AntiMalwareJuly 17, 2026🇷🇺Translated from Russian

Russian Interior Ministry Opens Five Criminal Cases Against 'Glaz Boga' Analog Platforms Selling Personal Data of Russian Citizens

The Ministry of Internal Affairs (MVD) of Russia has opened five criminal cases after identifying several internet platforms that were actively selling personal data belonging to Russian citizens. These services functioned according to the well-known model of «Glaz Boga» (Eye of God), where users could pay a fee and immediately receive comprehensive biographical information about individuals compiled into multiple files.

According to the ministry, the investigations are being conducted under Article 272.1 of the Criminal Code of the Russian Federation. This article specifically criminalizes the illegal use, transfer, collection, and storage of computer information that contains personal data. The platforms in question offered a wide range of confidential information, including passport details, information about bank accounts, and other sensitive records that had been aggregated from various sources.

Law enforcement officers have already seized the servers belonging to these services. Investigators are now examining the seized equipment in detail, studying its contents, and collecting additional evidence to support the criminal proceedings. At this stage, the MVD has not disclosed the names of the platforms involved, the total number of clients who used the services, or the exact volume of personal data that was sold through them.

It also remains unknown how many Russian citizens may have had their information included in these databases. The situation reflects a broader and long-standing problem: repeated large-scale data leaks have turned personal information into a commercial product, while underground services operate as ordinary marketplaces. Instead of offering discounts or delivery services, these platforms sell passports, financial account details, and fragments of private lives to anyone willing to pay.

The operators of the five platforms now face the task of explaining to investigators the origins of the databases they used, the identities of the buyers who purchased access, and the pricing structures applied to different levels of data access.

Related articles

AntiMalwareData Breaches & Leaks

Kaspersky MDR Adds Automatic Correlation with Leaked Credentials via Digital Footprint Intelligence

Kaspersky has updated its Managed Detection and Response service to automatically match security events against data from compromised logins and passwords. The enhancement integrates Kaspersky Digital Footprint Intelligence to provide analysts with additional context when suspicious activity coincides with known credential leaks. According to the company, a quarter of attacks investigated in 2025 began with the use of stolen credentials. The update also introduces notifications for asset protection status, allowing administrators to address connectivity or telemetry issues that could affect monitoring quality. Managed service providers can now configure per-client license usage limits, and the service adds support for Kaspersky Embedded Systems Security for Linux 4.0. The MDR platform continues to deliver 24/7 infrastructure monitoring, threat hunting, incident investigation, and response capabilities.

AntiMalwareData Breaches & Leaks

Hacktivist Group Cyberleek Leaks Alleged GTA VI Gameplay and Map Details in Protest Against Digital-Only Releases

A hacktivist collective calling itself Cyberleek has released two purported gameplay clips from GTA VI along with images that may depict the full map of Leonida state. The group claims the leak is a protest against Rockstar's decision to sell physical editions that contain only a download code rather than an actual disc. Cyberleek is also demanding an end to digital pre-orders, the practice of selling built-in content as DLC, and mandatory online connectivity for single-player modes. Rockstar and parent company Take-Two have already filed DMCA takedown requests, which some observers view as indirect confirmation of the material's authenticity. The footage reportedly shows basketball mechanics, vehicle customization, trunk-opening animations, a stamina meter, and an honor system reminiscent of Red Dead Redemption 2. The alleged map includes five counties, an extensive rail network, and numerous small islands. At the same time, Cyberleek is promoting a Solana-based token and soliciting donations, prompting several outlets to question whether the operation is partly a cryptocurrency marketing scheme.

AntiMalwareData Breaches & Leaks

Russian Medical Data Leaks Explode in July: 88 Million Records Exposed

In July 2026 more than 100 million records containing personal data of Russian citizens appeared in open access. Experts from Perspektivny Monitoring recorded 17 separate leaks originating from commercial organizations, online platforms, government bodies, e-commerce stores and medical institutions. The medical sector accounted for the overwhelming majority with 88.37 million records leaked, a sharp increase from 1.7 million in June. Two major incidents, one involving a large medical information system, drove the spike. Head of cyber threat research Nikolay Galkin stated that medical data has now leaked for four consecutive months and that attackers are deliberately targeting highly sensitive information. Other sectors also suffered losses, with 11.12 million records from commercial entities, 8.45 million from online platforms, 8.36 million from government organizations and 2.1 million from internet shops. Stolen databases are routinely traded in messenger channels and dark web marketplaces for use in fraud schemes.

BoletimSecData Breaches & Leaks

SplitVPN Data Breach Exposes Personal Information of 865,000 Users

A data breach at the Russian VPN provider SplitVPN, formerly known as NotVPN, has exposed the personal details of approximately 865,000 users. The incident, which occurred in July 2026, involved a 17 GB SQL database containing emails, IP addresses, geolocation data, and partial payment card information. The stolen material was later distributed on a cybercrime forum, revealing 23.4 million user records, 13.6 million devices, and 2.6 million payment entries. Nearly 58 million connection logs spanning June 2025 to 21 July 2026 were also included, contradicting the company’s previous no-logs policy. The exposure is particularly concerning for users relying on the service to evade censorship and surveillance.