Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Panda Security reported in its Q3 2016 report that data belonging to 33 million QIP.ru users was stolen. That figure is not reconciled with today’s breach catalogs: Have I Been Pwned lists 26.2 million QIP accounts, while Mozilla Monitor dates its QIP breach record to June 1, 2011. The available sources do not establish whether those figures describe the same incident or datasets.

What is known about the QIP breach?

QIP is the service named in several breach listings and reports. Mozilla Monitor records a QIP breach dated June 1, 2011, and says the record was added to its database on January 8, 2017. Its listing identifies passwords, email addresses, usernames, and website activity as compromised data. Mozilla Monitor’s QIP breach page

Have I Been Pwned’s current breach catalog lists QIP at 26.2 million accounts. That is the catalog’s current count; it does not establish that Panda Security’s 33 million figure is incorrect or that both sources refer to an identical dataset. Have I Been Pwned’s breach catalog

Why do sources report 26.2 million and 33 million?

Source Figure or date What it establishes
Mozilla Monitor June 1, 2011; record added January 8, 2017 Dates its QIP breach listing and names the exposed data fields. Source
Have I Been Pwned 26.2 million accounts Current count in its QIP breach catalog listing. Source
Panda Security / PandaLabs 33 million users Its Q3 2016 report states that data belonging to 33 million QIP.ru users was stolen. The surfaced report text does not establish that this was the same event as the 2011 listing. Source
GalaxyWarden 26.2 million Secondary summary of the 2011 incident and exposed-field list; this is corroborating reporting, not an original incident notice. Source

No located QIP or regulator notice reconciles the count, date, or overlap between the datasets. It is therefore more accurate to describe 33 million as Panda Security’s reported figure and 26.2 million as Have I Been Pwned’s current catalog count, rather than treating either number as a confirmed count for a single, settled incident record.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What information was exposed?

Mozilla Monitor’s listing names passwords, email addresses, usernames, and website activity. GalaxyWarden’s secondary summary also lists these fields for the 2011 incident. The sources do not establish whether every account in the separate 33 million figure had exactly these same data fields exposed.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should you do if you used a QIP password?

  1. Change it anywhere it is still in use. If you reused the QIP password on another account, replace it on each of those services.
  2. Make every replacement unique. Mozilla Monitor advises changing an exposed password and not reusing it. A password exposed in an old breach should not remain the key to another account. Mozilla Monitor’s guidance
  3. Check whether your email address appears in a breach notification service. Such a check can help identify listed exposures, but it cannot prove that an account was unaffected when no match appears.

The cited sources do not identify a currently operating QIP response channel, so do not assume the historical service can reset an account or remediate the exposure.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.