{
  "query": {
    "page": "31"
  },
  "count": 20,
  "total": 1018,
  "page": 31,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T02:47:12.621Z",
    "kev": "2026-10-07T03:46:14.963Z",
    "epss": "2026-10-07T00:58:23.423Z",
    "breaches": "2026-10-07T00:46:23.055Z",
    "posts": "2026-10-07T03:47:15.195Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=31"
  },
  "warnings": [],
  "results": [
    {
      "name": "HalloweenSpot",
      "title": "The Halloween Spot",
      "domain": "thehalloweenspot.com",
      "breach_date": "2019-09-27",
      "added": "2020-03-16T05:20:32.000Z",
      "accounts": 10653,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2019, the Halloween costume store The Halloween Spot suffered a data breach. Originally misattributed to fancy dress store Smiffys, the breach contained 13GB of data with over 10k unique email addresses alongside names, physical and IP addresses, phone numbers and order histories. The Halloween Spot advised customers the breach was traced back to \"an old shipping information database\".",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#HalloweenSpot"
    },
    {
      "name": "AnimeGame",
      "title": "AnimeGame",
      "domain": "animegame.me",
      "breach_date": "2020-02-27",
      "added": "2020-03-09T05:52:08.000Z",
      "accounts": 1431378,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2020, the gaming website AnimeGame suffered a data breach. The incident affected 1.4M subscribers and exposed email addresses, usernames and passwords stored as salted MD5 hashes. The data was subsequently shared on a popular hacking forum and was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#AnimeGame"
    },
    {
      "name": "Straffic",
      "title": "Straffic",
      "domain": "straffic.io",
      "breach_date": "2020-02-14",
      "added": "2020-02-27T19:28:29.000Z",
      "accounts": 48580249,
      "data_classes": [
        "Email addresses",
        "Genders",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2020, Israeli marketing company Straffic exposed a database with 140GB of personal data. The publicly accessible Elasticsearch database contained over 300M rows with 49M unique email addresses. Exposed data also included names, phone numbers, physical addresses and genders. In their breach disclosure message, Straffic stated that \"it is impossible to create a totally immune system, and these things can occur\".",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Straffic"
    },
    {
      "name": "Slickwraps",
      "title": "Slickwraps",
      "domain": "slickwraps.com",
      "breach_date": "2020-02-16",
      "added": "2020-02-22T19:20:00.000Z",
      "accounts": 857611,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2020, the online store for consumer electronics wraps Slickwraps suffered a data breach. The incident resulted in the exposure of 858k unique email addresses across customer records and newsletter subscribers. Additional impacted data included names, physical addresses, phone numbers and purchase histories.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Slickwraps"
    },
    {
      "name": "MGM",
      "title": "MGM Resorts",
      "domain": "mgmresorts.com",
      "breach_date": "2019-07-25",
      "added": "2020-02-20T00:52:55.000Z",
      "accounts": 3081321,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2019, MGM Resorts discovered a data breach of one of their cloud services. The breach included 10.6M guest records with 3.1M unique email addresses stemming back to 2017. The exposed data included email and physical addresses, names, phone numbers and dates of birth and was subsequently shared on a popular hacking forum in February 2020 where it was extensively redistributed. The data was provided to HIBP by Under The Breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MGM"
    },
    {
      "name": "AdultFriendFinder2016",
      "title": "Adult FriendFinder (2016)",
      "domain": "adultfriendfinder.com",
      "breach_date": "2016-10-16",
      "added": "2020-02-06T23:53:53.000Z",
      "accounts": 169746810,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Spoken languages",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2016, the adult entertainment company Friend Finder Networks suffered a massive data breach. The incident impacted multiple separate online assets owned by the company, the largest of which was the Adult FriendFinder website alleged to be \"the world's largest sex & swinger community\". Exposed data included usernames, passwords stored as SHA-1 hashes and 170 million unique email addresses. This incident is separate to the 2015 data breach Adult FriendFinder also suffered. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#AdultFriendFinder2016"
    },
    {
      "name": "DailyObjects",
      "title": "DailyObjects",
