CSIDB logo
Incident

VK

Incident posture

Attack window
May 2016
Location
Russia
Status
Historical
CIA posture
Available to members
Updated
2025-12-20 00:00

Linked entities

Victim
VK
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
May 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hacktivists breached and leaked the personal email inbox of the chief executive of Russian social network VK, allegedly containing sensitive internal communications. The exposed correspondence included discussions on budget negotiations, business relationships with messaging app Telegram, dealings with offshore entities, and advertising affiliate commissions. The incident also revived past controversies involving a co-founder who previously accused the platform's management of coercing user data disclosures related to Ukrainian protest groups. While the leaked materials purportedly revealed strategic corporate discussions, their authenticity remained unverified.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around May 6, 2016, hacktivist actors identifying as "Anons" (commonly associated with Anonymous) breached and publicly leaked the personal email inbox of Boris Dobrodeev, the chief executive of VKontakte (VK), Russia's largest social networking platform. The leaked data, spanning communications from 2014, included sensitive internal discussions regarding VK's budget negotiations, proposed agendas for high-level business meetings, and strategic partnerships. Specific details involved VK's commercial relationship with Telegram, the encrypted messaging app founded by VK co-creator Pavel Durov, alongside references to financial arrangements with offshore entities and shareholding companies Blesmir Developments and Palagon. The emails also contained information about advertising affiliate commissions, suggesting operational and financial priorities during Dobrodeev's leadership. The attackers disseminated the data publicly, though the article explicitly noted the authenticity of the leaked materials remained unverified at the time of reporting.

The incident revived scrutiny of VK's governance and historical controversies, particularly the 2014 departure of co-founder Pavel Durov, who alleged he was coerced by pro-Kremlin interests into disclosing user data linked to Ukraine's Euromaidan protest movement. While the leaked emails did not directly reference this prior dispute, their exposure underscored persistent tensions surrounding VK's alignment with Russian political authorities. No statements from Dobrodeev or VK confirming the breach or addressing the leak's validity were cited in the source material. The compromised communications primarily revealed corporate operational details rather than user data, limiting immediate evidence of broader system infiltration beyond Dobrodeev's personal email account. The incident highlighted vulnerabilities in executive digital security and the ongoing targeting of high-profile Russian tech entities by hacktivist groups.

Sources

Sources available to members: 1 source.

CSIDB