{
  "query": {
    "page": "33"
  },
  "count": 20,
  "total": 1018,
  "page": 33,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T04:47:17.455Z",
    "kev": "2026-10-07T05:46:19.852Z",
    "epss": "2026-10-07T00:58:23.423Z",
    "breaches": "2026-10-07T00:46:23.055Z",
    "posts": "2026-10-07T05:47:20.222Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=33"
  },
  "warnings": [],
  "results": [
    {
      "name": "CafePress",
      "title": "CafePress",
      "domain": "cafepress.com",
      "breach_date": "2019-02-20",
      "added": "2019-08-05T01:18:43.000Z",
      "accounts": 23205290,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2019, the custom merchandise retailer CafePress suffered a data breach. The exposed data included 23 million unique email addresses with some records also containing names, physical addresses, phone numbers and passwords stored as SHA-1 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CafePress"
    },
    {
      "name": "ClubPenguinRewrittenJul2019",
      "title": "Club Penguin Rewritten (July 2019)",
      "domain": "cprewritten.net",
      "breach_date": "2019-07-27",
      "added": "2019-07-30T14:05:10.000Z",
      "accounts": 4007909,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2019, the children's gaming site Club Penguin Rewritten (CPRewritten) suffered a data breach (note: CPRewritten is an independent recreation of Disney's Club Penguin game). In addition to an earlier data breach that impacted 1.7 million accounts, the subsequent breach exposed 4 million unique email addresses alongside IP addresses, usernames and passwords stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ClubPenguinRewrittenJul2019"
    },
    {
      "name": "AnimePlanet",
      "title": "Anime-Planet",
      "domain": "anime-planet.com",
      "breach_date": "2016-01-01",
      "added": "2019-07-28T00:35:07.000Z",
      "accounts": 368507,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately 2016, the anime website Anime-Planet suffered a data breach that impacted 369k subscribers. The exposed data included usernames, IP and email addresses, dates of birth and passwords stored as unsalted MD5 hashes and for newer accounts, bcrypt hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#AnimePlanet"
    },
    {
      "name": "EpicNPC",
      "title": "EpicNPC",
      "domain": "epicnpc.com",
      "breach_date": "2016-01-02",
      "added": "2019-07-27T23:11:30.000Z",
      "accounts": 408795,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2016, the hacked account reseller EpicNPC suffered a data breach that impacted 409k subscribers. The impacted data included usernames, IP and email addresses and passwords stored as salted MD5 hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#EpicNPC"
    },
    {
      "name": "ClashOfKings",
      "title": "Clash of Kings",
      "domain": "f.elex.com",
      "breach_date": "2016-07-14",
      "added": "2019-07-27T22:03:03.000Z",
      "accounts": 1604957,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2016, the forum for the game \"Clash of Kings\" suffered a data breach that impacted 1.6 million subscribers. The impacted data included usernames, IP and email addresses and passwords stored as MD5 hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ClashOfKings"
    },
    {
      "name": "Snail",
      "title": "Snail",
      "domain": "snail.com",
      "breach_date": "2015-03-14",
      "added": "2019-07-27T16:24:09.000Z",
      "accounts": 1410899,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2015, the gaming website Snail suffered a data breach that impacted 1.4 million subscribers. The impacted data included usernames, IP and email addresses and passwords stored as unsalted MD5 hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Snail"
    },
    {
      "name": "Xiaomi",
      "title": "Xiaomi",
      "domain": "xiaomi.cn",
      "breach_date": "2012-08-01",
      "added": "2019-07-21T21:45:31.000Z",
      "accounts": 7088010,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2012, the Xiaomi user forum website suffered a data breach. In all, 7 million email addresses appeared in the breach although a significant portion of them were numeric aliases on the bbs_ml_as_uid.xiaomi.com domain. Usernames, IP addresses and passwords stored as salted MD5 hashes were also exposed. The data was provided with support from dehashed.com. Read more about Chinese data breaches in Have I Been Pwned.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Xiaomi"
    },
    {
      "name": "FlashFlashRevolution2019",
      "title": "Flash Flash Revolution (2019 breach)",
      "domain": "flashflashrevolution.com",
      "breach_date": "2019-07-16",
      "added": "2019-07-21T20:31:54.000Z",
      "accounts": 1858124,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2019, the music-based rhythm game Flash Flash Revolution suffered a data breach. The 2019 breach imapcted almost 1.9 million members and is in addition to the 2016 data breach of the same service. Email and IP addesses, usernames, dates of birth and salted MD5 hashes were all exposed in the breach. The data was provided with support from dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#FlashFlashRevolution2019"
    },
    {
      "name": "StrongholdKingdoms",
      "title": "Stronghold Kingdoms",
      "domain": "strongholdkingdoms.com",
      "breach_date": "2018-07-04",
      "added": "2019-07-21T15:36:01.000Z",
      "accounts": 5187305,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2018, the massive multiplayer online game Stronghold Kingdoms suffered a data breach. Almost 5.2 million accounts were impacted by the incident which exposed emails addresses, usernames and passwords stored as salted SHA-1 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#StrongholdKingdoms"
    },
    {
      "name": "GameSalad",
      "title": "GameSalad",
      "domain": "gamesalad.com",
      "breach_date": "2019-02-24",
      "added": "2019-07-21T14:18:46.000Z",
      "accounts": 1506242,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2019, the education and game creation website Game Salad suffered a data breach. The incident impacted 1.5M accounts and exposed email addresses, usernames, IP addresses and passwords stored as SHA-256 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GameSalad"
    },
    {
      "name": "ArmorGames",
      "title": "Armor Games",
      "domain": "armorgames.com",
      "breach_date": "2019-01-01",
      "added": "2019-07-20T06:03:31.000Z",
      "accounts": 10604307,
      "data_classes": [
        "Bios",
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Geographic locations",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2019, the game portal website Armor Games suffered a data breach. A total of 10.6 million email addresses were impacted by the breach which also exposed usernames, IP addresses, birthdays of administrator accounts and passwords stored as salted SHA-1 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ArmorGames"
