{
  "query": {
    "page": "36"
  },
  "count": 20,
  "total": 1020,
  "page": 36,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T08:47:26.795Z",
    "kev": "2026-10-07T08:46:26.631Z",
    "epss": "2026-10-07T06:59:23.041Z",
    "breaches": "2026-10-07T06:47:22.500Z",
    "posts": "2026-10-07T08:47:26.795Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=36"
  },
  "warnings": [],
  "results": [
    {
      "name": "Mappery",
      "title": "Mappery",
      "domain": "mappery.com",
      "breach_date": "2018-12-11",
      "added": "2018-12-18T16:19:50.000Z",
      "accounts": 205242,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2018, the mapping website Mappery suffered a data breach that exposed over 205k unique email addresses. The incident also exposed usernames, the geographic location of the user and passwords stored as unsalted SHA-1 hashes. No response was received from Mappery when contacted about the incident.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Mappery"
    },
    {
      "name": "BombujEu",
      "title": "Bombuj.eu",
      "domain": "bombuj.eu",
      "breach_date": "2018-12-07",
      "added": "2018-12-10T14:04:47.000Z",
      "accounts": 575437,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2018, the Slovak website for watching movies online for free Bombuj.eu suffered a data breach. The incident exposed over 575k unique email addresses and passwords stored as unsalted MD5 hashes. No response was received from Bombuj.eu when contacted about the incident.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BombujEu"
    },
    {
      "name": "Hub4Tech",
      "title": "Hub4Tech",
      "domain": "hub4tech.com",
      "breach_date": "2017-01-01",
      "added": "2018-12-09T22:40:51.000Z",
      "accounts": 36916,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "On an unknown date in approximately 2017, the Indian training and assessment service known as Hub4Tech suffered a data breach via a SQL injection attack. The incident exposed almost 37k unique email addresses and passwords stored as unsalted MD5 hashes. No response was received from Hub4Tech when contacted about the incident.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Hub4Tech"
    },
    {
      "name": "YouveBeenScraped",
      "title": "You've Been Scraped",
      "domain": null,
      "breach_date": "2018-10-05",
      "added": "2018-12-06T19:11:27.000Z",
      "accounts": 66147869,
      "data_classes": [
        "Email addresses",
        "Employers",
        "Geographic locations",
        "Job titles",
        "Names",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October and November 2018, security researcher Bob Diachenko identified several unprotected MongoDB instances believed to be hosted by a data aggregator. Containing a total of over 66M records, the owner of the data couldn't be identified but it is believed to have been scraped from LinkedIn hence the title \"You've Been Scraped\". The exposed records included names, both work and personal email addresses, job titles and links to the individuals' LinkedIn profiles.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#YouveBeenScraped"
    },
    {
      "name": "AerServ",
      "title": "AerServ",
      "domain": "aerserv.com",
      "breach_date": "2018-04-01",
      "added": "2018-12-06T02:58:12.000Z",
      "accounts": 66308,
      "data_classes": [
        "Email addresses",
        "Employers",
        "Job titles",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2018, the ad management platform known as AerServ suffered a data breach. Acquired by InMobi earlier in the year, the AerServ breach impacted over 66k unique email addresses and also included contact information and passwords stored as salted SHA-512 hashes. The data was publicly posted to Twitter later in 2018 after which InMobi was notified and advised they were aware of the incident.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#AerServ"
    },
    {
      "name": "ForumCommunity",
      "title": "ForumCommunity",
      "domain": "forumcommunity.net",
      "breach_date": "2016-06-01",
      "added": "2018-12-05T05:04:45.000Z",
      "accounts": 776648,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately mid-2016, the Italian-based service for creating forums known as ForumCommunity suffered a data breach. The incident impacted over 776k unique email addresses along with usernames and unsalted MD5 password hashes. No response was received from ForumCommunity when contacted.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ForumCommunity"
    },
    {
      "name": "Technic",
      "title": "Technic",
      "domain": "technicpack.net",
      "breach_date": "2018-11-30",
      "added": "2018-12-04T02:32:35.000Z",
      "accounts": 265410,
      "data_classes": [
        "Chat logs",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Private messages",
        "Time zones"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2018, the Minecraft modpack platform known as Technic suffered a data breach. Technic promptly disclosed the breach and advised that the impacted data included over 265k unique users' email and IP addresses, chat logs, private messages and passwords stored as bcrypt hashes with a work factor of 13. Technic self-submitted the breach to HIBP.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Technic"
