As VChK-OGPU and Rucriminal.info have learned, hearings have begun at Moscow’s Khoroshevsky Court in the case of Igor Morozkin, owner of the "User Box" Telegram bot used for unauthorized data lookups. Case files indicate that he became the "fall guy" in the FSB’s hunt for the source of a leaked agency database containing cross-border movement records. Testimony implicating him—and other players in the data lookup market—was provided by the owners and administrators of interconnected bots and websites known as Odyssey, Chimera, and Themis. Statements from these "witnesses" suggest they operate under the complete control of security services; their servers were even hosted by an organization that services government agencies and runs joint programs with the Interdepartmental Commission on the Protection of State Secrets.

Morozkin and Bashilov, another co-owner of User Box, are charged under Article 272.1 of the Russian Criminal Code (illegal trafficking of computer information containing personal data).

 

According to case materials reviewed by our project, the FSB’s Internal Security Directorate began searching for the source of the cross-border movement database leak in 2024. The "Chimera" project was the first to publish the data, though it quickly removed it. Furthermore, the project's creators announced that, in late 2024, they had relocated all staff out of Russia and moved their servers. However, they were either misleading the public or quickly struck a deal with the authorities. The case files regarding "User Box" contain a record of an interview conducted in late January 2025 by officers from the FSB’s Internal Security Directorate with Artem Tenishev, the technical administrator of the "Chimera" project; this interview took place right at Sheremetyevo Airport. He stated that the Chimera servers held a database of border crossings, which he downloaded before deletion and sold to the owners of "User Box" for $35,000.

 

He also identified a certain Matvey Trubitsyn as the key figure in the market responsible for compiling and launching such databases—including Chimera—and implicated him in "Manticora," another data-lookup project. The interview record reveals that FSB officers harbor a particular grudge against "Manticora" and are making every effort to track down those involved in it.

 

In early July 2025, an investigator questioned Stanislav Kirillov, the CEO and owner of Odissey.Info LLC. In early 2026, VChK-OGPU and Rucriminal.info published a major investigative report on this individual. Stanislav Kirillov (known by the handle Stas_272) had previously worked in the security departments of Gazprombank Leasing JSC and Carsharing-Russia LLC (Delimobil). He later became a co-founder of three interconnected data-lookup services: Himera Search, Femida Search, and Odissey. His partners included former Russian Interior Ministry officer Dmitry Zhuravlev (whose brother, Alexander, is an FSB officer) and programmer Khakan Abulov.

 

Kirillov, too, places the entire blame for the public leak of the border-crossing database on Matvey Trubitsyn. "I proposed that he work with us, specifically acting as a manager for sourcing and acquiring various databases," Kirillov stated during questioning. "During the time we worked with Matvey, we acquired around 150 databases, all of which were located by Trubitsyn... I am not acquainted with the individuals who provided him with the databases, nor do I know the details."

 

Kirillov explained that all his resources are hosted on leased servers belonging to the Scientific Center for Information Protection (SCIP). Publicly available information reveals that the SCIP’s government clients include the Russian Ministry of Science and Higher Education, the Kurchatov Institute Research Center, and the Rostov Regional Clinical Hospital (ROKB). The SCIP also conducts training programs for executives and specialists who handle restricted information, including data classified as state secrets. These programs are approved by the Interdepartmental Commission on the Protection of State Secrets, the FSB, and the FSTEC.

 

Kirillov acknowledges that his platforms were inactive from December 10, 2024, through the end of January 2025, attributing this to the "need to develop a new solution." From January 2025 onwards, the projects resumed operations under the previous arrangement (using SCIP servers).

 

Sources for VChK-OGPU and Rucriminal.info note that Himera Search, Femida Search, and Odyssey work closely with Russian intelligence agencies, and that the "market" has recently been cleared specifically to make way for them. This likely explains why the owners and administrators of these projects have become repeat witnesses in cases involving unauthorized data access ("probiv").