CSIDB logo
Incident

CDEK

Incident posture

Attack window
May 2020
Location
Russia
Status
Historical
CIA posture
Available to members
Updated
2025-10-30 00:00

Linked entities

Victim
CDEK
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A major data breach exposed personal information of approximately nine million customers of a Russian courier service, with the dataset offered for sale online at a price equivalent to $950. The incident represents the largest known personal data leak within Russia's delivery services sector. The affected company denied responsibility for the compromise, asserting that multiple entities—including government aggregators—collect similar customer information and could have been the source. No specific details regarding the types of exposed data or confirmation of the seller's claims were provided in the report.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around May 14, 2020, a dataset containing personal information of approximately nine million customers of CDEK Express, a Russian courier service, appeared for sale on the internet. The data was offered at a price of 70,000 rubles (equivalent to approximately $950 USD). This incident represented the largest known personal data breach involving a Russian delivery service at that time. The compromised information included customer details collected through CDEK's transportation services, though the specific data fields exposed were not detailed in available reports. The listing attracted attention from cybersecurity observers due to the substantial volume of affected individuals and the commercial nature of the data being marketed.

CDEK Express publicly denied responsibility for the data leak, asserting that no breach had occurred within their systems. A company representative emphasized that multiple entities, including government aggregators, collect similar customer data during delivery operations. This statement implied the breach could have originated from third-party partners or intermediaries rather than CDEK's direct infrastructure. No additional technical details regarding the leak's origin, data collection methods, or forensic investigation were disclosed by the company. The incident highlighted systemic risks in data handling practices across Russia's logistics sector, where customer information routinely passes through multiple organizational channels.

Sources

Sources available to members: 1 source.

CSIDB