LiMP VPN
← All news

Fewer Leaks, More Data: Russian Breaches Grew 31% in Volume in H1 2026

Fewer Leaks, More Data: Russian Breaches Grew 31% in Volume in H1 2026

In short: On September 25, 2026, two independent H1 2026 reports landed on the same day. Roskomnadzor logged 504 personal-data violations and 12 officially confirmed leaks. Separately, a Solar AURA report on external digital threats found that public leak postings fell 47% (214 incidents) while the volume of exposed data jumped 31% — from 288M to 378.4M rows. The new top target isn't government — it's microfinance firms and small-to-medium businesses.

What Roskomnadzor found

According to Roskomnadzor's press service, the regulator recorded 504 violations of personal-data law in the first six months of 2026: 490 under Article 13.11 of the Administrative Code (general data-processing violations) and 14 under Article 13.11.2 (unlawful use of foreign IT systems to store Russian citizens' data). No violations were recorded under the biometric-data article. The agency ran only one unscheduled inspection but conducted 728 preventive visits, issuing 89 orders — a clear shift toward prevention over after-the-fact punishment. The historical trend for Article 13.11 violations keeps climbing: 162 in 2020, 430 in 2023, 618 in 2024, and 705 across all of 2025.

Separately, the regulator confirmed 12 officially registered data leaks for the half-year — the figure that underpins fines under Russia's data-protection law, where penalties for repeat corporate incidents already reach hundreds of millions of rubles.

What the Solar AURA report shows

Independently of the regulator, analysts at Solar AURA (part of the Solar Group) documented a different but complementary picture: in H1 2026, 214 public postings about database leaks were recorded — 47% fewer than a year earlier. Yet the volume of compromised data grew 31% — from 288 million to 378.4 million rows. In other words, fewer leaks are surfacing in open channels, but each one is bigger.

The victim profile shifted too. The government sector's share of leaked volume collapsed from over half in 2025 to just 4% in 2026. Financial services now lead (38% of volume, 143.6M rows) — driven mainly by microfinance organizations — followed by the services sector (28%, 108M rows). Overall, small and medium businesses, including retail, accounted for 83% of incidents by count. The logic is simple: large banks and government agencies have spent a decade hardening data protection, while microfinance firms and small services often have neither a dedicated security team nor an audit budget.

Fewer leaks doesn't mean more safety

As with previous half-year roundups, a drop in public postings doesn't mean attacker activity is declining. Data that is stolen but never dumped publicly is often sold in closed Telegram groups and shadow forums — and never shows up in posting statistics. Rising volume alongside falling posting counts points to concentration: attackers are increasingly going after large, poorly secured databases at microfinance firms and small online services rather than spreading attacks across dozens of smaller targets.

You can check whether your own data has surfaced in one of these dumps — see our guide on checking for personal data leaks for concrete steps.

What this means for you

If you're a customer of a microfinance service, an online store, or a services-sector company, your odds of ending up in one of these dumps are higher than if your data lived only with a major bank. The typical dataset in MFO and SMB leaks includes full name, phone, email, ID details and payment history — enough for targeted phishing, fake "bank security" calls, and loans taken out in your name.

How to protect yourself

Check yourself against known leaks. Services like Have I Been Pwned show whether your email appears in known breaches.

Don't over-share with microfinance services and small retailers. Every operator you hand your ID or full card details to is a new risk point. Weigh necessity, not form convenience.

Unique passwords and 2FA. A password manager and two-factor authentication stop automated credential-stuffing built from leaked login pairs.

Encrypt your own connection. A VPN can't stop an MFO's database from being breached — that's outside any user's control. But it encrypts your own traffic and keeps no connection logs, shrinking the amount of data that can be collected about you in the first place. See the LiMP VPN pricing page and features page for details.

Sources