{
  "query": {
    "page": "43"
  },
  "count": 20,
  "total": 1020,
  "page": 43,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T14:47:40.746Z",
    "kev": "2026-10-07T14:46:40.605Z",
    "epss": "2026-10-07T12:59:36.323Z",
    "breaches": "2026-10-07T12:47:35.891Z",
    "posts": "2026-10-07T14:47:40.746Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=43"
  },
  "warnings": [],
  "results": [
    {
      "name": "TheCandidBoard",
      "title": "The Candid Board",
      "domain": "thecandidboard.com",
      "breach_date": "2015-09-03",
      "added": "2017-01-22T08:33:43.000Z",
      "accounts": 178201,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Geographic locations",
        "IP addresses",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2015, the non-consensual voyeurism site \"The Candid Board\" suffered a data breach. The hack of the vBulletin forum led to the exposure of over 178k accounts along with email and IP addresses, dates of birth and salted passwords hashed with MD5.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#TheCandidBoard"
    },
    {
      "name": "MrExcel",
      "title": "MrExcel",
      "domain": "mrexcel.com",
      "breach_date": "2016-12-05",
      "added": "2017-01-22T07:39:17.000Z",
      "accounts": 366140,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Social connections",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2016, the forum for the Microsoft Excel tips and solutions site Mr Excel suffered a data breach. The hack of the vBulletin forum led to the exposure of over 366k accounts along with email and IP addresses, dates of birth and salted passwords hashed with MD5. The owner of the MrExcel forum subsequently self-submitted the data to HIBP.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MrExcel"
    },
    {
      "name": "Eroticy",
      "title": "Eroticy",
      "domain": "eroticy.com",
      "breach_date": "2015-06-01",
      "added": "2017-01-10T02:19:56.000Z",
      "accounts": 1370175,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Payment histories",
        "Phone numbers",
        "Physical addresses",
        "Usernames",
        "Website activity"
      ],
      "verified": false,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2016, it's alleged that the adult website known as Eroticy was hacked. Almost 1.4 million unique accounts were found circulating in late 2016 which contained a raft of personal information ranging from email addresses to phone numbers to plain text passwords. Whilst many HIBP subscribers confirmed their data was legitimate, the actual source of the breach remains inconclusive. A detailed account of the data has been published in the hope of identifying the origin of the breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Eroticy"
    },
    {
      "name": "QIP",
      "title": "QIP",
      "domain": "qip.ru",
      "breach_date": "2011-06-01",
      "added": "2017-01-08T22:23:19.000Z",
      "accounts": 26183992,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2011, the Russian instant messaging service known as QIP (Quiet Internet Pager) suffered a data breach. The attack resulted in the disclosure of over 26 million unique accounts including email addresses and passwords with the data eventually appearing in public years later.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#QIP"
    },
    {
      "name": "PokemonNegro",
      "title": "Pokémon Negro",
      "domain": "pokemonnegro.com",
      "breach_date": "2016-10-01",
      "added": "2017-01-03T20:45:24.000Z",
      "accounts": 830155,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately October 2016, the Spanish Pokémon site Pokémon Negro suffered a data breach. The attack resulted in the disclosure of 830k accounts including email and IP addresses along with plain text passwords. Pokémon Negro did not respond when contacted about the breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#PokemonNegro"
    },
    {
      "name": "DaniWeb",
      "title": "DaniWeb",
      "domain": "daniweb.com",
      "breach_date": "2015-12-01",
      "added": "2016-12-28T23:12:16.000Z",
      "accounts": 1131636,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In late 2015, the technology and social site DaniWeb suffered a data breach. The attack resulted in the disclosure of 1.1 million accounts including email and IP addresses which were also accompanied by salted MD5 hashes of passwords. However, DaniWeb have advised that \"the breached password hashes and salts are incorrect\" and that they have since switched to new infrastructure and software.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#DaniWeb"
    },
    {
      "name": "Parapa",
      "title": "Пара Па",
      "domain": "parapa.mail.ru",
      "breach_date": "2016-08-08",
      "added": "2016-12-28T07:03:17.000Z",
      "accounts": 4946850,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2016, the Russian gaming site known as Пара Па (or parapa.mail.ru) was hacked along with a number of other forums on the Russian mail provider, mail.ru. The vBulletin forum contained 4.9 million accounts including usernames, email addresses and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Parapa"
    },
    {
      "name": "CrossFire",
      "title": "Cross Fire",
      "domain": "cfire.mail.ru",
      "breach_date": "2016-08-08",
      "added": "2016-12-28T00:29:28.000Z",
      "accounts": 12865609,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2016, the Russian gaming forum known as Cross Fire (or cfire.mail.ru) was hacked along with a number of other forums on the Russian mail provider, mail.ru. The vBulletin forum contained 12.8 million accounts including usernames, email addresses and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CrossFire"
    },
    {
      "name": "uuu9",
      "title": "uuu9",
      "domain": "uuu9.com",
      "breach_date": "2016-09-06",
      "added": "2016-12-27T10:05:41.000Z",
      "accounts": 7485802,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2016, data was allegedly obtained from the Chinese website known as uuu9.com and contained 7.5M accounts. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as \"unverified\". The data in the breach contains email addresses and user names. Read more about Chinese data breaches in Have I Been Pwned.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#uuu9"
    },
    {
      "name": "BotOfLegends",
      "title": "Bot of Legends",
      "domain": "botoflegends.com",
      "breach_date": "2014-11-13",
      "added": "2016-12-27T08:24:52.000Z",
      "accounts": 238373,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2014, the forum for Bot of Legends suffered a data breach. The IP.Board forum contained 238k accounts including usernames, email and IP addresses and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BotOfLegends"
    },
    {
