{
  "query": {
    "page": "16"
  },
  "count": 20,
  "total": 1018,
  "page": 16,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T10:45:36.976Z",
    "kev": "2026-10-06T10:44:36.922Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T10:45:36.976Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=16"
  },
  "warnings": [],
  "results": [
    {
      "name": "DCHealth",
      "title": "DC Health Link",
      "domain": "dchealthlink.com",
      "breach_date": "2023-03-06",
      "added": "2023-12-14T19:11:43.000Z",
      "accounts": 48145,
      "data_classes": [
        "Citizenship statuses",
        "Dates of birth",
        "Email addresses",
        "Employers",
        "Ethnicities",
        "Genders",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Purchases",
        "Social security numbers"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2023, DC Health Link discovered a data breach that was later publicly posted to a popular data breach forum. The impacted data included 48k unique email addresses alongside names, genders, dates of birth, home addresses, phone numbers and social security numbers.and \"IntelBroker\".",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#DCHealth"
    },
    {
      "name": "InflateVids",
      "title": "InflateVids",
      "domain": "tube.inflatevids.xyz",
      "breach_date": "2023-12-12",
      "added": "2023-12-12T00:13:41.000Z",
      "accounts": 13405,
      "data_classes": [
        "Email addresses",
        "Genders",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2023, the inflatable and balloon fetish videos website InflateVids suffered a data breach. The incident exposed over 13k unique email addresses alongside usernames, IP addresses, genders and SHA-1 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#InflateVids"
    },
    {
      "name": "Kaneva",
      "title": "Kaneva",
      "domain": "kaneva.com",
      "breach_date": "2016-07-01",
      "added": "2023-12-09T07:00:29.000Z",
      "accounts": 3901179,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2016, now defunct website Kaneva, the service to \"build and explore virtual worlds\", suffered a data breach that exposed 3.9M user records. The data included email addresses, usernames, dates of birth and salted MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Kaneva"
    },
    {
      "name": "Gemplex",
      "title": "Gemplex",
      "domain": "gemplex.tv",
      "breach_date": "2021-02-18",
      "added": "2023-12-09T02:19:40.000Z",
      "accounts": 4563166,
      "data_classes": [
        "Device information",
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2021, the Indian streaming platform Gemplex suffered a data breach that exposed 4.6M user accounts. The impacted data included device information, names, phone numbers, email addresses and bcrypt password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Gemplex"
    },
    {
      "name": "MovieForums",
      "title": "Movie Forums",
      "domain": "movieforums.com",
      "breach_date": "2022-11-24",
      "added": "2023-12-08T02:45:49.000Z",
      "accounts": 39914,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2022, the Movie Forums website suffered a data breach that affected 40k users. The breach exposed email and IP addresses, usernames, dates of birth and passwords stored as easily crackable salted MD5 hashes. The data was subsequently posted a popular clear web hacking forum.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MovieForums"
    },
    {
      "name": "JoyGames",
      "title": "JoyGames",
      "domain": "joygames.me",
      "breach_date": "2019-12-14",
      "added": "2023-12-07T05:52:24.000Z",
      "accounts": 4461787,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2019, the forum for the JoyGames website suffered a data breach that exposed 4.5M unique email addresses. The impacted data also included usernames, IP addresses and salted MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#JoyGames"
    },
    {
      "name": "RailYatri",
      "title": "RailYatri",
      "domain": "railyatri.in",
      "breach_date": "2022-12-26",
      "added": "2023-12-05T07:17:53.000Z",
      "accounts": 23209732,
      "data_classes": [
        "Email addresses",
        "Genders",
        "Names",
        "Phone numbers",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2022, India’s government-approved online travel agency RailYatri suffered a data breach. The incident impacted over 31M customers and exposed 23M unique email addresses. Also impacted were names, genders, phone numbers and tickets purchased, including travel information and fares.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#RailYatri"
    },
    {
      "name": "SoarGames",
      "title": "SoarGames",
      "domain": "soargames.com",
      "breach_date": "2019-12-16",
      "added": "2023-12-03T06:56:13.000Z",
      "accounts": 4774445,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2019, the now defunct gaming website SoarGames suffered a data breach that exposed 4.8M unique email addresses. The impacted data included usernames, email and IP addresses and salted MD5 password hashes. A significant number of the email addresses appeared to have been generated as opposed to organically provided by the user.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#SoarGames"
    },
    {
      "name": "GoNinja",
      "title": "Go Ninja",
      "domain": "goninja.de",
      "breach_date": "2019-12-17",
      "added": "2023-11-30T07:18:59.000Z",
      "accounts": 4999001,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2019, the now defunct German gaming website Go Ninja suffered a data breach that exposed 5M unique email addresses. The impacted data included usernames, email and IP addresses and salted MD5 password hashes. More than 4M of the email addresses appeared to have been generated as opposed to organically provided by the user.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GoNinja"
    },
    {
      "name": "EstanteVirtual",
      "title": "Estante Virtual",
      "domain": "estantevirtual.com.br",
      "breach_date": "2019-02-28",
      "added": "2023-11-29T22:13:34.000Z",
      "accounts": 5412603,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2019, the Brazilian book store Estante Virtual suffered a data breach that impacted 5.4M customers. The exposed data included names, usernames, email and physical addresses, phone numbers, dates of birth and unsalted SHA-1 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#EstanteVirtual"
    },
    {
      "name": "BleachAnime",
      "title": "Bleach Anime Forum",
      "domain": "bleachanime.org",
      "breach_date": "2015-01-01",
      "added": "2023-11-29T06:22:50.000Z",
      "accounts": 143711,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In 2015, the now defunct independent forum for the Bleach Anime series suffered a data breach that exposed 144k user records. The impacted data included usernames, email addresses and salted MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BleachAnime"
    },
    {
      "name": "IndiHome",
      "title": "IndiHome",
      "domain": "indihome.co.id",
      "breach_date": "2019-11-01",
      "added": "2023-11-27T07:02:10.000Z",
      "accounts": 12629245,
      "data_classes": [
        "Device information",
        "Email addresses",
        "Genders",
        "Geographic locations",
        "IP addresses",
        "Names"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2021, reports emerged of a data breach of Indonesia's telecommunications company, IndiHome. Over 26M rows of data alleged to have been sourced from the company was posted to a popular hacking forum and contained 12.6M unique email addresses alongside names, IP addresses, genders and geographic locations. The most recent data was stamped as being recorded in November 2019.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#IndiHome"
    },
    {
      "name": "JamTangan",
      "title": "Jam Tangan",
      "domain": "jamtangan.com",
      "breach_date": "2021-07-06",
      "added": "2023-11-27T03:49:33.000Z",
      "accounts": 434784,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2021, the online Indonesian watch store, Jam Tangan (AKA Machtwatch), suffered a data breach that exposed over 400k customer records which were subsequently posted to a popular hacking forum. The data included email and IP addresses, names, phone numbers, physical addresses and passwords stored as either unsalted MD5 or bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#JamTangan"
    },
    {
      "name": "KitchenPal",
      "title": "KitchenPal",
      "domain": "kitchenpalapp.com",
      "breach_date": "2023-11-14",
      "added": "2023-11-24T20:42:36.000Z",
      "accounts": 98726,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Geographic locations",
        "Names",
        "Passwords",
        "Physical attributes",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2023, the kitchen management application KitchenPal suffered a data breach that exposed 146k lines of data. When contacted about the incident, KitchenPal advised the corpus of data came from a staging environment, although acknowledged it contained a small number of users for debugging purposes and included passwords that could not be used. Impacted data included almost 100k email addresses, names, geolocations and incomplete data on dates of birth, genders, height and weight, social media profile identifiers and bcrypt password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#KitchenPal"
    },
    {
      "name": "OMGPOP",
      "title": "OMGPOP",
      "domain": "omgpop.com",
      "breach_date": "2013-01-01",
      "added": "2023-11-20T21:20:28.000Z",
      "accounts": 7071293,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately 2013, the maker of the Draw Something game OMGPOP suffered a data breach. Formerly known as i'minlikewithyou or iilwy and later purchased by Zynga, the breach exposed over 7M email address and plain text password pairs which were later leaked in 2019.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#OMGPOP"
    },
    {
      "name": "Avito",
      "title": "Avito",
      "domain": "avito.ma",
      "breach_date": "2022-11-18",
      "added": "2023-11-14T06:51:25.000Z",
      "accounts": 2721835,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "IP addresses",
        "Names",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2022, the Moroccan e-commerce service Avito suffered a data breach that exposed the personal information of 2.7M customers. The data included name, email, phone, IP address and geographic location.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Avito"
    },
    {
      "name": "Chess",
      "title": "Chess.com (2023)",
      "domain": "chess.com",
      "breach_date": "2023-11-08",
      "added": "2023-11-10T02:02:26.000Z",
      "accounts": 1274077,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "Names",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2023, over 800k user records were scraped from the Chess.com website and posted to a popular hacking forum. The data included email address, name, username and the geographic location of the user. A further 446k scraped records were later provided and added to HIBP.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Chess"
    },
    {
      "name": "GamingMonk",
      "title": "GamingMonk",
      "domain": "gamingmonk.com",
      "breach_date": "2020-12-02",
      "added": "2023-11-05T23:05:37.000Z",
      "accounts": 654510,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2020, India's \"largest esports community\" GamingMonk (since acquired by and redirected to MPL Esports), suffered a data breach. The incident exposed 655k unique email addresses along with names, usernames, phone numbers, dates of birth and bcrypt password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GamingMonk"
    },
    {
      "name": "Fitmart",
      "title": "Fitmart",
      "domain": "fitmart.de",
      "breach_date": "2021-10-01",
      "added": "2023-11-03T05:57:10.000Z",
      "accounts": 214492,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2021, data from the German fitness supplies store Fitmart was obtained and later redistributed online. The data included 214k unique email addresses accompanied by plain text passwords, allegedly \"dehashed\" from the original stored version.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Fitmart"
    },
    {
      "name": "GameSprite",
      "title": "GameSprite",
      "domain": "gamesprite.me",
      "breach_date": "2019-12-17",
      "added": "2023-10-30T02:32:54.000Z",
      "accounts": 6164643,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2019, the now defunct gaming platform GameSprite suffered a data breach that exposed over 6M unique email addresses. The impacted data also included usernames, IP addresses and salted MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GameSprite"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
