The Russian instant messaging service QIP suffered a major data breach in 2011 that exposed tens of millions of user accounts. Reporting on the incident indicates that between 26 million and more than 33 million accounts were affected, with compromised records including email addresses and passwords tied to the service.
Although the intrusion occurred years earlier, the stolen data did not become widely available immediately and surfaced publicly later, drawing renewed attention to the scale of the compromise. The exposure added QIP to the list of legacy breaches in which old credential datasets re-emerged online, increasing the risk of account takeover and password reuse abuse for affected users.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
The data stolen in the QIP breach did not become broadly public immediately after the intrusion. By September 2016, reporting indicated the old breach data had surfaced publicly.
In mid-2011, the Russian instant messaging service QIP experienced a data breach. The incident exposed more than 26 million user accounts, with reports citing over 33 million compromised accounts including email addresses and passwords.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.