Unknown attackers accessed payment accounts used by the Russian fundraising initiatives Davayte and You Are Not Alone through a shared Stripe-to-WooCommerce integration used for online auctions. The mid-August intrusions exposed some donor email addresses and, for certain donors, payment-card last four digits and issuing-bank information; organizers said full card numbers, cardholder names, donation details, and evidence of fraudulent transactions were not identified.
Davayte supports Ukrainian civilians affected by Russia’s invasion, while You Are Not Alone aids Russian political prisoners and their families. Stripe reportedly stopped the unauthorized access before complete donor-email databases could be downloaded, but the exposed identities create heightened danger because Russian authorities designate the organizations behind the projects as “undesirable,” potentially putting donors at risk of prosecution. The activity remains unattributed, although You Are Not Alone said involvement by Russian security services cannot be excluded.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Unknown attackers accessed payment accounts used by Davayte and You Are Not Alone through their Stripe-WooCommerce integrations, which had been used for online auctions. The attackers obtained some donor email addresses and, in some cases, card last four digits and issuing-bank information.
A threat actor using the alias Satanic posted an alleged archive containing data from 669 Stripe merchants and more than 1,000 access keys on a cybercrime forum. No confirmed connection was established between this archive and the fundraising-project breaches.
Independent Russian media organizations, including Meduza and TV Rain, launched Davayte to raise funds for Ukrainian civilians affected by Russia's invasion.
Independent Russian media and opposition groups began organizing the You Are Not Alone initiative to support Russian political prisoners and their families.
Davayte and You Are Not Alone disclosed the incidents; Stripe reportedly blocked access before complete donor-email databases were downloaded and found no evidence of fraudulent transactions. Davayte disabled third-party integrations, rotated access keys, and notified a European data-protection authority, while You Are Not Alone investigated possible attribution and issued donor-travel and payment-safety advice.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.