[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1b0by9h4fvb0s":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":12,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":18,"affectedCountUnit":20,"hasEnglishDescription":4,"contentLocale":21,"availableLocales":22,"translations":24,"severity":27,"dataClasses":28,"description":34,"seoTitle":35,"seoDescription":36,"logoUrl":37,"isVerified":38,"isSensitive":4,"isSpamList":38,"isMalware":38,"company":39},"b552705c66b2e580f01a3790","Grastin","Grastin.ru 2022 Data Exposure Claim","grastin-ru-2022","grastin.ru","2022-11-01T00:00:00.000Z","2026-08-31T04:48:12.972Z","2026-09-17T19:36:59.053Z","Sealed third-party Grastin CSV archive metadata and bounded public domain context","https:\u002F\u002Fweb.archive.org\u002Fcdx\u002Fsearch\u002Fcdx?url=grastin.ru&from=2021&to=2022&output=json",[15,17],"https:\u002F\u002Fweb.archive.org\u002Fweb\u002F*\u002Fhttps:\u002F\u002Fgrastin.ru\u002F",654125,"lower_bound","email_identifiers","en",[21,23],"tr",{"en":25,"tr":26},{"slug":9},{"slug":9},"High",[29,30,31,32,33],"Email addresses","Names","Phone numbers","Physical addresses","Geographic locations","\u003Cp>This record cautiously describes a dataset associated with the Grastin.ru domain and attributed by internal source metadata to November 2022. The archive description binds the organization to Grastin and grastin.ru, gives a source range from August 2021 through November 2022, and lists names, phone numbers, physical addresses, and e-mail addresses among the data classes. Internet Archive CDX metadata also confirms that grastin.ru had an operating web presence during that period. Public metadata does not by itself prove the authenticity of this private archive, show that the Grastin operator confirmed it, or establish the exact day on which data was exposed. The record is therefore not presented as a first-party verified breach announcement. isVerified remains false, and the local source claim is kept distinct from the limited public entity context.\u003C\u002Fp>\n\u003Cp>The date has month precision only. Internal metadata uses the phrase November 2022 for the breach date. The stored value of 1 November 2022 is a technical representation of that month; it does not claim that an incident occurred on the first day. The same metadata says the records cover a period from August 2021 to November 2022. That interval may describe order, customer, or delivery activity and cannot independently fix the day on which a dataset was collected or distributed. Bounded public research did not locate an official announcement, regulator notice, or reliable incident report confirming this exact dataset. breachDatePrecision is therefore month, exact-day authority is absent, and any future date change should require a new review backed by stronger primary evidence.\u003C\u002Fp>\n\u003Cp>The source is a complete 35,580,567-byte 7z archive. Its SHA-256 identity is sealed and a full 7z integrity test passed. All three regular members were extracted, sized, and independently hashed. They are a generic Breached_Info metadata member, an Info metadata member containing Grastin descriptions and source claims, and one 266,121,201-byte CSV data file. There are no nested archives and the source payload was not modified. The CSV has 1,581,126 physical lines. Seven embedded newlines inside quoted CSV fields mean that the logical data-record count, excluding the header, is 1,581,118. Strict CSV parsing found no syntax error, malformed column width, or incomplete record. Stable bytes and a readable structure prove source integrity, but they do not turn every historical statement inside the archive into a verified public fact.\u003C\u002Fp>\n\u003Cp>E-mail mapping relies only on the explicit header authored by the source. The six columns are buyer, phone, address, email, region, and month, in that order. Only the fourth column, email, is selected. The buyer field contains 332 whole cells that happen to pass strict e-mail syntax, but its declared semantic is buyer or name rather than e-mail, so those values are deliberately excluded. Text containing at-signs in the address field, along with phone, region, and month values, is also excluded from e-mail import. Examples or prose in the Info metadata member are not treated as account e-mail fields. No additional field was selected to approach the catalog claim of 653,907, no invalid value was repaired, and no counter was fitted to a target.\u003C\u002Fp>\n\u003Cp>Two independent compiled Go readers validated all 1,581,118 logical data records and the six-column schema without errors. Both counted 704,204 valid e-mail occurrences in the explicit email column, 1,233 rejected nonblank cells, and 875,681 blank cells. After occurrence deduplication and strict ASCII e-mail canonicalization, 654,125 sorted unique addresses remain. Both tools produced the same 14,499,807-byte occurrence stream and SHA-256 identity. They also agreed on the canonical output of 13,386,578 bytes, 654,125 lines, and one SHA-256 identity. The second validator checks the schema, aggregates, and existing canonical set without materializing a second canonical output. This independent path reduces the chance that a single parser implementation or record-buffer mistake can authorize the import.\u003C\u002Fp>\n\u003Cp>Internal metadata claims 653,907 e-mail records, while strict extraction from the explicit field yields 654,125 unique canonical addresses, a difference of 218. The discrepancy is preserved rather than hidden. The metadata claim is not reinterpreted as a unique-person count, a valid-address count, or a complete row count. totalRecords represents the 1,581,118 logical CSV data records, sourcePhysicalRecordCount records the 1,581,126 physical-line claim, and canonicalEmailCount reports only the 654,125 addresses verified in the explicit email column. affectedCountLowerBound uses the same technical address lower bound but is not a count of unique people. One person can control several addresses, and an address can be shared, abandoned, or reassigned. Because the affected-person population is unknown, pwnCount remains null.\u003C\u002Fp>\n\u003Cp>This LeakData operation writes only e-mail addresses to Mongo relationships. Names, phone numbers, physical addresses, regions, and month values are not imported by this job. The Info member is deferred as NON_AUTHORITATIVE_METADATA_SAMPLE, while the generic Breached_Info member is closed as RESOLVED_NO_EMAIL because it has no e-mail field. Mapping coverage remains PARTIAL; that label does not claim that every piece of text in the archive or the complete historical event has been verified. The record is marked sensitive and retains its status as an unverified third-party claim. Presence of an address in the canonical set does not prove that a person used the other fields, that the record is still current, or that Grastin confirmed this exact archive. If stronger official evidence later changes the identity, scope, date, or counts, the metadata should be revised through a separate, traceable evidence review.\u003C\u002Fp>","Grastin.ru 2022 Data Exposure Claim (At Least 654,125 Email Identifiers)","Review the Grastin.ru 2022 data exposure claim and the 654,125-address lower bound verified only from the explicit email column.","https:\u002F\u002Fwww.google.com\u002Fs2\u002Ffavicons?domain=grastin.ru&sz=128",false,{"name":7,"sector":40,"country":41,"website":42,"websiteArchiveUrl":43,"websiteStatus":43,"websiteCheckedAt":44},"Logistics and delivery","Russia","https:\u002F\u002Fgrastin.ru","",null]