{
  "query": {
    "page": "13"
  },
  "count": 20,
  "total": 1018,
  "page": 13,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T08:45:32.201Z",
    "kev": "2026-10-06T08:44:32.120Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T08:45:32.201Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=13"
  },
  "warnings": [],
  "results": [
    {
      "name": "NationalPublicData",
      "title": "National Public Data",
      "domain": null,
      "breach_date": "2024-04-09",
      "added": "2024-08-13T18:09:46.000Z",
      "accounts": 133957569,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Government issued IDs",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2024, a large trove of data made headlines as having exposed \"3 billion people\" due to a breach of the National Public Data background check service. The initial corpus of data released in the breach contained billions of rows of personal information, including US social security numbers. Further partial data sets were later released including extensive personal information and 134M unique email addresses, although the origin and accuracy of the data remains in question. This breach has been flagged as \"unverified\" and a full description of the incident is in the link above.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#NationalPublicData"
    },
    {
      "name": "Shadow",
      "title": "Shadow",
      "domain": "shadow.tech",
      "breach_date": "2023-09-28",
      "added": "2024-08-11T00:06:02.000Z",
      "accounts": 543295,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2023, the cloud gaming provider Shadow suffered a data breach that exposed over half a million customer records. The data included email and physical addresses, names and dates of birth.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Shadow"
    },
    {
      "name": "NotSOCRadar",
      "title": "Not SOCRadar",
      "domain": null,
      "breach_date": "2024-08-03",
      "added": "2024-08-09T09:28:24.000Z",
      "accounts": 282478425,
      "data_classes": [
        "Email addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2024, over 332M rows of email addresses were posted to a popular hacking forum. The post alleged the addresses were scraped from cybersecurity firm SOCRadar, however an investigation on their behalf concluded that \"the actor merely utilised functionalities inherent in the platform's standard offerings, designed to gather information from publicly available sources\". There is no suggestion the incident compromised SOCRadar's security or posed any risk to their customers. In total, the data set contained 282M unique addresses of valid email address format.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#NotSOCRadar"
    },
    {
      "name": "ShoeZone",
      "title": "Shoe Zone",
      "domain": "shoezone.com",
      "breach_date": "2024-06-28",
      "added": "2024-08-05T22:13:35.000Z",
      "accounts": 46140,
      "data_classes": [
        "Email addresses",
        "Names",
        "Partial credit card data",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2024, the UK footwear chain Shoe Zone disclosed a data breach that was subsequently posted for sale on a popular hacking forum. The data included over 100k orders containing names, addresses, partial credit card numbers (card type and last 4 digits), and 46k unique email addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ShoeZone"
    },
    {
      "name": "LuLu",
      "title": "LuLu",
      "domain": "luluhypermarket.com",
      "breach_date": "2024-07-06",
      "added": "2024-08-02T02:59:07.000Z",
      "accounts": 2796835,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2024, the Emirati-based LuLu retail store suffered a data breach. The impacted data included 190k email addresses and associated phone numbers which were subsequently shared on a popular hacking forum. The following month, the threat of leaking the full database was carried out and a backup from October 2022 with a further 2.6M unique email addresses appeared. This data also included names, physical addresses, orders and PBKDF2 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#LuLu"
    },
    {
      "name": "MultiplayerIt",
      "title": "Multiplayer.it",
      "domain": "multiplayer.it",
      "breach_date": "2018-09-01",
      "added": "2024-08-01T08:55:16.000Z",
      "accounts": 503957,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2024, over half a million records taken from the Italian gaming website Multiplayer.it were posted to a popular hacking forum. The impacted data included email addresses, usernames and salted MD5 password hashes. Multiplayer.it subsequently confirmed the breach dated back 6 years to September 2018 and was merely re-posted in 2024.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MultiplayerIt"
    },
    {
      "name": "TelegramStealerLogs",
      "title": "Stealer Logs Posted to Telegram",
      "domain": null,
      "breach_date": "2024-07-18",
      "added": "2024-08-01T05:38:53.000Z",
