{
  "query": {
    "page": "22"
  },
  "count": 20,
  "total": 1018,
  "page": 22,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T18:46:01.823Z",
    "kev": "2026-10-06T19:45:10.728Z",
    "epss": "2026-10-06T18:58:09.363Z",
    "breaches": "2026-10-06T18:46:01.457Z",
    "posts": "2026-10-06T19:46:10.731Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=22"
  },
  "warnings": [],
  "results": [
    {
      "name": "Eskimi",
      "title": "Eskimi",
      "domain": "eskimi.com",
      "breach_date": "2020-09-25",
      "added": "2022-07-16T07:51:26.000Z",
      "accounts": 1197620,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Geographic locations",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In late 2020, the AdTech platform Eskimi suffered a data breach that exposed 26M records with 1.2M unique email addresses. The data included usernames, dates of birth, genders and passwords stored as unsalted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Eskimi"
    },
    {
      "name": "LaPosteMobile",
      "title": "La Poste Mobile",
      "domain": "lapostemobile.fr",
      "breach_date": "2022-07-04",
      "added": "2022-07-14T00:29:21.000Z",
      "accounts": 533886,
      "data_classes": [
        "Bank account numbers",
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2022, the French telecommunications company La Poste Mobile was the target of an attack by the LockBit ransomware which resulted in company data being published publicly. The impacted data included 533k unique email addresses along with names, physical addresses, phone numbers, dates of births, genders and banking information. 10 days after the attack, the La Poste Mobile website remained offline.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#LaPosteMobile"
    },
    {
      "name": "Mangatoon",
      "title": "Mangatoon",
      "domain": "mangatoon.mobi",
      "breach_date": "2022-05-13",
      "added": "2022-07-06T21:04:25.000Z",
      "accounts": 23040238,
      "data_classes": [
        "Auth tokens",
        "Avatars",
        "Email addresses",
        "Genders",
        "Names",
        "Passwords",
        "Social media profiles",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2022, the Hong Kong based Manga service Mangatoon suffered a data breach that exposed 23M subscriber records. The breach exposed names, email addresses, genders, social media account identities, auth tokens from social logins and passwords stored as salted MD5 hashes. Mangatoon did not respond to multiple attempts to make contact regarding the breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Mangatoon"
    },
    {
      "name": "CapialEconomics",
      "title": "Capital Economics",
      "domain": "capitaleconomics.com",
      "breach_date": "2020-12-12",
      "added": "2022-07-04T08:16:36.000Z",
      "accounts": 263829,
      "data_classes": [
        "Email addresses",
        "Employers",
        "Job titles",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2020, the economic research company Capital Economics suffered a data breach that exposed 263k customer records. The exposed data included email and physical addresses, names, phone numbers, job titles and the employer of impacted customers.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CapialEconomics"
    },
    {
      "name": "Bookchor",
      "title": "Bookchor",
      "domain": "bookchor.com",
      "breach_date": "2021-01-28",
      "added": "2022-07-03T23:41:38.000Z",
      "accounts": 498297,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "IP addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2021, the Indian book trading website Bookchor suffered a data breach that exposed half a million customer records. The exposed data included email and IP addresses, names, genders, dates of birth, phone numbers and passwords stored as unsalted MD5 hashes. The data was subsequently traded on a popular hacking forum.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Bookchor"
    },
    {
      "name": "BourseDesVols",
      "title": "Bourse des Vols",
      "domain": "bourse-des-vols.com",
      "breach_date": "2021-01-12",
      "added": "2022-07-03T05:17:56.000Z",
      "accounts": 1460130,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Flights taken",
        "IP addresses",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2021, the French travel company Bourse des Vols suffered a data breach that exposed 1.46M unique email addresses across more than 1.2k .sql files and over 9GB of data. The impacted data exposed personal information and travel histories including names, phone numbers, IP and physical addresses, dates of birth along with flights taken and purchases.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BourseDesVols"
    },
    {
      "name": "DivXSubTitles",
      "title": "DivX SubTitles",
      "domain": "divxsubtitles.net",
