1000dosok
We noticed a significant data exposure originating from the Russian classifieds platform, 1000dosok, which came to light on August 14, 2025. The dataset, disseminated through a public Telegram channel, encompasses a substantial number of user records, presenting a clear risk of credential stuffing and targeted phishing campaigns. What struck us was the relatively low barrier to entry for posting on this platform, potentially indicating a less robust security posture that could have facilitated the initial compromise. The inclusion of IP addresses alongside email and usernames adds a layer of potential for correlating online activity and identifying user locations, even if indirectly.
The breach, identified on August 14, 2025, involved a database leak from 1000dosok, a free Russian classified advertisements website. This platform, which facilitates the posting of various listings without mandatory registration, saw 295,357 user records compromised. The exposed data includes email addresses, IP addresses, and usernames. The leak's dissemination via a public Telegram channel suggests a deliberate act of data exfiltration and subsequent public sharing. The threat themes here are primarily focused on identity compromise and potential for further exploitation. The absence of mandatory registration on 1000dosok might imply that the compromised database contained information from users who either chose to register or had their data scraped and aggregated, making the exposure particularly concerning for individuals who may not have directly interacted with the platform in a registered capacity.
While direct news coverage of this specific 1000dosok leak is not widely available in English-language cybersecurity reporting at this time, the nature of the data exposed aligns with broader trends observed in the Russian-speaking internet space. Similar incidents involving classifieds sites and forums, often facilitated by less stringent registration processes, have been documented by various OSINT researchers and data breach aggregators. The use of Telegram as a distribution channel is a common tactic for threat actors seeking broad reach and a degree of anonymity. This incident underscores the persistent vulnerability of platforms that rely on minimal user verification, creating fertile ground for credential harvesting and subsequent attacks on associated services.
Breach Breakdown
295,357 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds