Skip to content
Data breachResolved

Rambler data breach (2014)

A data dump of almost 100 million accounts from Russian internet portal Rambler — often called 'the Russian Yahoo' — surfaced for trade in 2016, exposing roughly 91 million unique usernames and passwords stored in plain text.

Victim
Rambler
records
91.4M
users
91.4M
SectorOther

The Russian internet portal Rambler — a Yahoo-style hub offering email, news, search and other services, and frequently dubbed "the Russian Yahoo" — was the victim of a mega-breach that exposed roughly 91 million accounts. Although the data is dated to around March 2014 and the original intrusion is believed to trace back to 2012, the breach only became public in late 2016 when the dataset surfaced for trade online.

What happened

In September 2016, the breach-notification service LeakedSource revealed that a dump of almost 100 million Rambler accounts was circulating. The dataset provided to Have I Been Pwned contained 91,436,280 unique usernames — which also form the local part of Rambler email addresses — along with passwords stored in plain text.

The records reportedly included usernames/email addresses, plaintext passwords, ICQ account numbers and other internal data. Russian outlets verified the authenticity of the leak by confirming credentials with affected account holders. Rambler later stated that an initial leak in March 2014 involved roughly 4 million accounts and that it had since forced password resets and strengthened security with encryption and phone verification.

Impact

  • Approximately 91 million unique accounts were exposed.
  • Most damaging, the passwords were stored without any encryption or hashing — in plain text — so attackers could use them immediately with no cracking effort.
  • Because Rambler usernames double as email-address local parts, the leak provided a directly usable map of email + password pairs, ideal fuel for credential-stuffing and account-takeover campaigns against other services.

Why it matters

The Rambler breach is one of the starkest examples of plaintext password storage at scale. Unlike breaches involving weak hashes such as unsalted MD5 — which at least require some cracking effort — Rambler's passwords were exposed in fully readable form, handing attackers instant access to tens of millions of credentials.

It also belongs to the 2016 wave of long-dormant "historical mega-breaches" (alongside LinkedIn, Myspace, VK and others) that suddenly appeared on the breach-trading market years after the original intrusions. That pattern underscored how stolen data can sit unseen for years before resurfacing, and why timely breach detection, mandatory password hashing with modern algorithms, and proactive credential-reset policies remain essential.

Timeline

  1. The original Rambler.ru intrusion is believed to have occurred, per analysis of the leaked dataset.

  2. The breach data is dated to around this period; Rambler later acknowledged a leak of roughly 4 million accounts in March 2014.

  3. Breach-notification service LeakedSource reveals a dump of almost 100 million Rambler accounts circulating online.

  4. A dataset of 91,436,280 unique accounts with plaintext passwords is added to Have I Been Pwned.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/Breach/Rambler
  2. csoonline.comhttps://www.csoonline.com/article/557795/98-million-rambler-ru-accounts-surface-after-2012-hack.html
  3. securityaffairs.comhttps://securityaffairs.com/50994/data-breach/rambler-ru-data-breach.html
  4. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/almost-100-million-accounts-leaked-in-rambler-ru-mega-breach/

Related incidents

Data breachResolved

KM.RU data breach (2016)

In February 2016, the Russian portal and email service KM.RU was the target of an attack which was consequently detailed on Reddit. Allegedly protesting "the foreign policy of Russia in regards to Ukraine", KM.RU was one of several Russian sites in the breach and impacted almost 1.5M accounts…

Victim
KM.RU
Records
1.5M
Data breachResolved

QIP data breach (2011)

In mid-2011, the Russian instant messaging service known as QIP (Quiet Internet Pager) suffered a data breach. The attack resulted in the disclosure of over 26 million unique accounts including email addresses and passwords with the data eventually appearing in public years later.

Victim
QIP
Records
26.2M
Data breachResolved

Team SoloMid data breach (2014)

In December 2014, the electronic sports organisation known as Team SoloMid was hacked and 442k members accounts were leaked. The accounts included email and IP addresses, usernames and salted hashes of passwords.

Victim
Team SoloMid
Records
442.2K
Data breachResolved

mail.ru Dump data breach (2014)

In September 2014, several large dumps of user accounts appeared on the Russian Bitcoin Security Forum including one with nearly 5M email addresses and passwords, predominantly on the mail.ru domain.

Victim
mail.ru Dump
Records
16.6M