      "accounts": 26105473,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": true,
      "description": "In July 2024, info stealer logs with 26M unique email addresses were collated from malicious Telegram channels. The data contained 22GB of logs consisting of email addresses, passwords and the websites they were used on, all obtained by malware running on infected machines.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#TelegramStealerLogs"
    },
    {
      "name": "AnimeLeague",
      "title": "AnimeLeague",
      "domain": "animeleague.net",
      "breach_date": "2024-07-04",
      "added": "2024-07-31T07:57:48.000Z",
      "accounts": 192134,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Phone numbers",
        "Private messages",
        "Purchases",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2024, AnimeLeague disclosed a data breach of their services. The data was posted for sale on a popular hacking forum and included 2 databases covering both event registration records and a dump of the phpBB bulletin board. The impacted data included passwords in various hashed formats including SHA-1, salted md5 and bcrypt, as well as usernames, private messages, dates of birth, purchases and 192k unique email addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#AnimeLeague"
    },
    {
      "name": "Ubook",
      "title": "Ubook",
      "domain": "ubook.com",
      "breach_date": "2024-07-28",
      "added": "2024-07-30T22:25:42.000Z",
      "accounts": 699908,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Profile photos"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2024, 700k unique email addresses from the audiobook platform Ubook were posted to a popular hacking forum. Allegedly scraped from the service, the data appears to be sourced from the Ubook Exchange (UBX) and also includes names, genders, dates of birth and links to profile photos.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Ubook"
    },
    {
      "name": "Spytech",
      "title": "Spytech",
      "domain": "spytech-web.com",
      "breach_date": "2024-06-04",
      "added": "2024-07-30T03:30:44.000Z",
      "accounts": 5645,
      "data_classes": [
        "Browsing histories",
        "Device information",
        "Email addresses",
        "Names",
        "Passwords",
        "Purchases",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2024, spyware maker Spytech suffered a data breach that exposed data collected as recently as the previous month. Designed to \"invisibly record everything users do\", the breach exposed information related to both purchasers and targets of the product. Target data collection (and subsequent exposure) included the infected computer name, browsing history, applications used, usernames of authenticated users, keywords being monitored, file operations (creation and deletion), computer usage times and email addresses, often captured within the spyware's logs. The data also included the names, purchases and md5 password hashes of purchasers.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Spytech"
    },
    {
      "name": "CondoCom",
      "title": "Condo.com",
      "domain": "condo.com",
      "breach_date": "2019-06-01",
      "added": "2024-07-25T04:12:07.000Z",
      "accounts": 1481555,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2019, now defunct website Condo.com suffered a data breach that was later redistributed as part of a larger corpus of data. The impacted data included 1.5M email addresses alongside names, phone numbers and for a small number of records, physical addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CondoCom"
    },
    {
      "name": "ExploreTalent",
      "title": "Explore Talent (July 2024)",
      "domain": "exploretalent.com",
      "breach_date": "2022-02-28",
      "added": "2024-07-25T03:21:40.000Z",
      "accounts": 5371574,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2024, a data breach attributed to Explore Talent was publicly posted to a popular hacking forum. Containing 5.7M rows with 5.4M unique email addresses, the incident has been described by various sources as occurring between early 2022 to 2023 and also contains names, phone numbers and physical addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ExploreTalent"
    },
    {
      "name": "Life360",
      "title": "Life360",
      "domain": "life360.com",
      "breach_date": "2024-03-01",
      "added": "2024-07-20T21:40:31.000Z",
      "accounts": 442519,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2024, data scraped from a misconfigured Life360 API was posted online after being obtained several months earlier. The records included 443k unique email addresses and in most cases, corresponding names and phone numbers (some records were null or obfuscated). Life360 promptly notified impacted users after the incident was discovered.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Life360"
    },
    {
      "name": "mSpy2024",
      "title": "mSpy (2024)",
      "domain": "mspy.com",
      "breach_date": "2024-06-09",
