HIGH SEVERITYSocial

VKontakte Data Breach

VK (VKontakte) Russian Social Network Breach (2024): 369 Million User Full Names Exposed by HikkI-Chan

Russian social network and digital services platform

Verified by ObscureIQ Intelligence

7.0Severity
369.3MRecords
1Fields
2024Year

ObscureIQ Breach Intelligence Scores
0.0
Breach Risk Index
5
Data Value
0
Market Recency
0
days
Since Breach

Risk Interpretation

Severe risk of account takeover, harassment, phishing, and identity linkage. Social-graph and communication data also support surveillance and targeted abuse.

🎯 Impact & Downstream Threats

In September 2024 a threat actor known as HikkI-Chan claimed to have exfiltrated over 370 million user records, publishing a 27.6GB dataset. The exposed data contained full names linked to VK accounts. VK has not made detailed public statements confirming the breach or outlining its response. The incident was added to Have I Been Pwned based on external researcher verification of the dataset. Given VK's operating environment and Russia's regulatory landscape, formal breach notification obligatio

Primary downstream threats:
  • Targeted phishing using exposed personal information
  • Credential reuse attacks across linked accounts

🔓 Threat Vectors

Name-based social engineering

📋 Breach Intelligence

EntityVKontakte (VK (VKontakte))
Organization • Russia
Breach Date2024-09-01
DBC Added2024-12-01
Records~369.3M (369,333,039 records)
Attack VectorMisconfiguration
Threat ActorHikkI-Chan
Data SubjectsUser
Breach PathwayDirect
SourceDataBreach.com / ObscureIQ
SensitivityStandard
Breach ID1437.0
StatusConfirmed

📝 Executive Summary

VKontakte (VK), Russia's largest social network, had personal data belonging to over 369 million users exposed in September 2024 when a threat actor known as HikkI-Chan published a 27.6 GB dataset online. The breach pathway was not a system intrusion. Instead, the data appears to have been harvested through automated web scraping, a technique that collects information already visible on public-facing profile pages. VK denied that any security breach had occurred, stating that no confidential information had been accessed and that its internal systems remained intact. The exposed data consisted of users' full names linked to their VK accounts. While names alone may appear low-risk, at a scale of 369 million records they become a meaningful asset for profiling. Attackers can cross-reference names against other leaked datasets to build richer profiles, identify individuals across platforms, or target them with phishing attempts and harassment. The sheer volume of the dataset amplifies these risks considerably. VK has not issued detailed public statements confirming the incident or describing a formal response. Because VK operates under Russian jurisdiction, Western breach notification frameworks do not apply, and there is no documented regulatory action. The dataset was independently verified by security researchers and added to Have I Been Pwned, giving affected users one avenue to check their exposure. People whose names appear in the dataset should be alert to unsolicited contact, suspicious login attempts, and any messages that reference personal details they did not knowingly share.

🏢 About VKontakte

VKontakte, commonly known as VK, is Russia's largest social network and digital services platform. The company operates a broad suite of services including social networking, messaging, music streaming, video, gaming, and payments under the VK brand. It is headquartered in Saint Petersburg and is publicly listed on the Moscow Exchange. VK serves hundreds of millions of registered users, concentrated in Russia and Russian-speaking communities globally, and functions as a dominant internet platform across multiple content and communications categories.

Platform | Social networking, messaging, and community media sharing | Social network | Russia
Russiavk.com

🗂 Why They Hold Your Data

Social-network platforms collect user identity, contact details, messages, social graphs, posts, media uploads, and engagement records tied to messaging and social-media workflows.

📰 Recent Developments

VK has operated under sustained western sanctions and geopolitical pressure following Russia's invasion of Ukraine in 2022, limiting its partnerships and investment options in European and American markets. The company has continued expanding domestic Russian digital services and has been associated with compliance with Russian state data localization laws. International growth has effectively stalled. No major structural or ownership changes have been reported in the most recent period.

🔍 Data Points Exposed

1 verified field types:
Name

Canonical Fields

full_name

🌐 Dark Web Verification

Confirmed
  • Dataset containing ~369.3M records identified in breach intelligence sources
  • Data indexed and searchable across breach notification platforms
  • Source: vk.com-2012

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of VKontakte
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

MisconfigurationSocial

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom