{
  "query": {
    "page": "11"
  },
  "count": 20,
  "total": 1018,
  "page": 11,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T06:45:27.610Z",
    "kev": "2026-10-06T06:44:27.275Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T06:45:27.610Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=11"
  },
  "warnings": [],
  "results": [
    {
      "name": "MC2Data",
      "title": "MC2 Data",
      "domain": null,
      "breach_date": "2024-08-18",
      "added": "2024-12-15T17:47:05.000Z",
      "accounts": 2122280,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2024, data aggregator MC2 Data left a database publicly accessible without a password which was subsequently discovered by a security researcher. The breach exposed the personal information of 2.1M subscribers to the service which was marketed under a series of different brand names. The data included email addresses, names and salted SHA-256 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MC2Data"
    },
    {
      "name": "Yonema",
      "title": "Yonéma",
      "domain": "yonema.com",
      "breach_date": "2024-11-21",
      "added": "2024-12-14T07:28:27.000Z",
      "accounts": 35962,
      "data_classes": [
        "Dates of birth",
        "Device information",
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2024, data from the Senegalese payment platform Yonéma was posted to a popular hacking forum. The data included 36k unique email addresses alongside phone numbers, names and what appears to be encrypted passwords and dates of birth.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Yonema"
    },
    {
      "name": "Tibber",
      "title": "Tibber",
      "domain": "tibber.com",
      "breach_date": "2024-11-10",
      "added": "2024-12-14T06:49:41.000Z",
      "accounts": 50002,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "Names",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2024, the German electricity provider Tibber suffered a data breach that exposed the personal information of 50k customers. The data included names, email addresses, geographic locations (city and postcode) and total spend on purchases.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Tibber"
    },
    {
      "name": "SeniorDating",
      "title": "Senior Dating",
      "domain": "seniordating.app",
      "breach_date": "2024-11-23",
      "added": "2024-12-09T12:38:50.000Z",
      "accounts": 765517,
      "data_classes": [
        "Bios",
        "Dates of birth",
        "Drinking habits",
        "Education levels",
        "Email addresses",
        "Genders",
        "Geographic locations",
        "Latitude and longitude pairs",
        "Occupations",
        "Profile photos",
        "Relationship statuses",
        "Smoking habits",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In 2024, the 40+ dating website Senior Dating suffered a data breach. Attributed to an exposed Firebase database, the breach included extensive personal information on 766k users of the service including email addresses, photos, genders, links to Facebook accounts, dates of birth and precise latitude and longitude, among other personal attributes. The website was shut down after the breach was acknowledged by the site operator in December, along with a breach of the \"ladies.com\" website run by the same organisation.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#SeniorDating"
    },
    {
      "name": "Ladies",
      "title": "Ladies.com",
      "domain": "ladies.com",
      "breach_date": "2024-07-03",
      "added": "2024-12-09T11:45:16.000Z",
      "accounts": 118809,
      "data_classes": [
        "Bios",
        "Dates of birth",
        "Drinking habits",
        "Education levels",
        "Email addresses",
        "Family structure",
        "Genders",
        "Geographic locations",
        "Latitude and longitude pairs",
        "Photos",
        "Profile photos",
        "Relationship statuses",
        "Sexual orientations",
        "Smoking habits",
        "Tattoo status",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In 2024, the lesbian dating website ladies.com suffered a data breach. Attributed to an exposed Firebase database, the breach included extensive personal information on 119k users of the service including email addresses, photos, sexual orientation, genders, dates of birth and precise latitude and longitude, among other personal attributes. The website was shut down in mid-2024 and the breach later acknowledged by the site operator in December, along with a breach of the \"Senior Dating\" website run by the same organisation.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Ladies"
    },
    {
      "name": "TheRealWorld",
      "title": "The Real World",
      "domain": "therealworld.net",
      "breach_date": "2024-11-15",
      "added": "2024-11-22T21:55:44.000Z",
      "accounts": 324382,
      "data_classes": [
        "Chat logs",
