{
  "query": {
    "page": "25"
  },
  "count": 20,
  "total": 1018,
  "page": 25,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T22:46:18.712Z",
    "kev": "2026-10-06T22:45:18.551Z",
    "epss": "2026-10-06T18:58:09.363Z",
    "breaches": "2026-10-06T18:46:01.457Z",
    "posts": "2026-10-06T22:46:18.712Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=25"
  },
  "warnings": [],
  "results": [
    {
      "name": "Eatigo",
      "title": "Eatigo",
      "domain": "eatigo.com",
      "breach_date": "2018-10-16",
      "added": "2021-08-25T03:42:31.000Z",
      "accounts": 2789609,
      "data_classes": [
        "Email addresses",
        "Genders",
        "Names",
        "Passwords",
        "Phone numbers",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2018, the restaurant reservation service Eatigo suffered a data breach that exposed 2.8 million accounts. The data included email addresses, names, phone numbers, social media profiles, genders and passwords stored as unsalted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Eatigo"
    },
    {
      "name": "OrderSnapp",
      "title": "OrderSnapp",
      "domain": "ordersnapp.com",
      "breach_date": "2020-06-29",
      "added": "2021-08-08T01:53:33.000Z",
      "accounts": 1304447,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2020, the restaurant solutions provider OrderSnapp suffered a data breach which exposed 1.3M unique email addresses. Impacted data also included names, phone numbers, dates of birth and passwords stored as bcrypt hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#OrderSnapp"
    },
    {
      "name": "MMGFusion",
      "title": "MMG Fusion",
      "domain": "mmgfusion.com",
      "breach_date": "2020-12-20",
      "added": "2021-08-07T23:46:32.000Z",
      "accounts": 2660295,
      "data_classes": [
        "Appointments",
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Marital statuses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2020, the dental practice management service MMG Fusion was the victim of a data breach which exposed 2.6M unique email addresses. The data also included patient appointments, names, phone numbers, dates of birth, genders and physical addresses. A small number of records also included passwords stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MMGFusion"
    },
    {
      "name": "Audi",
      "title": "Audi",
      "domain": "audiusa.com",
      "breach_date": "2019-08-14",
      "added": "2021-07-23T06:31:33.000Z",
      "accounts": 2743539,
      "data_classes": [
        "Dates of birth",
        "Driver's licenses",
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Social security numbers",
        "Vehicle details"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2019, Audi USA suffered a data breach after a vendor left data unsecured and exposed on the internet. The data contained 2.7M unique email addresses along with names, phone numbers, physical addresses and vehicle information including VIN. In a disclosure statement from Audi, they also advised some customers had driver's licenses, dates of birth, social security numbers and other personal information exposed.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Audi"
    },
    {
      "name": "Guntrader",
      "title": "Guntrader",
      "domain": "guntrader.uk",
      "breach_date": "2021-07-17",
      "added": "2021-07-21T20:24:24.000Z",
      "accounts": 112031,
      "data_classes": [
        "Browser user agent details",
        "Email addresses",
        "Geographic locations",
        "IP addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Salutations"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2021, the United Kingdom based website Guntrader suffered a data breach that exposed 112k unique email addresses. Extensive personal information was also exposed including names, phone numbers, geolocation data, IP addresses and various physical address attributes (cities for all users, complete addresses for some). Passwords stored as bcrypt hashes were also exposed.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Guntrader"
    },
    {
      "name": "ShortEdition",
      "title": "Short Édition",
      "domain": "short-edition.com",
      "breach_date": "2021-06-26",
      "added": "2021-07-19T04:49:43.000Z",
      "accounts": 505466,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Social media profiles",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2021, the French publishing house of short literature Short Édition suffered a data breach that exposed 505k records. Impacted data included email and physical addresses, names, usernames, phone numbers, dates of birth, genders and passwords stored as either salted SHA-1 or salted SHA-512 hashes. Short Édition self-submitted the impacted data to HIBP.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ShortEdition"
