[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1dswl0i9ohcey":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":28,"seoTitle":29,"seoTitleEn":30,"seoDescription":29,"seoDescriptionEn":31,"logoUrl":32,"isVerified":4,"isSensitive":33,"isSpamList":33,"isMalware":33,"company":34},"68e3266eda11adda48825406","VK","VK Data Breach","vk","vk.com","2012-01-01T00:00:00.000Z","2016-06-09T09:16:36.000Z","2026-07-19T00:00:57.120Z","Verified breach record","https:\u002F\u002Fwww.securityweek.com\u002F100-million-passwords-sale-russian-social-network-vk\u002F",[15,17],"https:\u002F\u002Fwww.businessinsider.com\u002Fvkontakte-hacked-100-million-user-accounts-for-sale-1-bitcoin-vk-2016-6",93338602,"known",null,"unknown","Critical",[24,25,26,27],"Email addresses","Names","Passwords","Phone numbers","\u003Cp>The VK data breach is a large-scale security incident dating back to 2012, associated with the Russia-based social networking service. The verified scope is 93,338,602 unique email addresses. The dataset includes email addresses, name information, passwords, and phone numbers. The exposure of the password field in plain text significantly increases the risk of account takeover in cases where the same password is reused across different accounts.\u003C\u002Fp>\u003Cp>This incident is high-risk because the social media account and real identity and phone information are combined in the same data set. Email, name, and phone information can give attackers the opportunity to prepare messages that appear to come from a real social network relationship. If the password is in plain text, it poses a risk not only for the VK account but also for email, social media, shopping, and work accounts if the same password has been used on other services.\u003C\u002Fp>\u003Ch2>Types of Leaked Data and Their Risks\u003C\u002Fh2>\u003Cp>The verified data types in the VK dataset are email addresses, name information, passwords, and phone numbers. Email addresses can be used for targeted phishing, password reset scams, and account matching. Name information personalizes messages. Phone numbers pose a risk for fake support calls, SMS fraud, and requests coming under the pretext of recovering a social network account.\u003C\u002Fp>\u003Cp>The exposure of passwords in plain text is the most critical part of this incident. A plain text password allows the attacker to try the same value on other services without needing a password cracking process. If the same password remains valid on different accounts even years later, an old social network breach can become a current account security problem.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The violation date for VK should be considered as January 1, 2012, the record addition date as June 9, 2016, and the number of affected accounts as 93,338,602. Although the incident became publicly visible in 2016, the data source is based on old social network credentials. Therefore, the announcement time and the data source time should not be confused in the date assessment.\u003C\u002Fp>\u003Cp>One should not go beyond verified data classes. The fields to be reliably provided for VK are email addresses, name information, passwords, and phone numbers. Payment cards, bank accounts, identification documents, private message content, or social connection lists should not be described as definite leakage areas. Risk explanation should be based on how these four fields can be misused together.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The main group at risk consists of people who had a VK account in 2012 or earlier, or who have used the same email and phone information on social networks. Users who reuse the same password on email, other social media, gaming, shopping, cloud storage, or work accounts carry a higher risk. Forgetting an old account does not eliminate the risk if the password is still used elsewhere.\u003C\u002Fp>\u003Cp>Users with phone numbers should be more cautious against messages themed around fake account recovery, security alerts, friend requests, payment requests, or support calls. Messages that come with name and email information may appear realistic. Especially old social network connections and other accounts opened with the same username can make it easier for attackers to act as if they know the person.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users who have been matched on VK should change their passwords on their VK account and on all accounts where the same password was used. Priority should be given to email accounts, social media, payment services, shopping sites, cloud storage, and work accounts. New passwords should be long, unique, and chosen from values stored in a password manager.\u003C\u002Fp>\u003Cp>Two-factor authentication should be enabled on all major accounts that support it, active sessions and connected devices should be checked, and unrecognized sessions should be closed. Before clicking on links in social network security alerts received via email or phone, you should log in through the service's known web address or official mobile application. One-time codes, account passwords, or recovery links should not be shared in any support interaction.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, a unique password for each service, a password manager, and two-factor authentication are the basic defense. Maintaining the same email and password pattern on social network accounts for years makes it easier for data from old breaches to be tried on new accounts. Using a separate email address or an alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Users should regularly review their old social network accounts, close accounts that are no longer necessary, and keep their recovery email and phone information up to date. When phone and email information is exposed, the risk does not end with just changing the password; one must remain cautious for a long time against personalized scam messages, fake friend requests, and requests that come under the pretext of account recovery.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is found in the VK dataset. A positive result means that the email address is present in this dataset and that the verified data fields should be considered in the risk assessment. This result does not prove that every field is completely found for every user; however, due to the risk of plain text passwords and contact information, it is a sufficient warning for protective measures.\u003C\u002Fp>\u003Cp>A negative result only means that no match was found in the VK dataset; it does not rule out the possibility of appearing in other data breaches. Users who receive a positive result should clear their password reuse, enable two-factor authentication, review old sessions, and verify social network security messages received via phone or email through a separate channel.\u003C\u002Fp>","","VK Data Breach (93.3 Million Reported Records)","VK Data Breach. 93.3 Million reported records were reported. Reported data: Email addresses, Names, Passwords. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002Fvk_com.webp",false,{"name":7,"sector":35,"country":36,"website":10,"websiteArchiveUrl":29,"websiteStatus":29,"websiteCheckedAt":20},"Social media","Russia"]