{
  "query": {
    "page": "27"
  },
  "count": 20,
  "total": 1018,
  "page": 27,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T22:46:18.712Z",
    "kev": "2026-10-06T23:45:20.765Z",
    "epss": "2026-10-06T18:58:09.363Z",
    "breaches": "2026-10-06T18:46:01.457Z",
    "posts": "2026-10-06T23:46:20.864Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=27"
  },
  "warnings": [],
  "results": [
    {
      "name": "Ticketcounter",
      "title": "Ticketcounter",
      "domain": "ticketcounter.nl",
      "breach_date": "2021-02-22",
      "added": "2021-03-01T22:37:54.000Z",
      "accounts": 1921722,
      "data_classes": [
        "Bank account numbers",
        "Dates of birth",
        "Email addresses",
        "Genders",
        "IP addresses",
        "Names",
        "Payment histories",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2020, the Dutch ticketing service Ticketcounter inadvertently published a database backup to a publicly accessible location where it was then found and downloaded in February 2021. The data contained 1.9M unique email addresses which were offered for sale on a hacking forum and in some cases included names, physical and IP addresses, genders, dates of birth, payment histories and bank account numbers. Ticketcounter was later held to ransom with the threat of the breached being released publicly.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Ticketcounter"
    },
    {
      "name": "SuperVPNGeckoVPN",
      "title": "SuperVPN & GeckoVPN",
      "domain": null,
      "breach_date": "2021-02-25",
      "added": "2021-02-28T22:30:29.000Z",
      "accounts": 20339937,
      "data_classes": [
        "Device information",
        "Device serial numbers",
        "Email addresses",
        "Geographic locations",
        "IMSI numbers",
        "Login histories"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2021, a series of \"free\" VPN services were breached including SuperVPN and GeckoVPN, exposing over 20M records. The data appeared together in a single file with a small number of records also included from FlashVPN, suggesting that all three brands may share the same platform. Impacted data also included email addresses, the country logged in from and the date and time each login occurred alongside device information including the make and model, IMSI number and serial number.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#SuperVPNGeckoVPN"
    },
    {
      "name": "FilmaiIn",
      "title": "Filmai.in",
      "domain": "filmai.in",
      "breach_date": "2020-01-01",
      "added": "2021-02-23T08:52:26.000Z",
      "accounts": 645786,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately 2019 or 2020, the Lithuanian movie streaming service Filmai.in suffered a data breach exposing 645k email addresses, usernames and plain text passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#FilmaiIn"
    },
    {
      "name": "NurseryCam",
      "title": "NurseryCam",
      "domain": "nurserycam.co.uk",
      "breach_date": "2021-02-12",
      "added": "2021-02-23T07:58:02.000Z",
      "accounts": 10585,
      "data_classes": [
        "Email addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2021, a series of egregiously bad security flaws were identified in the NurseryCam system designed for parents to remotely monitor their children whilst attending nursery. The flaws led to the exposure of over 10k parent records before the service was shut down. The email addresses alone were provided to Have I Been Pwned to ensure parents were properly notified of the incident.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#NurseryCam"
    },
    {
      "name": "PeoplesEnergy",
      "title": "People's Energy",
      "domain": "peoplesenergy.co.uk",
      "breach_date": "2020-12-16",
      "added": "2021-02-23T03:25:44.000Z",
      "accounts": 358822,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2020, the UK power company People's Energy suffered a data breach. The breach exposed almost 7GB of files containing 359k unique email addresses along with names, phones numbers, physical addresses and dates of birth. The incident also included People's Energy staff email addresses and bcrypt password hashes (no customer passwords were exposed).",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#PeoplesEnergy"
    },
    {
      "name": "NetGalley",
      "title": "NetGalley",
      "domain": "netgalley.com",
      "breach_date": "2020-12-21",
      "added": "2021-02-23T01:38:21.000Z",
      "accounts": 1436435,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2020, the book promotion site NetGalley suffered a data breach. The incident exposed 1.4 million unique email addresses alongside names, usernames, physical and IP addresses, phone numbers, dates of birth and passwords stored as salted SHA-1 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#NetGalley"
