Two Russian fundraising initiatives, Davayte and You Are Not Alone, disclosed that their payment accounts were compromised by hackers. Davayte raises funds for Ukrainian civilians affected by the conflict, while You Are Not Alone supports Russian political prisoners and their families. Both projects reported the incidents on Tuesday, stating the attacks took place in mid-August.
The attackers exploited a vulnerability in an integration between the payment processor Stripe and WooCommerce, an e-commerce plugin for WordPress. Both projects utilized this integration for conducting online auctions. The threat actor gained access through this common entry point.
The breach resulted in the exposure of donor email addresses. In some instances, the last four digits of payment cards and information about the issuing banks were also accessed. Full card numbers, cardholders' names, and specific donation details were not compromised. Stripe intervened, blocking unauthorized access before the entire database of donor email addresses could be downloaded, and found no evidence of fraudulent transactions.
Following the incident, Davayte disabled third-party integrations, rotated its access keys, and informed the relevant European data protection authority. The identity of the attackers remains unknown. You Are Not Alone stated they are investigating whether the attack was carried out by cybercriminals or Russian security services.
Davayte, launched in February 2024 by independent Russian media organizations like Meduza and TV Rain, has raised over $437,000 for humanitarian aid in Ukraine. You Are Not Alone, organized by independent Russian media and opposition groups since 2023, has raised approximately $1.4 million and assisted around 800 political prisoners and their relatives.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Two Russian fundraising projects, Davayte and You Are Not Alone, reported that hackers accessed their payment accounts in mid-August, exposing donor email addresses and partial payment card information. The breach occurred through an integration between Stripe and WooCommerce used for online auctions, affecting projects supporting Ukrainian civilians and Russian political prisoners.