Moscow IT Department Data Breach: 910,501 Russian Citizen Records Exposed
Moscow IT Department Breach: 910,501 Russian Citizens' Records Leaked From Government Portal
In August 2025, a dataset containing 910,501 records was posted on a prominent hacking forum, attributed to the Moscow Department of Information Technologies (DIT) -- the official portal responsible for managing digital government services across Moscow. Unlike many breaches, this one contained no passwords: instead, it exposed a rich dataset of personal identfier information including email addresses, phone numbers, full names, birthdates, and physical addresses. The absence of passwords does not reduce the risk -- it shifts it from credential compromise to identity theft, targeted phishing, and physical surveillance enablement.
Moscow IT Department (August 2025): Breach Summary
- Records Exposed: 910,501
- Data Types: Email addresses, phone numbers, full names, birthdates, physical addresses
- Breach Type: Database breach
- Password Exposure: None -- no password data was included in this breach
- Country: Russian Federation
- Date Leaked: August 17, 2025
PII Without Passwords: Why This Breach Is Still Dangerous
The Moscow IT Department breach is a case study in how password-free datasets can still cause serious harm. The combination of full name, email address, phone number, birthdate, and physical address is a near-complete identity kit. With this data, attackers can impersonate individuals in financial and government contexts using real personal details; conduct SIM-swap attacks using name, phone number, and birthdate to convince mobile carriers; launch hyper-targeted phishing campaigns that reference real identty details to appear legitimate; and in extreme cases, use residential addresses for physical threats or targeted operations. The governement origin of this data adds another dimension -- records from Moscow's IT department are likely to include civil servants, government contractors, and residents who have interacted with official digital services.
Moscow Government Infrastructure as a Target
Moscow's Department of Information Technologies manages one of the largest municipal digital ecosystems in the world -- a platform through which millions of residents access government services, pay utilities, register vehicles, and interact with civic infrastructure. This scale makes the DIT a high-value target for any actor seeking a comprehensive registry of Moscow residents. The breach, which surfaced on a hacking forum in August 2025, aligns with a pattern of increased targeting of Russian and Eastern European government infrastructure. Whether this breach represents external intrusion, insider access, or a third-party data handler failure remains unclear from the public disclosure.
The Long Tail of Government Data Breaches
Unlike commercial platform breaches where users can simply change their passwords, a governement PII breach offers no equivalent remediation. You cannot change your legal name, birthdate, or permanent address to protect yourself from a government database exposure. The 910,501 individuals whose records appeared in this dataset face a permanent expansion of the threat surface around their identites -- one that cannot be closed by any action on their part. The data will circulate in criminal databases indefinitely, available for phishing, fraud, and impersonation operations for years to come.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion exposed records, including government and municipal database breaches. If you have interacted with Moscow government digital services or suspect your personal information may have been included in the August 2025 DIT breach, run a free scan now to see what information about you is circulating in breach databases.
Breach Breakdown
910,501 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds