[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f35zvq32nmkvcc":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":27,"seoTitle":28,"seoTitleEn":29,"seoDescription":28,"seoDescriptionEn":30,"logoUrl":31,"isVerified":32,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda48825293","MailRu","mail.ru Dump Alleged Data Exposure","mailru-dump","mail.ru","2014-09-10T00:00:00.000Z","2014-09-12T04:50:22.000Z","2018-01-09T03:38:56.000Z","2026-07-20T00:52:46.793Z","Credential collection","https:\u002F\u002Fglobalvoices.org\u002F2014\u002F09\u002F10\u002Frussia-email-yandex-mailru-passwords-hacking\u002F",[16,18],"https:\u002F\u002Fwww.troyhunt.com\u002Fintroducing-unverified-breaches-to-have-i-been-pwned\u002F",16630988,"known",null,"email_identifiers","Critical",[25,26],"Email addresses","Passwords","\u003Cp>mail.ru Dump is a mixed-source collection of 16,630,988 email-password records, not a confirmed breach of Mail.ru's own systems.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The collection contained email addresses and passwords. Its first published portion held about 4.5 million login records, with most addresses using the mail.ru domain. Additional data alleged to contain email addresses and plaintext passwords was added in January 2018, bringing the deduplicated total to 16,630,988. It is not established that every row came from the same method, that every password remained valid when published or that every address represented a Mail.ru mailbox. \u003Cstrong>A dominant email domain does not prove that Mail.ru infrastructure was breached\u003C\u002Fstrong>; people may have used those addresses to register with other sites where credentials were later captured. Plaintext or immediately usable password pairs create account-takeover risk when passwords are reused. Payment, profile, telephone, physical-address and other personal-data classes are not added to the verified scope of this record.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>On 10 September 2014, approximately 4.5 million Mail.ru-style logins and passwords appeared on a Russian-language security forum. Mail.ru said its analysis found that 95% of listed accounts had previously been marked as compromised, prompted to change passwords, restricted from sending mail or rendered inactive. The company maintained that the data may have come from user-side phishing, malware or unrelated services rather than a direct attack on its servers. The record was added to the catalogue on 12 September 2014. In January 2018, further email-password pairs associated with mail.ru addresses increased the total to \u003Cstrong>16,630,988 records\u003C\u002Fstrong>, and the incident was explicitly marked unverified. The date should therefore be read as the period of the first major publication, not the precise day of one intrusion; this record must not be described as a confirmed corporate database breach or a single-source combo list.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The highest risk applies to people who reused a password appearing in the collection on Mail.ru, social media, shopping, forums or another service. Attackers can test an email-password pair automatically and, after finding a working match, attempt to reach password-reset messages in the associated mailbox. However, presence in this record does not prove that the person was a Mail.ru customer, that a Mail.ru mailbox was accessed or that the password came from Mail.ru systems. According to Mail.ru's review, a very large share of accounts in the first portion had already been flagged, restricted or inactive, so current risk varies by row. The circulation of an address in criminal collections can nevertheless sustain spam, phishing, fraudulent security warnings and future password-testing attempts.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>If you remember your password from around 2014, identify every account that still uses the same or a similar form. \u003Cstrong>Permanently retire the old password and all of its variations\u003C\u002Fstrong>; adding a number or symbol does not create sufficient separation. Prioritize your primary email account because access to it can endanger password-reset flows for many other services. Review unfamiliar sessions, forwarding rules, recovery addresses and connected devices, then enable multi-factor authentication wherever possible. Do not follow links in messages claiming “your password leaked,” “your account will close” or “verify your identity” on behalf of Mail.ru or another provider. Open the service independently and check the warning in its account panel. Never disclose a password, one-time code or recovery key to a caller or message sender, and verify unexpected session notices through a separate channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Use a password manager to generate a random, unique credential for every service, removing password reuse that gives mixed-source collections their greatest value. Keep multi-factor authentication enabled on email, preferring phishing-resistant security keys or device-based methods when available. Do not turn a small variation of an old password into a new credential, and avoid public biographical facts in account-recovery answers. Remember that naming a dataset after an email domain does not establish that the provider was hacked; source uncertainty should remain part of the security assessment. Close abandoned accounts, terminate old sessions and review recovery information periodically. If an address appeared in a historical collection, it can still be used in current phishing campaigns; a sender's knowledge of a real address or old password does not make the message trustworthy.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Use the secure search field on this page to check each current and historical email address you used in or before 2014. A match may show that the address appears in this unverified mixed-source collection; it does not prove Mail.ru was hacked, that the password still works or that the record's origin is known. If you receive a result, recall the password used at the time and replace every remaining identical or similar credential. Review mailbox security history, recovery settings and active sessions as well. No result is an absolute guarantee because the collection may be incomplete, an address may have been written differently or another dataset may apply. Enter only the supported identifier in the search field; never submit a password, one-time code or recovery key to a breach checker. Even when a notification displays an old password, avoid its embedded link and access the relevant service directly.\u003C\u002Fp>","","mail.ru Dump Alleged Data Exposure (16.6 Million Email Identifiers)","mail.ru Dump Alleged Data Exposure. 16.6 Million email identifiers were reported. Reported data: Email addresses, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fmail_ru.webp",false,{"name":34,"sector":15,"country":28,"website":28,"websiteArchiveUrl":28,"websiteStatus":28,"websiteCheckedAt":21},"mail.ru Credential Collection"]