Switch Language

This translation was made by AI

Both projects have informed donors about the data breach in emails and statements on their websites. The attack itself took place on 11 August.

The perpetrators gained access to the charity projects’ Stripe accounts and extracted the email addresses of some donors. In some cases, the last four digits of the bank card and information about the issuing bank were also leaked, according to the projects. Full card numbers, cardholder names, and information about the donations themselves were not affected.

“We are investigating this breach and at this stage cannot say whether it was the work of ordinary cybercriminals or Russian security forces. <…> Because of the email leak, you may receive spam or phishing emails. Please remain vigilant and stay mindful of digital security,” reads the marathon’s statement.

What are the risks?

“Let’s” is a project providing aid to Ukrainians, launched in February 2024 by Helpdesk Media, Meduza, and Dozhd. The same media outlets, together with Mediazona and FBK structures, hold the annual “You Are Not Alone” marathon: in 2024 it raised more than €378,000.

The Russian authorities consider Meduza, Dozhd, and the Helpdesk Media Foundation (the legal entity of Helpdesk) to be “undesirable organisations,” and FBK to be an “extremist and terrorist organisation.” Donating to such organisations could lead to criminal charges.

This is how the breach was commented on by an OVD-Info lawyer:

At-risk are donors to the projects who are in Russia or visit the country. It is important, however, to distinguish between real and potential risks. At present, we do not know for certain what data actually leaked, or whether it is sufficient to identify donors and build criminal cases.

The last four digits of a bank card are unlikely to identify a person. Without additional information about the payer, these details have limited value.

Email addresses are a different situation. In theory, security forces could use this information to try to identify donors—for example, if the same address is linked to other online accounts. This, in turn, could draw increased attention: interviews, home visits, attempts to access devices. However, it is unlikely a single email address would be enough to pursue a criminal case: an email alone does not prove the owner’s identity, nor the fact of a donation, let alone make up a case.

It is also not entirely clear whether the leaks include information about the donations themselves—that is, amounts, dates, and payment purposes. According to the information published, these details were not leaked. It is difficult to say that the offenders or security forces have a comprehensive record of who donated, when, and how much.

As for specific criminal charges, we do not know how security forces might choose to interpret the situation. On one hand, the projects themselves are joint charitable initiatives by several organisations and media outlets, not an activity of a specific organisation. Because of this, trying to categorise such donations as financing “prohibited” organisations seems unreasonable and incorrect.

On the other hand, these projects are linked to organisations that have been designated as toxic in Russia. So we cannot be sure that security forces will not try to associate a particular project with a specific organisation. Whether they actually do so is another question.

There is particular concern about the possibility that donations for humanitarian aid to Ukrainians could be categorised as a severe criminal offence. In this case, security forces could characterise a particular donation as “state treason.” However, they would probably have to link a specific donation to a particular fundraising initiative.