{
  "query": {
    "page": "32"
  },
  "count": 20,
  "total": 1018,
  "page": 32,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T04:47:17.455Z",
    "kev": "2026-10-07T04:46:17.408Z",
    "epss": "2026-10-07T00:58:23.423Z",
    "breaches": "2026-10-07T00:46:23.055Z",
    "posts": "2026-10-07T04:47:17.455Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=32"
  },
  "warnings": [],
  "results": [
    {
      "name": "GPSUnderground",
      "title": "GPS Underground",
      "domain": "gpsunderground.com",
      "breach_date": "2016-07-01",
      "added": "2019-11-19T06:13:42.000Z",
      "accounts": 669584,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In early 2017, GPS Underground was amongst a collection of compromised vBulletin websites that were found being sold online. The breach dated back to mid-2016 and included 670k records with usernames, email and IP addresses, dates of birth and salted MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GPSUnderground"
    },
    {
      "name": "ToonDoo",
      "title": "ToonDoo",
      "domain": "toondoo.com",
      "breach_date": "2019-08-21",
      "added": "2019-11-11T06:19:53.000Z",
      "accounts": 6002694,
      "data_classes": [
        "Email addresses",
        "Genders",
        "Geographic locations",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2019, the comic strip creation website ToonDoo suffered a data breach. The data was subsequently redistributed on a popular hacking forum in November where the personal information of over 6M subscribers was shared. Impacted data included email and IP addresses, usernames, genders, the location of the individual and salted password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ToonDoo"
    },
    {
      "name": "Vedantu",
      "title": "Vedantu",
      "domain": "vedantu.com",
      "breach_date": "2019-07-08",
      "added": "2019-11-01T05:13:40.000Z",
      "accounts": 686899,
      "data_classes": [
        "Browser user agent details",
        "Email addresses",
        "Genders",
        "IP addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Spoken languages",
        "Time zones",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2019, the Indian interactive online tutoring platform Vedantu suffered a data breach which exposed the personal data of 687k users. The JSON formatted database dump exposed extensive personal information including email and IP address, names, phone numbers, genders and passwords stored as bcrypt hashes. When contacted about the incident, Vedantu advised that they were aware of the breach and were in the process of informing their customers.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Vedantu"
    },
    {
      "name": "HookersNL",
      "title": "Hookers.nl",
      "domain": "hookers.nl",
      "breach_date": "2019-10-10",
      "added": "2019-10-23T09:51:59.000Z",
      "accounts": 290955,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2019, the Dutch prostitution forum Hookers.nl suffered a data breach which exposed the personal information of sex workers and their customers. The IP and email addresses, usernames and either bcrypt or salted MD5 password hashes of 291k members were accessed via an unpatched vulnerability in the vBulletin forum software.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#HookersNL"
    },
    {
      "name": "Zooville",
      "title": "Zooville",
      "domain": "zooville.org",
      "breach_date": "2019-09-27",
      "added": "2019-10-19T21:22:44.000Z",
      "accounts": 71407,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2019, the zoophilia and bestiality forum Zooville suffered a data breach. The usernames and email addresses of 71k members were accessed via an unpatched vulnerability in the vBulletin forum software then subsequently distributed online. A second data set was later provided to HIBP which contained a complete vBulletin database dump including IP addresses, dates of birth and passwords stored as bcrypt hashes. The site administrator advised that following the breach, all data had been deleted from the forum and a new one had been stood up on the XenForo platform.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Zooville"
    },
    {
      "name": "StreetEasy",
      "title": "StreetEasy",
      "domain": "streeteasy.com",
      "breach_date": "2016-06-28",
      "added": "2019-10-06T18:18:50.000Z",
      "accounts": 988230,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately June 2016, the real estate website StreetEasy suffered a data breach. In total, 988k unique email addresses were included in the breach alongside names, usernames and SHA-1 hashes of passwords, all of which appeared for sale on a dark web marketplace in February 2019.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#StreetEasy"
    },
    {
      "name": "Sephora",
