
Ukrainian hackers are proud to put a huge number of personal data of Russians into public access. And where does Roskomnadzor look?
How much data flowed in Russia for 2022 in Russia is difficult to say - the numbers are called different. Roskomnadzor counted 150 large leaks. Kaspersky laboratory reported 168 , this is about 2 billion lines, of which 48 million contained passwords. The “Network Freedom” project identified 60 largest plums. The numbers are different, but everyone converges in the fact that there are more leaks and the main reason for this is the war .
After the Russia's invasion, hundreds of thousands of hackers around the world showed the desire to support Ukraine. “My colleagues and I control the principle of“ if you can hack it, then this must be hacking. ” That is, we believe that we need to break everything that we can reach. And the more significant for the enemy Target, the better for us, ”the hacker under the nickname of Theway, a representative of the Cyber.anarchy.squad group, shares with“ important stories ”.
The main goal of hacking of Russian state structures and business is data mining that can be useful to the law enforcement agencies of Ukraine, explains BlackBird, one of the founders of the DC8044 community: “Personal data obtained by our groups are given to power structures. They cluster them, consolidate in large massifs, which are already suitable for analytics and ensure their operations. ”
If we spend a day to hack something, our victims should spend at least a week to restore
Hackers are tightly cooperating with Ukrainian special services: they are engaged in intelligence, sabotage and information operations, Andrei Baranovich, the co -founder of the UKRANIANIAN CYber Alliance group, agrees. “If we spend a day to hack something, our victims should spend at least a week on recovery, and in the optimal case the victim should not recover in principle,” he explains.
Hackers unanimously claim that the well -known leaks are the tip of the iceberg, in most cases, having gained access to data, the crackers try not to shine it so as not to lose. “Some databases that hackers already have access are constantly saturated with a large volume of new data, and spitting them out into the public means to lose this access,” says BlackBird.
The data fall into the public when hackers want to make the enemy painfully or make a reputation for themselves. For money, data, of course, are also sold to spamers, scammers, data aggregators. “We constantly sell and drain the data. Basically, we try to help our servicemen, but we must also serve their technical points, ”the UHG Michael Myers hacker group, admits a member of the hacker group.
Obviously, ceterisis equal, the more people use the Internet, leaving their data there, the more chances that these data flow. Russia is among the world leaders in the use of the Internet, and the pandemic of Covid taught people to use delivery services: in 2020, the number of customers has grown seven times, and since then - an order of magnitude. Delivery services account for a third of leaks.
The sanctions do not facilitate the matter: many IT companies have limited their activities in Russia, the finished solutions of which were previously bought by the domestic business-Cisco, IBM, IMPERVA, FORTINET, NORTON, AVAST. “If earlier Russian companies could afford to use the largest, most eminent, most proven decisions, now you have to improvise,” says one of the experts who wished to remain anonymous. “The fact that Russia is extremely dependent on Western technologies that are difficult to maintain in the absence of manufacturers, a pleasant addition, but the level of security was already low. There are so many goals that you have to choose, ”said Baranovich from the Ukranian Cyber Alliance.
The whole fight against leaks today is in the mailing of letters and imitation of violent activity
Together with the increase in the number of stolen data, their aggregators develop. Access to them for a small fee, or even any user can get free today. The harmless seemingly information, being collected in one place and structured, reports a person unexpectedly about a person. Having drove the name, you can immediately get not only the address and phone, but also passport, SNILS, TIN, car number, parking lot, discount cards, accounts in social networks, etc.

In theory, Roskomnadzor should protect personal data. This is a very active state body - it blocks opposition sites, imposes censorship in Russia, studies ways to turn off the Runet from the Internet and ensures that Putin is not called offensive words (“important stories” talk about it here ). There are simply no resources left to protect the personal data of Russians, and the law does not allow any real levers today.
“The whole struggle against leaks today is in the mailing of letters and imitation of violent activity. And some meager fines are used only after a scandal arises in the media, ”the information security expert believes.
The protection of personal data looks like this. Each personal data operator - whether Yandex or the District Pizza Delivery Service should be included in the register of operators. Now it has almost a million companies. If there is a leak, the company is obliged to notify Roskomnadzor, which will start the verification, and then, perhaps, will bring the company to administrative responsibility under Article 13.11 of the Code of Administrative Offenses (“Violation of the legislation of the Russian Federation in the field of personal data”). The maximum fine for it is 100 thousand rubles. And that's it. It is not surprising that such cases are not too popular - in Moscow for 2022 we found 114 such administrative cases, eight of them are associated with leaks.
Now the mincifers are preparing a bill that can reduce the number of leaks. It increases fines for the company with which data has flowed. For the first leak - 3-15 million rubles (depending on the scale), for the second - 3% of the company's annual turnover, but not less than 15 million and no more than 500 million rubles.
At the same time, the company will be able to reduce the fine if it is able to agree with the majority of the victims - people whose data leaked by offering them compensation. It is supposed to do this through the "public services".
Roskomnadzor invites the same law to introduce the actual licensing of large personal data operators (more than a million records). Now they fall into his register in a notification order. Roskomnadzor wants to change the order for permitting - the company will have to fulfill several conditions: to hire at least five employees with higher education in the field of information protection, to be able to pay at least 100 million rubles of a fine and process data only in Russia. Then Roskomnadzor conducts an audit of its IT infrastructure and decides whether to include in the register or not.
Subscribe to our rash alphabet we send only important storiesDespite the fact that all this sounds reasonably, the business is traditionally afraid that, having received a lever in the form of large fines and licensing, officials will use it not for the good, but in their interests. “Such a law is more likely to encourage officials to work to increase the number of fines than stop leaks,” the expert believes. “And to compensate for harm, citizens need not to create a dubious mechanism with“ public services ”, but to allow them to file collective claims to the court,” the expert argues.
How security officials protect theirMeanwhile, another project has already been included in the State Duma, which should fulfill the dream of Russian security forces - so that they can bring them to the bases and take out of them those who are considered necessary. Now this is done on a one-time basis: in the Rosreestr, the sons of the former prosecutor general of Artem and Igor Chakk are renamed in LSDU3 and YFYAU9, then Vladimir Putin-in Igor Petrovich Sergeyev-Gradsky .
This process is proposed to be put on the legislative basis. From September 1, 2025, a register of “individual categories of persons” may appear in Russia, the data of which security forces will be able to adjust at their discretion in any bases. Theoretically, this will allow them to avoid hits in leaks with the subsequent identification of activists.
But the expert believes that such a law will only strengthen the zeal of hackers: “If several people are sitting in the room, but light bulbs are burning over some of them, whom the attackers will be interested in first of all? That is, in fact, each personal data operator of some conditional “Pyaterochka” will receive information that Ivan Ivanovich Petrov is the husband of the SVR employee Olga Petrovna Petrova, and therefore the data must be stored especially secretly about him. ”
Another problem of the bill, in his opinion, is the increasing risks of data safety: “The power with one hand requires the business to ensure maximum safety, with the other hand to increase the number of windows and doors in the room where it is necessary to ensure maximum safety. And provide an unhindered passage to your employees. Business, taking into account the number of criminal cases related to propagation, does not trust law enforcement officers, because who is engaged in our stroke? They are. "
An increase in fines for leaks and the development of the institution of collective claims is quite in the spirit of Western legislation.
For example, in 2018, as a result of a hacker attack, British Airways was stolen about 380 thousand personal data of customers and airline employees, including information on credit cards and CVV codes. Initially, the companies assigned a fine of 183 million pounds - this is 1.5% of its annual turnover in 2017, but then reduced to 20 million pounds, taking into account the consequences of Covid, deplorable for the air industry. 4500 victims filed against British Airways collective lawsuit, which was settled in a pre -trial manner. This, most likely, means that the company went to the terms of the plaintiffs and paid compensation.