{
  "query": {
    "page": "17"
  },
  "count": 20,
  "total": 1018,
  "page": 17,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T10:45:36.976Z",
    "kev": "2026-10-06T11:44:39.558Z",
    "epss": "2026-10-06T06:57:27.860Z",
    "breaches": "2026-10-06T06:45:27.314Z",
    "posts": "2026-10-06T11:45:39.554Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=17"
  },
  "warnings": [],
  "results": [
    {
      "name": "MemeChat",
      "title": "MemeChat",
      "domain": "memechat.app",
      "breach_date": "2022-06-01",
      "added": "2023-10-29T05:02:56.000Z",
      "accounts": 4348570,
      "data_classes": [
        "Email addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2022, \"the ultimate hub of memes\" MemeChat suffered a data breach that exposed 7.4M records. Alleged to be due to a misconfigured Elasticsearch instance, the data contained 4.3M unique email addresses alongside usernames.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MemeChat"
    },
    {
      "name": "Toumei",
      "title": "Toumei",
      "domain": "toumei.co.jp",
      "breach_date": "2023-10-18",
      "added": "2023-10-27T07:16:19.000Z",
      "accounts": 76682,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2023, the Japanese consultancy firm Toumei suffered a data breach. The breach exposed over 100M lines and 10GB of data including 77k unique email addresses along with names, phone numbers and physical addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Toumei"
    },
    {
      "name": "Tunngle",
      "title": "Tunngle",
      "domain": "tunngle.net",
      "breach_date": "2016-07-01",
      "added": "2023-10-21T21:20:33.000Z",
      "accounts": 8192928,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In 2016, the now defunct global LAN gaming network Tunngle suffered a data breach that exposed 8.2M unique email addresses. The compromised data also included usernames, IP addresses and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Tunngle"
    },
    {
      "name": "Sphero",
      "title": "Sphero",
      "domain": "sphero.com",
      "breach_date": "2023-09-09",
      "added": "2023-10-20T07:16:25.000Z",
      "accounts": 832255,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Geographic locations",
        "Names",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2023, over 1M rows of data from the educational robots company Sphero was posted to a popular hacking forum. The data contained 832k unique email addresses alongside names, usernames, dates of birth and geographic locations.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Sphero"
    },
    {
      "name": "AndroidLista",
      "title": "AndroidLista",
      "domain": "androidlista.com",
      "breach_date": "2021-07-28",
      "added": "2023-10-17T21:15:55.000Z",
      "accounts": 6640643,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2021, the Android applications and games review site AndroidLista suffered a data breach. The incident exposed 6.6M user records containing email addresses, names, usernames and passwords stored as salted SHA-1 hashes, all of which were subsequently posted to a popular hacking forum. AndroidLista did not respond when contacted about the breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#AndroidLista"
    },
    {
      "name": "Phoenix",
      "title": "Phoenix",
      "domain": "phoenixim.ddns.net",
      "breach_date": "2021-06-05",
      "added": "2023-10-17T02:27:58.000Z",
      "accounts": 74776,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2021, the \"vintage messaging reborn\" service Phoenix suffered a data breach that exposed 75k unique email addresses. The breach also exposed IP addresses, usernames and passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Phoenix"
    },
    {
      "name": "BVD",
      "title": "Public Business Data",
      "domain": "bvdinfo.com",
      "breach_date": "2021-08-19",
      "added": "2023-10-09T07:05:10.000Z",
      "accounts": 27917714,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Job titles",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately August 2021, hundreds of gigabytes of business data collated from public sources was obtained and later published to a popular hacking forum. Sourced from a customer of Bureau van Dijk's (BvD) \"Orbis\" product, the corpus of data released contained hundreds of millions of lines about corporations and individuals, including personal information such as names and dates of birth. The data also included 28M unique email addresses along with physical addresses (presumedly corporate locations), phone numbers and job titles. There was no unauthorised access to BvD's systems, nor did the incident expose any of their or parent company's Moody's clients.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BVD"
    },
    {
      "name": "PaySystemTech",
      "title": "PaySystem.tech",
      "domain": "paysystem.tech",
      "breach_date": "2022-04-29",
      "added": "2023-10-08T23:07:02.000Z",
      "accounts": 1410764,
      "data_classes": [
        "Credit cards",
        "Email addresses",
        "Purchases"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2022, data alleged to have been sourced from the Russian payment provider PaySystem.tech appeared in hacking circles where it was made publicly available for download. Consisting of 16M rows with 1.4M unique email addresses, the data also included purchases and full credit card numbers and expiry dates. The data could not be independently attributed back to PaySystem.tech and the breach has been flagged as \"unverified\".",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#PaySystemTech"
    },
    {
      "name": "Hjedd",
      "title": "Hjedd",
      "domain": "hjedd.com",
      "breach_date": "2022-07-18",
      "added": "2023-10-05T03:41:42.000Z",
      "accounts": 13204029,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2022, the Chinese adult website Hjedd was found to be leaking more than 13M customer records which subsequently appeared on a popular hacking forum. The exposed data included email and IP addresses, usernames and passwords stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Hjedd"
    },
    {
      "name": "Activision",
      "title": "Activision",
      "domain": "activision.com",
      "breach_date": "2022-12-04",
      "added": "2023-10-03T07:09:49.000Z",
      "accounts": 16006,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "Job titles",
        "Names",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2022, attackers socially engineered an Activision HR employee into disclosing information which led to the breach of almost 20k employee records. The data contained 16k unique email addresses along with names, phone numbers, job titles and the office location of the employee. Activision advised that no sensitive employee information was included in the breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Activision"
    },
    {
      "name": "HorseIsle",
      "title": "Horse Isle",
      "domain": "horseisle.com",
      "breach_date": "2020-09-19",
      "added": "2023-10-02T06:47:11.000Z",
      "accounts": 27786,
      "data_classes": [
        "Email addresses",
        "Genders",
        "IP addresses",
        "Names",
        "Passwords",
        "Purchases",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2020 then again in September that same year, Horse Isle \"The Secrent Land of Horses\" suffered a data breach. The incident exposed 28k unique email addresses along with names, usernames, IP addresses, genders, purchases and plain text passwords. The system also stored and exposed failed password attempts for each user with the password retained in plain text.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#HorseIsle"
    },
    {
      "name": "dBforums",
      "title": "dBforums",
      "domain": "dbforums.com",
      "breach_date": "2016-07-04",
      "added": "2023-09-20T07:26:28.000Z",
      "accounts": 363468,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2016, a data breach of the now defunct database forum \"dBforums\" appeared for sale alongside several others hacked from the parent company, Penton. The breach of the vBulletin based forum contained 363k unique email addresses alongside usernames, IP addresses, dates of birth and salted MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#dBforums"
    },
    {
      "name": "MalindoAir",
      "title": "MalindoAir",
      "domain": "malindoair.com",
      "breach_date": "2019-03-01",
      "added": "2023-09-14T08:52:38.000Z",
      "accounts": 4328232,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Loyalty program details",
        "Names",
        "Nationalities",
        "Passport numbers",
        "Phone numbers",
        "Physical addresses",
        "Salutations"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In early 2019, the Malaysian airline Malindo Air suffered a data breach that exposed tens of millions of customer records. Containing 4.3M unique email addresses, the breach also exposed extensive personal information including names, dates of birth, genders, physical addresses, phone numbers and passport details. The data was later extensively shared on popular hacking forums.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MalindoAir"
    },
    {
      "name": "VivaAir",
      "title": "Viva Air",
      "domain": "vivaair.com",
      "breach_date": "2022-03-14",
      "added": "2023-09-11T07:11:30.000Z",
      "accounts": 932232,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Partial credit card data",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2022, the now defunct Colombian airline Viva Air suffered a data breach and subsequent ransomware attack. Among a trove of other ransomed data, the incident exposed a log of 2.6M transactions with 932k unique email addresses, physical and IP addresses, names, phone numbers and partial credit card data (last 4 digits).",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#VivaAir"
    },
    {
      "name": "Dymocks",
      "title": "Dymocks",
      "domain": "dymocks.com.au",
      "breach_date": "2023-06-20",
      "added": "2023-09-08T07:35:22.000Z",
      "accounts": 836120,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2023, the Australian book retailer Dymocks announced a data breach. The data dated back to June 2023 and contained 1.2M records with 836k unique email addresses. The breach also exposed names, dates of birth, genders, phone numbers and physical addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Dymocks"
    },
    {
      "name": "CERTPolandPhish",
      "title": "Phished Data via CERT Poland",
      "domain": null,
      "breach_date": "2023-02-25",
      "added": "2023-08-31T05:53:44.000Z",
      "accounts": 67943,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2023, CERT Poland observed a phishing campaign that collected credentials from 68k victims. The campaign collected email addresses and passwords via a phishing email masquerading as a purchase order confirmation. CERT Poland identified a further 202 other phishing campaigns operating on the same C2 server, which has now been dismantled.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CERTPolandPhish"
    },
    {
      "name": "Pampling",
      "title": "Pampling",
      "domain": "pampling.com",
      "breach_date": "2020-01-04",
      "added": "2023-08-31T05:09:24.000Z",
      "accounts": 383468,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2020, the online clothing retailer Pampling suffered a data breach that exposed 383k unique customer email addresses. The data was later shared on a popular hacking forum and also included names, usernames and unsalted MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Pampling"
    },
    {
      "name": "PlayCyberGames",
      "title": "PlayCyberGames",
      "domain": "playcybergames.com",
      "breach_date": "2023-08-09",
      "added": "2023-08-31T02:22:55.000Z",
      "accounts": 3681753,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2023, PlayCyberGames which \"allows users to play any games with LAN function or games using IP address\" suffered a data breach which exposed 3.7M customer records. The data included email addresses, usernames and MD5 password hashes with a constant value in the \"salt\" field. PlayCyberGames did not respond to multiple attempts to disclose the breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#PlayCyberGames"
    },
    {
      "name": "Qakbot",
      "title": "Qakbot",
      "domain": null,
      "breach_date": "2023-08-29",
      "added": "2023-08-29T19:40:03.000Z",
      "accounts": 6431319,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": true,
      "malware": true,
      "stealer_log": false,
      "description": "In August 2023, the US Justice Department announced a multinational operation involving actions in the United States, France, Germany, the Netherlands, and the United Kingdom to disrupt the botnet and malware known as Qakbot and take down its infrastructure. After the takedown, 6.43M email addresses were provided to HIBP to help notify victims of the malware.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Qakbot"
    },
    {
      "name": "SevenRooms",
      "title": "SevenRooms",
      "domain": "sevenrooms.com",
      "breach_date": "2022-12-11",
      "added": "2023-08-24T21:49:00.000Z",
      "accounts": 1205385,
      "data_classes": [
        "Email addresses",
        "Names",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2022, over 400GB of data belonging to restaurant customer management platform SevenRooms was posted for sale to a popular hacking forum. The data included 1.2M unique email addresses alongside names and purchases. SevenRooms advised that the breach was due to unauthorised access of \"a file transfer interface of a third-party vendor\".",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#SevenRooms"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
