{
  "query": {
    "page": "12"
  },
  "count": 20,
  "total": 1018,
  "page": 12,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T06:45:27.610Z",
    "kev": "2026-10-06T07:44:30.071Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T07:45:30.209Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=12"
  },
  "warnings": [],
  "results": [
    {
      "name": "FairVoteCanada",
      "title": "Fair Vote Canada",
      "domain": "fairvote.ca",
      "breach_date": "2024-03-02",
      "added": "2024-10-21T05:04:21.000Z",
      "accounts": 134336,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Political donations"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2024, the Canadian national citizens' campaign for proportional representation Fair Vote Canada suffered a data breach. The incident was attributed to \"a well-meaning volunteer\" who inadvertently exposed data from 2020 which included 134k unique email addresses, names, physical addresses, phone numbers and, for some individuals, date and amount of a donation.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#FairVoteCanada"
    },
    {
      "name": "AlpineReplay",
      "title": "AlpineReplay",
      "domain": "traceup.com",
      "breach_date": "2019-08-27",
      "added": "2024-10-17T04:01:13.000Z",
      "accounts": 898681,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Passwords",
        "Physical attributes",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In 2019, the snow sports tracking app AlpineReplay suffered a data breach that exposed 900k unique email addresses. Later rolled into the Trace service, the breach included names, usernames, genders, dates of birth, weights and passwords stored as either unsalted MD5 or bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#AlpineReplay"
    },
    {
      "name": "InternetArchive",
      "title": "Internet Archive",
      "domain": "archive.org",
      "breach_date": "2024-09-28",
      "added": "2024-10-09T22:31:53.000Z",
      "accounts": 31081179,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2024, the digital library of internet sites Internet Archive suffered a data breach that exposed 31M records. The breach exposed user records including email addresses, screen names and bcrypt password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#InternetArchive"
    },
    {
      "name": "Muah",
      "title": "Muah.AI",
      "domain": "muah.ai",
      "breach_date": "2024-09-17",
      "added": "2024-10-08T22:05:01.000Z",
      "accounts": 1910261,
      "data_classes": [
        "AI prompts",
        "Email addresses",
        "Sexual fetishes"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2024, the \"AI girlfriend\" website Muah.AI suffered a data breach. The breach exposed 1.9M email addresses alongside prompts to generate AI-based images. Many of the prompts were highly sexual in nature, with many also describing child exploitation scenarios.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Muah"
    },
    {
      "name": "Switch",
      "title": "Switch",
      "domain": "switchit.hu",
      "breach_date": "2024-10-01",
      "added": "2024-10-05T20:18:44.000Z",
      "accounts": 5397,
      "data_classes": [
        "Email addresses",
        "Job applications",
        "Names",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2024, the Hungarian IT headhunting service Switch inadvertently exposed thousands of customer records via a public GitHub repository. The exposed data contained job applications with names, email addresses and in some cases, commentary on the applicant.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Switch"
    },
    {
      "name": "BudTrader",
      "title": "BudTrader",
      "domain": "budtrader.com",
      "breach_date": "2024-06-27",
      "added": "2024-10-01T13:51:19.000Z",
      "accounts": 2721185,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2024, a data breach of the now defunct cannabis social platform BudTrader was posted for sale on a hacking forum. Dating back to the previous month, the breach of the website exposed 2.7M email addresses, usernames and WordPress password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BudTrader"
    },
    {
      "name": "CentralTickets",
      "title": "Central Tickets",
      "domain": "centraltickets.co.uk",
      "breach_date": "2024-07-01",
      "added": "2024-09-30T15:57:13.000Z",
      "accounts": 722860,
      "data_classes": [
        "Device information",
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2024, data from the ticketing service Central Tickets was publicly posted to a hacking forum. The data suggests the breach occurred several months earlier and exposed 723k unique email addresses alongside names, phone numbers, IP addresses, purchases and passwords stored as unsalted SHA-1 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CentralTickets"
    },
    {
      "name": "GameVN",
      "title": "GameVN",
      "domain": "gamevn.com",
      "breach_date": "2016-05-01",
      "added": "2024-09-23T01:39:12.000Z",
      "accounts": 1369485,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2016, the Vietnamese gaming forum GameVN suffered a data breach that was later redistributed as part of a larger corpus of data. Data breached from the XenForo-based forum included 1.4M unique email addresses, usernames, IP addresses and salted MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GameVN"
    },
    {
      "name": "HuntStand",
      "title": "HuntStand",
      "domain": "huntstand.com",
      "breach_date": "2024-03-08",
      "added": "2024-09-19T07:31:13.000Z",
      "accounts": 2795947,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Geographic locations",
        "Names"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2024, millions of records scraped from the hunting and land management service HuntStand were publicly posted to a popular hacking forum. The data included 2.8M unique email addresses with many records also containing name, date of birth and country.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#HuntStand"
    },
    {
      "name": "InstitutoNacionalDeDeportesDeChile",
      "title": "Instituto Nacional de Deportes de Chile",
      "domain": "ind.cl",
      "breach_date": "2024-09-12",
      "added": "2024-09-16T22:04:06.000Z",
      "accounts": 319613,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2024, the Instituto Nacional de Deportes de Chile (Chile's National Sports Institute) suffered a data breach. The incident exposed 1.7M rows of data with 320k unique email addresses alongside names, dates of birth, genders and bcrypt password hashes. The newest records in the data date back to August 2022, suggesting the breach may be of an older data set.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#InstitutoNacionalDeDeportesDeChile"
    },
    {
      "name": "GamesBox",
      "title": "Games Box",
      "domain": "gamesbox.com",
      "breach_date": "2020-09-21",
      "added": "2024-09-15T02:41:52.000Z",
      "accounts": 1439354,
      "data_classes": [
        "Ages",
        "Email addresses",
        "Genders",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2020, now defunct website Games Box suffered a data breach that was later redistributed as part of a larger corpus of data. The impacted data included 1.4M email addresses alongside usernames, genders, ages and passwords stored as either a hash or plain text.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GamesBox"
    },
    {
      "name": "BloomsToday",
      "title": "Blooms Today",
      "domain": "bloomstoday.com",
      "breach_date": "2023-11-11",
      "added": "2024-09-03T07:06:36.000Z",
      "accounts": 3184010,
      "data_classes": [
        "Email addresses",
        "Names",
        "Partial credit card data",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2024, 15M records from the online florist Blooms Today were listed for sale on a popular hacking forum. The most recent data in the breach corpus was from November 2023 and appeared alongside 3.2M unique email addresses, names, phone numbers physical addresses and partial credit card data (card type, 4 digits of the number and expiry date). The breach did not expose sufficient card data to make purchases. Blooms Today did not respond when contacted about the incident.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BloomsToday"
    },
    {
      "name": "MarketMoveis",
      "title": "Market Moveis",
      "domain": "marketmoveis.pt",
      "breach_date": "2023-08-30",
      "added": "2024-09-01T07:22:42.000Z",
      "accounts": 28220,
      "data_classes": [
        "Email addresses",
        "Names"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2023, the Portuguese home decor company Market Moveis suffered a data breach that impacted 28k records. The exposed records were limited to names and email addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MarketMoveis"
    },
    {
      "name": "Lookiero",
      "title": "Lookiero",
      "domain": "lookiero.com",
      "breach_date": "2024-03-27",
      "added": "2024-08-30T05:23:12.000Z",
      "accounts": 4981760,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2024, a data breach from the online styling service Lookiero was posted to a popular hacking forum. Dating back to March 2024, the data included 5M unique email addresses, with many of the records also including name, phone number and physical address. When contacted about the incident, Lookiero advised that they would \"look into it and get back to you if necessary\".",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Lookiero"
    },
    {
      "name": "Sport2000",
      "title": "Sport 2000",
      "domain": "sport2000.fr",
      "breach_date": "2024-04-18",
      "added": "2024-08-28T06:56:12.000Z",
      "accounts": 3189643,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Purchases",
        "Salutations"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2024, the French sporting equipment manufacturer Sport 2000 announced it had suffered a data breach. The data was subsequently put up for sale on a popular hacking forum and included 4.4M rows with 3.2M unique email addresses alongside names, physical addresses, phone numbers, dates of birth and purchases made by store name.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Sport2000"
    },
    {
      "name": "Traderie",
      "title": "Traderie",
      "domain": "traderie.com",
      "breach_date": "2022-09-24",
      "added": "2024-08-25T20:08:07.000Z",
      "accounts": 364898,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Social media profiles",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2022, the in-game trading marketplace Traderie suffered a data breach that exposed almost 400k records (this preceded a subsequent breach the following year). The incident exposed email and IP addresses, usernames and links to social media profiles.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Traderie"
    },
    {
      "name": "Tracki",
      "title": "Tracki",
      "domain": "tracki.com",
      "breach_date": "2024-08-15",
      "added": "2024-08-19T07:52:19.000Z",
      "accounts": 372557,
      "data_classes": [
        "Email addresses",
        "Names"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2024, a slew of security vulnerabilities were identified with a conglomerate of online services which included the GPS tracking service Tracki. Multiple vulnerabilities exposed the personal records of 372k users of the service including names and email addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Tracki"
    },
    {
      "name": "ExploreTalentAug2024",
      "title": "Explore Talent (August 2024)",
      "domain": "exploretalent.com",
      "breach_date": "2024-08-15",
      "added": "2024-08-19T05:52:35.000Z",
      "accounts": 8929384,
      "data_classes": [
        "Email addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2024, a slew of security vulnerabilities were identified with a conglomerate of online services which included the talent network Explore Talent. A vulnerable API exposed the personal records of 11.4M users of the service of which 8.9M unique email addresses were provided to HIBP. This incident is separate to the Explore Talent breach which occurred in 2022 and was loaded into HIBP in July 2024.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ExploreTalentAug2024"
    },
    {
      "name": "ChrisLeong",
      "title": "Chris Leong",
      "domain": "chrisleong.com",
      "breach_date": "2024-08-10",
      "added": "2024-08-13T22:16:41.000Z",
      "accounts": 27096,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Nationalities",
        "Phone numbers",
        "Physical addresses",
        "Purchases",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2024, the website of Master Chris Leong \"a leading Tit Tar practitioner in Malaysia\" suffered a data breach. The incident exposed 27k unique email addresses along with names, physical addresses, dates of birth, genders, nationalities and in many cases, links to Facebook profiles. The company did not respond when contacted about the breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ChrisLeong"
    },
    {
      "name": "LDLC",
      "title": "LDLC",
      "domain": "ldlc.com",
      "breach_date": "2024-02-28",
      "added": "2024-08-13T21:05:38.000Z",
      "accounts": 1266026,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Salutations"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2024, French retailer LDLC disclosed a data breach that impacted customers of their physical stores. The data was previously listed for sale on a popular hacking forum and contained 1.26M unique email addresses along with names, phone numbers and physical addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#LDLC"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
