{
  "query": {
    "page": "23"
  },
  "count": 20,
  "total": 1018,
  "page": 23,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T20:46:13.413Z",
    "kev": "2026-10-06T20:45:13.270Z",
    "epss": "2026-10-06T18:58:09.363Z",
    "breaches": "2026-10-06T18:46:01.457Z",
    "posts": "2026-10-06T20:46:13.412Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=23"
  },
  "warnings": [],
  "results": [
    {
      "name": "Aimware",
      "title": "Aimware",
      "domain": "aimware.net",
      "breach_date": "2019-04-28",
      "added": "2022-05-02T02:13:41.000Z",
      "accounts": 305470,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Private messages",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2019, the video game cheats website \"Aimware\" suffered a data breach that exposed hundreds of thousands of subscribers' personal information. Data included email and IP addresses, usernames, forum posts, private messages, website activity and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Aimware"
    },
    {
      "name": "DevilTorrents",
      "title": "Devil-Torrents.pl",
      "domain": "devil-torrents.pl",
      "breach_date": "2021-01-04",
      "added": "2022-05-01T23:56:34.000Z",
      "accounts": 63451,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In early 2021, the Polish torrents website Devil-Torrents.pl suffered a data breach. A subset of the data including 63k unique email addresses and cracked passwords were subsequently socialised on a popular data breach sharing service.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#DevilTorrents"
    },
    {
      "name": "Avvo",
      "title": "Avvo",
      "domain": "avvo.com",
      "breach_date": "2019-12-17",
      "added": "2022-04-15T03:39:42.000Z",
      "accounts": 4101101,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately December 2019, an alleged data breach of the lawyer directory service Avvo was published to an online hacking forum and used in an extortion scam (it's possible the exposure dates back earlier than that). The data contained 4.1M unique email addresses alongside SHA-1 hashes, most likely representing user passwords. Multiple attempts at contacting Avvo over the course of a week were unsuccessful and the authenticity of the data was eventually verified with common Avvo and HIBP subscribers.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Avvo"
    },
    {
      "name": "Travelio",
      "title": "Travelio",
      "domain": "travelio.com",
      "breach_date": "2021-11-23",
      "added": "2022-04-08T00:05:43.000Z",
      "accounts": 471376,
      "data_classes": [
        "Auth tokens",
        "Dates of birth",
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2021, the Indonesian real estate website Travelio suffered a data breach that exposed over 470k customer accounts. The data included email addresses, names, password hashes, phone numbers and for some accounts, dates of birth, physical address and Facebook auth tokens.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Travelio"
    },
    {
      "name": "RoyalEnfield",
      "title": "Royal Enfield",
      "domain": "royalenfield.com",
      "breach_date": "2019-01-01",
      "added": "2022-03-31T21:13:58.000Z",
      "accounts": 420873,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Social media profiles",
        "Vehicle details"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2020, motorcycle maker Royal Enfield left a database publicly exposed that resulted in the inadvertent publication of over 400k customers. The impacted data included email and physical addresses, names, motorcycle information, social media profiles, passwords, and other personal information.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#RoyalEnfield"
    },
    {
      "name": "ZAPHosting",
      "title": "ZAP-Hosting",
      "domain": "zap-hosting.com",
      "breach_date": "2021-11-22",
      "added": "2022-03-19T23:48:45.000Z",
      "accounts": 746682,
      "data_classes": [
        "Browser user agent details",
        "Chat logs",
        "Email addresses",
        "IP addresses",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2021, web host ZAP-Hosting suffered a data breach that exposed over 60GB of data containing 746k unique email addresses. The breach also contained support chat logs, IP addresses, names, purchases, physical addresses and phone numbers.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ZAPHosting"
    },
    {
      "name": "CDEK",
      "title": "CDEK",
      "domain": "cdek.ru",
      "breach_date": "2022-03-09",
      "added": "2022-03-17T06:19:02.000Z",
