Hackers Obtained the Email Addresses of Donors to the "Davayte" Project and the "You Are Not Alone" Marathon in Support of Political Prisoners. What Are the Risks?

Original source

Hackers obtained the email addresses of donors to the "Davayte" project and the "You Are Not Alone" marathon in support of political prisoners. What are the risks?

Both projects reported the leak in letters to donors and statements on their websites. The attack itself took place on August 11.

The attackers gained access to the charity projects' accounts in the Stripe payment system and extracted the email addresses of some donors. In some cases, the last four digits of a card and information about the issuing bank were also leaked, the projects say. At the same time, full card numbers, cardholder names, and information about the donations themselves were not affected.

"We are investigating this hack and cannot yet say whether ordinary cybercriminals or Russian security forces are behind it. Because of the email-address leak, you may receive spam and phishing emails. Please stay vigilant and do not forget about digital security," the marathon's statement says.

What are the risks?

"Davayte" is a project helping Ukrainians that was launched in February 2024 by Support Service, Meduza, and Dozhd. The same media outlets, together with Mediazona and FBK structures, hold the annual "You Are Not Alone" marathon every year: in 2024 it raised more than €378,000.

The Russian authorities consider Meduza, Dozhd, and Helpdesk Media Foundation (the legal entity of Support Service) undesirable organizations, and FBK an extremist and terrorist organization. Donating to such organizations can lead to criminal prosecution.

Here is how an OVD-Info lawyer comments on the leak:

The risk group includes donors to the projects who are in Russia or visit the country. At the same time, real and potential risks should be distinguished. At the moment, we do not reliably know what data actually leaked, or whether it is sufficient to identify donors and build cases.

The last four digits of a bank card are unlikely to make it possible to identify a person. Without additional information about the payer, this data has limited value.

The situation is different with email addresses. Potentially, this information can be used by security forces to establish the identity of donors if, for example, the same address is linked to other accounts. And this, in turn, may become grounds for closer attention: conversations, home visits, attempts to gain access to devices. At the same time, a single email address is unlikely to be enough for a criminal case: an address by itself proves neither the identity of its owner, nor the fact of a donation, nor, even more so, the elements of an offense.

It is also still not entirely clear whether the leaks include information about the donations themselves, that is, amounts, dates, and payment purposes. According to the published information, this data was not leaked. Right now it is difficult to claim that the attackers or security forces have a full registry of who donated, when, and how much.

As for specific criminal charges, we cannot know what qualification the security forces will want to use. On the one hand, the projects themselves are joint charitable initiatives of several organizations and media outlets, not a form of activity of a specific organization. Because of this, any attempt to classify such activity as financing a "prohibited" organization seems inherently disputable and incorrect.

On the other hand, organizations connected with these projects have received toxic statuses in Russia. So we cannot be sure that the security forces will not want to tie a particular project to a particular organization. Whether they will do so is another question.

A separate concern is the possibility of classifying donations for humanitarian aid to affected Ukrainians. In that case, a donation to one fundraiser or another could be classified by the security forces under the grave charge of "treason." But in that case, they would probably need to connect a specific donation to a specific fundraiser.

⭕️ If you think the leak may have affected you as well, write to us at @ovdinfobot and we will explain the risks and ways to protect yourself.

❗️ Sharing this post publicly may be unsafe because the Russian authorities have declared OVD-Info an extremist organization. But you can still read us and like our posts!

A Data Leak Put Charity at Risk

Donor email addresses leaked from the payment system accounts.

Donating now comes with basic countermeasures.