Hackers stole the emails of people who donated to Ukrainians and Russian political prisoners
Hackers stole the emails of people who donated money to Ukrainians and Russian political prisoners. The “Davayte” and “Ty Ne Odin” projects were targeted by the attack.
The projects reported a breach of personal accounts in the Stripe payment service. The attackers obtained the email addresses of some donors, as well as the last four digits of their bank cards and the names of the banks that issued them.
According to the projects, the hack occurred through Stripe’s integration with the WooCommerce service. “Davayte” clarified: “The attack lasted 61 seconds.” Both projects said that all donations are safe.
“All organizers of ‘Davayte’ have been declared ‘undesirable organizations’ by the Russian authorities. Donations to ‘Davayte’ may be grounds for administrative or criminal prosecution,” Davayte said.
“The ‘Ty Ne Odin’ marathon does not accept payments from Russian cards. We fear that donations to the marathon may be associated with its partners, some of whom have been directly banned by the Russian authorities. Thus, Meduza, Dozhd, and Sluzhba Podderzhki have been added to the register of ‘undesirable’ organizations, while the FBK has been designated an ‘extremist’ and ‘terrorist’ organization,” Ty Ne Odin said.
Donations Safe, Donors Left Exposed
Donor emails and card digits leaked through the payment setup.
The funds were safe. The donors were not.