Hackers reportedly gained access to payment accounts used by two Russian fundraising projects supporting Ukrainians and political prisoners, exposing donor email addresses and limited payment card information. The unknown threat actor targeted Davayte, which raises money for civilians in Ukraine affected by Russia’s invasion, and You Are Not Alone, a project supporting Russian political prisoners and their families. Both initiatives disclosed the incidents Tuesday, saying the attacks occurred in mid-August and involved the same entry point: an integration between payment processor Stripe and WooCommerce, an open-source e-commerce plugin for WordPress, that the projects had used to conduct online auctions. The attackers obtained email addresses belonging to some donors and, in certain cases, the last four digits of their payment cards and information about the banks that issued them, according to statements from the projects. Full card numbers, cardholders’ names and details about individual donations were not exposed, they said. Stripe blocked the unauthorized access before the attackers could download the entire database of donor email addresses, the projects said, adding that Stripe had found no evidence of fraudulent transactions involving their accounts. Davayte has since disabled third-party integrations, rotated its access keys and notified the relevant European data protection authority. It remains unclear who was behind the attacks. “We are investigating this breach and cannot yet say whether it was carried out by ordinary cybercriminals or Russian security services,” You Are Not Alone said. Davayte was launched in February 2024 by several independent Russian media organizations, including Meduza and TV Rain, to provide humanitarian assistance to civilians affected by Russia’s war in Ukraine. The project says it raised more than $437,000 in 2024. You Are Not Alone has been organized by independent Russian media and opposition groups since 2023. Donations are used to provide prisoners with food and medicine, fund their prison accounts, cover legal and everyday expenses, help relatives travel for visits and assist some prisoners after their release. The campaign said it raised around $1.4 million during its first three years and has provided assistance to roughly 800 political prisoners and their relatives. Russian authorities have labeled the organizations behind both initiatives as “undesirable,” putting people in Russia who support them at risk of prosecution. Under Russian law, donating to or raising money for an “undesirable” organization can carry a prison sentence of up to five years, making information that could identify donors particularly sensitive. The incidents come amid reports that hackers have been targeting Stripe merchants more broadly, although there is no confirmed connection between those attacks and the breaches disclosed this week. Earlier in August, a hacker using the alias “Satanic” posted an archive on a cybercrime forum that allegedly contained data from 669 Stripe merchants and more than 1,000 access keys associated with their accounts. It is unclear whether Stripe itself was breached in that incident. According to independent Russian outlet The Bell, records in the leaked archive end on June 1, meaning the data stolen from Davayte and You Are Not Alone in August could not have been part of that dataset. The outlet reported that Davayte had asked Stripe for information that could help establish whether other customers of the service had encountered similar activity. Stripe did not respond to a request for comment. Following the breach, You Are Not Alone advised people who live in or travel to Russia, as well as those required to report foreign bank transactions to Russian tax authorities, not to donate using foreign-issued cards. The organization has never accepted payments from Russian-issued cards. Davayte has similarly urged donors to exercise caution if they plan to travel to Russia.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.