      "title": "Sephora",
      "domain": "sephora.com.au",
      "breach_date": "2017-01-09",
      "added": "2019-10-06T15:14:12.000Z",
      "accounts": 780073,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Ethnicities",
        "Genders",
        "Names",
        "Physical attributes"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately January 2017, the beauty store Sephora suffered a data breach. Impacting customers in South East Asia, Australia and New Zealand, 780k unique email addresses were included in the breach alongside names, genders, dates of birth, ethnicities and other personal information.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Sephora"
    },
    {
      "name": "Wanelo",
      "title": "Wanelo",
      "domain": "wanelo.com",
      "breach_date": "2018-12-13",
      "added": "2019-09-30T17:15:11.000Z",
      "accounts": 23165793,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately December 2018, the digital mall Wanelo suffered a data breach. The data was later placed up for sale on a dark web marketplace along with a collection of other data breaches in April 2019. A total of 23 million unique email addresses were included in the breach alongside passwords stored as either MD5 or bcrypt hashes. After the initial HIBP load, further data containing names, shipping addresses and IP addresses were also provided to HIBP, albeit without direct association to the email addresses and passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Wanelo"
    },
    {
      "name": "LuminPDF",
      "title": "Lumin PDF",
      "domain": "luminpdf.com",
      "breach_date": "2019-04-01",
      "added": "2019-09-18T05:00:15.000Z",
      "accounts": 15453048,
      "data_classes": [
        "Auth tokens",
        "Email addresses",
        "Genders",
        "Names",
        "Passwords",
        "Spoken languages",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2019, the PDF management service Lumin PDF suffered a data breach. The breach wasn't publicly disclosed until September when 15.5M records of user data appeared for download on a popular hacking forum. The data had been left publicly exposed in a MongoDB instance after which Lumin PDF was allegedly been \"contacted multiple times, but ignored all the queries\". The exposed data included names, email addresses, genders, spoken language and either a bcrypt password hash or Google auth token.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#LuminPDF"
    },
    {
      "name": "KiwiFarms",
      "title": "KiwiFarms",
      "domain": "kiwifarms.net",
      "breach_date": "2019-09-10",
      "added": "2019-09-17T09:48:25.000Z",
      "accounts": 4606,
      "data_classes": [
        "Avatars",
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2019, the forum for discussing \"lolcows\" (people who can be milked for laughs) Kiwi Farms suffered a data breach. The disclosure notice advised that email and IP addresses, dates of birth and content created by members were all exposed in the incident.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#KiwiFarms"
    },
    {
      "name": "Minehut",
      "title": "Minehut",
      "domain": "minehut.com",
      "breach_date": "2019-05-17",
      "added": "2019-09-17T08:27:31.000Z",
      "accounts": 396533,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2019, the Minecraft server website Minehut suffered a data breach. The company advised a database backup had been obtained after which they subsequently notified all impacted users. 397k email addresses from the incident were provided to HIBP. A data set with both email addresses and bcrypt password hashes was also later provided to HIBP.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Minehut"
    },
    {
      "name": "VoidTO",
      "title": "Void.to",
      "domain": "void.to",
      "breach_date": "2019-06-13",
      "added": "2019-09-11T06:47:08.000Z",
      "accounts": 95431,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Private messages",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2019, the hacking website Void.to suffered a data breach. There were 95k unique email addresses spread across 86k forum users and other tables in the database. A rival hacking website claimed responsibility for breaching the MyBB based forum which disclosed email and IP addresses, usernames, private messages and passwords stored as either salted MD5 or bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#VoidTO"
    },
    {
      "name": "Poshmark",
      "title": "Poshmark",
      "domain": "poshmark.com",
      "breach_date": "2018-05-16",
      "added": "2019-09-02T03:36:05.000Z",
      "accounts": 36395491,
      "data_classes": [
        "Email addresses",
        "Genders",
