START
| Primary URL | Location | Industry | start[.]ru |
Country
Russia
|
Entertainment
|
|---|
Profile
The organisation operates as a streaming platform that delivers video‑on‑demand content to its users. It is headquartered in Russia and is known by the alias START. The service provides access to movies, television series, and other digital media through an online interface that requires users to register an account and authenticate before viewing. Account creation entails the submission of personal identifiers such as an email address, a phone number, and a chosen username, which are stored alongside subscription information that reflects the user’s chosen service tier. Users can then stream the available catalogue on a range of devices, including smartphones, tablets, computers, and smart televisions, after successful login.
The platform’s scale became evident after a security incident disclosed on 22 September 2021, when attackers gained unauthorized access and exfiltrated a database containing approximately 7.5 million user records. This figure indicates that the service had reached a multi‑million‑user base at the time of the breach. The compromised data included email addresses, phone numbers, usernames, MD5‑hashed passwords, IP addresses, login logs, and subscription details, while financial information and browsing history remained unaffected according to the organisation’s statement. The breadth of the exposed information shows that the platform collects a variety of data points for account management, service personalization, and security monitoring.
Several distinguishing attributes can be inferred from the breach description. The platform stored passwords using the MD5 hashing algorithm, which is considered weak by contemporary security standards and suggests that the organisation’s credential protection practices were outdated at the time. Although the organisation confirmed the intrusion, it initially downplayed the risk, asserting that the leaked data could not facilitate account takeovers; however, external researchers demonstrated that the MD5 hashes could be cracked or used with password‑recovery tools to gain valid access, highlighting a gap between the company’s risk assessment and independent verification. In response, the organisation remediated the underlying vulnerability and advised affected users to reset their passwords, though it did not impose a mandatory global credential reset. These facts point to a Russian‑based streaming service that, while offering a large‑scale digital media platform, exhibited security practices that later proved insufficient to protect user credentials.
