Skip to content
Data breachResolved

VK data breach (2012)

Russia's largest social network VK was compromised around 2012, exposing roughly 93 million accounts with names, phone numbers, email addresses and plaintext passwords. The data surfaced for sale in 2016 via the broker 'Peace'.

Victim
VK
records
93.3M
users
93.3M

Around 2012, VK (VKontakte), Russia's largest social network, suffered a credential breach that stayed out of public view for roughly four years. It burst into the open on 5 June 2016, when a seller using the alias "Peace" (also seen as peace_of_mind) advertised roughly 100 million VK accounts on a Tor-based marketplace for 1 bitcoin β€” about US$580 at the time.

What happened

VK never acknowledged a direct compromise of its infrastructure. When the data surfaced in 2016, the company said the records were "old logins/passwords that had been collected by fraudsters in 2011-2012" rather than the product of a fresh intrusion. Whatever the exact vector, the dataset was real and large: after de-duplication, Have I Been Pwned indexed 93,338,602 unique accounts.

The same broker, "Peace," was simultaneously listing other mega-breaches from the same era β€” LinkedIn (2012), MySpace and Tumblr β€” all of which came to market in mid-2016. VK was part of that wave of historic social-media dumps being monetised years after the fact.

Data exposed

Each record contained:

  • Full names
  • Email addresses
  • Phone numbers
  • Passwords stored in plaintext

The plaintext passwords were the most damaging element. Unlike the LinkedIn breach of the same year β€” where passwords were at least unsalted SHA-1 hashes requiring cracking β€” VK's credentials were directly readable, giving anyone who bought the dump immediate, usable login pairs.

Impact

With nearly 93 million email/phone-and-password pairs exposed in cleartext, the principal risk was account takeover and credential stuffing. Many users reuse passwords across services, so a VK password readable in plaintext could unlock email, banking or other accounts elsewhere. VK responded by blocking affected accounts and forcing password resets for users whose credentials matched the leaked set.

Why it matters

The VK breach is a textbook example of two enduring problems. First, storing passwords in plaintext is indefensible: it converts any data exposure into an instant, total credential compromise with no cracking required. Second, breaches have a long tail β€” data stolen around 2012 caused real harm in 2016 and beyond, because credentials retain value as long as users keep reusing them. Together with the LinkedIn, MySpace and Tumblr dumps that surfaced the same year, VK helped define the 2016 wave of "historical mega-breaches" that reshaped public awareness of password hygiene.

Timeline

  1. VK user credentials are compromised (the breach is later dated to the 2011-2012 period).

  2. A seller using the alias 'Peace' lists ~100 million VK accounts on a Tor-based market for 1 bitcoin.

  3. LeakedSource and press confirm the dump; passwords are found stored in plaintext.

  4. VK states the data was old credentials collected by fraudsters in 2011-2012, not a fresh breach of its systems.

  5. Have I Been Pwned loads 93,338,602 unique VK accounts after de-duplication.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/breach/VK
  2. helpnetsecurity.comhttps://www.helpnetsecurity.com/2016/06/06/100-milion-vk-accounts-put-sale/
  3. infosecurity-magazine.comhttps://www.infosecurity-magazine.com/news/over-100-million-vkcom-customer/

Related incidents

Data breachResolved

CDEK data breach (2022)

In early 2022, a collective known as IT Army whose stated goal is to "completely de-anonymise most Russian users by leaking hundreds of gigabytes of databases" published over 30GB of data allegedly sourced from Russian courier service CDEK.

Victim
CDEK
Records
19.2M
Data breachResolved

BookCrossing data breach (2012)

In August 2022, the book social networking site BookCrossing disclosed a data breach that dated back to a database backup from November 2012. The incident exposed almost 1.6M records including names, usernames, email and IP addresses, dates of birth and plain text passwords.

Victim
BookCrossing
Records
1.6M
Data breachResolved

The Botting Network data breach (2012)

In August 2012, the forum for making money with botting "The Botting Network" suffered a data breach that exposed 96k user records. The now defunct vBulletin forum leaked 96k email addresses, usernames, dates of birth and salted MD5 password hashes.

Victim
The Botting Network
Records
96.3K