Russian e-commerce giant Elevel exposed buyers’ delivery addresses


Founded in 1991, Elevel (previously Eleko) positions itself as the leading Russian electrical engineering company that runs both an e-commerce business and wholesale stores.

On January 24, the Cybernews research team discovered an open dataset with 1.1TB of data and attributed it to e.way – an Elevel-owned online shop with 25,000 monthly visitors.

The dataset with seven million data entries leaked two years’ worth of sensitive data, including names, surnames, phone numbers, email addresses, and delivery addresses of customers.

“If left exposed, threat actors could download and clone the cluster’s data and use it for nefarious purposes, including phishing attacks, as they possess sufficient PII and to make their scam seem legitimate,” Cybernews researchers said.

Moreover, it contained login data and passwords in URL encoding, which is considered a relatively weak protection mechanism since it can be decoded easily.

“As a number of usernames and passwords are exposed, it could enable threat actors with valid credentials to gain further sensitive data and to impersonate users to make fraudulent purchases,” Cybernews researchers noted.

The dataset is now closed. Cybernews is still waiting to receive the company’s official response.

For more information go to:

Chris Price
For latest tech stories go to