AntiMalwareAugust 5, 2026🇷🇺Translated from Russian

Russian Medical Data Leaks Explode in July: 88 Million Records Exposed

In July 2026 more than 100 million records containing personal data of Russian citizens appeared in open access. Experts from Perspektivny Monitoring recorded 17 separate leaks originating from commercial organizations, online platforms, government bodies, e-commerce stores and medical institutions.

The medical sector became the main source of the month’s leaks, accounting for 88.37 million records. For comparison, the same sector leaked only 1.7 million records in June and 2.2 million records across March, April and May combined. The sharp rise was caused by just two incidents, one of which involved a large medical information system.

Nikolay Galkin, Head of Cyber Threat Research at Perspektivny Monitoring, noted that medical data has now been leaking for four consecutive months. He added that threat actors are clearly targeting the most confidential categories of information while protection measures in healthcare remain extremely weak.

Other industries also failed to keep their databases secure. The commercial sector lost 11.12 million records, online platforms lost 8.45 million records, government organizations lost 8.36 million records, and internet shops lost an additional 2.1 million records. The government sector reappeared in the statistics after a period of calm; April had seen a record 159 million records leaked from state sources, followed by two months without new public disclosures.

Stolen databases are typically distributed through specialized messenger channels and dark web marketplaces, where the personal information is quickly converted into raw material for fraud operations.

Related articles

AntiMalwareData Breaches & Leaks

Kaspersky MDR Adds Automatic Correlation with Leaked Credentials via Digital Footprint Intelligence

Kaspersky has updated its Managed Detection and Response service to automatically match security events against data from compromised logins and passwords. The enhancement integrates Kaspersky Digital Footprint Intelligence to provide analysts with additional context when suspicious activity coincides with known credential leaks. According to the company, a quarter of attacks investigated in 2025 began with the use of stolen credentials. The update also introduces notifications for asset protection status, allowing administrators to address connectivity or telemetry issues that could affect monitoring quality. Managed service providers can now configure per-client license usage limits, and the service adds support for Kaspersky Embedded Systems Security for Linux 4.0. The MDR platform continues to deliver 24/7 infrastructure monitoring, threat hunting, incident investigation, and response capabilities.

AntiMalwareData Breaches & Leaks

Hacktivist Group Cyberleek Leaks Alleged GTA VI Gameplay and Map Details in Protest Against Digital-Only Releases

A hacktivist collective calling itself Cyberleek has released two purported gameplay clips from GTA VI along with images that may depict the full map of Leonida state. The group claims the leak is a protest against Rockstar's decision to sell physical editions that contain only a download code rather than an actual disc. Cyberleek is also demanding an end to digital pre-orders, the practice of selling built-in content as DLC, and mandatory online connectivity for single-player modes. Rockstar and parent company Take-Two have already filed DMCA takedown requests, which some observers view as indirect confirmation of the material's authenticity. The footage reportedly shows basketball mechanics, vehicle customization, trunk-opening animations, a stamina meter, and an honor system reminiscent of Red Dead Redemption 2. The alleged map includes five counties, an extensive rail network, and numerous small islands. At the same time, Cyberleek is promoting a Solana-based token and soliciting donations, prompting several outlets to question whether the operation is partly a cryptocurrency marketing scheme.

BoletimSecData Breaches & Leaks

SplitVPN Data Breach Exposes Personal Information of 865,000 Users

A data breach at the Russian VPN provider SplitVPN, formerly known as NotVPN, has exposed the personal details of approximately 865,000 users. The incident, which occurred in July 2026, involved a 17 GB SQL database containing emails, IP addresses, geolocation data, and partial payment card information. The stolen material was later distributed on a cybercrime forum, revealing 23.4 million user records, 13.6 million devices, and 2.6 million payment entries. Nearly 58 million connection logs spanning June 2025 to 21 July 2026 were also included, contradicting the company’s previous no-logs policy. The exposure is particularly concerning for users relying on the service to evade censorship and surveillance.

HabrData Breaches & Leaks

Click to Pray App Exposed Personal Data of 719,000 Users Through Unprotected API Endpoint

Security researcher BobDaHacker discovered an IDOR vulnerability in the official Click to Pray application run by the Pope's Worldwide Prayer Network. The flaw allowed anyone to retrieve full user profiles, including names, emails, countries, and birth dates, by simply incrementing numeric user IDs in API requests. No authorization checks or rate limits were present on the endpoint despite the service holding data for over 719,000 registered accounts. The researcher reported the issue to nine contacts in January 2026 but received no response for seven months. Dark Reading independently verified the exposure before publication, after which the endpoint was quickly restricted. The same service had suffered similar authorization failures in 2019 involving PIN code exposure through its eRosary application. The case highlights persistent gaps in object-level authorization and responsible disclosure channels at the Vatican-backed platform.