Moto85
Our threat intelligence platform flagged an unusual surge in activity originating from a public Telegram channel on February 9th, 2025. We noticed a substantial dataset being disseminated, and upon initial analysis, it became clear this was not routine chatter but a significant exfiltration of user credentials and personal information. What struck us was the relatively clean presentation of the data, suggesting a deliberate and organized leak rather than a chaotic dump, and the immediate association with a prominent e-commerce entity.
The breach, attributed to the Russian online retailer Moto85, exposed the sensitive information of 22,033 users. The leaked data, discovered in a Telegram channel, comprised a comprehensive profile for each affected individual. This included email addresses, usernames, first and last names, and phone numbers. Crucially, the dataset also contained password hashes, specifically utilizing the bcrypt algorithm, which, while a stronger hashing method, still presents a significant risk if brute-forced or subjected to rainbow table attacks. The source structure appears to be a direct dump from a user database, likely obtained through a SQL injection vulnerability or compromised database credentials, given the breadth and consistency of the fields present. The leak location, a public Telegram channel, amplifies the risk of broad dissemination and subsequent exploitation by malicious actors.
While direct news coverage immediately following the leak was limited to niche cybersecurity forums and OSINT aggregators, the nature of the data and the platform of dissemination suggest a potential for wider impact. The use of Telegram for data leaks is a recurring theme in threat actor TTPs, often serving as a marketplace or distribution hub for compromised credentials. This incident aligns with broader trends of e-commerce platforms being targeted for their rich user data, which can be monetized through phishing campaigns, account takeovers, or sale on dark web marketplaces. Further investigation into the specific Telegram channel and associated threat actor profiles may reveal additional context regarding the motive and potential future targets.
Breach Breakdown
22,033 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds