Sibr.ru

03 Oct 2025 N/A 03-Oct-2025 Database,Combolist
11,336 Records Affected
Database,Combolist Source Structure
Darkweb Breach Location
High-risk data exposed (passwords and/or SSN). Immediate credential reset and monitoring are recommended.

Breach Details

Domain N/A
Leaked Data Types Email Address,Plaintext Password
Password Types Plaintext

Description

We've been tracking the resurgence of older breaches appearing in combilists and credential stuffing attacks. Often these are dismissed due to their age, but the reuse of credentials remains a significant risk. Our team recently identified a dataset from Sibr.ru, a now-defunct Russian community news and forums website, initially compromised in August 2018. What really struck us wasn't the relatively small number of records (11,336), but the exposure of plaintext passwords, a security practice that should have been retired long before 2018. This highlights the long tail of risk associated with outdated security practices and the ongoing value of even older data to malicious actors.

Sibr.ru's Legacy: A Reminder of Password Security's Past Sins

The Sibr.ru breach, surfacing again after several years, serves as a stark reminder of the dangers of storing passwords in plaintext. The dataset was initially leaked in August 2018 and has recently resurfaced on underground forums, likely being incorporated into larger combilists used for credential stuffing attacks. We discovered this dataset while monitoring activity on a popular Russian-language hacking forum. The post advertising the data specifically highlighted the presence of plaintext passwords, which immediately raised our concern due to the elevated risk of credential reuse.

The breach matters to enterprises now because these exposed credentials, even if outdated, could still be valid for users who haven't updated their passwords across various online services. The reuse of passwords across multiple platforms is a well-documented phenomenon, and attackers often leverage older breaches to gain access to current accounts. This incident underscores the importance of proactive password management, including regular password updates and the use of unique passwords for each online account, as well as monitoring for leaked credentials associated with your organization.

Key point: Total records exposed: 11,336

Key point: Types of data included: Email Addresses, Plaintext Passwords

Key point: Source structure: Likely a database dump (details unavailable)

Key point: Leak location(s): Underground hacking forums

Key point: Date of first appearance: August 21, 2018

External Context & Supporting Evidence

While the Sibr.ru breach itself didn't garner significant media attention at the time, the practice of storing passwords in plaintext has been widely criticized by security experts. Security researcher Troy Hunt, creator of Have I Been Pwned, has frequently highlighted the dangers of this practice, emphasizing that it makes it trivial for attackers to compromise user accounts. The appearance of this data in combilists aligns with broader threat themes related to the aggregation and exploitation of leaked credentials. Many threat actors actively trade and utilize these combilists to automate attacks against various online platforms.

Leaked Data Types

Email · Address · Plaintext · Password

Breach Rank

Ranked by number of affected users

Impact Score

Impact Score: 0.45

Based on data sensitivity, breach size, and recency

Estimated Financial Impact

$82.0K

This is an estimate based on potential fraud, phishing, and data misuse. Not all users will be affected.

Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance