More databases leaked in Russia than in four world regions combined

11.09.2026 7 min 22

A Russian cyber-intelligence firm has counted the databases that surfaced publicly over eighteen months and arrived at two numbers that travelled fast: 326 leaked Russian databases and about 1.18 billion rows of data. Both figures are real. What they measure is narrower than the headlines they produced, and the difference is worth understanding wherever you live, because the same counting problems appear in every leak report.

In short

  • F6 counted 326 public publications of Russian company databases across 2025 and the first half of 2026, containing roughly 1.175 billion rows.
  • That is close to double the 164 cases recorded across Latin America, the Middle East and Africa, Asia-Pacific and other CIS states combined.
  • Europe and North America are not in the published comparison, so "first in the world" is the headline framing rather than a like-for-like global ranking.
  • A row is not a person. One person can appear in many rows, and rows vary from an email address to passport data and service passwords.

What was counted

The unit here is a publication, not a breach. F6 is counting databases that appeared publicly, on forums and channels where stolen data gets dumped, during 2025 and the first six months of 2026. A company that was breached quietly and never saw its data posted does not enter this count at all, which means the number tracks what leaked into the open rather than what was stolen.

326public publications of Russian company databases
1.175bnrows of data in them
164cases across the four other studied regions combined
257mrows from Central Asia, more than a third of the global total

Set the Russian figures aside and the rest of the studied world distributes as follows: Latin America 33 percent of recorded cases, the Middle East and Africa 29 percent, Asia-Pacific 8 percent, the remaining CIS states 4 percent. But the largest volume of rows did not come from the region with the most incidents. Central Asia contributed 257 million rows, more than a third of the global total, and most of that is one country: Tajikistan accounts for roughly 217 million rows, or 84 percent of the Central Asian total, ahead of Kazakhstan on 25 million and Uzbekistan on 15 million.

Three things the numbers do not say

This is the part that matters more than the ranking, and it applies to every leak statistic you will read this year.

  1. A row is not a person. One individual can appear many times across a single database, and the same person appears again in every other database that holds them. Summing rows across leaks counts the same people repeatedly.
  2. Rows are not equal. One may hold nothing but an email address; another may hold a full name, a passport number and a password for a service. The total tells you nothing about that mix.
  3. Regions are not compared like for like. The published breakdown covers Latin America, the Middle East and Africa, Asia-Pacific and CIS states. Europe and North America do not appear in it, so a global first place is not something these figures can establish.
Why this keeps happening: "records exposed" is the easiest number to produce and the hardest to interpret. It is generated by counting lines in a file, which is why it appears in every report, and why the same person can be counted a dozen times across a year of coverage without anyone lying.

What the researchers attribute it to

F6 links the concentration of incidents to attacks on companies and state organisations intensifying during the geopolitical conflict, with the goal of causing maximum damage to the companies and their customers rather than simply profiting from the data. The firm also reports something the headline numbers obscure: in the first half of 2026 the number of published Russian databases fell, while the intensity of attacks stayed at what it calls an unprecedented level.

There is a second explanation that has nothing to do with attackers, offered in Russian coverage of the report and worth keeping in view. Volume of leaked data follows volume of collected data. A country where state services, banking, telemedicine, delivery and car sharing are all digital and widely used simply holds more personal records than a country where those services are thinner, and there is more to lose in every direction.

What to do with a number like this

Worth doing

  • Check your own addresses against a breach search service, and repeat it occasionally rather than once.
  • Change any password you have reused, starting with email and banking, because credential stuffing is what leaked rows are actually used for.
  • Turn on two-factor authentication wherever it exists, and prefer an app or a hardware key over SMS.
  • Treat a passport or ID number in a leak as permanent. Unlike a password it cannot be rotated, so the response is watching for misuse rather than changing it.

Not worth doing

  • Reading a row count as a headcount, or adding up totals across reports.
  • Assuming a country with a low number is safer. It may simply have fewer digital services, or fewer researchers counting.
  • Expecting a VPN to help here. Data leaks from a company's servers, not from your connection.
  • Panicking about a leak that predates your current passwords. Old rows matter less once the credentials in them are dead.

The VPN point deserves its one sentence and no more, because the temptation to stretch it is obvious. A tunnel protects traffic in transit and hides which network you are on. It does nothing about a database sitting on a company's server with your name already in it, and any service that suggests otherwise is selling you something.

The useful reading

Taken narrowly, the report says that Russian databases dominated public dumps over eighteen months among the regions studied, and that Central Asia contributed a disproportionate share of the raw volume from a small number of incidents. Taken broadly, it is a reminder that the size of a leak is decided by how much was collected in the first place. Every service that asks for a passport scan to verify an account is adding rows to somebody's future total, which is the part of this worth arguing about while it is still a design decision rather than a news story.

Does this mean Russia has the most leaks in the world?
It means Russia had more public database publications than the other regions in this study combined. Europe and North America are not in the published breakdown, so the figures do not establish a worldwide ranking.
Were 1.18 billion people affected?
No. That is a count of rows. One person appears in many rows, both within a single database and across different ones, so the number of individuals is far lower and is not stated in the report.
Why does Tajikistan appear so high?
Because volume of rows and number of incidents are different measures. A small number of very large databases can outweigh many small ones, and Central Asia's 257 million rows come mostly from Tajikistan.
Is the situation getting better or worse?
Both, on the report's own account. F6 recorded fewer published Russian databases in the first half of 2026, while describing the intensity of attacks as unprecedented. Fewer publications does not mean fewer intrusions.
What is the single most useful thing to do?
Stop reusing passwords, starting with your email account, since it is the reset path for everything else. Leaked credentials are valuable mainly because people use them in more than one place.

data breachprivacyrussiacentral asiapasswordscybersecuritystatisticsdata protectionleaks2fa

Read also