Breach report
Social MediaVK (VKontakte)
Another Day, Another Hack: 100 Million Accounts for VK, Russia's Facebook
More than 100 million accounts from VK, Russia's biggest social network, went up for sale in 2016 with names, emails, phone numbers and passwords that the seller said had been stored in plain text.
Reported by Vice (Motherboard)
Records exposed
100M
More than 100 million accounts
Scale vs. largest on file
- When
- 2011–2013 (disclosed 2016)
- How they got in
- Database theft; passwords stored in plaintext
- Sector
- Social Media
In early June 2016, the seller known as Peace, already notorious for the LinkedIn, Myspace and Tumblr dumps, listed another massive dataset: more than 100 million user records from VK, the Russian social network formerly known as VKontakte. The asking price was a single bitcoin, then worth a few hundred dollars. Breach search site LeakedSource, which obtained a copy, put the total even higher, at roughly 171 million accounts.
The records reportedly included first and last names, email addresses, phone numbers and passwords. According to the seller, VK stored passwords in plaintext at the time of the theft, meaning no cracking was required at all. Analysis of the data showed the familiar pattern of weak choices, with "123456" by far the most common password, used by hundreds of thousands of accounts. The breach was believed to have occurred sometime between 2011 and 2013, though the exact date and method were never publicly established.
VK, owned at the time by Mail.Ru Group, denied that its current systems had been compromised. The company said the dataset appeared to date from 2011 and 2012, that it had been compiled by attackers at that time, and that passwords for the affected accounts had since been forcibly changed. It urged users to set new passwords and enable additional protections, while maintaining that its databases had not been breached recently.
For a platform with a user base concentrated in Russia and neighboring countries, the dump represented one of the largest exposures of personal data in the region. Even if VK had reset passwords, the email and password combinations remained useful for credential-stuffing attacks against other services where users had reused them, and the phone numbers and names could be used for fraud and phishing.
The VK leak rounded out a remarkable few weeks in 2016 in which several hundred million old credentials from different social networks surfaced through the same seller. Taken together, those dumps demonstrated how long stolen data can remain hidden before resurfacing, and why storing passwords in plaintext is among the most serious security failures a company can make. They also accelerated industry adoption of breach monitoring and forced password resets.