      "breach_date": "2010-01-01",
      "added": "2022-06-14T02:57:46.000Z",
      "accounts": 783058,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately 2010, the now defunct website DivX SubTitles suffered a data breach that exposed 783k user accounts including email addresses, usernames and plain text passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#DivXSubTitles"
    },
    {
      "name": "CTARS",
      "title": "CTARS",
      "domain": "ctars.com.au",
      "breach_date": "2021-05-21",
      "added": "2022-05-31T22:58:15.000Z",
      "accounts": 12314,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Passwords",
        "Personal health data",
        "Phone numbers",
        "Physical addresses",
        "Salutations",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2022, the client management system for the Australian government's NDIS (National Disability Insurance Scheme) suffered a data breach which was subsequently posted to an online hacking forum. The CTARS cloud platform is used by care providers to record information about NDIS participants and often contains sensitive medical information. Impacted data includes over 12k unique email addresses, physical addresses, names, dates of birth, phone numbers and data related to patient conditions and treatments.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CTARS"
    },
    {
      "name": "Adecco",
      "title": "Adecco",
      "domain": "adecco.com",
      "breach_date": "2021-01-03",
      "added": "2022-05-31T06:33:24.000Z",
      "accounts": 4284538,
      "data_classes": [
        "Email addresses",
        "Genders",
        "Geographic locations",
        "Marital statuses",
        "Names",
        "Passwords",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2021, news broke of a massive data breach impacting millions of Adecco customers in South America which was subsequently sold on a popular hacking forum. The breach exposed over 4M unique email addresses as well as genders, dates of birth, marital statuses, phone numbers and passwords stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Adecco"
    },
    {
      "name": "MGM2022Update",
      "title": "MGM Resorts (2022 Update)",
      "domain": "mgmresorts.com",
      "breach_date": "2019-07-25",
      "added": "2022-05-29T01:43:46.000Z",
      "accounts": 24842001,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2019, MGM Resorts discovered a data breach of one of their cloud services. The breach included 10.6M guest records with 3.1M unique email addresses stemming back to 2017. In May 2022, a superset of the data totalling almost 25M unique email addresses across 142M rows was extensively shared on Telegram. On analysis, it's highly likely the data stems from the same incident with 142M records having been discovered for sale on a dark web marketplace in mid-2020. The exposed data included email and physical addresses, names, phone numbers and dates of birth.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MGM2022Update"
    },
    {
      "name": "PreenMe",
      "title": "Preen.Me",
      "domain": "preen.me",
      "breach_date": "2020-05-25",
      "added": "2022-05-26T00:58:43.000Z",
      "accounts": 236105,
      "data_classes": [
        "Email addresses",
        "Names",
        "Social media profiles",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2020, social media marketing company Preen.Me was the target of a ransom attack that resulted in hundreds of thousands of records being publicly posted. Over 236k unique email addresses were exposed in the attack alongside names, usernames and links to social media profiles.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#PreenMe"
    },
    {
      "name": "AmartFurniture",
      "title": "Amart Furniture",
      "domain": "amartfurniture.com.au",
      "breach_date": "2022-05-16",
      "added": "2022-05-25T23:43:23.000Z",
      "accounts": 108940,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2022, the Australian retailer Amart Furniture advised that their warranty claims database hosted on Amazon Web Services had been the target of a cyber attack. Over 100k records containing email and physical address, names, phone numbers and passwords stored as bcrypt hashes were exposed and shared online by the attacker.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#AmartFurniture"
    },
    {
      "name": "Wendys",
      "title": "Wendy's",
      "domain": "wendys.com.ph",
      "breach_date": "2018-03-31",
      "added": "2022-05-24T23:50:35.000Z",
      "accounts": 52485,
      "data_classes": [
        "Education levels",
        "Email addresses",
        "IP addresses",
        "Job applications",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2018, Wendy's in the Philippines suffered a data breach which impacted over 52k customers and job applicants. The breach exposed extensive personal information including names, email and IP addresses, physical addresses, phone numbers and passwords stored as MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Wendys"
