VK data breach (2012)
Russia's largest social network VK was compromised around 2012, exposing roughly 93 million accounts with names, phone numbers, email addresses and plaintext passwords. The data surfaced for sale in 2016 via the broker 'Peace'.
- Victim
- VK
- records
- 93.3M
- users
- 93.3M
Around 2012, VK (VKontakte), Russia's largest social network, suffered a credential breach that stayed out of public view for roughly four years. It burst into the open on 5 June 2016, when a seller using the alias "Peace" (also seen as peace_of_mind) advertised roughly 100 million VK accounts on a Tor-based marketplace for 1 bitcoin β about US$580 at the time.
What happened
VK never acknowledged a direct compromise of its infrastructure. When the data surfaced in 2016, the company said the records were "old logins/passwords that had been collected by fraudsters in 2011-2012" rather than the product of a fresh intrusion. Whatever the exact vector, the dataset was real and large: after de-duplication, Have I Been Pwned indexed 93,338,602 unique accounts.
The same broker, "Peace," was simultaneously listing other mega-breaches from the same era β LinkedIn (2012), MySpace and Tumblr β all of which came to market in mid-2016. VK was part of that wave of historic social-media dumps being monetised years after the fact.
Data exposed
Each record contained:
- Full names
- Email addresses
- Phone numbers
- Passwords stored in plaintext
The plaintext passwords were the most damaging element. Unlike the LinkedIn breach of the same year β where passwords were at least unsalted SHA-1 hashes requiring cracking β VK's credentials were directly readable, giving anyone who bought the dump immediate, usable login pairs.
Impact
With nearly 93 million email/phone-and-password pairs exposed in cleartext, the principal risk was account takeover and credential stuffing. Many users reuse passwords across services, so a VK password readable in plaintext could unlock email, banking or other accounts elsewhere. VK responded by blocking affected accounts and forcing password resets for users whose credentials matched the leaked set.
Why it matters
The VK breach is a textbook example of two enduring problems. First, storing passwords in plaintext is indefensible: it converts any data exposure into an instant, total credential compromise with no cracking required. Second, breaches have a long tail β data stolen around 2012 caused real harm in 2016 and beyond, because credentials retain value as long as users keep reusing them. Together with the LinkedIn, MySpace and Tumblr dumps that surfaced the same year, VK helped define the 2016 wave of "historical mega-breaches" that reshaped public awareness of password hygiene.
Timeline
VK user credentials are compromised (the breach is later dated to the 2011-2012 period).
A seller using the alias 'Peace' lists ~100 million VK accounts on a Tor-based market for 1 bitcoin.
LeakedSource and press confirm the dump; passwords are found stored in plaintext.
VK states the data was old credentials collected by fraudsters in 2011-2012, not a fresh breach of its systems.
Have I Been Pwned loads 93,338,602 unique VK accounts after de-duplication.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/breach/VK
- helpnetsecurity.comhttps://www.helpnetsecurity.com/2016/06/06/100-milion-vk-accounts-put-sale/
- infosecurity-magazine.comhttps://www.infosecurity-magazine.com/news/over-100-million-vkcom-customer/