    },
    {
      "name": "CityBee",
      "title": "CityBee",
      "domain": "citybee.lt",
      "breach_date": "2021-02-05",
      "added": "2021-02-17T00:52:52.000Z",
      "accounts": 110156,
      "data_classes": [
        "Email addresses",
        "Government issued IDs",
        "Names",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2021, the Lithuanian car-sharing service CityBee announced they'd suffered a data breach that exposed 110k customers' personal information. The breach exposed names, email addresses, government issued IDs and passwords stored as unsalted SHA-1 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CityBee"
    },
    {
      "name": "Gett",
      "title": "Ge.tt",
      "domain": "ge.tt",
      "breach_date": "2017-05-04",
      "added": "2021-02-16T06:22:20.000Z",
      "accounts": 2481121,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2017, the file sharing platform Ge.tt suffered a data breach. The data was subsequently put up for sale on a dark web marketplace in February 2019 alongside a raft of other breaches. The Ge.tt breach included names, social media profile identifiers, SHA256 password hashes and almost 2.5M unique email addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Gett"
    },
    {
      "name": "StoryBird",
      "title": "StoryBird",
      "domain": "storybird.com",
      "breach_date": "2015-08-07",
      "added": "2021-02-02T00:39:58.000Z",
      "accounts": 1047200,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2015, the storytelling service StoryBird suffered a data breach exposing 4 million records with 1 million unique email addresses. Impacted data also included names, usernames and passwords stored as PBKDF2 hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#StoryBird"
    },
    {
      "name": "Pixlr",
      "title": "Pixlr",
      "domain": "pixlr.com",
      "breach_date": "2020-10-07",
      "added": "2021-02-01T03:40:29.000Z",
      "accounts": 1906808,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "Names",
        "Passwords",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2020, the online photo editing application Pixlr suffered a data breach exposing 1.9 million subscribers. Impacted data included names, email addresses, social media profiles, the country signed up from and passwords stored as SHA-512 hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Pixlr"
    },
    {
      "name": "MeetMindful",
      "title": "MeetMindful",
      "domain": "meetmindful.com",
      "breach_date": "2020-01-26",
      "added": "2021-01-31T02:59:06.000Z",
      "accounts": 1422717,
      "data_classes": [
        "Dates of birth",
        "Drinking habits",
        "Drug habits",
        "Email addresses",
        "Genders",
        "Geographic locations",
        "IP addresses",
        "Marital statuses",
        "Names",
        "Passwords",
        "Physical attributes",
        "Religions",
        "Sexual orientations",
        "Smoking habits",
        "Social media profiles",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In early 2020, the online dating service MeetMindful suffered a data breach that exposed 1.4 million unique customer email addresses. Included in the data was an extensive array of personal information used to find romantic matches including physical attributes, use of alcohol, drugs and cigarettes, marital statuses, birthdates, genders and the gender being sought. Additional personal information such as names, geographical locations and IP addresses were also exposed, along with passwords stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MeetMindful"
    },
    {
      "name": "Bonobos",
      "title": "Bonobos",
      "domain": "bonobos.com",
      "breach_date": "2020-08-14",
      "added": "2021-01-31T00:09:25.000Z",
      "accounts": 2811929,
      "data_classes": [
        "Email addresses",
        "Historical passwords",
        "IP addresses",
        "Names",
        "Partial credit card data",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2020, the clothing store Bonobos suffered a data breach that exposed almost 70GB of data containing 2.8 million unique email addresses. The breach also exposed names, physical and IP addresses, phone numbers, order histories and passwords stored as salted SHA-512 hashes, including historical passwords. The breach also exposed partial credit card data including card type, the name on the card, expiry date and the last 4 digits of the card. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Bonobos"
    },
    {
      "name": "Nitro",
      "title": "Nitro",
      "domain": "gonitro.com",
      "breach_date": "2020-09-28",
      "added": "2021-01-19T10:45:32.000Z",
