{
  "query": {
    "page": "34"
  },
  "count": 20,
  "total": 1020,
  "page": 34,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T06:47:22.780Z",
    "kev": "2026-10-07T06:46:22.231Z",
    "epss": "2026-10-07T06:59:23.041Z",
    "breaches": "2026-10-07T06:47:22.500Z",
    "posts": "2026-10-07T06:47:22.780Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=34"
  },
  "warnings": [],
  "results": [
    {
      "name": "SHEIN",
      "title": "SHEIN",
      "domain": "shein.com",
      "breach_date": "2018-06-01",
      "added": "2019-07-17T13:59:41.000Z",
      "accounts": 39086762,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2018, online fashion retailer SHEIN suffered a data breach. The company discovered the breach 2 months later in August then disclosed the incident another month after that. A total of 39 million unique email addresses were found in the breach alongside MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#SHEIN"
    },
    {
      "name": "piZap",
      "title": "piZap",
      "domain": "pizap.com",
      "breach_date": "2017-12-07",
      "added": "2019-07-16T05:43:27.000Z",
      "accounts": 41817893,
      "data_classes": [
        "Email addresses",
        "Genders",
        "Geographic locations",
        "Names",
        "Passwords",
        "Social media profiles",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately December 2017, the online photo editing site piZap suffered a data breach. The data was later placed up for sale on a dark web marketplace along with a collection of other data breaches in February 2019. A total of 42 million unique email addresses were included in the breach alongside names, genders and links to Facebook profiles when the social media platform was used to authenticate to piZap. When accounts were created directly on piZap without using Facebook for authentication, passwords stored as SHA-1 hashes were also exposed.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#piZap"
    },
    {
      "name": "Netlog",
      "title": "Netlog",
      "domain": "netlog.com",
      "breach_date": "2012-11-01",
      "added": "2019-07-15T10:25:07.000Z",
      "accounts": 49038354,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2018, the Belgian social networking site Netlog identified a data breach of their systems dating back to November 2012 (PDF). Although the service was discontinued in 2015, the data breach still impacted 49 million subscribers for whom email addresses and plain text passwords were exposed.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Netlog"
    },
    {
      "name": "Evite",
      "title": "Evite",
      "domain": "evite.com",
      "breach_date": "2013-08-11",
      "added": "2019-07-14T14:51:51.000Z",
      "accounts": 100985047,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2019, the social planning website for managing online invitations Evite identified a data breach of their systems. Upon investigation, they found unauthorised access to a database archive dating back to 2013. The exposed data included a total of 101 million unique email addresses, most belonging to recipients of invitations. Members of the service also had names, phone numbers, physical addresses, dates of birth, genders and passwords stored in plain text exposed.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Evite"
    },
    {
      "name": "MindJolt",
      "title": "Mindjolt",
      "domain": "mindjolt.com",
      "breach_date": "2019-03-18",
      "added": "2019-07-13T19:21:12.000Z",
      "accounts": 28364826,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2019, the online gaming website MindJolt suffered a data breach that exposed 28M unique email addresses. Also impacted were names and dates of birth, but no passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MindJolt"
    },
    {
      "name": "Zhenai",
      "title": "Zhenai.com",
      "domain": "zhenai.com",
      "breach_date": "2011-12-21",
      "added": "2019-07-11T06:31:32.000Z",
      "accounts": 5024908,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": false,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2011, the Chinese dating site known as Zhenai.com suffered a data breach that impacted 5 million subscribers. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as \"unverified\". The data in the breach contains email addresses and plain text passwords. Read more about Chinese data breaches in Have I Been Pwned.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Zhenai"
    },
    {
      "name": "WienerBuchereien",
      "title": "Wiener Büchereien",
      "domain": null,
      "breach_date": "2019-06-10",
      "added": "2019-06-28T07:51:50.000Z",
      "accounts": 224119,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2019, the library of Vienna (Wiener Büchereien) suffered a data breach. The compromised data included 224k unique email addresses, names, physical addresses, phone numbers and dates of birth. The breached data was subsequently posted to Twitter by the alleged perpetrator of the breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#WienerBuchereien"
    },
    {
      "name": "SocialEngineered",
      "title": "Social Engineered",
      "domain": "socialengineered.net",
      "breach_date": "2019-06-13",
      "added": "2019-06-23T20:46:39.000Z",
      "accounts": 89392,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Private messages",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2019, the \"Art of Human Hacking\" site Social Engineered suffered a data breach. The breach of the MyBB forum was published on a rival hacking forum and included 89k unique email addresses spread across 55k forum users and other tables in the database. The exposed data also included usernames, IP addresses, private messages and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#SocialEngineered"
    },
    {
      "name": "D3scene",
      "title": "D3Scene",
      "domain": "d3scene.com",
      "breach_date": "2016-01-01",
      "added": "2019-06-15T15:19:11.000Z",
      "accounts": 568827,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2016, the gaming website D3Scene, suffered a data breach. The compromised vBulletin forum exposed 569k million email addresses, IP address, usernames and passwords stored as salted MD5 hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#D3scene"
    },
    {
      "name": "Emuparadise",
      "title": "Emuparadise",
      "domain": "emuparadise.me",
      "breach_date": "2018-04-01",
      "added": "2019-06-09T06:23:35.000Z",
      "accounts": 1131229,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2018, the self-proclaimed \"biggest retro gaming website on earth\", Emuparadise, suffered a data breach. The compromised vBulletin forum exposed 1.1 million email addresses, IP address, usernames and passwords stored as salted MD5 hashes. The data was provided to HIBP by dehashed.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Emuparadise"
