Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Panda Security reported in its Q3 2016 report that data belonging to 33 million QIP.ru users was stolen. That figure is not reconciled with today’s breach catalogs: Have I Been Pwned lists 26.2 million QIP accounts, while Mozilla Monitor dates its QIP breach record to June 1, 2011. The available sources do not establish whether those figures describe the same incident or datasets.
What is known about the QIP breach?
QIP is the service named in several breach listings and reports. Mozilla Monitor records a QIP breach dated June 1, 2011, and says the record was added to its database on January 8, 2017. Its listing identifies passwords, email addresses, usernames, and website activity as compromised data. Mozilla Monitor’s QIP breach page
Have I Been Pwned’s current breach catalog lists QIP at 26.2 million accounts. That is the catalog’s current count; it does not establish that Panda Security’s 33 million figure is incorrect or that both sources refer to an identical dataset. Have I Been Pwned’s breach catalog
Why do sources report 26.2 million and 33 million?
| Source | Figure or date | What it establishes |
|---|---|---|
| Mozilla Monitor | June 1, 2011; record added January 8, 2017 | Dates its QIP breach listing and names the exposed data fields. Source |
| Have I Been Pwned | 26.2 million accounts | Current count in its QIP breach catalog listing. Source |
| Panda Security / PandaLabs | 33 million users | Its Q3 2016 report states that data belonging to 33 million QIP.ru users was stolen. The surfaced report text does not establish that this was the same event as the 2011 listing. Source |
| GalaxyWarden | 26.2 million | Secondary summary of the 2011 incident and exposed-field list; this is corroborating reporting, not an original incident notice. Source |
No located QIP or regulator notice reconciles the count, date, or overlap between the datasets. It is therefore more accurate to describe 33 million as Panda Security’s reported figure and 26.2 million as Have I Been Pwned’s current catalog count, rather than treating either number as a confirmed count for a single, settled incident record.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
What information was exposed?
Mozilla Monitor’s listing names passwords, email addresses, usernames, and website activity. GalaxyWarden’s secondary summary also lists these fields for the 2011 incident. The sources do not establish whether every account in the separate 33 million figure had exactly these same data fields exposed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should you do if you used a QIP password?
- Change it anywhere it is still in use. If you reused the QIP password on another account, replace it on each of those services.
- Make every replacement unique. Mozilla Monitor advises changing an exposed password and not reusing it. A password exposed in an old breach should not remain the key to another account. Mozilla Monitor’s guidance
- Check whether your email address appears in a breach notification service. Such a check can help identify listed exposures, but it cannot prove that an account was unaffected when no match appears.
The cited sources do not identify a currently operating QIP response channel, so do not assume the historical service can reset an account or remediate the exposure.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