      "domain": "dailyobjects.com",
      "breach_date": "2018-01-01",
      "added": "2020-01-28T10:50:00.000Z",
      "accounts": 464260,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately January 2018, a collection of more than 464k customer records from the Indian online retailer DailyObjects were leaked online. The data included names, physical and email addresses, phone numbers and \"pincodes\" stored in plain text. After multiple attempts to contact them, DailyObjects responded and received a copy of the data for verification, however failed to respond to multiple contact attempts following that.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#DailyObjects"
    },
    {
      "name": "Tout",
      "title": "Tout",
      "domain": "tout.com",
      "breach_date": "2014-09-11",
      "added": "2020-01-25T06:12:28.000Z",
      "accounts": 652683,
      "data_classes": [
        "Bios",
        "Email addresses",
        "Geographic locations",
        "IP addresses",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately September 2014, the now defunct social networking service Tout suffered a data breach. The breach subsequently appeared years later and included 653k unique email addresses, names, IP addresses, the location of the user, their bio and passwords stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Tout"
    },
    {
      "name": "EuropaJobs",
      "title": "europa.jobs",
      "domain": "europa.jobs",
      "breach_date": "2019-08-11",
      "added": "2020-01-15T08:51:05.000Z",
      "accounts": 226095,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Geographic locations",
        "Job applications",
        "Names",
        "Passwords",
        "Phone numbers",
        "Spoken languages"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2019, the now defunct European jobs website europa.jobs (Google cache link) suffered a data breach. The incident exposed 226k unique email addresses alongside extensive personal information including names, dates of birth, job applications and passwords. The data was subsequently redistributed on a popular hacking forum.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#EuropaJobs"
    },
    {
      "name": "PlanetCalypso",
      "title": "Planet Calypso",
      "domain": "planetcalypsoforum.com",
      "breach_date": "2019-07-01",
      "added": "2020-01-12T09:48:57.000Z",
      "accounts": 62261,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately July 2019, the forums for the Planet Calypso game suffered a data breach. The breach of the vBulletin based forum exposed email and IP addresses, usernames and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#PlanetCalypso"
    },
    {
      "name": "BtoBet",
      "title": "BtoBet",
      "domain": "btobet.com",
      "breach_date": "2019-12-26",
      "added": "2020-01-11T20:16:42.000Z",
      "accounts": 444241,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Financial transactions",
        "Geographic locations",
        "IP addresses",
        "Names",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2019, a large collection of data from Nigerian gambling company Surebet247 was sent to HIBP. Alongside the Surebet247, database backups from gambling sites BetAlfa, BetWay, BongoBongo and TopBet was also included. Further investigation implicated betting platform provider BtoBet as being the common source of the data. Impacted data included user records and extensive information on gambling histories.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BtoBet"
    },
    {
      "name": "GoGames",
      "title": "Go Games",
      "domain": "gogames.me",
      "breach_date": "2015-10-24",
      "added": "2020-01-11T00:06:33.000Z",
      "accounts": 3430083,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately October 2015, the manga website Go Games suffered a data breach. The exposed data included 3.4M customer records including email and IP addresses, usernames and passwords stored as salted MD5 hashes. Go Games did not respond when contacted about the incident. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GoGames"
    },
    {
      "name": "IndianRailways",
      "title": "Indian Railways",
      "domain": "indianrails.in",
      "breach_date": "2019-10-28",
      "added": "2020-01-10T19:13:39.000Z",
      "accounts": 583377,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2019, the website for Indian Rail left more than 2M records exposed on an unprotected Firebase database instance. The exposed data included 583k unique email addresses alongside usernames and passwords stored in plain text.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#IndianRailways"
    },
    {
      "name": "Universarium",
      "title": "Universarium",
      "domain": "universarium.org",
      "breach_date": "2019-11-01",
