Hackers Compromise Russian Fundraising Projects Supporting Ukraine and Political Prisoners, Exposing Donor Data
Two Russian fundraising initiatives, **Davayte** and **You Are Not Alone**, have reported data breaches impacting donor information. The attacks, which occurred in mid-August, exploited a vulnerability in the **Stripe** and **WooCommerce** integration, exposing email addresses and partial payment card details of individuals supporting Ukrainian civilians and Russian political prisoners.
Hackers have reportedly gained access to payment accounts used by two Russian fundraising projects, exposing sensitive donor information. The targeted initiatives, **Davayte** and **You Are Not Alone**, provide crucial support to Ukrainians affected by the ongoing conflict and Russian political prisoners, respectively.
### Breach Details Emerge
Both projects disclosed the incidents on Tuesday, confirming that the attacks took place in mid-August. The threat actors exploited a shared vulnerability: an integration between the payment processor **Stripe** and **WooCommerce**, an open-source e-commerce plugin for **WordPress**, which the organizations utilized for online auctions.
### Data Compromised and Secured
The attackers successfully obtained email addresses of some donors. In certain instances, they also accessed the last four digits of payment cards and information regarding the issuing banks. Crucially, full card numbers, cardholdersβ names, and details of individual donations were not exposed.
**Stripe** acted swiftly, blocking unauthorized access before the attackers could download the complete database of donor email addresses. The payment processor also found no evidence of fraudulent transactions related to these accounts.
### Post-Breach Actions and Ongoing Investigation
**Davayte** has since disabled all third-party integrations, rotated its access keys, and notified the relevant European data protection authority. The identity of the perpetrators remains unknown, with **You Are Not Alone** stating, "We are investigating this breach and cannot yet say whether it was carried out by ordinary cybercriminals or Russian security services."
### The High Stakes for Donors
**Davayte**, launched in February 2024 by independent Russian media organizations like **Meduza** and **TV Rain**, has raised over $437,000 for humanitarian aid in Ukraine. **You Are Not Alone**, organized by independent Russian media and opposition groups since 2023, has raised approximately $1.4 million to support political prisoners and their families.
The sensitivity of the exposed data is particularly high due to the political climate. Russian authorities have labeled organizations behind both initiatives as βundesirable,β making individuals in Russia who support them vulnerable to prosecution, with potential prison sentences of up to five years for donating or fundraising for such entities.
### Broader Context of Stripe Merchant Attacks
These incidents occur amidst broader reports of hackers targeting **Stripe** merchants. Earlier in August, a hacker using the alias βSatanicβ released an archive on a cybercrime forum, allegedly containing data from 669 **Stripe** merchants and over 1,000 associated access keys. However, independent Russian outlet **The Bell** reported that the data stolen from **Davayte** and **You Are Not Alone** in August could not have been part of that earlier dataset, as records in the leaked archive ended on June 1. **Stripe** has not yet commented on these broader reports.
### Donor Guidance
Following the breach, **You Are Not Alone** has advised individuals residing in or traveling to Russia, as well as those required to report foreign bank transactions to Russian tax authorities, against donating with foreign-issued cards. **Davayte** has issued similar warnings to donors planning travel to Russia. Neither organization accepts payments from Russian-issued cards.