CSIDB logo
Incident

VK

Incident posture

Attack window
Jan 2012
Location
Russia
Status
Historical
CIA posture
Available to members
Updated
2026-01-23 22:06

Linked entities

Victim
VK
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jan 2012
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Russian social media platform suffered a large-scale breach resulting in the compromise of approximately 100 million user credentials, with some estimates suggesting up to 170 million accounts affected. The stolen data included names, login details, and phone numbers, allegedly obtained through unauthorized access occurring several years prior. The credentials were later offered for sale on a dark web marketplace by an entity linked to other high-profile data breaches. Exposed information posed risks of identity theft and could facilitate brute-force attacks against user accounts across multiple services due to password reuse. The incident highlighted vulnerabilities in protecting sensitive user data against persistent cybercriminal activity targeting major online platforms.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In June 2016, cybersecurity monitoring service LeakedSource reported that approximately 100 million user credentials from Russian social networking platform VK.com (VKontakte) were being offered for sale on the dark web marketplace The Real Deal. The seller, operating under the alias "Tessa88," priced the database at 1 Bitcoin (approximately $580 USD at the time). Analysis of the 17GB data cache indicated the breach likely occurred between 2012 and 2013, though the exact intrusion method and timing remained unconfirmed. The exposed records contained usernames, account login identifiers, plaintext passwords, and associated phone numbers. LeakedSource obtained and verified portions of the dataset, noting that the volume of records suggested potential exposure of VK's entire user base, with some estimates reaching 170 million accounts. The seller "Tessa88" had previously been associated with the sale of compromised MySpace credentials, though the authenticity of all records in the VK database remained untested at the time of reporting.

The stolen credentials posed significant risks for credential-stuffing attacks and identity fraud, as criminals could leverage the personal information to bypass security checks on other platforms. The inclusion of plaintext passwords particularly enabled more efficient brute-force attacks against accounts where users had reused credentials. No evidence indicated that financial data or private messages were compromised in this incident. VK.com did not issue public statements regarding the breach confirmation or mitigation efforts based on the available source material. The incident highlighted ongoing challenges in protecting large-scale user databases, as stolen records from historical breaches continued to circulate in cybercriminal markets years after initial compromises.

Sources

Sources available to members: 1 source.

CSIDB