Platform · Online dating and matchmaking · General dating platform · Global
Russian online dating platform.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
LovePlanet, a Russian online dating platform serving users in Russia, Ukraine, and Belarus, suffered a data breach in approximately January 2015 when attackers exploited security flaws in LovePlanet's systems and exfiltrated a database containing personal information and credentials for approximately 20.1 million users. The breach has been attributed to the GnosticPlayers hacker group, which was responsible for a series of high-profile breaches at dating, consumer, and social platforms during the 2014 to 2019 period. The breach data was originally distributed on RaidForums, the dark-web breach-trading forum that was subsequently seized by law enforcement, before broader redistribution. DataBreach.com indexed the breach on February 3-4, 2025, approximately ten years after the original incident. The breach affected approximately 20,077,733 unique user accounts based on records indexed by breach-tracking services. Compromised fields included usernames, email addresses, and passwords stored in plaintext. The plaintext password storage represents a critical security failure that exposes the original credential values directly, with no cryptographic protection of any kind. The breach was originally posted under the description 'loveplanet.ru 20m users plaintext' on RaidForums. For affected users, the practical risk profile combines credential-reuse exposure with niche dating-platform-specific reputational risk in Russian and CIS markets. The plaintext password exposure means that any account where the user reused the LovePlanet password is fully compromised, with credential-stuffing risks expected on email, social media, financial, and other accounts where Russian and CIS users may have used the same password. The combination of email address, username, and confirmed dating-platform membership supports targeted phishing referencing the platform or related services. Inclusion in the dataset confirms a dating-platform relationship that may carry reputational consequences depending on the user's circumstances. Affected users who receive extortion attempts should not pay ransom demands because payment does not stop further extortion. Users should change all reused passwords immediately, enable two-factor authentication where available, document any extortion communications, and report extortion attempts to law enforcement. The ten-year gap between the original breach and the recent redistribution means that affected users should expect long-term exposure rather than a time-limited incident, with the dataset likely to remain in circulation indefinitely.
Full threat analysis, exploitation vectors, and principal guidance below.
12 additional sections · verified field analysis · defensive doctrine
20.1M records analyzed
LovePlanet (loveplanet.ru) is a Russian online dating platform that serves users primarily in Russia, Ukraine, and Belarus, with approximately 22 million users at the time of public reporting on the breach. The platform operates a freemium model with both free account access and premium subscription tiers, and supports both heterosexual and same-sex matchmaking with search by country, city, age, gender, and physical attributes. LovePlanet has been the subject of consumer reviews questioning the legitimacy of profiles on the platform, with multiple reviewers alleging that the platform contains a substantial proportion of bot or operator-created profiles in a pattern similar to other large dating platforms. As an account-based dating platform, LovePlanet maintains user account data including identity, contact information, and login credentials.
Dating platforms collect profile data, photos, messages, social activity, and subscription records tied to online matchmaking and relationship discovery.
The LovePlanet breach was publicly indexed by DataBreach.com on February 3-4, 2025, approximately ten years after the original 2015 incident, as part of the broader 2024 to 2025 wave of historical dating-platform breach redistribution and indexing. The breach has been attributed by DataBreach.com and other breach-tracking publications to the GnosticPlayers hacker group, which was responsible for a series of dating-platform and consumer-platform breaches during the 2014 to 2019 period. LovePlanet itself does not appear to have publicly acknowledged the breach, and the platform reportedly continues to operate. The breach was originally distributed on RaidForums (now defunct following law enforcement seizure) before broader redistribution.
The institutional impact on LovePlanet has been limited based on publicly available information, in part because the platform operates primarily in Russia and adjacent CIS markets where breach-notification and regulatory frameworks differ substantially from those in the United States and European Union. LovePlanet has not publicly acknowledged the breach. The reputational impact concentrated within the Russian and CIS dating-platform sector, although the breach has been broadly cited in international cybersecurity coverage as part of the GnosticPlayers attack series alongside other GnosticPlayers victims. The breach's redistribution and indexing in early 2025 has renewed attention to the case as part of the broader historical-breach redistribution pattern.
• Credential stuffing against reused passwords across other platforms | • Targeted phishing campaigns using exposed email addresses
An intimate-data breach: preferences, orientation or explicit content linked to an identity create acute coercion and blackmail exposure. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.
Motivation: Financial
A prolific breach seller persona active around 2019 and associated with large batches of stolen account databases. Some modern reporting groups GnosticPlayers with the broader ShinyHunters data-theft ecosystem, but that relationship should be handled cautiously.
Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.
We will only reveal whether a specific person appears in this breach to that person.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation