
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
mail.ru
What happened
In September 2014, several large dumps of user accounts appeared on the Russian Bitcoin Security Forum including one with nearly 5M email addresses and passwords, predominantly on the mail.ru domain. Whilst unlikely to be the result of a direct attack against mail.ru, the credentials were confirmed by many as legitimate for other services they had subscribed to. Further data allegedly valid for mail.ru and containing email addresses and plain text passwords was added in January 2018 bringing to total to more than 16M records. The incident was also then flagged as "unverified", a concept that was introduced after the initial data load in 2014.
Data exposed
Frequently asked questions
The mail.ru Dump data breach occurred on September 10, 2014. It was added to Have I Been Pwned's breach catalog on September 12, 2014.
16,630,988 accounts were affected by the mail.ru Dump data breach, according to Have I Been Pwned's records.
The mail.ru Dump breach exposed the following data types: Email addresses, Passwords.
Have I Been Pwned has not independently verified the mail.ru Dump breach. Unverified breaches can still be genuine — verification just means HIBP hasn't been able to confirm the data's authenticity directly, often because the source is a smaller or less-publicized incident.
Use KazaSec's free Email Breach Checker (/tools/breach-check) to check whether a specific email address has surfaced in the mail.ru Dump breach, or any other known breach — the tool never stores what you search.
Our free Email Breach Checker tells you whether a specific email address has surfaced in this breach — or any other known breach — without ever storing what you search.
Check your email →Talk to us about this
We help organizations find and fix the gaps that lead to a breach, before they do.