A threat actor claims to have breached Max.ru, a Russian service described as both a messenger and an e-commerce application. The actor is offering a database dump for sale containing approximately 46.2 million user rows.
In the post, the actor also alleges to have persistent VPN access to the company’s internal network, including its Salesforce instance and other tools.
According to the threat actor, the compromised data comes from a user_profiles table. The allegedly stolen information includes:
- User IDs
- Full names (first and last)
- Phone numbers
gosuslugi_id(related to the Russian e-government portal)gosuslugi_enabledstatus- Profile picture identifiers