    },
    {
      "name": "Vastaamo",
      "title": "Vastaamo",
      "domain": "vastaamo.fi",
      "breach_date": "2019-03-31",
      "added": "2021-07-17T01:51:01.000Z",
      "accounts": 30433,
      "data_classes": [
        "Email addresses",
        "Names",
        "Personal health data",
        "Social security numbers"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2020, the Finnish psychotherapy service Vastaamo was the subject of a ransomware attack targeting first the company itself, followed by their patients directly. The original security incident dates back to a period between late 2018 and early 2019 and exposed data including 30k unique email addresses, names, social security numbers and notes on individuals' psychotherapy sessions. This breach has been flagged as \"sensitive\" and is only searchable by owners of the email addresses and domains exposed in the incident.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Vastaamo"
    },
    {
      "name": "Raychat",
      "title": "Raychat",
      "domain": "raychat.ir",
      "breach_date": "2021-01-31",
      "added": "2021-07-04T00:52:38.000Z",
      "accounts": 938981,
      "data_classes": [
        "Browser user agent details",
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2021, the now defunct Iranian social media platform Raychat suffered a data breach that exposed 939 thousand unique email addresses. The data included names, IP addresses, browser user agent strings and passwords stored as bcrypt hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Raychat"
    },
    {
      "name": "Teespring",
      "title": "Teespring",
      "domain": "teespring.com",
      "breach_date": "2020-04-01",
      "added": "2021-06-25T06:58:48.000Z",
      "accounts": 8234193,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "Names",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2020, the custom printed apparel website Teespring suffered a data breach that exposed 8.2 million customer records. The data included email addresses, names, geographic locations and social media IDs.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Teespring"
    },
    {
      "name": "YoteprestoCom",
      "title": "yotepresto.com",
      "domain": "yotepresto.com",
      "breach_date": "2020-06-22",
      "added": "2021-06-25T05:04:47.000Z",
      "accounts": 1444629,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2020, the Mexican lending platform yotepresto.com suffered a data breach. Over 1.4 million customers were impacted by the breach which disclosed email and IP addresses, usernames and passwords stored as bcrypt hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#YoteprestoCom"
    },
    {
      "name": "UC",
      "title": "University of California",
      "domain": "universityofcalifornia.edu",
      "breach_date": "2020-12-24",
      "added": "2021-06-20T07:44:34.000Z",
      "accounts": 547422,
      "data_classes": [
        "Dates of birth",
        "Education levels",
        "Email addresses",
        "Ethnicities",
        "Genders",
        "Job titles",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Social security numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2020, the University of California suffered a data breach due to vulnerability in in a third-party provider, Accellion. The breach exposed extensive personal data on both students and staff including 547 thousand unique email addresses, names, dates of birth, genders, social security numbers, ethnicities and other academic related data attributes. Further analysis is available in Exploring the Impact of the UC Data Breach. The data was provided to HIBP courtesy of Cyril Gorlla.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#UC"
    },
    {
      "name": "Fotolog",
      "title": "Fotolog",
      "domain": "fotolog.com",
      "breach_date": "2018-12-01",
      "added": "2021-06-15T03:20:43.000Z",
      "accounts": 16717854,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2018, the photo sharing social network Fotolog suffered a data breach that exposed 16.7 million unique email addresses. The data also included usernames and unsalted SHA-256 password hashes. The site was dissolved the following year and repurposed as a news website based in Brcko, Bosnia and Herzegovina.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Fotolog"
    },
    {
      "name": "NamelessMalware",
      "title": "Nameless Malware",
      "domain": null,
      "breach_date": "2020-01-01",
      "added": "2021-06-09T10:28:14.000Z",
      "accounts": 1121484,
      "data_classes": [
        "Email addresses"
      ],
      "verified": true,
      "sensitive": true,
      "malware": true,
      "stealer_log": false,