      "added": "2024-07-11T19:29:21.000Z",
      "accounts": 2394179,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Photos"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2024, a huge trove of data from spyware maker mSpy was obtained by hacktivists and published online. Comprising of 142GB of user data and support tickets along with 176GB of more than half a million attachments, the data contained 2.4M unique email addresses, IP addresses names and photos. The data was predominantly support tickets seeking help to install the spyware on target devices, whilst the attachments contained various data including screen grans of financial transactions, photos of credit cards and nude selfies.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#mSpy2024"
    },
    {
      "name": "TheHeritageFoundation",
      "title": "The Heritage Foundation",
      "domain": "heritage.org",
      "breach_date": "2024-07-09",
      "added": "2024-07-10T06:51:28.000Z",
      "accounts": 72004,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2024, hacktivists published almost 2GB of data taken from The Heritage Foundation and their media arm, The Daily Signal. The data contained 72k unique email addresses, primarily used for commenting on articles (along with names, IP addresses and the comments left) and by content contributors (along with usernames and passwords stored as either MD5 or phpass hashes).",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#TheHeritageFoundation"
    },
    {
      "name": "NeimanMarcus",
      "title": "Neiman Marcus",
      "domain": "neimanmarcus.com",
      "breach_date": "2024-04-14",
      "added": "2024-07-09T19:27:32.000Z",
      "accounts": 31152842,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Names",
        "Partial credit card data",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2024, the American luxury retailer Neiman Marcus suffered a data breach which was later posted to a popular hacking forum. The data included 31M unique email addresses, names, phone numbers, dates of birth, physical addresses and partial credit card data (note: this is insufficient to make purchases). The breach was traced back to a series of attacks against the Snowflake cloud service which impacted 165 organisations worldwide.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#NeimanMarcus"
    },
    {
      "name": "HuskyOwners",
      "title": "Husky Owners",
      "domain": "husky-owners.com",
      "breach_date": "2024-07-04",
      "added": "2024-07-07T20:40:12.000Z",
      "accounts": 16502,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Time zones",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2024, the Husky Owners forum website was defaced and linked to a breach of user data containing 16k records. The exposed data included usernames, email addresses, dates of birth and time zones.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#HuskyOwners"
    },
    {
      "name": "RobloxDeveloperConference2024",
      "title": "FNTECH",
      "domain": "fntech.com",
      "breach_date": "2024-07-04",
      "added": "2024-07-06T01:21:29.000Z",
      "accounts": 10386,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2024, the events management platform FNTECH suffered a data breach that exposed 10k unique email addresses. The data contained registrants from various events, including participants of the Roblox Developer Conference registration list. The data also included names and IP addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#RobloxDeveloperConference2024"
    },
    {
      "name": "DateHotBrunettes",
      "title": "Date Hot Brunettes",
      "domain": "datehotbrunettes.com",
      "breach_date": "2021-01-12",
      "added": "2024-07-04T05:08:43.000Z",
      "accounts": 1494078,
      "data_classes": [
        "Bios",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2021, the now defunct website Date Hot Brunettes which provided a service to \"Date Neglected Women Who Can Keep a Secret\", suffered a data breach. The incident exposed 1.5M unique email addresses along with IP addresses, usernames, user-entered bios and MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#DateHotBrunettes"
    },
    {
      "name": "AdvanceAutoParts",
      "title": "Advance Auto Parts",
      "domain": "advanceautoparts.com",
      "breach_date": "2024-06-05",
      "added": "2024-06-24T09:51:11.000Z",
      "accounts": 79243727,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2024, Advance Auto Parts confirmed they had suffered a data breach which was posted for sale to a popular hacking forum. Linked to unauthorised access to Snowflake cloud services, the breach exposed a large number of records related to both customers and employees. In total, 79M unique email addresses were included in the breach, alongside names, phone numbers, addresses and further data attributes related to company employees.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#AdvanceAutoParts"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
