Personal data of over 500,000 customers on Russian crypto exchanges exposed in security breach

Personal data of over 500,000 customers on Russian crypto exchanges exposed in security breach

Personal data of customers at nine Russia-based cryptocurrency exchanges was exposed for more than two months due to a security incident, the Cybernews Research team found.

The exposed information included highly sensitive data such as full names, credit card numbers, email addresses, IP addresses, payment and withdrawal request amounts, transaction descriptors like BTCRUB, and additional authentication details like user agents. The leaked data encompasses more than 615,000 payment requests and over 28,000 withdrawal requests.

The affected exchanges include sova[.]gg, coinstart[.]cc, pocket-exchange[.]com, onemoment[.]cc, cripta[.]cc, metka[.]cc, alt-coin[.]cc, ferma[.]cc, in-to[.]cc.

While these are relatively small players in the crypto space, the leak could be a potentially valuable resource for law enforcement agencies and cybersecurity researchers worldwide as Russian crypto exchanges have often been linked to facilitating illicit activities, the research team noted.

The discovery was made on October 10, 2023, when the team identified a MongoDB server that was leaking sensitive personal data due to a misconfiguration.

Interestingly, a malicious script was planted on the server that destroyed all the data. At this point, it’s unclear who is responsible for the leak and the consequent destruction of the data, the researchers noted.


Back to the list

Latest Posts

Russia-linked Coldriver hackers deploy new espionage malware in targeted attacks

Russia-linked Coldriver hackers deploy new espionage malware in targeted attacks

LOSTKEYS is designed to steal sensitive files, harvest system information, and exfiltrate details about running processes.
8 May 2025
Russia-aligned operation manipulates audio and images to impersonate experts

Russia-aligned operation manipulates audio and images to impersonate experts

The operation primarily focused on undermining NATO support for Ukraine and spreading false narratives to disrupt domestic politics in EU member states.
7 May 2025
Global network of DDoS-for-hire services dismantled in international police op

Global network of DDoS-for-hire services dismantled in international police op

The suspects are believed to have administered six now-defunct websites, which operated as stresser or booter services.
7 May 2025