      "added": "2020-01-03T09:40:01.000Z",
      "accounts": 564962,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately November 2019, the Russian \"Remote preparatory faculty for IT specialties\" Universarium suffered a data breach. The incident exposed 565k email addresses and passwords in plain text. Universarium did not respond to multiple attempts to make contact over a period of many weeks. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Universarium"
    },
    {
      "name": "Factual",
      "title": "Factual",
      "domain": "factual.com",
      "breach_date": "2017-03-22",
      "added": "2019-12-24T10:56:18.000Z",
      "accounts": 2461696,
      "data_classes": [
        "Email addresses",
        "Employers",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2017, a file containing 8M rows of data allegedly sourced from data aggregator Factual was compiled and later exchanged on the premise it was a \"breach\". The data contained 2.5M unique email addresses alongside business names, addresses and phone numbers. After consultation with Factual, they advised the data was \"publicly available information about businesses and other points of interest that Factual makes available on its website and to customers\".",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Factual"
    },
    {
      "name": "Zynga",
      "title": "Zynga",
      "domain": "zynga.com",
      "breach_date": "2019-09-01",
      "added": "2019-12-19T04:54:45.000Z",
      "accounts": 172869660,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Phone numbers",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2019, game developer Zynga (the creator of Words with Friends) suffered a data breach. The incident exposed 173M unique email addresses alongside usernames and passwords stored as salted SHA-1 hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Zynga"
    },
    {
      "name": "AgusiQTorrents",
      "title": "AgusiQ-Torrents.pl",
      "domain": "agusiq-torrents.pl",
      "breach_date": "2019-09-24",
      "added": "2019-12-04T21:54:50.000Z",
      "accounts": 90478,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2019, Polish torrent site AgusiQ-Torrents.pl suffered a data breach. The incident exposed 90k member records including email and IP addresses, usernames and passwords stored as MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#AgusiQTorrents"
    },
    {
      "name": "PDL",
      "title": "Data Enrichment Exposure From PDL Customer",
      "domain": null,
      "breach_date": "2019-10-16",
      "added": "2019-11-22T20:13:04.000Z",
      "accounts": 622161052,
      "data_classes": [
        "Email addresses",
        "Employers",
        "Geographic locations",
        "Job titles",
        "Names",
        "Phone numbers",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2019, security researchers Vinny Troia and Bob Diachenko identified an unprotected Elasticsearch server holding 1.2 billion records of personal data. The exposed data included an index indicating it was sourced from data enrichment company People Data Labs (PDL) and contained 622 million unique email addresses. The server was not owned by PDL and it's believed a customer failed to properly secure the database. Exposed information included email addresses, phone numbers, social media profiles and job history data.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#PDL"
    },
    {
      "name": "GateHub",
      "title": "GateHub",
      "domain": "gatehub.net",
      "breach_date": "2019-06-04",
      "added": "2019-11-20T00:29:29.000Z",
      "accounts": 1408078,
      "data_classes": [
        "Email addresses",
        "Encrypted keys",
        "Mnemonic phrases",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2019, 1.4M accounts from the cryptocurrency wallet service GateHub were posted to a popular hacking forum. GateHub had previously acknowledged a data breach in June, albeit with a smaller number of impacted accounts. Data from the breach included email addresses, mnemonic phrases, encrypted master keys, encrypted recovery keys and passwords stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GateHub"
    },
    {
      "name": "EpicBot",
      "title": "EpicBot",
      "domain": "epicbot.com",
      "breach_date": "2019-09-01",
      "added": "2019-11-19T23:29:42.000Z",
      "accounts": 816662,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2019, the RuneScape bot provider EpicBot suffered a data breach that impacted 817k subscribers. Data from the breach was subsequently shared on a popular hacking forum and included usernames, email and IP addresses and passwords stored as either salted MD5 or bcrypt hashes. EpicBot did not respond when contacted about the incident.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#EpicBot"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