      "accounts": 19218203,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In early 2022, a collective known as IT Army whose stated goal is to \"completely de-anonymise most Russian users by leaking hundreds of gigabytes of databases\" published over 30GB of data allegedly sourced from Russian courier service CDEK. The data contained over 19M unique email addresses along with names and phone numbers. The authenticity of the breach could not be independently established and has been flagged as \"unverified\".",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CDEK"
    },
    {
      "name": "Robinhood",
      "title": "Robinhood",
      "domain": "robinhood.com",
      "breach_date": "2021-11-03",
      "added": "2022-03-03T22:47:32.000Z",
      "accounts": 5003937,
      "data_classes": [
        "Email addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2021, the online trading platform Robinhood suffered a data breach after a customer service representative was socially engineered. The incident exposed over 5M customer email addresses and 2M customer names.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Robinhood"
    },
    {
      "name": "MacGeneration",
      "title": "MacGeneration",
      "domain": "macg.co",
      "breach_date": "2022-01-29",
      "added": "2022-03-03T03:07:19.000Z",
      "accounts": 101004,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2022, the French Apple news website MacGeneration suffered a data breach. The incident exposed over 100k usernames, email addresses and passwords stored as salted SHA-512 hashes. After discovering the incident, MacGeneration self-submitted data to HIBP.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MacGeneration"
    },
    {
      "name": "NVIDIA",
      "title": "NVIDIA",
      "domain": "nvidia.com",
      "breach_date": "2022-02-23",
      "added": "2022-03-02T23:50:10.000Z",
      "accounts": 71335,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2022, microchip company NVIDIA suffered a data breach that exposed employee credentials and proprietary code. Impacted data included over 70k employee email addresses and NTLM password hashes, many of which were subsequently cracked and circulated within the hacking community.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#NVIDIA"
    },
    {
      "name": "GiveSendGo",
      "title": "GiveSendGo",
      "domain": "givesendgo.com",
      "breach_date": "2022-02-07",
      "added": "2022-02-15T00:01:14.000Z",
      "accounts": 89966,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "Names",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2022, the Christian fundraising service GiveSendGo suffered a data breach which exposed the personal data of 90k donors to the Canadian \"Freedom Convoy\" protest against vaccine mandates. The breach exposed names, email addresses, post codes, donation amount and comments left at the time of donation.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GiveSendGo"
    },
    {
      "name": "RedDoorz",
      "title": "RedDoorz",
      "domain": "reddoorz.com",
      "breach_date": "2020-09-04",
      "added": "2022-01-28T03:44:12.000Z",
      "accounts": 5890277,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Occupations",
        "Passwords",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2020, the hotel management & booking platform RedDoorz suffered a data breach that exposed over 5.8M user accounts. The breached data included names, email addresses, phone numbers, genders, dates of birth and passwords stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#RedDoorz"
    },
    {
      "name": "BTCAlpha",
      "title": "BTC-Alpha",
      "domain": "btc-alpha.com",
      "breach_date": "2021-11-02",
      "added": "2022-01-27T23:39:18.000Z",
      "accounts": 362426,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2021, the crypto exchange platform BTC-Alpha suffered a ransomware attack data breach after which customer data was publicly dumped. The impacted data included 362k email and IP addresses, usernames and passwords stored as PBKDF2 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BTCAlpha"
    },
    {
      "name": "ShockGore",
      "title": "ShockGore",
      "domain": "shockgore.com",
      "breach_date": "2020-08-11",
      "added": "2022-01-20T00:07:47.000Z",
      "accounts": 73944,
      "data_classes": [
        "Email addresses",
        "Genders",
        "IP addresses",
        "Passwords",
        "Private messages",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2020, the website for sharing graphic videos and images of gore and animal cruelty suffered a data breach. The breach exposed 74k unique email addresses alongside usernames, IP addresses, genders and unsalted SHA-1 password hashes. Private messages were also exposed, many containing requests for material of a depraved nature.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ShockGore"
    },
    {
      "name": "OpenSubtitles",
      "title": "Open Subtitles",
