logo

Hacker Claims Full Breach of Russia’s Max Messenger, Threatens Public Leak

ID: 85089ac1-5a16-5980-8b47-de22497df0d8

STIX ID: report--85089ac1-5a16-5980-8b47-de22497df0d8

Feed Name: HackRead

Threat Score
72/100

Date Published: 2026-01-14

Date Updated: 2026-04-22

Author: Waqas

...
...

Alleged major breach of Max Messenger: an actor calling themselves CamelliaBtw claims they exfiltrated the full production environment (~142 GB) — including ~15.4M user records, active auth tokens (bypassing 2FA), bcrypt passwords, communication metadata, unencrypted media, SSH keys, S3 configs, and backend source code — via a claimed RCE in the media processing engine and is threatening to publish data unless paid within 24 hours; Max has not confirmed the incident and no sample data has been independently verified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.