        "Email addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2024, the online course founded by Andrew Tate known as \"The Real World\" (previously \"Hustler's University\" suffered a data breach that exposed almost 325k users of the platform. The impacted data was limited to usernames, email addresses and chat logs.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#TheRealWorld"
    },
    {
      "name": "FlipaClip",
      "title": "FlipaClip",
      "domain": "flipaclip.com",
      "breach_date": "2024-11-18",
      "added": "2024-11-20T22:37:58.000Z",
      "accounts": 892854,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Geographic locations",
        "Names"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2024, the animation app FlipaClip suffered a data breach that exposed almost 900k records due to an exposed Firebase server. The impacted data included name, email address, country and date of birth. FlipaClip advised the issue has since been rectified.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#FlipaClip"
    },
    {
      "name": "Finsure",
      "title": "Finsure",
      "domain": "finsure.com.au",
      "breach_date": "2024-10-15",
      "added": "2024-11-19T04:25:18.000Z",
      "accounts": 296124,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2024, almost 300k unique email addresses from Australian mortgage broking group Finsure were obtained from the ActivePipe real estate marketing platform. The impacted data also included names, phone numbers and physical addresses. The incident did not directly affect any of Finsure's systems or expose any passwords or financial data.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Finsure"
    },
    {
      "name": "DemandScience",
      "title": "DemandScience by Pure Incubation",
      "domain": "demandscience.com",
      "breach_date": "2024-02-28",
      "added": "2024-11-13T09:53:35.000Z",
      "accounts": 121796165,
      "data_classes": [
        "Email addresses",
        "Employers",
        "Job titles",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In early 2024, a large corpus of data from DemandScience (a company owned by Pure Incubation), appeared for sale on a popular hacking forum. Later attributed to a leak from a decommissioned legacy system, the breach contained extensive data that was largely business contact information aggregated from public sources. Specifically, the data included 122M unique corporate email addresses, physical addresses, phone numbers, employers and job titles. It also included names and for many individuals, a link to their LinkedIn profile.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#DemandScience"
    },
    {
      "name": "HotTopic",
      "title": "Hot Topic",
      "domain": "hottopic.com",
      "breach_date": "2024-10-19",
      "added": "2024-11-11T07:50:58.000Z",
      "accounts": 56904909,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Partial credit card data",
        "Phone numbers",
        "Physical addresses",
        "Purchases",
        "Salutations"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2024, retailer Hot Topic suffered a data breach that exposed 57 million unique email addresses. The impacted data also included physical addresses, phone numbers, purchases, genders, dates of birth and partial credit data containing card type, expiry and last 4 digits.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#HotTopic"
    },
    {
      "name": "Earth2",
      "title": "Earth 2",
      "domain": "earth2.io",
      "breach_date": "2024-10-16",
      "added": "2024-11-07T04:49:02.000Z",
      "accounts": 420961,
      "data_classes": [
        "Email addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2024, 421k unique email addresses from the virtual earth game Earth 2 were derived from embedded Gravatar images. Appearing alongside player usernames, the root cause was related to how Gravatar presents links to avatars as MD5 hashes within consuming services, a feature Earth 2 advised has now been disabled on their platform. This incident did not expose any further personal information, passwords or financial data.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Earth2"
    },
    {
      "name": "DennisKirk",
      "title": "Dennis Kirk",
      "domain": "denniskirk.com",
      "breach_date": "2021-09-04",
      "added": "2024-11-05T22:11:58.000Z",
      "accounts": 1356026,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "Names",
        "Phone numbers",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2024, almost 20GB of data containing 1.3M unique email addresses from motorcycle supplies store Dennis Kirk was circulated. Dating back to September 2021, the data also contained purchases from the online store along with customer names, phone numbers and postcodes. Dennis Kirk did not respond to multiple attempts to make contact about the breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#DennisKirk"
    },
    {
      "name": "Altenen",
      "title": "Altenen",
      "domain": "altenens.is",