      "accounts": 77159696,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2020, the Nitro PDF service suffered a massive data breach which exposed over 70 million unique email addresses. The breach also exposed names, bcrypt password hashes and the titles of converted documents. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Nitro"
    },
    {
      "name": "Romwe",
      "title": "Romwe",
      "domain": "romwe.com",
      "breach_date": "2018-06-01",
      "added": "2021-01-18T09:15:42.000Z",
      "accounts": 19531820,
      "data_classes": [
        "Geographic locations",
        "IP addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2018, the Hong Kong-based retailer Romwe suffered a data breach which exposed almost 20 million customers. The data was subsequently sold online and includes names, phone numbers, email and IP addresses, customer geographic locations and passwords stored as salted SHA-1 hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Romwe"
    },
    {
      "name": "JobAndTalent",
      "title": "Jobandtalent",
      "domain": "jobandtalent.com",
      "breach_date": "2018-02-01",
      "added": "2021-01-17T22:31:00.000Z",
      "accounts": 10981207,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately February 2018, the employment website Jobandtalent suffered a data breach which then appeared for sale alongside other breaches a year later. The incident impacted 11 million subscribers and exposed their names, email and IP addresses and passwords stored as salted SHA-1 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#JobAndTalent"
    },
    {
      "name": "Glofox",
      "title": "Glofox",
      "domain": "glofox.com",
      "breach_date": "2020-03-27",
      "added": "2021-01-10T01:30:48.000Z",
      "accounts": 2330735,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Passwords",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2020, the Irish gym management software company Glofox suffered a data breach which exposed 2.3M membership records. The data included email addresses, names, phone numbers, genders, dates of birth and passwords stored as unsalted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Glofox"
    },
    {
      "name": "GeniusU",
      "title": "GeniusU",
      "domain": "geniusu.com",
      "breach_date": "2020-10-02",
      "added": "2021-01-08T21:49:21.000Z",
      "accounts": 1301460,
      "data_classes": [
        "Email addresses",
        "Genders",
        "IP addresses",
        "Names",
        "Passwords",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2020, a collection of data breaches were made public including the \"Entrepreneur Success Platform\", GeniusU. Dating back to the previous month, the data included 1.3M names, email and IP addresses, genders, links to social media profiles and passwords stored as bcrypt hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GeniusU"
    },
    {
      "name": "Ledger",
      "title": "Ledger",
      "domain": "ledger.com",
      "breach_date": "2020-06-25",
      "added": "2020-12-20T21:14:56.000Z",
      "accounts": 1075241,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2020, the hardware crypto wallet manufacturer Ledger suffered a data breach that exposed over 1 million email addresses. The data was initially sold before being dumped publicly in December 2020 and included names, physical addresses and phone numbers. The data was provided to HIBP by Alon Gal, CTO of cybercrime intelligence firm Hudson Rock.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Ledger"
    },
    {
      "name": "Peatix",
      "title": "Peatix",
      "domain": "peatix.com",
      "breach_date": "2019-01-20",
      "added": "2020-12-06T22:53:53.000Z",
      "accounts": 4227907,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2019, the event organising platform Peatix suffered a data breach. The incident exposed 4.2M email addresses, names and salted password hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Peatix"
    },
    {
      "name": "PlutoTV",
      "title": "Pluto TV",
      "domain": "pluto.tv",
      "breach_date": "2018-10-12",
      "added": "2020-12-05T22:27:36.000Z",
      "accounts": 3225080,
      "data_classes": [
        "Dates of birth",
        "Device information",
        "Email addresses",
        "Genders",
        "IP addresses",
        "Names",
        "Passwords",
        "Social media profiles",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2018, the internet television service Pluto TV suffered a data breach which was then shared extensively in hacking communities. Pluto TV \"decided not to proactively inform users of the breach\" which contained 3.2M unique email and IP addresses, names, usernames, genders, dates of birth and passwords stored as bcrypt hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#PlutoTV"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
