Over 98M records leaked online from 2012 hack of Russia's Yahoo-like service Rambler.ru, each record contains: username/email address, plaintext password, more
Nearly 100 million records have been leaked online in yet another “mega breach”, this time from the website Rambler.ru …
Context & Ripple Effects
Rambler.ru is now the third major Russian web property to surface in the 2016 credential-dump wave, after VK's 100M records with unencrypted passwords went on sale in June and the 272.3M email credentials traded in the Russian underworld made headlines in May. Like the 2012 Last.fm hack whose dump surfaced days earlier, this is an old intrusion — dated to 2012 — only now published by LeakedSource.
The distinguishing detail is storage hygiene: where Last.fm's hashes were mostly cracked within hours, Rambler stored passwords in plaintext, meaning every one of the 98M+ records is immediately usable. That puts it closer to the VK case than to hashed-password breaches, and it lands weeks before Yahoo's own 500M-account state-sponsored breach confirmation made 2016 the year of the mega-breach.
First-order effects
- Rambler.ru users whose passwords were reused on other services face immediate account-takeover risk, since plaintext records need no cracking before credential stuffing begins.
- LeakedSource adds another searchable corpus to its index, making 2012-era Rambler credentials trivially queryable for anyone checking exposure.
Second-order effects
- Email providers are positioned to repeat the Mail.ru-Google playbook from May, when they reported that 98%+ of the 272M credentials on their services were already invalid — expect similar validity filtering to blunt much of this dump's impact while flagging the residual live accounts.
- Rival Russian consumer services face renewed pressure to demonstrate hashing practices, since plaintext storage is now publicly documented twice over via VK and Rambler.
Third-order effects
- The recurring gap between intrusion date and public disclosure — 2012 hacks surfacing in 2016 for both Last.fm and Rambler — points toward structural demand for mandatory breach-notification timelines rather than voluntary or accidental discovery.
- If plaintext and weakly-hashed storage keeps producing the largest dumps, password storage standards shift from best practice to regulatory and liability question for consumer web operators.
The trend: Old intrusions surfacing as searchable mega-breach dumps years later is becoming the standard disclosure pattern, with storage quality determining whether each dump is a forensic puzzle or an instantly usable weapon.