteCheckedAt":18},"Convex","Telecommunications \u002F ISP","Russia"]