        "Geographic locations",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2018, social commerce marketplace Poshmark suffered a data breach that exposed 36M user accounts. The compromised data included email addresses, names, usernames, genders, locations and passwords stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Poshmark"
    },
    {
      "name": "MastercardPricelessSpecials",
      "title": "Mastercard Priceless Specials",
      "domain": "specials.mastercard.de",
      "breach_date": "2019-08-20",
      "added": "2019-09-01T20:37:49.000Z",
      "accounts": 89388,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Partial credit card data",
        "Phone numbers",
        "Salutations"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2019, the German Mastercard bonus program \"Priceless Specials\" suffered a data breach. Personal data on almost 90k program members was subsequently extensively circulated online and included names, email and IP addresses, phone numbers and partial credit card data. Following the incident, the program was subsequently suspended.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MastercardPricelessSpecials"
    },
    {
      "name": "XKCD",
      "title": "XKCD",
      "domain": "xkcd.com",
      "breach_date": "2019-07-01",
      "added": "2019-09-01T08:58:32.000Z",
      "accounts": 561991,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2019, the forum for webcomic XKCD suffered a data breach that impacted 562k subscribers. The breached phpBB forum leaked usernames, email and IP addresses and passwords stored in MD5 phpBB3 format. The data was provided to HIBP by white hat security researcher and data analyst Adam Davies.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#XKCD"
    },
    {
      "name": "Coinmama",
      "title": "Coinmama",
      "domain": "coinmama.com",
      "breach_date": "2017-08-03",
      "added": "2019-08-30T20:53:29.000Z",
      "accounts": 478824,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2017, the crypto coin brokerage service Coinmama suffered a data breach that impacted 479k subscribers. The breach was discovered in February 2019 with exposed data including email addresses, usernames and passwords stored as MD5 WordPress hashes. The data was provided to HIBP by white hat security researcher and data analyst Adam Davies.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Coinmama"
    },
    {
      "name": "Chegg",
      "title": "Chegg",
      "domain": "chegg.com",
      "breach_date": "2018-04-28",
      "added": "2019-08-16T07:24:58.000Z",
      "accounts": 39721127,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2018, the textbook rental service Chegg suffered a data breach that impacted 40 million subscribers. The exposed data included email addresses, usernames, names and passwords stored as unsalted MD5 hashes. A small number of records also contained physical address or phone number.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Chegg"
    },
    {
      "name": "CrackedTO",
      "title": "Cracked.to",
      "domain": "cracked.to",
      "breach_date": "2019-07-21",
      "added": "2019-08-12T11:18:56.000Z",
      "accounts": 749161,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Private messages",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2019, the hacking website Cracked.to suffered a data breach. There were 749k unique email addresses spread across 321k forum users and other tables in the database. A rival hacking website claimed responsibility for breaching the MyBB based forum which disclosed email and IP addresses, usernames, private messages and passwords stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CrackedTO"
    },
    {
      "name": "StockX",
      "title": "StockX",
      "domain": "stockx.com",
      "breach_date": "2019-07-26",
      "added": "2019-08-10T15:34:08.000Z",
      "accounts": 6840339,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Physical addresses",
        "Purchases",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2019, the fashion and sneaker trading platform StockX suffered a data breach which was subsequently sold via a dark webmarketplace. The exposed data included 6.8 million unique email addresses, names, physical addresses, purchases and passwords stored as salted MD5 hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#StockX"
    },
    {
      "name": "Canva",
      "title": "Canva",
      "domain": "canva.com",
      "breach_date": "2019-05-24",
      "added": "2019-08-09T14:24:01.000Z",
      "accounts": 137272116,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2019, the graphic design tool website Canva suffered a data breach that impacted 137 million subscribers. The exposed data included email addresses, usernames, names, cities of residence and passwords stored as bcrypt hashes for users not using social logins.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Canva"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