    },
    {
      "name": "SirHurt",
      "title": "SirHurt",
      "domain": "sirhurt.net",
      "breach_date": "2021-04-23",
      "added": "2022-05-24T05:06:08.000Z",
      "accounts": 90655,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2021, the the Roblox cheats website SirHurt suffered a data breach that exposed over 90k customer records. The exposed data included email and IP addresses, usernames and passwords stored as MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#SirHurt"
    },
    {
      "name": "Fanpass",
      "title": "Fanpass",
      "domain": "fanpass.co.uk",
      "breach_date": "2022-04-30",
      "added": "2022-05-24T03:55:30.000Z",
      "accounts": 112251,
      "data_classes": [
        "Email addresses",
        "Genders",
        "Names",
        "Partial dates of birth",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Purchases",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2022, the UK based website for buying and selling soccer tickets Fanpass suffered a data breach which exposed 112k customer records. Impacted data includes names, phone numbers, physical addresses, purchase histories and salted password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Fanpass"
    },
    {
      "name": "ReadNovel",
      "title": "Read Novel",
      "domain": "readnovel.com",
      "breach_date": "2019-05-01",
      "added": "2022-05-16T08:41:14.000Z",
      "accounts": 22424472,
      "data_classes": [
        "Email addresses",
        "Genders",
        "Passwords",
        "Phone numbers",
        "Usernames"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2019, the Chinese literature website Read Novel allegedly suffered a data breach that exposed 22M unique email addresses. Data also included usernames, genders, phone numbers and passwords stored as salted MD5 hashes. Read more about Chinese data breaches in Have I Been Pwned.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ReadNovel"
    },
    {
      "name": "BlackBerryFans",
      "title": "BlackBerry Fans",
      "domain": "blackberryfans.org",
      "breach_date": "2022-05-06",
      "added": "2022-05-16T02:15:13.000Z",
      "accounts": 174168,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2022, the Chinese BlackBerry enthusiasts website BlackBerry Fans suffered a data breach that exposed 174k member records. The impacted data included usernames, email and IP addresses and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BlackBerryFans"
    },
    {
      "name": "OGUsers2021",
      "title": "OGUsers (2021 breach)",
      "domain": "ogusers.com",
      "breach_date": "2021-04-11",
      "added": "2022-05-16T00:40:46.000Z",
      "accounts": 348302,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2021, the account hijacking and SIM swapping forum OGusers suffered a data breach, the fourth since December 2018. The breach was subsequently sold on a rival hacking forum and contained usernames, email and IP addresses and passwords stored as either salted MD5 or argon2 hashes. A total of 348k unique email addresses appeared in the breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#OGUsers2021"
    },
    {
      "name": "ParagonCheats",
      "title": "Paragon Cheats",
      "domain": "paragoncheats.com",
      "breach_date": "2021-05-22",
      "added": "2022-05-14T02:26:40.000Z",
      "accounts": 188089,
      "data_classes": [
        "Browser user agent details",
        "Email addresses",
        "IP addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2021, the Grand Theft Auto Online cheats website Paragon Cheats suffered a data breach that lead to the shutdown of the service. The breach exposed 188k customer records including usernames, email and IP addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ParagonCheats"
    },
    {
      "name": "PayHere",
      "title": "PayHere",
      "domain": "payhere.lk",
      "breach_date": "2022-03-27",
      "added": "2022-05-02T05:26:25.000Z",
      "accounts": 1580249,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Partial credit card data",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In late March 2022, the Sri Lankan payment gateway PayHere suffered a data breach that exposed more than 65GB of payment records including over 1.5M unique email addresses. The data also included IP and physical addresses, names, phone numbers, purchase histories and partially obfuscated credit card data (card type, first 6 and last 4 digits plus expiry date). A month later, PayHere published a blog on the incident titled Ensuring Integrity on PayHere Cybersecurity Incident.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#PayHere"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
