Site iconSite icon ForkLog

Navalny team names former staffer who leaked supporters’ database

Navalny team names former staffer who leaked supporters' database

The leak of users’ email addresses registered on Free.navalny.com was organised by former Alexei Navalny team staffer Fedor Gorozhanko, who was responsible for mailings. This was reported by the opposition’s associates.

The data was not stolen from the site itself but from the Mailgun mailing service.

According to [simple_tooltip content=’This organization is listed in the Russian registry of “foreign agents”. We indicate this as required by the authorities of the Russian Federation.’]Anti-Corruption Foundation (FBK)[/simple_tooltip], Gorozhanko gained access to the FBK account via a special API key that provides access without login and password. He was identified by IP address — the same one used to access FBK’s corporate email.

Investigation authors suggested the former employee acted in exchange for a cash reward. After the breach, he deposited more than 1.2 million rubles into a bank account. Moreover, in March 2021 Gorozhanko could not pay off a debt to collectors totaling 96,000 rubles.

Data: navalny.com.
Data: navalny.com.

According to Current Time, the presidential administration was the client behind the hack.

Fedor Gorozhanko himself denies involvement in the breach of the mail server.

“Well, of course, it wasn’t me,” he said in a comment to Open Media.

Update:

In a conversation with the Telegram channel Baza Gorozhanko said that he worked at FBK from 2015 and left in 2019 due to disagreements with the team. He claims that upon leaving he handed all accesses to other employees, and the account with his data was removed in the summer of 2019.

“After leaving, I joined a normal firm with a Moscow salary — hence the deposits to my card. I did not take any microloans. Even while employed, a loan was taken out in my name by third parties. I am suing over this,” he said.

In April, users registered on the ‘Free Navalny’ site began receiving emails containing their addresses. In three days, the Navalny team identified the former employee as responsible but did not name him or his position.

Subscribe to ForkLog news on Telegram: ForkLog Feed — the full feed of news, ForkLog — the most important news, infographics and opinions.

Exit mobile version