In short: A new F6 Threat Intelligence report published September 10–11, 2026 found that Russia ranked #1 globally for public database leaks: 326 documented incidents and over 1.17 billion exposed records across the 18 months spanning 2025 and the first half of 2026. That is double the combined total of all other world regions.
The F6 report: what it found
F6's Threat Intelligence unit analysed publicly posted database leaks globally across 2025 and H1 2026. Russia tops every metric: 326 public leak incidents compared to 164 cases across all other regions combined — Latin America, the Middle East, Africa, Asia-Pacific, and the CIS excluding Russia. Russia alone accounts for more public data incidents than the rest of the world put together.
The total volume of records exposed in Russian leaks exceeded 1.175 billion rows. For context, Central Asian data in the same period amounted to roughly 257 million records, of which 217 million were attributed to Tajikistan, 25 million to Kazakhstan, and 15 million to Uzbekistan. The findings were reported by ComNews and IT Zine.
Why the number is so high: context
F6's methodology counts only public leaks — databases openly published on dark web forums or accessible platforms. These are not all incidents, only those criminals chose to disclose: for extortion, underground trading, or capability demonstration.
Russia has accumulated a large base of vulnerable digital services — retail, healthcare, financial companies, and government organisations have all been targeted over the years. A notable nuance: F6's earlier H1 2026 report showed the number of published leaks falling 46% year-on-year, but analysts attribute that to a tactical shift: criminals increasingly monetise stolen data directly rather than posting it publicly. The actual scale of breaches may therefore be larger than public numbers suggest.
What this means for your personal data
A high public-leak rate means that personal details of Russian users — phone numbers, email addresses, passport data, purchase history, medical records — are statistically likely to appear in at least one published breach database. Even if consequences are not immediately apparent, exposed data can be used for:
- Targeted phishing and social engineering attacks;
- Credential stuffing — automated login attempts using leaked username/password pairs;
- Fraud calls leveraging real personal details to appear credible;
- Resale of aggregated profiles to data brokers and ad networks.
You can check whether your email has appeared in known breaches via independent services such as Have I Been Pwned. Unique passwords per service, a password manager, and two-factor authentication form the baseline defence. For more context on protecting your privacy, visit our privacy blog.
How to reduce the impact of data leaks
You cannot prevent companies from experiencing breaches — but you can limit the downstream impact on your accounts and digital life:
- Use a password manager — unique passwords per service prevent the domino effect when one account is compromised.
- Enable two-factor authentication — even if a password leaks, a second factor blocks unauthorised access.
- Encrypt your internet traffic — a VPN will not undo an existing database breach, but it prevents adversaries on the same network from intercepting your current connections and capturing new data. Learn more on the LiMP VPN features page and see pricing plans.
- Monitor breach notifications — many platforms are required to notify users of incidents within 72 hours; an email about a breach is a prompt to change your password immediately.