      "domain": "opensubtitles.org",
      "breach_date": "2021-08-01",
      "added": "2022-01-19T04:51:36.000Z",
      "accounts": 6783158,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2021, the subtitling website Open Subtitles suffered a data breach and subsequent ransom demand. The breach exposed almost 7M subscribers' personal data including email and IP addresses, usernames, the country of the user and passwords stored as unsalted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#OpenSubtitles"
    },
    {
      "name": "Upstox",
      "title": "Upstox",
      "domain": "upstox.com",
      "breach_date": "2021-04-08",
      "added": "2022-01-19T03:29:03.000Z",
      "accounts": 111002,
      "data_classes": [
        "Bank account numbers",
        "Dates of birth",
        "Email addresses",
        "Family members' names",
        "Genders",
        "Government issued IDs",
        "Income levels",
        "Marital statuses",
        "Nationalities",
        "Occupations",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2021, Indian brokerage firm Upstox suffered a data breach. The incident exposed extensive personal information on over 100k customers including names, genders, dates of birth, physical addresses, banking information and passwords stored as bcrypt hashes. Extensive \"know your customer\" information was also exposed including scans of bank statements, cheques and identity documents complete with Aadhaar numbers.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Upstox"
    },
    {
      "name": "CardingMafiaDec2021",
      "title": "Carding Mafia (December 2021)",
      "domain": "cardmafia.cc",
      "breach_date": "2021-12-28",
      "added": "2022-01-16T00:04:04.000Z",
      "accounts": 303877,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2021, the Carding Mafia forum suffered a data breach that exposed over 300k members' email addresses. Dedicated to the theft and trading of stolen credit cards, the forum breach also exposed usernames, IP addresses and passwords stored as salted MD5 hashes. This breach came only 9 months after another breach of the forum in March 2021.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CardingMafiaDec2021"
    },
    {
      "name": "ABFRL",
      "title": "Aditya Birla Fashion and Retail",
      "domain": "abfrl.com",
      "breach_date": "2021-12-01",
      "added": "2022-01-15T02:58:39.000Z",
      "accounts": 5470063,
      "data_classes": [
        "Email addresses",
        "Genders",
        "Income levels",
        "Job titles",
        "Marital statuses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Purchases",
        "Religions",
        "Salutations"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2021, Indian retailer Aditya Birla Fashion and Retail Ltd was breached and ransomed. The ransom demand was allegedly rejected and data containing 5.4M unique email addresses was subsequently dumped publicly on a popular hacking forum the next month. The data contained extensive personal customer information including names, phone numbers, physical addresses, DoBs, order histories and passwords stored as MD5 hashes. Employee data was also dumped publicly and included salary grades, marital statuses and religions.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ABFRL"
    },
    {
      "name": "GunsDotCom",
      "title": "Guns.com",
      "domain": "guns.com",
      "breach_date": "2021-01-12",
      "added": "2022-01-13T05:14:53.000Z",
      "accounts": 375928,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names",
        "Partial credit card data",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2021, the firearms website guns.com suffered a data breach. The breach exposed 376k unique email addresses along with names, phone numbers, physical addresses, gun purchases, partial credit card data, dates of birth and passwords stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GunsDotCom"
    },
    {
      "name": "Doxbin",
      "title": "Doxbin",
      "domain": "doxbin.com",
      "breach_date": "2022-01-05",
      "added": "2022-01-08T05:51:48.000Z",
      "accounts": 370794,
      "data_classes": [
        "Browser user agent details",
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2022, the \"doxing\" website designed to disclose the personal information of targeted individuals (\"doxes\") Doxbin suffered a data breach. The breach was subsequently leaked online and included over 370k unique email addresses across user accounts and doxes. User accounts also included usernames, password hashes and browser user agents. The personal information disclosed in the doxes was often extensive including names, physical addresses, phone numbers and more.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Doxbin"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