      "name": "OVH",
      "title": "OVH",
      "domain": "ovh.com",
      "breach_date": "2015-05-01",
      "added": "2016-12-27T07:49:12.000Z",
      "accounts": 452899,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2015, the forum for the hosting provider known as OVH suffered a data breach. The vBulletin forum contained 453k accounts including usernames, email and IP addresses and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#OVH"
    },
    {
      "name": "Kimsufi",
      "title": "Kimsufi",
      "domain": "kimsufi.com",
      "breach_date": "2015-05-01",
      "added": "2016-12-27T07:05:43.000Z",
      "accounts": 504565,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2015, the forum for the providers of affordable dedicated servers known as Kimsufi suffered a data breach. The vBulletin forum contained over half a million accounts including usernames, email and IP addresses and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Kimsufi"
    },
    {
      "name": "Ethereum",
      "title": "Ethereum",
      "domain": "ethereum.org",
      "breach_date": "2016-12-16",
      "added": "2016-12-20T23:56:26.000Z",
      "accounts": 16431,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Private messages",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2016, the forum for the public blockchain-based distributed computing platform Ethereum suffered a data breach. The database contained over 16k unique email addresses along with IP addresses, private forum messages and (mostly) bcrypt hashed passwords. Ethereum elected to self-submit the data to HIBP, providing the service with a list of email addresses impacted by the incident.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Ethereum"
    },
    {
      "name": "QuinStreet",
      "title": "QuinStreet",
      "domain": "quinstreet.com",
      "breach_date": "2015-12-14",
      "added": "2016-12-17T07:44:31.000Z",
      "accounts": 4907802,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately late 2015, the maker of \"performance marketing products\" QuinStreet had a number of their online assets compromised. The attack impacted 28 separate sites, predominantly technology forums such as flashkit.com, codeguru.com and webdeveloper.com (view a full list of sites). QuinStreet advised that impacted users have been notified and passwords reset. The data contained details on over 4.9 million people and included email addresses, dates of birth and salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#QuinStreet"
    },
    {
      "name": "PayAsUGym",
      "title": "PayAsUGym",
      "domain": "payasugym.com",
      "breach_date": "2016-12-15",
      "added": "2016-12-17T06:45:44.000Z",
      "accounts": 400260,
      "data_classes": [
        "Browser user agent details",
        "Email addresses",
        "IP addresses",
        "Names",
        "Partial credit card data",
        "Passwords",
        "Phone numbers",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2016, an attacker breached PayAsUGym's website exposing over 400k customers' personal data. The data was consequently leaked publicly and broadly distributed via Twitter. The leaked data contained personal information including email addresses and passwords hashed using MD5 without a salt.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#PayAsUGym"
    },
    {
      "name": "GeekedIn",
      "title": "GeekedIn",
      "domain": "geekedin.net",
      "breach_date": "2016-08-15",
      "added": "2016-11-17T19:44:24.000Z",
      "accounts": 1073164,
      "data_classes": [
        "Email addresses",
        "Geographic locations",
        "Names",
        "Professional skills",
        "Usernames",
        "Years of professional experience"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2016, the technology recruitment site GeekedIn left a MongoDB database exposed and over 8M records were extracted by an unknown third party. The breached data was originally scraped from GitHub in violation of their terms of use and contained information exposed in public profiles, including over 1 million members' email addresses. Full details on the incident (including how impacted members can see their leaked data) are covered in the blog post on 8 million GitHub profiles were leaked from GeekedIn's MongoDB - here's how to see yours.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GeekedIn"
    },
    {
      "name": "ArmyForceOnline",
      "title": "Army Force Online",
      "domain": "armyforceonline.com",
      "breach_date": "2016-05-18",
      "added": "2016-11-10T03:24:38.000Z",
      "accounts": 1531235,
      "data_classes": [
        "Avatars",
        "Email addresses",
        "Geographic locations",
        "IP addresses",
        "Names",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2016, the online gaming site Army Force Online suffered a data breach that exposed 1.5M accounts. The breached data was found being regularly traded online and included usernames, email and IP addresses and MD5 passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ArmyForceOnline"
    },
    {
      "name": "Dodonew",
      "title": "Dodonew.com",
      "domain": "dodonew.com",
      "breach_date": "2011-12-01",
      "added": "2016-11-10T00:26:01.000Z",
      "accounts": 8718404,
      "data_classes": [
        "Email addresses",
        "Usernames"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In late 2011, data was allegedly obtained from the Chinese website known as Dodonew.com and contained 8.7M accounts. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as \"unverified\". The data in the breach contains email addresses and user names. Read more about Chinese data breaches in Have I Been Pwned.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Dodonew"
    },
    {
      "name": "Lookbook",
      "title": "Lookbook",
      "domain": "lookbook.nu",
      "breach_date": "2012-08-24",
      "added": "2016-11-08T09:03:44.000Z",
      "accounts": 1074948,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2012, the fashion site Lookbook suffered a data breach. The data later appeared listed for sale in June 2016 and included 1.1 million usernames, email and IP addresses, birth dates and plain text passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Lookbook"
    },
    {
      "name": "CheapAssGamer",
      "title": "CheapAssGamer.com",
      "domain": "cheapassgamer.com",
      "breach_date": "2015-07-01",
      "added": "2016-11-08T01:58:39.000Z",
      "accounts": 444767,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately mid-2015, the forum for CheapAssGamer.com suffered a data breach. The database from the IP.Board based forum contained 445k accounts including usernames, email and IP addresses and salted MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CheapAssGamer"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