      "description": "In January 2021, NordLocker provided HIBP 1.1 million email addresses collected by nameless malware. The malware campaign ran between 2018 and 2020 and infected 3.25 million computers, stealing files, credentials and taking screenshots and photos using the computer's webcam. Read more in NordLocker's writeup about the Nameless malware that stole 1.2 TB of private data.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#NamelessMalware"
    },
    {
      "name": "DominosIndia",
      "title": "Domino's India",
      "domain": "dominos.co.in",
      "breach_date": "2021-03-24",
      "added": "2021-06-03T02:18:39.000Z",
      "accounts": 22527655,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2021, 13TB of compromised Domino's India appeared for sale on a hacking forum after which the company acknowledged a major data breach they dated back to March. The compromised data included 22.5 million unique email addresses, names, phone numbers, order histories and physical addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#DominosIndia"
    },
    {
      "name": "JD",
      "title": "JD",
      "domain": "jd.com",
      "breach_date": "2013-01-01",
      "added": "2021-06-02T07:06:02.000Z",
      "accounts": 77449341,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Phone numbers",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In 2013 (exact date unknown), the Chinese e-commerce service JD suffered a data breach that exposed 13GB of data containing 77 million unique email addresses. The data also included usernames, phone numbers and passwords stored as SHA-1 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#JD"
    },
    {
      "name": "MobiFriends",
      "title": "MobiFriends",
      "domain": "mobifriends.com",
      "breach_date": "2020-01-06",
      "added": "2021-05-23T03:16:52.000Z",
      "accounts": 3512952,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2020, the Barcelona-based dating app MobiFriends suffered a data breach that exposed 3.5 million unique email addresses. The data also included usernames, genders, dates of birth and MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MobiFriends"
    },
    {
      "name": "Moneycontrol",
      "title": "Moneycontrol",
      "domain": "moneycontrol.com",
      "breach_date": "2017-09-07",
      "added": "2021-05-22T22:37:30.000Z",
      "accounts": 762874,
      "data_classes": [
        "Email addresses",
        "Genders",
        "Geographic locations",
        "Passwords",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2021, hackers posted data for sale originating from the online Indian financial platform, Moneycontrol. The data included 763 thousand unique email addresses (allegedly a subset of a larger 40 million account breach), alongside geographic locations, phone numbers, genders, dates of birth and plain text passwords. The date of the original breach is unclear, although the breached data indicates the file was created in September 2017 and Moneycontrol has stated that the breach is \"an old data set\".",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Moneycontrol"
    },
    {
      "name": "Yam",
      "title": "Yam",
      "domain": "yam.com",
      "breach_date": "2013-06-02",
      "added": "2021-05-22T08:02:31.000Z",
      "accounts": 13258797,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2013, the Taiwanese website Yam.com suffered a data breach which was shared to a popular hacking forum in 2021. The data included 13 million unique email addresses alongside names, usernames, phone numbers, physical addresses, dates of birth and unsalted MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Yam"
    },
    {
      "name": "Livpure",
      "title": "Livpure",
      "domain": "livpure.com",
      "breach_date": "2020-08-29",
      "added": "2021-05-22T01:46:59.000Z",
      "accounts": 269552,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Purchases",
        "Salutations"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2020, the Indian retailer Livpure suffered a data breach which exposed over 1 million customer purchases with 270 thousand unique email addresses. The data also included names, phone numbers, physical addresses and details of purchased items.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Livpure"
    },
    {
      "name": "DailyQuiz",
      "title": "Daily Quiz",
      "domain": "dailyquiz.me",
      "breach_date": "2021-01-13",
      "added": "2021-05-21T05:15:39.000Z",
      "accounts": 8032404,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2021, the quiz website Daily Quiz suffered a data breach that exposed over 8 million unique email addresses. The data also included usernames, IP addresses and passwords stored in plain text.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#DailyQuiz"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