      "breach_date": "2022-06-24",
      "added": "2024-11-05T06:20:27.000Z",
      "accounts": 1267701,
      "data_classes": [
        "Cryptocurrency wallet addresses",
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2022, the malicious \"carding\" (referring to credit card fraud) website Altenen suffered a data breach that was later redistributed as part of a larger corpus of data. The data included 1.3M unique email addresses, usernames, bcrypt password hashes and cryptocurrency wallet addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Altenen"
    },
    {
      "name": "ZLib",
      "title": "Z-lib",
      "domain": "z-lib.is",
      "breach_date": "2024-06-20",
      "added": "2024-11-04T04:12:07.000Z",
      "accounts": 9737374,
      "data_classes": [
        "Cryptocurrency wallet addresses",
        "Email addresses",
        "Geographic locations",
        "Passwords",
        "Purchases",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2024, almost 10M user records from Z-lib were discovered exposed online. Now defunct, Z-lib was a malicious clone of Z-Library, a well-known shadow online platform for pirating books and academic papers. The exposed data included usernames, email addresses, countries of residence, Bitcoin and Monero cryptocurrency wallet addresses, purchases and bcrypt password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ZLib"
    },
    {
      "name": "StalkerOnline",
      "title": "Stalker Online",
      "domain": "stalker.so",
      "breach_date": "2020-05-05",
      "added": "2024-10-31T20:11:33.000Z",
      "accounts": 1385472,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2020, over 1.3M records from the MMO game Stalker Online were breached. The data included email and IP addresses, usernames and hashed passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#StalkerOnline"
    },
    {
      "name": "TNAFlix",
      "title": "TNAFlix",
      "domain": "tnaflix.com",
      "breach_date": "2022-06-01",
      "added": "2024-10-30T23:01:03.000Z",
      "accounts": 1374344,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2022, the adult website TNAFlix suffered a data breach that was later redistributed as part of a larger corpus of data. The data included 1.4M records of email and IP addresses, usernames and plain text passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#TNAFlix"
    },
    {
      "name": "VimeWorld",
      "title": "VimeWorld",
      "domain": "vimeworld.com",
      "breach_date": "2018-10-01",
      "added": "2024-10-30T07:02:43.000Z",
      "accounts": 3118964,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2018, the Russian Minecraft service VimeWorld suffered a data breach that was later redistributed as part of a larger corpus of data. The data included 3.1M records of usernames, email and IP addresses and passwords stored as either MD5 or bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#VimeWorld"
    },
    {
      "name": "StreamCraft",
      "title": "StreamCraft",
      "domain": "streamcraft.net",
      "breach_date": "2020-07-06",
      "added": "2024-10-27T21:01:08.000Z",
      "accounts": 1772620,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2020, the Russian Minecraft service StreamCraft suffered a data breach that was later redistributed as part of a larger corpus of data. The data included 1.8M records of usernames, email and IP addresses and passwords stored as either MD5 or bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#StreamCraft"
    },
    {
      "name": "TheClubPenguinExperience",
      "title": "The Club Penguin Experience",
      "domain": "thecpexperience.com",
      "breach_date": "2024-10-14",
      "added": "2024-10-26T05:21:55.000Z",
      "accounts": 6342,
      "data_classes": [
        "Age groups",
        "Email addresses",
        "Password hints",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2024, The Club Penguin Experience (TCPE) suffered a data breach. The incident exposed over 6k subscribers' email addresses alongside usernames, age groups, passwords stored as bcrypt hashes and in some cases, plain text password hints. TCPE sent prompt disclosure notices to impacted customers following the breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#TheClubPenguinExperience"
    },
    {
      "name": "digiDirect",
      "title": "digiDirect",
      "domain": "digidirect.com.au",
      "breach_date": "2024-09-29",
      "added": "2024-10-25T02:01:08.000Z",
      "accounts": 304337,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2024, a data breach sourced from the Australian retailer digiDirect was published to a popular hacking forum. The breach exposed over 300k rows of data including email and physical address, name, phone number and date of birth. Approximately half the email addresses were on domains from external marketplaces including Amazon, eBay and Westfield.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#digiDirect"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
