Hackers expose donor data from Russian fundraisers for Ukrainians, political prisoners
Hackers exposed donor data from two Russian fundraising projects – Davayte and You Are Not Alone – supporting Ukrainians and Russian political prisoners. The breaches stemmed from a vulnerability in a Stripe and WooCommerce integration. While full card numbers weren't exposed, donor email addresses and partial payment card information were compromised, raising concerns due to Russian laws regarding donations to ‘undesirable’ organizations. The incidents highlight a broader trend of targeting Stripe merchants and underscore the risks faced by those supporting Russian opposition.
Hackers have exposed donor data from two Russian fundraising projects, Davayte and You Are Not Alone, which were supporting Ukrainians and Russian political prisoners. The attacks occurred in mid-August and exploited a vulnerability in a Stripe and WooCommerce integration that both organizations had utilized to conduct online auctions. As a result, donor email addresses were compromised, and in some cases, the last four digits of their payment cards and information about the banks that issued them were exposed. Full card numbers, cardholders’ names, and details about individual donations were not exposed.
Davayte, launched in February 2024 by several independent Russian media organizations, including Meduza and TV Rain, raised over $437,000 in 2024. You Are Not Alone has been organized by independent Russian media and opposition groups since 2023, providing assistance to approximately 800 political prisoners and their families, raising around $1.4 million in its first three years. Russian authorities have labeled the organizations behind both initiatives as ‘undesirable,’ carrying a potential prison sentence of up to five years for those who donate to them.
Following the breach, You Are Not Alone advised individuals residing in or traveling to Russia, as well as those required to report foreign bank transactions to Russian tax authorities, not to donate using foreign-issued cards. Davayte similarly urged donors to exercise caution if they plan to travel to Russia. The incidents come amid reports of broader targeting of Stripe merchants, though it’s unclear if the data exposed this week originated from the earlier August breach containing data from 669 Stripe merchants and over 1,000 access keys.
Stripe blocked unauthorized access before the attackers could download the entire database of donor email addresses, and the projects are investigating to determine if other customers of the service experienced similar activity. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine, specializing in cybersecurity in Eastern Europe and the cyberwar between Ukraine and Russia.
