Skip to main content
LiMP VPN
All news

88M Russian Medical Records Leaked in July 2026

88M Russian Medical Records Leaked in July 2026

In short: On 5 August 2026 analysts at Perspective Monitoring (part of the InfoTeKS group) reported that in July more than 100 million personal records of Russians were published in open access, and 88.37 million of them — the overwhelming majority — came from the medical sector. Health data is the most sensitive category there is, its protection remains weak, and once a database is on the dark web it cannot be recalled. You cannot patch a leak that already happened, but you can limit how much attackers learn about you next.

What happened

According to Perspective Monitoring, July saw 17 separate leak incidents. Two of them involved medical data, including one that hit a "large medical information system," and together they accounted for 88.37 million records. The exposed data included personal details, contact information and user accounts. The stolen databases were spread through specialised messenger channels and dark-web marketplaces — the same distribution route we keep documenting in our security breakdowns.

The scale is what makes July stand out. For comparison, the analysts note that June produced about 1.7 million leaked medical records, and March through May combined produced roughly 2.2 million. July's 88 million is an order-of-magnitude jump, not a gradual drift.

How the numbers break down

Medicine dominated, but it was not the only sector hit. Perspective Monitoring's July breakdown looked like this:

  • Medical — 88.37 million records, the bulk of the month's total.
  • Commercial sector — 11.12 million records.
  • Online platforms — 8.45 million records.
  • Government sector — 8.36 million records.
  • Online stores — 2.1 million records.

Nikolay Galkin, who heads cyber-threat research at the company, points out that medical data has now been leaking for four months in a row, and that attackers are deliberately going after the most confidential information precisely because its protection is so weak.

Why medical leaks are especially dangerous

A leaked password can be changed; a diagnosis, a treatment history or a policy number cannot. Medical records tie your name and contacts to intimate facts about you, and that combination is gold for social engineering. Scammers use it to build convincing pretexts — a call "from your clinic" that quotes a real appointment, a phishing message about test results, a fake insurance refund. Because the details are accurate, the usual advice "just recognise the fraud" stops working. This is the same mechanism behind the broader wave of data-driven scams we cover across the privacy tools section.

What it means for you

If your data was in one of these databases, you will most likely never be told. There is no reliable way to "delete" a record that is already circulating. The realistic goal is damage control: assume that your name, phone number and some medical context may be in the hands of scammers, and treat any unexpected call or message that references your health with suspicion — especially if it pushes you to confirm codes, pay something or follow a link.

How to protect yourself

A few habits meaningfully reduce your exposure:

  • Distrust "accurate" cold contact. A caller knowing your clinic or diagnosis proves a leak, not legitimacy. Hang up and call the organisation back on its official number.
  • Turn on two-factor authentication on your government-services and medical-portal accounts, so a leaked login alone is not enough to get in.
  • Give clinics and apps the minimum. Every extra field you hand over is one more thing that can leak later.
  • Protect the network layer. A no-logs LiMP VPN app does not stop a hospital's database from being breached — that is out of your hands — but it encrypts your own traffic on public and untrusted Wi-Fi so an intermediary cannot harvest what you send, and because of the no-logs policy the service itself keeps no record of your activity.

Keep the layers separate: organisations are responsible for guarding the databases they hold, while a VPN and good hygiene reduce how much you personally expose. For more on that mindset, see our plans and the wider LiMP VPN blog.

Sources

88M Russian Medical Records Leaked in July 2026 | LiMP VPN