leaksear.ch has indexed a CDEK leak containing 194,865,000 records, with email addresses and names searchable in the dataset (leaksear.ch metadata). Mozilla Monitor lists the CDEK breach date as March 9, 2022, and CDEK describes itself as a Russian delivery service with domestic and international shipping services (monitor.mozilla.org, cdek-world.com).
What happened
Public breach-notification sources identify CDEK as breached on March 9, 2022, and Mozilla Monitor says the breach was added to its database on March 17, 2022, with breach data provided by Have I Been Pwned (monitor.mozilla.org).
Public breach-count figures are not one-to-one. HIBP's catalogue lists CDEK at about 19.2 million pwned addresses, and HIBP's API documentation defines PwnCount as email addresses loaded into its system, often lower than broader reported totals because of duplicates or source-data issues. leaksear.ch's indexed source contains 194,865,000 records (haveibeenpwned.com, haveibeenpwned.com, leaksear.ch metadata).
Neither the supplied leaksear.ch metadata nor the public pages cited here establish a specific intrusion vector such as ransomware, scraping, or misconfigured storage. BleepingComputer reported in February 2022 that Ukraine's volunteer IT Army was organizing cyberattacks against Russian entities, and a later Twingate summary described the CDEK attribution to IT Army as alleged, so attribution should be treated as unconfirmed based on the sources available here (bleepingcomputer.com, twingate.com).
What data was exposed
Based on the leaksear.ch indexing metadata, this source exposes email addresses and names, and both fields are searchable pivots in the index (leaksear.ch metadata). Mozilla Monitor's CDEK breach page, which attributes breach data to HIBP, also lists phone numbers in the public breach record, but phone numbers are not listed in the supplied leaksear.ch metadata for this indexed source (monitor.mozilla.org, leaksear.ch metadata).
Mozilla Monitor states that passwords were not exposed in the CDEK breach notification page. The supplied leaksear.ch metadata does not identify passwords, payment-card data, national IDs, or physical addresses for this indexed source (monitor.mozilla.org, leaksear.ch metadata).
Why this matters
Email and name pairs from a delivery-service dataset can support targeted phishing, especially lures about parcel tracking, failed deliveries, customs issues, or account updates (leaksear.ch metadata). Security teams should monitor for CDEK-themed phishing, suspicious credential-reset activity, and messages sent to exposed addresses. Individuals should treat unexpected delivery notifications as untrusted and avoid clicking shipment links in unsolicited messages. Readers who want to check whether their data appears in this leak should search leaksear.ch by email address or name.
Check your exposure
Vetted researchers and incident-response teams can request access or sign in if they already have access to check this dataset. Searchable pivots for this leak include email and name.