    },
    {
      "name": "DataAndLeads",
      "title": "Data & Leads",
      "domain": "datanleads.com",
      "breach_date": "2018-11-14",
      "added": "2018-11-28T19:32:19.000Z",
      "accounts": 44320330,
      "data_classes": [
        "Email addresses",
        "Employers",
        "IP addresses",
        "Job titles",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2018, security researcher Bob Diachenko identified an unprotected database believed to be hosted by a data aggregator. Upon further investigation, the data was linked to marketing company Data & Leads. The exposed Elasticsearch instance contained over 44M unique email addresses along with names, IP and physical addresses, phone numbers and employment information. No response was received from Data & Leads when contacted by Bob and their site subsequently went offline.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#DataAndLeads"
    },
    {
      "name": "Adapt",
      "title": "Adapt",
      "domain": "adapt.io",
      "breach_date": "2018-11-05",
      "added": "2018-11-22T19:43:06.000Z",
      "accounts": 9363740,
      "data_classes": [
        "Email addresses",
        "Employers",
        "Job titles",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Social media profiles"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2018, security researcher Bob Diachenko identified an unprotected database hosted by data aggregator \"Adapt\". A provider of \"Fresh Quality Contacts\", the service exposed over 9.3M unique records of individuals and employer information including their names, employers, job titles, contact information and data relating to the employer including organisation description, size and revenue. No response was received from Adapt when contacted.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Adapt"
    },
    {
      "name": "HTHStudios",
      "title": "HTH Studios",
      "domain": "hthstudios.com",
      "breach_date": "2018-08-24",
      "added": "2018-11-20T21:22:09.000Z",
      "accounts": 411755,
      "data_classes": [
        "Browser user agent details",
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Purchases",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2018, the adult furry interactive game creator HTH Studios suffered a data breach impacting multiple repositories of customer data. Several months later, the data surfaced on a popular hacking forum and included 411k unique email addresses along with physical and IP addresses, names, orders, salted SHA-1 and salted MD5 hashes. HTH Studios is aware of the incident.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#HTHStudios"
    },
    {
      "name": "ElasticsearchSalesLeads",
      "title": "Elasticsearch Instance of Sales Leads on AWS",
      "domain": null,
      "breach_date": "2018-10-29",
      "added": "2018-11-17T09:04:54.000Z",
      "accounts": 5788169,
      "data_classes": [
        "Email addresses",
        "Employers",
        "Names",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2018, security researcher Bob Diachenko identified multiple exposed databases with hundreds of millions of records. One of those datasets was an Elasticsearch instance on AWS containing sales lead data and 5.8M unique email addresses. The data contained information relating to individuals and the companies they worked for including their names, email addresses and company name and contact information. Despite best efforts, it was not possible to identify the owner of the data hence this breach as been titled \"Elasticsearch Sales Leads\".",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ElasticsearchSalesLeads"
    },
    {
      "name": "KnownCircle",
      "title": "KnownCircle",
      "domain": "knowncircle.com",
      "breach_date": "2016-04-12",
      "added": "2018-11-17T02:33:54.000Z",
      "accounts": 1957600,
      "data_classes": [
        "Email addresses",
        "Email messages",
        "Genders",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately April 2016, the \"marketing automation for agents and professional service providers\" company KnownCircle had a large volume of data obtained by an external party. The data belonging to the now defunct service appeared in JSON format and contained gigabytes of data related to the real estate and insurance sectors. The personal data in the breach appears to have primarily been used for marketing purposes, including logs of emails sent and tracking of gift cards. A small number of passwords for KnownCircle staff were also present and were stored as bcrypt hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#KnownCircle"
    },
    {
      "name": "RbxRocks",
      "title": "Rbx.Rocks",
      "domain": "rbx.rocks",
      "breach_date": "2018-08-06",
      "added": "2018-11-07T13:26:42.000Z",
      "accounts": 149958,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2018, the Roblox trading site Rbx.Rocks suffered a data breach. Almost 25k records were sent to HIBP in November and included names, email addresses and passwords stored as bcrypt hashes. In July 2019, a further 125k records emerged bringing the total size of the incident to 150k. The website has since gone offline with a message stating that \"Rbx.Rocks v2.0 is currently under construction\".",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#RbxRocks"