    },
    {
      "name": "Roll20",
      "title": "Roll20",
      "domain": "roll20.net",
      "breach_date": "2018-12-26",
      "added": "2019-07-19T14:26:05.000Z",
      "accounts": 3994436,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Partial credit card data",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2018, the tabletop role-playing games website Roll20 suffered a data breach. Almost 4 million customers were impacted by the breach and had email and IP addresses, names, bcrypt hashes of passwords and the last 4 digits of credit cards exposed.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Roll20"
    },
    {
      "name": "Artvalue",
      "title": "Artvalue.com",
      "domain": "artvalue.com",
      "breach_date": "2019-06-19",
      "added": "2019-07-19T13:16:52.000Z",
      "accounts": 157692,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Salutations",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2019, the France-based art valuation website Artvalue.com (now defunct) left their 158k member subscriber base publicly exposed in a text file on their website. The exposed data included names, usernames, email addresses and passwords stored as MD5 hashes. The site operator did not respond when contacted about the incident, although the exposed file was subsequently removed.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Artvalue"
    },
    {
      "name": "EatStreet",
      "title": "EatStreet",
      "domain": "eatstreet.com",
      "breach_date": "2019-05-03",
      "added": "2019-07-19T11:29:35.000Z",
      "accounts": 6353564,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Partial credit card data",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2019, the online food ordering service EatStreet suffered a data breach affecting 6.4 million customers. An extensive amount of personal data was obtained including names, phone numbers, addresses, partial credit card data and passwords stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#EatStreet"
    },
    {
      "name": "BulgarianNationalRevenueAgency",
      "title": "Bulgarian National Revenue Agency",
      "domain": "nap.bg",
      "breach_date": "2019-07-15",
      "added": "2019-07-18T18:38:49.000Z",
      "accounts": 471167,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Taxation records"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2019, a massive data breach of the Bulgarian National Revenue Agency began circulating with data on 5 million people. Allegedly obtained in June, the data was broadly shared online and included taxation information alongside names, phone numbers, physical addresses and 471 thousand unique email addresses. The breach is said to have affected \"nearly all adults in Bulgaria\".",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BulgarianNationalRevenueAgency"
    },
    {
      "name": "YouNow",
      "title": "YouNow",
      "domain": "younow.com",
      "breach_date": "2019-02-15",
      "added": "2019-07-18T08:59:45.000Z",
      "accounts": 18241518,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Social media profiles",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2019, data from the live broadcasting service YouNow appeared for sale on a dark web marketplace. Whilst it's not clear what date the actual breach occurred on, the impacted data included 18M unique email addresses, IP addresses, names, usernames and links to social media profiles. As authentication is performed via social providers, no passwords were exposed in the breach. Many records didn't have associated email addresses thus the unique number is lower than the reported total number of accounts.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#YouNow"
    },
    {
      "name": "Animoto",
      "title": "Animoto",
      "domain": "animoto.com",
      "breach_date": "2018-07-10",
      "added": "2019-07-18T05:04:08.000Z",
      "accounts": 22437749,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Geographic locations",
        "Names",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2018, the cloud-based video making service Animoto suffered a data breach. The breach exposed 22 million unique email addresses alongside names, dates of birth, country of origin and salted password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Animoto"
    },
    {
      "name": "BlackSpigotMC",
      "title": "BlackSpigotMC",
      "domain": "blackspigot.com",
      "breach_date": "2019-07-14",
      "added": "2019-07-17T18:44:17.000Z",
      "accounts": 140029,
      "data_classes": [
        "Device information",
        "Email addresses",
        "Genders",
        "Geographic locations",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2019, the hacking website BlackSpigotMC suffered a data breach. The XenForo forum based site was allegedly compromised by a rival hacking website and resulted in 8.5GB of data being leaked including the database and website itself. The exposed data included 140k unique email addresses, usernames, IP addresses, genders, geographic locations and passwords stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BlackSpigotMC"
    },
    {
      "name": "SHEIN",
      "title": "SHEIN",
      "domain": "shein.com",
      "breach_date": "2018-06-01",
      "added": "2019-07-17T13:59:41.000Z",
      "accounts": 39086762,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2018, online fashion retailer SHEIN suffered a data breach. The company discovered the breach 2 months later in August then disclosed the incident another month after that. A total of 39 million unique email addresses were found in the breach alongside MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#SHEIN"
    },
    {
      "name": "piZap",
      "title": "piZap",
      "domain": "pizap.com",
      "breach_date": "2017-12-07",
      "added": "2019-07-16T05:43:27.000Z",
      "accounts": 41817893,
      "data_classes": [
        "Email addresses",
        "Genders",
        "Geographic locations",
        "Names",
        "Passwords",
        "Social media profiles",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately December 2017, the online photo editing site piZap suffered a data breach. The data was later placed up for sale on a dark web marketplace along with a collection of other data breaches in February 2019. A total of 42 million unique email addresses were included in the breach alongside names, genders and links to Facebook profiles when the social media platform was used to authenticate to piZap. When accounts were created directly on piZap without using Facebook for authentication, passwords stored as SHA-1 hashes were also exposed.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#piZap"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
