Press play to start listening
More than 600 million user records appeared in 164 database leak listings tracked by Russian cybersecurity firm F6 during 2025 and the first half of 2026. Of these, 91 databases were published openly on underground forums and Telegram channels, while 73 were offered for sale.
F6 said it analyzes threat data concerning Russia and Belarus separately, and neither country appears in the data-leak chapter’s CIS breakdown. Its regional totals should therefore not be treated as a complete global comparison. The company shared the findings with Hackread.com.
F6 said threat actors usually provided no technical details explaining how they obtained the databases. Additionally, because the findings are largely based on underground advertisements and publications, individual breach claims may not have been independently confirmed by the affected organizations.
Regions With the Most Exposed Records
Among the regional totals presented, the Commonwealth of Independent States (CIS) had more than 257 million exposed records, despite accounting for just 4% of the leaks. Tajikistan had roughly 217 million of those records following a September 2025 leak. Kazakhstan had 25 million, and Uzbekistan had 15 million.
Latin America (LATAM) had the largest share of tracked leaks at 33%. The region also had more than 210 million exposed records. Argentina was responsible for roughly 120 million of them, followed by Mexico with 38 million.
In the Middle East and Africa (MEA), 29% of the tracked leaks involved more than 136 million exposed records. Egypt had 54 million, followed by Saudi Arabia with 27 million, the UAE with 25 million, and Qatar with 22 million.
APAC accounted for 8% of the tracked leaks and more than 83 million exposed records. Malaysia had roughly 35 million, India 34 million, and China 9 million.
Government and AI Data Among Major Targets
Government-sector databases accounted for just 23% of the tracked leak listings, but their records represented 56% of all exposed data in F6’s dataset. Retail followed with 20%, while real estate, education and finance accounted for 7%, 6% and 5%, respectively.
F6 also documented claimed data breaches affecting companies in the AI industry during 2025 and the first half of 2026. Its researchers identified leaks involving an AI cloud platform, an AI marketing company, an AI video analytics firm and several AI workflow services. The exposed information reportedly included source code, user records and complete AI conversation logs.
One claimed leak involving an AI workflow platform included data associated with more than 500,000 users and two million interaction logs, including hashed passwords and complete AI conversation histories, according to an underground forum post documented by F6.
F6 said threat actors sometimes publish databases openly to build their reputations on underground forums. Those selling data generally provide samples and contact details to negotiate with prospective buyers.
The report also examined changes in ransomware operations. F6 identified 54 new ransomware groups during 2025 and another 12 during the first half of 2026. It recorded more than 9,300 ransomware incidents across the reporting period.
F6 attributed more than 1,000 attacks to Qilin in 2025 and nearly 500 during the first half of 2026. The company said ransomware operators were placing less emphasis on payments for decrypting files and applying more pressure through stolen-data publication and reputational damage.
F6 predicts that competition among Qilin, DragonForce and LockBit 5.0 will intensify as the groups seek to consolidate their affiliate networks and attract members with better terms and greater automation.
Lada Kryukova, Head of the Underground Research Unit at F6, said the amount of data circulating online can be much larger than the number of breaches that originally produced it.
“Our research shows that the volume of records in circulation can far exceed the number of breaches that produced them,” Kryukova said. “Large compilations, repeated publications, and high-volume leaks amplify the impact of a single intrusion long after the original incident.”

