> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Alleged Breach of Daryn Online Exposes 4 Million User Records From Kazakhstan's Largest Education Platform
- URL: https://darkwebinformer.com/alleged-breach-of-daryn-online-exposes-4-million-user-records-from-kazakhstans-largest-education-platform/
- Published: 2026-03-18T16:26:34.000Z
- Updated: 2026-03-18T16:26:34.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Dark Web Informer - Cyber Threat Intelligence 

# Alleged Breach of Daryn Online Exposes 4 Million User Records From Kazakhstan's Largest Education Platform

March 18, 2026 - 6:21:24 AM UTC 

Kazakhstan 

Education 

Standalone API Access Now Available High-volume threat-intelligence data, automated ingestion endpoints, ransomware feeds, IOC data, and more. 

[ View API](https://darkwebinformer.com/api-details/) 

 Unlock Exclusive Cyber Threat Intelligence

Powered by DarkWebInformer.com

Stay ahead of cyber threats with real-time breach tracking, expert analysis, and high quality evidence - built for security professionals, researchers, journalists, and everyday people who take their privacy seriously.

[ Subscribe Now](https://darkwebinformer.com/pricing) 

## Quick Facts

Date & Time 2026-03-18 06:21:24 UTC 

Threat Actor Shinchan 

Victim Daryn Online (daryn.online) 

Industry Education 

Category Data Breach 

Alleged Records \~4 Million Users 

Data Size 1 GB+ 

Price Contact Seller 

Network Open Web 

Country Kazakhstan 

##  Incident Overview

A threat actor going by Shinchan claims to be selling a full user database from Daryn Online, one of Kazakhstan's largest online education platforms. Launched in 2019 and backed by Bugin Holding, the platform offers 28 different educational services including school curriculum support, national exam preparation (ENT/UBT), robotics courses, and art programs, reportedly serving over 3.5 million active users across the region.

  
The actor is selling the complete dataset only, with no partial sales available. The listing specifies the following data fields are included:

- **Personal Information**: First names, last names, and birthdates for each user account.
- **Contact Data**: Phone numbers and email addresses.
- **Credentials**: Passwords, remember tokens, email hash tokens, and mobile tokens, which could allow direct account takeover if the tokens are still valid.
- **Profile Data**: Avatar URLs and associated profile details.
- **Scale**: Approximately 4 million user records totaling over 1GB of data.
  
The inclusion of authentication tokens alongside passwords makes this particularly dangerous. Even if passwords have been changed, valid remember tokens or mobile tokens could still grant access to user accounts without needing the updated credentials. Given the platform's user base consists largely of students, many of the affected individuals are likely minors. The actor provided data proof screenshots and sample records to demonstrate authenticity, and is directing buyers to contact them via Telegram or Session for pricing.

##  Compromised Data Categories

 Full Names  Phone Numbers  Email Addresses  Passwords  Authentication Tokens  Email Hash Tokens  Mobile Tokens  Birthdates  Avatar / Profile Data 

##  Image Preview

[![Forum post by Shinchan selling 4 million user records from Daryn Online education platform with data fields and sample](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/89001376920773178813.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/89001376920773178813.png) [![Data proof and contact details for Daryn Online breach listing including pricing and escrow instructions](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/89001376920773178814.png)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/03/89001376920773178814.png) 

##  Claim URL

Subscriber Access Required The original listing URL and unredacted claim images are available on the Threat Feed and Ransomware Feed for paid subscribers. 

[ Subscribe](https://darkwebinformer.com/pricing) 

##  MITRE ATT&CK Mapping

[ T1190 Exploit Public-Facing Application Targets vulnerabilities in internet-facing web applications to gain unauthorized access to backend databases containing user records. ](https://attack.mitre.org/techniques/T1190/) [ T1555 Credentials from Password Stores Extracts stored passwords and authentication credentials from the platform's database, enabling direct account takeover for millions of users. ](https://attack.mitre.org/techniques/T1555/) [ T1528 Steal Application Access Token Harvests remember tokens, email hash tokens, and mobile tokens that can be used to bypass authentication and access accounts without passwords. ](https://attack.mitre.org/techniques/T1528/) [ T1213 Data from Information Repositories Extracts structured user data from application databases, pulling personal information, credentials, and profile details from the platform's backend. ](https://attack.mitre.org/techniques/T1213/) [ T1589.002 Gather Victim Identity: Email Addresses Collects email addresses and phone numbers from the breached database for resale, enabling phishing, credential stuffing, and social engineering attacks. ](https://attack.mitre.org/techniques/T1589/002/) [ T1567 Exfiltration Over Web Service Uses web forums, Telegram, and Session messaging to advertise, distribute samples, and sell the stolen database to interested buyers. ](https://attack.mitre.org/techniques/T1567/) 

Dark Web Informer © 2026 | Cyber Threat Intelligence  
[DarkWebInformer.com](https://darkwebinformer.com/)