    },
    {
      "name": "SIAE",
      "title": "Società Italiana degli Autori ed Editori",
      "domain": "siae.it",
      "breach_date": "2018-11-03",
      "added": "2018-11-07T04:31:14.000Z",
      "accounts": 14609,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2018, the Società Italiana degli Autori ed Editori (Italian Society of Authors and Publishers, or SIAE) was hacked, defaced and almost 4GB of data leaked publicly via Twitter. The data included over 14k registered users' names, email addresses and passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#SIAE"
    },
    {
      "name": "WPSandbox",
      "title": "WPSandbox",
      "domain": "wpsandbox.io",
      "breach_date": "2018-11-04",
      "added": "2018-11-06T07:26:07.000Z",
      "accounts": 858,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2018, the WordPress sandboxing service that allows people to create temporary websites WP Sandbox discovered their service was being used to host a phishing site attempting to collect Microsoft OneDrive accounts. After identifying the malicious site, WP Sandbox took it offline, contacted the 858 people who provided information to it then self-submitted their addresses to HIBP. The phishing page requested both email addresses and passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#WPSandbox"
    },
    {
      "name": "JoomlArt",
      "title": "JoomlArt",
      "domain": "joomlart.com",
      "breach_date": "2018-01-30",
      "added": "2018-11-01T03:27:26.000Z",
      "accounts": 22477,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Payment histories",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2018, the Joomla template website JoomlArt inadvertently exposed more than 22k unique customer records in a Jira ticket. The exposed data was from iJoomla and JomSocial, both services that JoomlArt acquired the previous year. The data included usernames, email addresses, purchases and passwords stored as MD5 hashes. When contacted, JoomlArt advised they were aware of the incident and had previously notified impacted parties.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#JoomlArt"
    },
    {
      "name": "MacForums",
      "title": "Mac Forums",
      "domain": "mac-forums.com",
      "breach_date": "2016-07-03",
      "added": "2018-10-29T23:47:44.000Z",
      "accounts": 326714,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2016, the self-proclaimed \"Ultimate Source For Your Mac\" website Mac Forums suffered a data breach. The vBulletin-based system exposed over 326k usernames, email and IP addresses, dates of birth and passwords stored as salted MD5 hashes. The data was later discovered being traded on a popular hacking forum. Mac Forums did not respond when contacted about the incident via their contact us form.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MacForums"
    },
    {
      "name": "BabyNames",
      "title": "Baby Names",
      "domain": "babynames.com",
      "breach_date": "2008-10-24",
      "added": "2018-10-24T06:27:03.000Z",
      "accounts": 846742,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately 2008, the site to help parents name their children known as Baby Names suffered a data breach. The incident exposed 846k email addresses and passwords stored as salted MD5 hashes. When contacted in October 2018, Baby Names advised that \"the breach happened at least ten years ago\" and that members were notified at the time.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BabyNames"
    },
    {
      "name": "WifeLovers",
      "title": "Wife Lovers",
      "domain": "wifelovers.com",
      "breach_date": "2018-10-07",
      "added": "2018-10-20T20:26:13.000Z",
      "accounts": 1274051,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2018, the site dedicated to posting naked photos and other erotica of wives Wife Lovers suffered a data breach. The underlying database supported a total of 8 different adult websites and contained over 1.2M unique email addresses. Wife Lovers acknowledged the breach which impacted names, usernames, email and IP addresses and passwords hashed using the weak DEScrypt algorithm. The breach has been marked as \"sensitive\" due to the nature of the site.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#WifeLovers"
    },
    {
      "name": "Facepunch",
      "title": "Facepunch",
      "domain": "facepunch.com",
      "breach_date": "2016-06-03",
      "added": "2018-10-17T13:15:39.000Z",
      "accounts": 342913,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2016, the game development studio Facepunch suffered a data breach that exposed 343k users. The breached data included usernames, email and IP addresses, dates of birth and salted MD5 password hashes. Facepunch advised they were aware of the incident and had notified people at the time. The data was provided to HIBP by whitehat security researcher and data analyst Adam Davies.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Facepunch"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
