Home / Data Breaches / mail.ru Dump
Verified breach record

mail.ru Dump Data Breach

Understand what this public breach record reports and choose next steps based on the information involved.

Breach date: September 10, 201416,630,988 affected accounts in the record
01

What happened?

In September 2014, several large dumps of user accounts appeared on the Russian Bitcoin Security Forum including one with nearly 5M email addresses and passwords, predominantly on the mail.ru domain. Whilst unlikely to be the result of a direct attack against mail.ru , the credentials were confirmed by many as legitimate for other services they had subscribed to. Further data allegedly valid for mail.ru and containing email addresses and plain text passwords was added in January 2018 bringing to total to more than 16M records. The incident was also then flagged as "unverified", a concept that was introduced after the initial data load in 2014 .

02

When did it happen?

The breach date in the public record is September 10, 2014. The record was added to the catalogue on September 12, 2014 and last updated there on January 9, 2018.

03

What information was reported as exposed?

  • Email addresses
  • Passwords

These are incident-level categories. The record does not prove that every category was exposed for every affected person.

04

Who may be affected?

This record may be relevant to people who had an account or other relationship with mail.ru Dump or used mail.ru around September 10, 2014. A catalogue entry does not establish that every customer was affected or that every listed data category applied to each person. Compare the record with an official notice addressed to you.

05

What should you do?

Verify whether the notice applies to you

Compare the organization, dates, and information categories with any notice you received. Use contact details you independently confirm.

Secure affected accounts

Change exposed or reused passwords, begin with your email account, and turn on multi-factor authentication where available.

Expect targeted phishing

Treat unexpected breach follow-ups with caution. Do not use links or phone numbers in a suspicious message; contact the organization directly.

Choose actions that match the information involved. If you find signs that someone is using your identity, the Federal Trade Commission provides a personal recovery plan at IdentityTheft.gov.

Sources and review information

Page reviewed September 14, 2026 by the Data Breach Help Editorial Team. Catalogue details reflect the provider record and may change.