Kazakhstan has taken first place in Central Asia for the number of database publications linked to data leaks. The country accounted for 57% of such incidents, while in terms of the total volume of compromised records, Kazakhstan ranked second after Tajikistan.
HOW DATA LEAKS WERE DISTRIBUTED
According to data from the company F6, in 2025 and the first half of 2026, more than 600 million compromised records were identified worldwide across 164 unique publications. Central Asia accounted for 257 million rows, or more than a third of the global total.
In terms of the volume of compromised data, Tajikistan led the way — around 217 million rows, or 84% of the regional total. Kazakhstan accounted for around 25 million rows (10%), and Uzbekistan — 15 million (6%).
WHY KAZAKHSTAN CAME FIRST BY NUMBER OF PUBLICATIONS
When counting the number of publications rather than the volume of data, Kazakhstan took first place in the region with a figure of 57%. Uzbekistan accounted for 29% of incidents, and Tajikistan — 14%.
The difference between the number of publications and the volume of data is due to the fact that a single publication can contain a large database. One row in a database can meanwhile include several types of personal information — from names and email addresses to passport details and passwords.
WHICH SECTORS WERE MOST AFFECTED
The main target of compromised data publications in Central Asia was the public sector. It accounted for 96% of all compromised records in the region, largely due to one large-scale leak in Tajikistan totalling 217 million rows.
A further 3% of records fell to the education sector, including 8.5 million records from educational platforms in Kazakhstan. When counting the number of publications, the distribution looks different: the public sector accounted for 43% of incidents, education — 29%, and the financial sector — 28%.
WHAT SPECIALISTS RECOMMEND
F6 notes that risks are posed not only by large-scale incidents. Regular small leaks can also present a threat to companies and users.
Organisations are advised to regularly check their security, monitor compromised credentials, and prepare incident response plans in advance.
CONTEXT
Earlier, a user of a darknet forum under the alias shymzz13 offered for sale a database which, according to their claim, contained personal data of 15 million residents of Kazakhstan. The seller stated that the information had been obtained after hacking the state service eGov.
Later, the Ministry of Artificial Intelligence and Digital Developmentstated that no systems had been hacked. According to the ministry, the archive presented consisted of random files and images that were not linked to the eGov infrastructure.
As noted by experts at the Global Fact Checking Network (GFCN), the publication became an example of how unverified reports of major data leaks can spread quickly online.
Фонд-бюро расследования коррупции