{
  "query": {
    "page": "20"
  },
  "count": 20,
  "total": 1018,
  "page": 20,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T14:45:46.442Z",
    "kev": "2026-10-06T14:44:46.299Z",
    "epss": "2026-10-06T12:57:42.533Z",
    "breaches": "2026-10-06T12:45:41.825Z",
    "posts": "2026-10-06T14:45:46.442Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=20"
  },
  "warnings": [],
  "results": [
    {
      "name": "LimeVPN",
      "title": "LimeVPN",
      "domain": "limevpn.com",
      "breach_date": "2020-10-08",
      "added": "2023-02-06T21:42:01.000Z",
      "accounts": 23348,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2020, the VPN provider LimeVPN suffered a data breach that exposed the personal information of tens of thousands of customers. The data included email, IP and physical addresses, names, phone numbers, purchase histories and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#LimeVPN"
    },
    {
      "name": "TruthFinder",
      "title": "Truth Finder",
      "domain": "truthfinder.com",
      "breach_date": "2019-04-12",
      "added": "2023-02-04T07:02:52.000Z",
      "accounts": 8159573,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In 2019, the public records search service TruthFinder suffered a data breach that later came to light in early 2023. The data included over 8M unique customer email addresses, names, phone numbers and passwords stored as scrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#TruthFinder"
    },
    {
      "name": "InstantCheckmate",
      "title": "Instant Checkmate",
      "domain": "instantcheckmate.com",
      "breach_date": "2019-04-12",
      "added": "2023-02-04T00:26:28.000Z",
      "accounts": 11943887,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In 2019, the public records search service Instant Checkmate suffered a data breach that later came to light in early 2023. The data included almost 12M unique customer email addresses, names, phone numbers and passwords stored as scrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#InstantCheckmate"
    },
    {
      "name": "SchoolDistrict42",
      "title": "School District 42",
      "domain": "sd42.ca",
      "breach_date": "2023-01-15",
      "added": "2023-02-02T05:27:50.000Z",
      "accounts": 18850,
      "data_classes": [
        "Email addresses",
        "Names"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2023, Pitt Meadows School District 42 in British Columbia suffered a data breach. The incident exposed the names and email addresses of approximately 19k students and staff which were consequently redistributed on a popular hacking forum.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#SchoolDistrict42"
    },
    {
      "name": "PlanetIce",
      "title": "Planet Ice",
      "domain": "planet-ice.co.uk",
      "breach_date": "2023-01-14",
      "added": "2023-01-31T02:00:53.000Z",
      "accounts": 240488,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "IP addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2023, the UK-based ice skating rink booking service Planet Ice suffered a data breach. The incident exposed the personal data of 240k people including email and physical addresses, phone numbers, genders, dates of birth and passwords stored as MD5 hashes. The data also included the names, genders and dates of birth of children having parties.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#PlanetIce"
    },
    {
      "name": "KomplettFritid",
      "title": "KomplettFritid",
      "domain": "komplettfritid.no",
      "breach_date": "2021-02-01",
      "added": "2023-01-23T22:24:47.000Z",
      "accounts": 139401,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2023, the online Norwegian store KomplettFritid was reported as having had a data breach dating back to February 2021. The incident exposed 140k customer records including physical, email and IP addresses, names, phone numbers and passwords. Most passwords were stored as bcrypt hashes with a small number appearing in plain text.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#KomplettFritid"
    },
    {
      "name": "Autotrader",
      "title": "Autotrader",
      "domain": "autotrader.com",
      "breach_date": "2023-01-06",
      "added": "2023-01-23T06:24:21.000Z",
      "accounts": 20032,
      "data_classes": [
        "Email addresses",
        "Phone numbers",
        "Physical addresses",
        "Vehicle details",
        "Vehicle identification numbers (VINs)"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2023, 1.4M records from the Autotrader online vehicle marketplace appeared on a popular hacking forum. Autotrader stated that the \"data in question relates to aged listing data that was generally publicly available on our site at the time and open to automated collection methods\". The data contained 20k unique email addresses alongside physical addresses and phone numbers of dealers and vehicle details including VIN numbers.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Autotrader"
    },
    {
      "name": "Zurich",
      "title": "Zurich",
      "domain": "zurich.co.jp",
      "breach_date": "2023-01-08",
      "added": "2023-01-22T22:30:56.000Z",
      "accounts": 756737,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Vehicle details"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2023, the Japanese arm of Zurich insurance suffered a data breach that exposed 2.6M customer records with over 756k unique email addresses. The data was subsequently posted to a popular hacking forum and also included names, genders, dates of birth and details of insured vehicles.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Zurich"
    },
    {
      "name": "DoorDash",
      "title": "DoorDash",
      "domain": "doordash.com",
      "breach_date": "2022-08-02",
      "added": "2023-01-07T03:59:32.000Z",
      "accounts": 367476,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "Names",
        "Partial credit card data"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2022, the food ordering and delivery service DoorDash disclosed a data breach that impacted a portion of their customers. DoorDash attributed the breach to an unnamed \"third-party vendor\" they stated was the victim of a phishing campaign. The incident exposed 367k unique personal email addresses alongside names, post codes and partial card data, namely the brand, expiry data and last four digits of the card.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#DoorDash"
    },
    {
      "name": "SlideTeam",
      "title": "SlideTeam",
      "domain": "slideteam.net",
      "breach_date": "2021-04-06",
      "added": "2023-01-07T01:05:24.000Z",
      "accounts": 1464271,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2021, the \"world’s largest collection of pre-designed presentation slides\" SlideTeam had 1.4M records breached and later published to a popular hacking forum the following year. Allegedly sourced from a compromised Magento instance, the data included names, email addresses and passwords stored as salted hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#SlideTeam"
    },
    {
      "name": "Twitter200M",
      "title": "Twitter (200M)",
      "domain": "twitter.com",
      "breach_date": "2021-01-01",
      "added": "2023-01-05T20:49:16.000Z",
      "accounts": 211524284,
      "data_classes": [
        "Email addresses",
        "Names",
        "Social media profiles",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In early 2023, over 200M records scraped from Twitter appeared on a popular hacking forum. The data was obtained sometime in 2021 by abusing an API that enabled email addresses to be resolved to Twitter profiles. The subsequent results were then composed into a corpus of data containing email addresses alongside public Twitter profile information including names, usernames and follower counts.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Twitter200M"
    },
    {
      "name": "Deezer",
      "title": "Deezer",
      "domain": "deezer.com",
      "breach_date": "2019-04-22",
      "added": "2023-01-02T03:10:50.000Z",
      "accounts": 229037936,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Geographic locations",
        "IP addresses",
        "Names",
        "Spoken languages",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In late 2022, the music streaming service Deezer disclosed a data breach that impacted over 240M customers. The breach dated back to a mid-2019 backup exposed by a 3rd party partner which was subsequently sold and then broadly redistributed on a popular hacking forum. Impacted data included 229M unique email addresses, IP addresses, names, usernames, genders, DoBs and the geographic location of the customer.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Deezer"
    },
    {
      "name": "Benchmark",
      "title": "Benchmark",
      "domain": "benchmark.rs",
      "breach_date": "2019-11-01",
      "added": "2023-01-01T01:50:43.000Z",
      "accounts": 93343,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2019, the Serbian technology news website Benchmark suffered a breach of its forum that exposed 93k customer records. The breach exposed IP and email addresses, usernames and passwords stored as salted MD5 hashes. A forum administrator subsequently advised that the breach was due to the forum previously running on an outdated vBulletin instance.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Benchmark"
    },
    {
      "name": "Gemini",
      "title": "Gemini",
      "domain": "gemini.com",
      "breach_date": "2022-12-13",
      "added": "2022-12-16T16:47:43.000Z",
      "accounts": 5274214,
      "data_classes": [
        "Email addresses",
        "Partial phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In late 2022, a hacker posted a data set to a public hacking forum which they alleged was sourced from the Gemini crypto exchange, a claim that was later proven to be false as the data was traced back to an incident at a third-party vendor. The source of the breach was later established as being Twilio, who processed the data of some Gemini customers using their Authy service for 2FA. Twilio described the incident as stemming from a sophisticated social engineering attack designed to steal employee credentials.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Gemini"
    },
    {
      "name": "CoinTracker",
      "title": "CoinTracker",
      "domain": "cointracker.io",
      "breach_date": "2022-12-01",
      "added": "2022-12-12T08:55:48.000Z",
      "accounts": 1557153,
      "data_classes": [
        "Email addresses",
        "Partial phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2022, the Crypto & NFT taxes service CoinTracker reported a data breach that impacted over 1.5M of their customers. The company later attributed the breach to a compromise SendGrid in an attack that targeted multiple customers of the email provider. The breach exposed email addresses and partially redacted phone numbers, with CoinTracker advising that the later did not originate from their service.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CoinTracker"
    },
    {
      "name": "Abandonia2022",
      "title": "Abandonia (2022)",
      "domain": "abandonia.com",
      "breach_date": "2022-11-15",
      "added": "2022-12-07T06:04:17.000Z",
      "accounts": 919790,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2022, the gaming website dedicated to classic DOS games Abandonia suffered a data breach resulting in the exposure of 920k unique user records. This breach was in addition to another one 7 years earlier in 2015. The data contained email and IP addresses, usernames and salted MD5 hashes of passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Abandonia2022"
    },
    {
      "name": "NotAcxiom",
      "title": "Not Acxiom",
      "domain": null,
      "breach_date": "2020-06-21",
      "added": "2022-11-22T19:17:40.000Z",
      "accounts": 51730831,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In 2020, a corpus of data containing almost a quarter of a billion records spanning over 400 different fields was misattributed to database marketing company Acxiom and subsequently circulated within the hacking community. On review, Acxiom concluded that \"the claims are indeed false and that the data, which has been readily available across multiple environments, does not come from Acxiom and is in no way the subject of an Acxiom breach\". The data contained almost 52M unique email addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#NotAcxiom"
    },
    {
      "name": "GetRevengeOnYourEx",
      "title": "Get Revenge On Your Ex",
      "domain": "getrevengeonyourex.com",
      "breach_date": "2022-09-09",
      "added": "2022-11-15T01:57:17.000Z",
      "accounts": 79195,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2022, the revenge website Get Revenge On Your Ex suffered a data breach that exposed almost 80k unique email addresses. The data spanned both customers and victims including names, IP and physical addresses, phone numbers, purchase histories and plain text passwords. The data was subsequently shared on a public hacking forum, Get Revenge On Your Ex did not reply when contacted.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GetRevengeOnYourEx"
    },
    {
      "name": "GGCorp",
      "title": "GGCorp",
      "domain": "ggcorp.me",
      "breach_date": "2022-08-11",
      "added": "2022-11-08T07:35:13.000Z",
      "accounts": 2376330,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2022, the MMORPG website GGCorp suffered a data breach that exposed almost 2.4M unique email addresses. The data also included IP addresses, usernames and MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GGCorp"
    },
    {
      "name": "Lolzteam",
      "title": "Lolzteam",
      "domain": "lolzteam.net",
      "breach_date": "2018-05-13",
      "added": "2022-11-06T02:58:23.000Z",
      "accounts": 398011,
      "data_classes": [
        "Email addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2018, the Russian hacking forum Lolzteam suffered a data breach that exposed 400k members. The impacted data included usernames and email addresses which were later redistributed via another hacking forum.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Lolzteam"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
