StarNet
We've observed a worrying trend of older breaches resurfacing, often repackaged and sold on new platforms to threat actors who may not have had access to them previously. What really struck us about the recent reappearance of the StarNet breach wasn't the novelty of the data itself – the breach initially occurred in 2015 – but rather the context in which it was being offered: threat actors were combining it with newer datasets to create more comprehensive profiles of potential targets. The setup here felt different because it highlighted the long tail risk associated with even relatively small breaches from nearly a decade ago.
StarNet's 2015 Breach Resurfaces, Fueling Identity Risk
The 2015 breach of Moldavian ISP StarNet, which exposed nearly 140,000 email addresses along with first and last names, has resurfaced in several dark web forums and Telegram channels. While the initial breach was widely reported at the time, its reappearance highlights the persistent threat posed by older data leaks. The data had been circulating quietly, but we noticed it being offered as part of a larger package of compromised user data, bundled with more recent breaches to create more comprehensive user profiles. This matters to enterprises now because seemingly innocuous data points, when combined with other leaked information, can be used for targeted phishing attacks, identity theft, and other malicious activities. This reinforces the broader threat theme of data aggregation and the increasing sophistication of threat actors in leveraging older breaches for new attacks.
Breach Stats:
* Total records exposed: 140,000
* Types of data included: Email addresses, First Names, Last Names
* Sensitive content types: PII
* Source structure: Database
* Leak location(s): Dark web forums, Telegram channels
* Date of first appearance: February 2015, reappeared in 2024
External Context & Supporting Evidence
The initial StarNet breach was reported by several security news outlets in 2015. While not a major incident in terms of sheer volume, the fact that it is resurfacing now underscores the need for continuous monitoring of dark web channels and threat intelligence feeds. One Telegram post claimed the files were "useful for social engineering campaigns targeting Eastern European users". The reappearance of this breach aligns with a broader trend of threat actors exploiting older data leaks, as detailed in recent threat reports from cybersecurity firms.
Breach Breakdown
43,809 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds