VYPR
breachPublished Sep 2, 2026· 1 source

Hackers Breach Russian Fundraisers for Ukrainians and Political Prisoners, Exposing Donor Data

Two Russian fundraising projects supporting Ukrainians and political prisoners have suffered data breaches, exposing donor email addresses and partial payment card details due to a compromise of their payment processing integration.

Hackers have successfully breached the payment accounts of two Russian fundraising initiatives, "Davayte" and "You Are Not Alone," which support Ukrainians and Russian political prisoners, respectively. The attackers gained access to donor email addresses and, in some instances, the last four digits of payment cards and issuing bank information. Both organizations disclosed the incidents, which occurred in mid-August, stating that the breach originated from an integration between the payment processor Stripe and WooCommerce, an e-commerce plugin for WordPress.

The compromised integration served as the entry point for the attackers. While full payment card numbers and donor names were not exposed, the exposure of email addresses and partial payment details poses a significant risk, particularly given the sensitive nature of the causes supported. Stripe was able to block further unauthorized access before the attackers could exfiltrate the entire donor database, and the payment processor reported no evidence of fraudulent transactions stemming from the incident.

In response, "Davayte" has disabled third-party integrations, rotated access keys, and notified the relevant European data protection authority. The exact identity of the attackers remains unknown, with "You Are Not Alone" suggesting the possibility of involvement by ordinary cybercriminals or Russian security services. The organizations behind these initiatives are designated as "undesirable" by Russian authorities, meaning individuals supporting them in Russia face potential prosecution, making donor identification particularly dangerous.

"Davayte," launched in February 2024 by independent Russian media outlets like Meduza and TV Rain, has raised over $437,000 in 2024 to provide humanitarian aid to civilians impacted by the war in Ukraine. "You Are Not Alone," operating since 2023, has raised approximately $1.4 million to support Russian political prisoners and their families with essential needs, legal assistance, and post-release aid.

The incidents occur amidst broader reports of hackers targeting Stripe merchants. Earlier in August, a hacker known as "Satanic" claimed to have posted data from hundreds of Stripe merchants and associated access keys on a cybercrime forum. However, records from that alleged leak end in June, suggesting the data stolen from "Davayte" and "You Are Not Alone" in August was not part of that specific dataset.

"You Are Not Alone" has advised individuals traveling to or residing in Russia, or those required to report foreign transactions, to avoid donating with foreign-issued cards. The organization has historically not accepted payments from Russian-issued cards. "Davayte" has issued similar cautionary advice for donors planning to travel to Russia.

The breach underscores the persistent risks faced by individuals and organizations engaged in humanitarian and political support, especially in environments with heightened state surveillance and censorship. The reliance on third-party integrations, while convenient, presents a critical attack vector that threat actors can exploit to gain access to sensitive user data.

This incident highlights the complex interplay between cybersecurity, political activism, and international conflict, where even seemingly minor technical vulnerabilities can have significant repercussions for individuals supporting sensitive causes.

Synthesized by Vypr AI