    },
    {
      "name": "OrdineAvvocatiDiRoma",
      "title": "Ordine Avvocati di Roma",
      "domain": "ordineavvocatiroma.it",
      "breach_date": "2019-05-07",
      "added": "2019-05-26T23:24:11.000Z",
      "accounts": 41960,
      "data_classes": [
        "Email addresses",
        "Email messages",
        "Geographic locations",
        "Passwords",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2019, the Lawyers Order of Rome suffered a data breach by a group claiming to be Anonymous Italy. Data on tens of thousands of Roman lawyers was taken from the breached system and redistributed online. The data included contact information, email addresses and email messages themselves encompassing tens of thousands of unique email addresses. A total of 42k unique addresses appeared in the breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#OrdineAvvocatiDiRoma"
    },
    {
      "name": "OGUsers",
      "title": "OGUsers (2019 breach)",
      "domain": "ogusers.com",
      "breach_date": "2018-12-26",
      "added": "2019-05-19T22:45:45.000Z",
      "accounts": 161143,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Private messages",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2019, the account hijacking and SIM swapping forum OGusers suffered a data breach. The breach exposed a database backup from December 2018 which was published on a rival hacking forum. There were 161k unique email addresses spread across 113k forum users and other tables in the database. The exposed data also included usernames, IP addresses, private messages and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#OGUsers"
    },
    {
      "name": "Appartoo",
      "title": "Appartoo",
      "domain": "appartoo.com",
      "breach_date": "2017-03-25",
      "added": "2019-05-02T07:07:24.000Z",
      "accounts": 49681,
      "data_classes": [
        "Ages",
        "Auth tokens",
        "Email addresses",
        "Employment statuses",
        "Genders",
        "IP addresses",
        "Marital statuses",
        "Names",
        "Passwords",
        "Physical addresses",
        "Private messages",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2017, the French Flatsharing site known as Appartoo suffered a data breach. The incident exposed an extensive amount of personal information on almost 50k members including email addresses, genders, ages, private messages sent between users of the service and passwords stored as SHA-256 hashes. Appartoo advised that all subscribers were notified of the incident in early 2017.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Appartoo"
    },
    {
      "name": "ClubPenguinRewritten",
      "title": "Club Penguin Rewritten (January 2018)",
      "domain": "cprewritten.net",
      "breach_date": "2018-01-21",
      "added": "2019-04-23T05:05:16.000Z",
      "accounts": 1688176,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2018, the children's gaming site Club Penguin Rewritten (CPRewritten) suffered a data breach (note: CPRewritten is an independent recreation of Disney's Club Penguin game). The incident exposed almost 1.7 million unique email addresses alongside IP addresses, usernames and passwords stored as bcrypt hashes. When contacted, CPRewritten advised they were aware of the breach and had \"contacted affected users\".",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ClubPenguinRewritten"
    },
    {
      "name": "MoreleNet",
      "title": "Morele.net",
      "domain": "morele.net",
      "breach_date": "2018-10-10",
      "added": "2019-04-20T22:57:28.000Z",
      "accounts": 2467304,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2018, the Polish e-commerce website Morele.net suffered a data breach. The incident exposed almost 2.5 million unique email addresses alongside phone numbers, names and passwords stored as md5crypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MoreleNet"
    },
    {
      "name": "Bukalapak",
      "title": "Bukalapak",
      "domain": "bukalapak.com",
      "breach_date": "2017-10-23",
      "added": "2019-04-18T01:57:35.000Z",
      "accounts": 13369666,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2019, the Indonesian e-commerce website Bukalapak discovered a data breach of the organisation's backups dating back to October 2017. The incident exposed approximately 13 million unique email addresses alongside IP addresses, names and passwords stored as bcrypt and salted SHA-512 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Bukalapak"
    },
    {
      "name": "DataCamp",
      "title": "DataCamp",
      "domain": "datacamp.com",
      "breach_date": "2017-01-30",
      "added": "2019-04-09T04:29:55.000Z",
      "accounts": 760561,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "IP addresses",
        "Names",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2018, the data science website DataCamp suffered a data breach of records dating back to January 2017. The incident exposed 760k unique email and IP addresses along with names and passwords stored as bcrypt hashes. In 2019, the data appeared listed for sale on a dark web marketplace (along with several other large breaches) and subsequently began circulating more broadly.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#DataCamp"
    },
    {
      "name": "Knuddels",
      "title": "Knuddels",
      "domain": "knuddels.de",
      "breach_date": "2018-09-05",
      "added": "2019-04-08T21:11:56.000Z",
      "accounts": 808330,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2018, the German social media website Knuddels suffered a data breach. The incident exposed 808k unique email addresses alongside usernames, real names, the city of the person and their password in plain text. Knuddels was subsequently fined €20k for the breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Knuddels"
    },
    {
      "name": "DemonForums",
      "title": "Demon Forums",
      "domain": "demonforums.net",
      "breach_date": "2019-02-20",
      "added": "2019-04-04T07:14:34.000Z",
      "accounts": 52623,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2019, the hacking forum Demon Forums suffered a data breach. The compromise of the vBulletin forum exposed 52k unique email addresses alongside usernames and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#DemonForums"
    },
    {
      "name": "EverybodyEdits",
      "title": "Everybody Edits",
      "domain": "everybodyedits.com",
      "breach_date": "2019-03-23",
      "added": "2019-04-03T10:50:16.000Z",
      "accounts": 871190,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2019, the multiplayer platform game Everybody Edits suffered a data breach. The incident exposed 871k unique email addresses alongside usernames and IP addresses. The data was subsequently distributed online across a collection of files.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#EverybodyEdits"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
