Search TorWire

Find cybersecurity guides and research articles

Home > News > Deep Web > Threat Actor Reposts Alleged Ukraine’s Diia Database with 2.56 Million Records on Dark Web

Threat Actor Reposts Alleged Ukraine’s Diia Database with 2.56 Million Records on Dark Web

By: Morgan Cipher Senior Privacy Journalist

Last updated: July 15, 2026

Human Written
Threat Actor Reposts Alleged Ukraine’s Diia Database with 2.56 Million Records on Dark Web
  • A threat actor is advertising the re-release of a database allegedly linked to the Diia digital government platform.

  • The seller claims the dataset contains 2.56 million records of user information from an older leak that occurred three years ago.

  • Security analysts state that the post is a recycled database rather than evidence of a new system breach.

Cyber security data surfaced once again as an online threat actor advertised a massive file collection on an underground digital market. The merchant claims the package contains extensive personal records directly linked to a major national administration service. The seller targets the prominent state-run portal that millions of European citizens use daily to access their official identity papers.

However, independent network researchers quickly realized that the criminal group is merely trying to resell a classic, older data collection. They warn that the public should not view this recycling of outdated lists as a fresh breach of current state systems.

Furthermore, local technology security leaders are closely inspecting their virtual defensive walls to confirm that their current systems remain totally uncompromised. The incident highlights how digital thieves often package ancient leaks to create the false illusion of a successful new network robbery.

The Hidden Details of the Exposed Database

The dubious publication on the internet concentrates on one important resource, which is known as the Diia digital government network. The government of Ukraine established this mobile project in the past so that its citizens could upload their driver’s licenses and official IDs onto smartphones. Since the service is extremely efficient, it stores important documents of a huge number of local people.   

However, the seller from the dark web claims that he has acquired the full copy of this government database. The seller mentions that the database includes approximately 2.56 million entries.

In addition, the malicious actor disclosed the precise size of the digital files as evidence of its success. The compressed package has a total of 137 megabytes – but it stretches up to 645 megabytes in size once unpacked on a computer.

Also, the hacker provided samples of files from the leak to attract potential customers on the dark web forum. However, the seller readily states that the files were obtained from an older security incident that took place in 2023. Safety experts view this advertisement as a simple attempt to squeeze fresh money out of historical data. 

How Underground Sellers Package Historical Leaks to Deceive the Tech Community

Security researchers state that the underground trading market currently contains several recycled informational files. Quite often, opportunistic digital thieves take old databases, mix them with public registration files, and label them as new hacks. These sellers create artificial panic to make quick cash from less-informed criminal buyers.

The pattern extends to gaming platforms, and a threat actor has claimed a GrabCraft Minecraft database breach without providing any evidence.

According to the Ministry of Digital Transformation of Ukraine, the creator of the state platform, there is no central record of citizens available in the software system. The application functions as a tool that connects users to the necessary information from highly protected existing state registers. Consequently, there is no massive central treasure chest of documents for a single hacker to steal during a typical database raid.

Nevertheless, the exposure of even outdated phone numbers and names can still assist scammers in crafting trick messages. Devious groups combine these old details with public social media accounts to build highly convincing profiles of their targets.

Thus, the constant re-sharing of old files keeps the threat of personal identity theft alive for years. Moreover, regular people often use the same passwords for multiple websites, which makes these old leaks highly dangerous if those codes remain unchanged.

Shifting Everyday Habits to Neutralize Constant Database Reselling Exploits

Everyday web users can completely disarm these underground data sellers by modifying a few basic online behaviors. For example, people frequently use the exact same password for their social profiles and bank accounts. Consequently, a data leak from years ago suddenly gives thieves the keys to every active account. Instead, individuals should instantly assign unique password strings to each separate application. 

In addition, having a second verification layer on your mobile device prevents hackers from entering, even with your valid password credentials. The extra step protects you against unauthorized access by requiring a quick code before entry. Thus, simple adjustments to your device setup build a solid shield against persistent dark web merchants.

Software creators must build stronger digital locks to keep backend file cabinets safe from public eyes. With some security rules, programmers can write clean code that naturally keeps sensitive user information private. Also, average users need to treat every unsolicited text message with extreme suspicion. 

Criminals frequently send fake parcel tracking alerts to trick people into downloading harmful phone applications. Therefore, deleting these strange incoming links before opening them remains a highly effective way to protect your money. With a sharp eye on your accounts, you can easily stay one step ahead of digital outlaws.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.