A major Keenetic router data leak could put a million households at risk

Data leak
(Image credit: Shutterstock)

  • Keenetic suffered a data leak in 2023, but the hacker said the data was destroyed and not shared
  • However Cybernews researchers recently received a sample database
  • Almost a million Russian households are at risk, experts say

Information on Keenetic router users, originally stolen in March 2023 and thought to have been deleted back then, has surfaced online, potentially putting a million households at significant risk.

In a security notification published on the company’s website, Keenetic said an independent IT researcher reached out in mid-March 2023 to warn about unauthorized access to the Keenetic Mobile App database.

“After verifying the nature and credibility of the risk, we immediately resolved the issue on the afternoon of March 15th 2023,” the company said. Keenetic was then told that the data hadn’t been shared with anybody, and was subsequently destroyed. However, it now seems that wasn’t really the case, since security researchers from Cybernews were recently shown samples via an anonymous tip.

Monitor your credit score with TransUnion starting at $29.95/month

Monitor your credit score with TransUnion starting at $29.95/month

TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You'll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnion’s advanced risk assessment tools.

Preferred partner (What does this mean?)

Names, emails, and plaintext passwords

Cybernews says the number of exposed records include more than a million emails, names, locales, Keycloak identity management system and Network Order IDs, and Telegram Code IDs.

Furthermore, there were 929,501 leaked records containing WiFi SSIDs and passwords in plain text, device models, serial numbers, interfaces, MAC addresses, domain names for external access, encryption keys, and much more.

Then, there were 558,371 device configuration records such as user access details, vulnerable MD-5 hashed passwords, assigned IP addresses, and expanded router settings.

Finally, comprehensive service logs containing over 53,869,785 records were also leaked, including hostnames, MAC addresses, IPs, access details, and even “owner_is_pirate” flags.

Most of the exposed users seem to be Russian-speaking (943,927), with 39,472 victims being English users, and 48,384 Turkish-language users.

After learning about the leak, Keenetic advised users who registered before March 16, 2023, to change their device user account passwords, WiFi passwords, and VPN-client passwords/pre-shared keys for PPTP/L2TP, L2TP/IPSec, IPSec Site-to-Site, SSTP.

Via Cybernews

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
No broadband network
Massive online data breach sees 2.7 billion records leaked - here's what we know
Suitcase next to a bed in a hotel
Millions of hotel users see personal info checked out in huge data leak
Data leak
Details of over 15,000 FortiGate devices leaked online, so be on your guard
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
Security padlock and circuit board to protect data
A major US TV broadcaster leaked over a million sensitive files online
Representational image of data security
Travel data of almost 500,000 users exposed in Daytrip leak
Latest in Security
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Latest in News
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS
Marvel Rivals
Marvel Rivals will get two new hero skins for Moon Knight and Black Panther this week meaning I'll now need to farm even more Units