Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 04, 2026 · 6 min read

Hackers Leaked Donors to Russian Political Prisoners

No card numbers, no names, no amounts. Just email addresses, taken through a payment plugin the charities did not write, in a country where giving the money was the crime.

A breach notice saying only email addresses were taken is normally the boring kind. Two Russian fundraising projects sent one on Tuesday, 1 September 2026, and theirs is not. Davayte funds humanitarian aid for civilians in Ukraine. You Are Not Alone pays for food, medicine and lawyers for Russian political prisoners. Both lost their donor lists, and in Russia a donor list is a target list.

Key Takeaways

  • Davayte and You Are Not Alone disclosed their breaches on 1 September 2026, three weeks after the intrusion.
  • OVD-Info dates the compromise to 11 August 2026 and traces both incidents to one door: the Stripe and WooCommerce integration behind their charity auctions.
  • Attackers took donor email addresses and sometimes the last four card digits and issuing bank; full card numbers, names and donation details were not affected.
  • Article 284.1 of the Russian Criminal Code punishes financing an undesirable organisation with up to five years, and donations to Ukrainian causes have produced treason sentences of 12 and 21 years.
  • You Are Not Alone cannot yet say whether criminals or Russian security services were responsible.

What Was Taken?

Email addresses, and for some donors the last four digits of a card plus the issuing bank. That is the whole inventory.

Full card numbers stayed out of reach, as did cardholder names and the amount and timing of donations. The Record reported that Stripe cut off the unauthorised access before the full database could be pulled. No fraudulent transaction has been confirmed since, and DataBreaches.net carried the story the next day.

Read that inventory as a fraud analyst and it is worthless: four digits and a bank name buy nothing. Read it as an investigator in Moscow and the email column is the only one that matters. Davayte raised more than $437,000 in 2024, You Are Not Alone around $1.4 million in three years, and the list of people behind those payments is what leaked.

Why an Email Address Is the Dangerous Part Here

Because in Russia the donation itself is the offence, so an address that ties a person to the donation is evidence rather than contact data.

The organisations behind both fundraisers are designated undesirable. Under Article 284.1 of the Criminal Code, the European Union Agency for Asylum records up to four years for taking part in such an organisation's activities and up to five for financing them, across 269 designated entities as of October 2025. Article 275.1 adds three to eight years for confidential cooperation with a foreign organisation.

Treason sits above both. Ksenia Karelina was jailed for 12 years over roughly $51 sent to a pro Ukraine charity; physicist Artyom Khoroshilov received 21 years after transfers to two Ukrainian funds. Those cases involved money reaching groups that supply the Ukrainian military, a different category from humanitarian aid. The precedent stands anyway: $51 cost somebody a decade.

OVD-Info's own lawyer drew the line carefully: the people at risk are donors inside Russia or those who travel there, and an address alone proves neither who owns it nor that a donation happened. What the lawyer would not rule out is interpretation.

The address is what closes that gap. It is not one fact but a join key: search it and it links this list to a social profile, a marketplace account and every other breach it sits in. That is the mechanic the EFF describes in its doxxing guidance, where the email address is the pivot point. Ordinarily the chain ends in spam. Here it ends at a door.

A laptop open on a kitchen table showing a blurred online payment form, a plain bank card lying beside it, lit by cold morning light from a window

How Did the Attackers Get In?

Not through the charities. Both intrusions came through the integration between Stripe and WooCommerce, the plugin the projects used to run auctions on their WordPress sites.

Neither project has published a root cause, and nobody should invent one. A compromised API key, a stale plugin version and a hijacked WordPress admin account produce the same symptom; OVD-Info describes the outcome simply as compromised Stripe accounts. The shape is documented even where the cause is not. The money layer failed, identically, at two organisations sharing nothing but a technology stack.

WooCommerce is the default way a small organisation takes money on WordPress. A four person NGO running an auction has the threat model of a bank and the budget of a book club. It inherits whatever posture its payment stack has, and usually learns what that was afterwards.

This is the second Stripe adjacent exposure in a fortnight, after a vendor mishandling left 1,033 live Stripe merchant API keys in an open store in late August. The processor was fine both times; the customer records walked out through somebody's integration.

Who Is Behind It?

Nobody knows. You Are Not Alone told The Record it was still investigating and could not say whether ordinary criminals or Russian security services were responsible.

Both readings hold. Payment adjacent databases are stolen constantly for resale, and neither victim was a prestige target. Against that, the pairing is hard to ignore: two politically inconvenient fundraisers, one method, one window in August.

For anyone on the list the distinction matters less than it sounds, because a stolen database is a product and products get sold to whoever pays.

What Should Exposed Donors Do?

Assume the link between address and donation is permanent, because a list cannot be unpublished. Both projects warned donors to expect spam and phishing.

  • Treat any message referencing the fundraiser as hostile. This list is a phishing script that writes itself: the sender knows your cause, your bank and your last four digits.
  • Do not click links in mail about the breach. Go to the project's site directly. Breach notices are the most impersonated message there is.
  • Move future giving to a separate address that is not the one on your bank, employer or social accounts.
  • Harden the exposed account now. A hardware key or passkey defeats the credential phishing that follows a list like this; app codes and SMS do not. On a Google account, Advanced Protection is built for this profile.
  • Audit what else that address is tied to. Every account and forum post it surfaces is another route from a bare address to a named person.

Before You Give to Any High Risk Cause

The lesson travels. Anyone giving to a cause their government dislikes, or one a future government might, is handing an identifier to a small organisation running commodity plugins.

  • Donate from an address that is not your identity address. Aliases break the join between the donation and the rest of your life; our comparison of Brave email aliases and Hide My Email covers where each leaks.
  • Check what the platform stores. A page that never touches your card still writes a receipt row with your address into a database the charity administers.
  • Pick a mailbox that fits the risk. Several private email providers we compared make throwaway addresses cheap enough to use one per cause. Anonymous giving removes the row entirely.

What to Watch Next

Whether anything gets built on the list. If donors inside Russia start reporting summons or home visits, this stops being a breach and becomes a case file, and OVD-Info is the place that will count them. The second order effect needs no case file. Exposing donors is not about prosecuting them all, it is about making the next person hesitate over the donate button.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.