Tvoydom (Твой Дом)
We noticed a significant data leak originating from a Telegram channel on October 5, 2023, involving a Russian retail entity. What struck us was the sheer volume of personally identifiable information (PII) compromised, impacting nearly 400,000 user accounts. The nature of the exposed data suggests a deep dive into customer profiles, extending beyond basic contact details to include sensitive demographic and personal identifiers. The retail sector, particularly those with both online and physical presences, remains a persistent target for attackers seeking to exploit customer data for various nefarious purposes.
The breach, attributed to a database compromise at Tvoydom (Твой Дом), a prominent Russian hypermarket chain, resulted in the exposure of 389,276 records. The leaked dataset contained a comprehensive array of user information, including email addresses, usernames, password hashes, first and last names, phone numbers, gender, and birthdays. While the exact vector of the database compromise is still under investigation, the breadth of data suggests a potential vulnerability in their customer relationship management (CRM) or e-commerce backend. The presence of password hashes, even if salted, presents a risk of offline brute-force attacks, especially if weak hashing algorithms were employed or if password reuse is prevalent among the affected user base. The inclusion of physical addresses, though not explicitly stated in the initial report, is a strong possibility given the comprehensive nature of the other PII, further amplifying the risk of identity theft and targeted phishing campaigns.
While specific news coverage directly linking this leak to major international outlets is limited, the incident aligns with a broader trend of retail data breaches observed globally. Open-source intelligence (OSINT) from cybersecurity forums and Telegram channels indicates this dataset was circulated for sale, a common monetization strategy for threat actors. Research from cybersecurity firms consistently highlights the retail sector as a prime target due to the high value of customer data for both direct financial gain and subsequent exploitation in more sophisticated attacks. The nature of the data suggests potential use in spear-phishing operations or for building detailed profiles for fraudulent activities.
Breach Breakdown
389,276 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds