{
  "query": {
    "page": "21"
  },
  "count": 20,
  "total": 1018,
  "page": 21,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T18:46:01.823Z",
    "kev": "2026-10-06T19:45:10.728Z",
    "epss": "2026-10-06T18:58:09.363Z",
    "breaches": "2026-10-06T18:46:01.457Z",
    "posts": "2026-10-06T19:46:10.731Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=21"
  },
  "warnings": [],
  "results": [
    {
      "name": "Doomworld",
      "title": "Doomworld",
      "domain": "doomworld.com",
      "breach_date": "2022-10-12",
      "added": "2022-10-24T06:10:24.000Z",
      "accounts": 34478,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2022, the Doomworld fourm suffered a data breach that exposed 34k member records. The data included email and IP addresses, usernames and bcrypt password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Doomworld"
    },
    {
      "name": "EPal",
      "title": "E-Pal",
      "domain": "epal.gg",
      "breach_date": "2022-04-15",
      "added": "2022-10-24T04:54:30.000Z",
      "accounts": 108887,
      "data_classes": [
        "Email addresses",
        "Purchases",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2022, the service dedicated to finding friends on Discord known as E-Pal disclosed a data breach. The compromised data included over 100k unique email addresses and usernames spanning approximately 1M orders. The data was subsequently distributed via a popular hacking forum.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#EPal"
    },
    {
      "name": "Wakanim",
      "title": "Wakanim",
      "domain": "wakanim.tv",
      "breach_date": "2022-08-28",
      "added": "2022-10-06T22:44:01.000Z",
      "accounts": 6706951,
      "data_classes": [
        "Browser user agent details",
        "Email addresses",
        "IP addresses",
        "Names",
        "Physical addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2022, the European streaming service Wakanim suffered a data breach which was subsequently advertised and sold on a popular hacking forum. The breach exposed 6.7M customer records including email, IP and physical addresses, names and usernames.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Wakanim"
    },
    {
      "name": "Bhinneka",
      "title": "Bhinneka",
      "domain": "bhinneka.com",
      "breach_date": "2020-01-27",
      "added": "2022-10-06T05:11:47.000Z",
      "accounts": 1274340,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In early 2020, the Indonesian consumer electronics website Bhinneka suffered a data breach that exposed almost 1.3M customer records. The data included email and physical addresses, names, genders, dates of birth, phone numbers and salted password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Bhinneka"
    },
    {
      "name": "TAPAirPortugal",
      "title": "TAP Air Portugal",
      "domain": "flytap.com",
      "breach_date": "2022-08-25",
      "added": "2022-09-23T05:33:05.000Z",
      "accounts": 6083479,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Nationalities",
        "Phone numbers",
        "Physical addresses",
        "Salutations",
        "Spoken languages"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2022, the Portuguese airline TAP Air Portugal was the target of a ransomware attack perpetrated by the Ragnar Locker gang who later leaked the compromised data via a public dark web site. Over 5M unique email addresses were exposed alongside other personal data including names, genders, DoBs, phone numbers and physical addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#TAPAirPortugal"
    },
    {
      "name": "BrandNewTube",
      "title": "Brand New Tube",
      "domain": "brandnewtube.com",
      "breach_date": "2022-08-14",
      "added": "2022-09-08T08:00:37.000Z",
      "accounts": 349627,
      "data_classes": [
        "Email addresses",
        "Genders",
        "IP addresses",
        "Passwords",
        "Private messages",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2022, the streaming website Brand New Tube suffered a data breach that exposed the personal information of almost 350k subscribers. The impacted data included email and IP addresses, usernames, genders, passwords stored as unsalted SHA-1 hashes and private messages.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BrandNewTube"
    },
    {
      "name": "Stripchat",
      "title": "Stripchat",
      "domain": "stripchat.com",
      "breach_date": "2021-11-05",
      "added": "2022-08-31T06:17:42.000Z",
      "accounts": 10001355,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2021, the live sex cams and adult chat website Stripchat left several databases exposed and unsecured. In June the following year, over 10M Stripchat records appeared on a popular hacking forum. The exposed data included usernames, email addresses and IP addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Stripchat"
    },
    {
      "name": "Start",
      "title": "START",
      "domain": "start.film",
      "breach_date": "2021-06-01",
      "added": "2022-08-30T02:48:30.000Z",
      "accounts": 7455386,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "Names",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2022, news broke of an attack against the Russian streaming service \"START\". The incident led to the exposure of 44M records containing 7.4M unique email addresses. The impacted data also included the subscriber's country and password hash. START subsequently acknowledged the incident in a Telegram post and stated that the data dated back to 2021.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Start"
    },
    {
      "name": "Banorte",
      "title": "Banorte",
      "domain": "banorte.com",
      "breach_date": "2014-08-18",
      "added": "2022-08-18T23:36:24.000Z",
      "accounts": 2107000,
      "data_classes": [
        "Account balances",
        "Email addresses",
        "Genders",
        "Government issued IDs",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2022, millions of records from Mexican bank \"Banorte\" were publicly dumped on a popular hacking forum including 2.1M unique email addresses, physical addresses, names, phone numbers, RFC (tax) numbers, genders and bank balances. Banorte have stated that the data is \"outdated\", although have not yet indicated how far back it dates to. Anecdotal feedback from HIBP subscribers suggests the data may date back 8 years to 2014.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Banorte"
    },
    {
      "name": "SitePoint",
      "title": "SitePoint",
      "domain": "sitepoint.com",
      "breach_date": "2020-06-20",
      "added": "2022-08-17T08:21:50.000Z",
      "accounts": 1021790,
      "data_classes": [
        "Bios",
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2020, the web development site SitePoint suffered a data breach that exposed over 1M customer records. Impacted data included email and IP addresses, names, usernames, bios and passwords stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#SitePoint"
    },
    {
      "name": "Shitexpress",
      "title": "Shitexpress",
      "domain": "shitexpress.com",
      "breach_date": "2022-08-08",
      "added": "2022-08-16T22:40:35.000Z",
      "accounts": 23817,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Physical addresses",
        "Private messages",
        "Purchases"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2022, the online faeces delivery service Shitexpress suffered a data breach that exposed 24k unique email addresses. The addresses spanned invoices, gift cards, promotions and PayPal records. The breach also exposed the IP and email addresses of senders, physical addresses of recipients and messages accompanying the shit delivery.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Shitexpress"
    },
    {
      "name": "Twitter",
      "title": "Twitter",
      "domain": "twitter.com",
      "breach_date": "2022-01-01",
      "added": "2022-08-13T02:29:52.000Z",
      "accounts": 6682453,
      "data_classes": [
        "Bios",
        "Email addresses",
        "Geographic locations",
        "Names",
        "Phone numbers",
        "Profile photos",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2022, a vulnerability in Twitter's platform allowed an attacker to build a database of the email addresses and phone numbers of millions of users of the social platform. In a disclosure notice later shared in August 2022, Twitter advised that the vulnerability was related to a bug introduced in June 2021 and that they are directly notifying impacted customers. The impacted data included either email address or phone number alongside other public information including the username, display name, bio, location and profile photo. The data included 6.7M unique email addresses across both active and suspended accounts, the latter appearing in a separate list of 1.4M addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Twitter"
    },
    {
      "name": "QuestionPro",
      "title": "QuestionPro",
      "domain": "questionpro.com",
      "breach_date": "2022-05-21",
      "added": "2022-08-05T00:05:34.000Z",
      "accounts": 22229637,
      "data_classes": [
        "Browser user agent details",
        "Email addresses",
        "IP addresses",
        "Survey results"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2022, the survey website QuestionPro was the target of an extortion attempt relating to an alleged data breach. Over 100GB of data containing 22M unique email addresses (some of which appear to be generated by the platform), are alleged to have been extracted from the service along with IP addresses, browser user agents and results relating to surveys. QuestionPro would not confirm whether a breach had occurred (although they did confirm they were the target of an extortion attempt), so the data was initially flagged as \"unverified\". Subsequent verification by impacted HIBP subscribers later led to the removal of the unverified flag.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#QuestionPro"
    },
    {
      "name": "TunedGlobal",
      "title": "Tuned Global",
      "domain": "tunedglobal.com",
      "breach_date": "2016-03-16",
      "added": "2022-08-03T00:00:15.000Z",
      "accounts": 985586,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2021, data from a number of breached services including Tuned Global were released to a public hacking forum. The breach appears to date back to 2016 and includes 985k records containing email addresses, names, a small number of physical addresses and phone numbers and passwords stored in plain text.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#TunedGlobal"
    },
    {
      "name": "MechoDownload",
      "title": "Mecho Download",
      "domain": "mechodownload.com",
      "breach_date": "2013-10-31",
      "added": "2022-08-02T04:04:59.000Z",
      "accounts": 437928,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2013, the (now defunct) downloads website \"Mecho Download\" suffered a data breach that exposed 438k records. Data from the vBulletin based website included email and IP addresses, usernames and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MechoDownload"
    },
    {
      "name": "Battlefy",
      "title": "Battlefy",
      "domain": "battlefy.com",
      "breach_date": "2016-01-11",
      "added": "2022-07-29T00:24:33.000Z",
      "accounts": 83610,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2016, the esports website Battlefy suffered a data breach that exposed 83k customer records. The impacted data included email addresses, usernames and passwords stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Battlefy"
    },
    {
      "name": "Shadi",
      "title": "Shadi.com",
      "domain": "shadi.com",
      "breach_date": "2016-07-09",
      "added": "2022-07-20T07:07:31.000Z",
      "accounts": 2021984,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2016, the Muslim dating site Shadi.com suffered a data breach that exposed over 2M members' email addresses. The breach also exposed passwords stored as MD5 hashes alongside their plain text equivalents.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Shadi"
    },
    {
      "name": "PPCGeeks",
      "title": "PPCGeeks",
      "domain": "ppcgeeks.com",
      "breach_date": "2016-08-19",
      "added": "2022-07-18T22:20:50.000Z",
      "accounts": 492518,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2016, the pocket PC fan site forum PPCGeeks suffered a data breach that exposed over 490k records. The breach of the vBulletin forum exposed email and IP addresses, usernames, dates of birth and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#PPCGeeks"
    },
    {
      "name": "JukinMedia",
      "title": "JukinMedia",
      "domain": "jukinmedia.com",
      "breach_date": "2021-10-28",
      "added": "2022-07-17T04:50:13.000Z",
      "accounts": 314290,
      "data_classes": [
        "Email addresses",
        "Employers",
        "IP addresses",
        "Names",
        "Occupations",
        "Passwords",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2021, the \"global leader in user-generated entertainment\" Jukin Media suffered a data breach. The breach exposed 13GB of code, configuration and data consisting of 314k unique email addresses along with names, phone numbers, IP addresses and bcrypt password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#JukinMedia"
    },
    {
      "name": "Famm",
      "title": "Famm",
      "domain": "famm.us",
      "breach_date": "2020-10-08",
      "added": "2022-07-16T09:57:48.000Z",
      "accounts": 535240,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In late 2020, the Japanese family photos website Famm suffered a data breach that subsequently exposed 1.3M customer records, including 535k unique email addresses. Impacted data also included names, dates of birth, genders and passwords stored as SHA-256 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Famm"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
