The OTP Bank Russia Breach Contains Exactly 76,511 Customer Phone Numbers and Full Names
HEROIC analysts identified a database breach affecting OTP Bank Russia, a retail banking subsidiary of the Hungarian OTP Group, in May 2025. The exposed dataset contained 76,511 customer records pulled from what appears to be the bank's call center system. Each record included phone numbers and full customer names, giving anyone who obtained the data a ready-made list of verified banking customers with direct contact details. The leak was identified after the data surfaced on dark web forums frequented by data brokers and cybercriminal operaters.
Why a Banking Customer List Is Particularly Dangerous
Even without passwords, a database of bank customers' names and phone numbers is a powerful tool for fraud. Criminals use this information to launch targeted phone scams, pretending to be bank employees and convincing victims to confirm account details or approve fraudulent transactions. Because the caller already knows the victim's name and that they are an OTP Bank Russia customer, the scam is far more convincing than a random phishing call. This type of attack is known as vishing, and it has been used to drain bank accounts with no technical hacking required.
What Was Exposed in the OTP Bank Russia Breach
- Phone Numbers
- First Names
- Last Names
Why This Matters for Affected Customers
Even a minimal dataset like this one creates real risk. Criminals combine phone numbers and names with publically available information to build detailed profiles used in identity theft and account takeover attempts. In the financial sector, that can mean fraudulent loan applications, unauthorized account changes, or targeted social engineering of both customers and bank employees. For individuals in the exposed list, unsolicited calls claiming to be from OTP Bank should be treated with extreme skepticism, and any request to verify account information over the phone should be refused and reported to the bank directly.
How Database Breaches Happen at Financial Institutions
A database breach occurs when an attacker gains unauthorized access to an organization's internal data storage systems. In banking environments, this often happens through compromised employee credentials, unpatched software vulnerabilities, or misconfigured cloud storage that accidentally exposes internal systems to the internet. Call center systems are a frequent target because they store large volumes of customer contact records and are often connected to third-party software vendors, each of which represents a potential entry point. Once inside, an attacker can extract thousands of records in minutes and the bank may not detect the intrusion for weeks.
Check If Your Information Was Part of This Breach
HEROIC's free breach scanner checks your email and personal information against more than 400 billion compromised records, including data from financial sector breaches. If you are an OTP Bank Russia customer or believe your information may have been exposed, a free scan takes under a minute and will alert you immediately if your data appears in any known breach dataset. Knowing your exposure status is the first step toward protecting yourself from follow-on fraud and scams.
Breach Breakdown
76,511 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds