Rambler data breach (2014)
A data dump of almost 100 million accounts from Russian internet portal Rambler — often called 'the Russian Yahoo' — surfaced for trade in 2016, exposing roughly 91 million unique usernames and passwords stored in plain text.
- Victim
- Rambler
- records
- 91.4M
- users
- 91.4M
The Russian internet portal Rambler — a Yahoo-style hub offering email, news, search and other services, and frequently dubbed "the Russian Yahoo" — was the victim of a mega-breach that exposed roughly 91 million accounts. Although the data is dated to around March 2014 and the original intrusion is believed to trace back to 2012, the breach only became public in late 2016 when the dataset surfaced for trade online.
What happened
In September 2016, the breach-notification service LeakedSource revealed that a dump of almost 100 million Rambler accounts was circulating. The dataset provided to Have I Been Pwned contained 91,436,280 unique usernames — which also form the local part of Rambler email addresses — along with passwords stored in plain text.
The records reportedly included usernames/email addresses, plaintext passwords, ICQ account numbers and other internal data. Russian outlets verified the authenticity of the leak by confirming credentials with affected account holders. Rambler later stated that an initial leak in March 2014 involved roughly 4 million accounts and that it had since forced password resets and strengthened security with encryption and phone verification.
Impact
- Approximately 91 million unique accounts were exposed.
- Most damaging, the passwords were stored without any encryption or hashing — in plain text — so attackers could use them immediately with no cracking effort.
- Because Rambler usernames double as email-address local parts, the leak provided a directly usable map of email + password pairs, ideal fuel for credential-stuffing and account-takeover campaigns against other services.
Why it matters
The Rambler breach is one of the starkest examples of plaintext password storage at scale. Unlike breaches involving weak hashes such as unsalted MD5 — which at least require some cracking effort — Rambler's passwords were exposed in fully readable form, handing attackers instant access to tens of millions of credentials.
It also belongs to the 2016 wave of long-dormant "historical mega-breaches" (alongside LinkedIn, Myspace, VK and others) that suddenly appeared on the breach-trading market years after the original intrusions. That pattern underscored how stolen data can sit unseen for years before resurfacing, and why timely breach detection, mandatory password hashing with modern algorithms, and proactive credential-reset policies remain essential.
Timeline
The original Rambler.ru intrusion is believed to have occurred, per analysis of the leaked dataset.
The breach data is dated to around this period; Rambler later acknowledged a leak of roughly 4 million accounts in March 2014.
Breach-notification service LeakedSource reveals a dump of almost 100 million Rambler accounts circulating online.
A dataset of 91,436,280 unique accounts with plaintext passwords is added to Have I Been Pwned.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/Breach/Rambler
- csoonline.comhttps://www.csoonline.com/article/557795/98-million-rambler-ru-accounts-surface-after-2012-hack.html
- securityaffairs.comhttps://securityaffairs.com/50994/data-breach/rambler-ru-data-breach.html
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/almost-100-million-accounts-leaked-in-rambler-ru-mega-breach/