[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1v1jap9zpj0pj":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":28,"seoTitle":15,"seoTitleEn":29,"seoDescription":15,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":32,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda48825340","raychat","Raychat Data Breach","raychat.ir","2021-01-31T00:00:00.000Z","2021-07-04T00:52:38.000Z","2026-07-03T23:38:27.452Z","2026-07-18T23:56:56.408Z","Third party breach","",[],938981,"known",null,"unknown","High",[23,24,25,26,27],"Browser user agent details","Email addresses","IP addresses","Names","Passwords","\u003Cp>The Raychat data breach is related to the exposure of user data belonging to the Iran-based social media and communication platform in January 2021. The scope is approximately 938,981 unique email addresses. This record was treated as a social media and messaging platform account breach; the company, country, industry, website, and data class fields were realigned with the verified scope. Errors in the retail industry and United States country were corrected.\u003C\u002Fp>\u003Cp>The text was rewritten to directly explain risk, scope, and actions to the user. The website domain was kept as raychat.ir; since no protocol was added, a format that would cause a double https on the connection side was not used. Even though the platform is no longer active, old account data may create a password reuse risk.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data seen in this record include browser user agent details, email addresses, IP addresses, names, and passwords. It was assessed that the passwords are stored as bcrypt hashes; the risk remains for weak or reused passwords. Unverified payment cards, bank accounts, private messages, health records, or additional profile fields were not added to the data class list; only supported fields were retained.\u003C\u002Fp>\u003Cp>IP and browser information can provide additional context about the device and access environment where the account is used. An email address alone poses a risk of unwanted messages; when combined with a phone number, address, IP, date of birth, password, official ID, support record, vehicle information, or physical address, it becomes easier for an attacker to generate messages specific to the user. The risk assessment was made based on this combined effect.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The scope was validated with Raychat data dated January 2021. Confirmed areas were retained while unverified areas were excluded. The events were not combined with similarly named data sets, events from different periods of the same company, or incorrect sector attributions.\u003C\u002Fp>\u003Cp>The registration is limited to the domain name raychat.ir and has not been merged with other Iranian platforms. The domain name, company name, and industry information were kept in the narrowest accurate context possible. In places of uncertainty, a verified flag or website domain was set accordingly; thus, no uncertain brand responsibility was shown to the user.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>User groups at risk may include users with a Raychat account and individuals who use the same email or password pattern on other social platforms. Matching users should also review their other accounts where they use the same email, phone number, username, or password pattern outside the relevant service.\u003C\u002Fp>\u003Cp>Even if the platform is no longer in use, old passwords may remain on current accounts. If there is a context of corporate email, game forum, motorcycle customer record, shopping mall application, support request, rental account, marketing list, or malware, the social engineering risk may increase. Details that appear correct are not a sign of trust on their own.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should change their Raychat password and all accounts where the same password is used. In records with a password field, all accounts using the same password should be updated; for records without a password field, focus should be on the risk of email, phone, fake notifications, privacy, and identity matching.\u003C\u002Fp>\u003Cp>Instead of clicking on the links in the message, the address of the relevant service should be typed manually or the record in a trusted password manager should be used. Invoice, account warning, game reward, support, shipping, customer service, maintenance appointment, public notice, or subscription renewal messages should not be accepted without verification through an independent channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Old social platform accounts should be closed or their passwords should be made unique, and the email account should be protected with two-factor authentication. Users should regularly clean up old accounts, unnecessary profile fields, duplicate usernames, and old phone and address information. Having a unique password for each service and enabling two-factor authentication wherever possible should be the basic rule.\u003C\u002Fp>\u003Cp>From the perspective of service providers, data minimization, strong password protection, monitoring of access logs, deletion of unnecessary fields, and having user notification processes ready are required. Closed or inactive social platforms also pose a risk in terms of user data protection and notification obligations. Accurate scope explanation is also part of the security work; exaggerated or incomplete information can lead users to incorrect actions.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The user should first verify with their email address on this record. If a match is found, it should be assumed that the fields of name, IP, browser information, and password may be at risk. The absence of a match does not completely rule out the use of a different email or the reuse of an old password; critical accounts should also be reviewed.\u003C\u002Fp>\u003Cp>This record remained verified; the country and sector information was contextualized to the Iranian social platform. In this arrangement, the data fields were left as English canonical classes, the description visible to the user was written in Turkish and original, unverified fields were not added, and the sensitivity flag was used only when supported by the risk context.\u003C\u002Fp>","Raychat Data Breach (939 Thousand Reported Records)","Raychat Data Breach. 939 Thousand reported records were reported. Reported data: Browser user agent details, Email addresses, IP addresses. Review the scope…","\u002Fuploads\u002Flogo\u002Fraychat_ir.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Raychat","Social Media \u002F Messaging Platform","Iran"]