{
  "query": {
    "page": "44"
  },
  "count": 20,
  "total": 1020,
  "page": 44,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T14:47:40.746Z",
    "kev": "2026-10-07T15:46:42.531Z",
    "epss": "2026-10-07T12:59:36.323Z",
    "breaches": "2026-10-07T12:47:35.891Z",
    "posts": "2026-10-07T15:47:42.703Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=44"
  },
  "warnings": [],
  "results": [
    {
      "name": "Aipai",
      "title": "Aipai.com",
      "domain": "aipai.com",
      "breach_date": "2016-09-27",
      "added": "2016-11-07T21:55:29.000Z",
      "accounts": 6496778,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2016, data allegedly obtained from the Chinese gaming website known as Aipai.com and containing 6.5M accounts was leaked online. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as \"unverified\". The data in the breach contains email addresses and MD5 password hashes. Read more about Chinese data breaches in Have I Been Pwned.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Aipai"
    },
    {
      "name": "CivilOnline",
      "title": "Civil Online",
      "domain": "co188.com",
      "breach_date": "2011-07-10",
      "added": "2016-11-07T20:41:52.000Z",
      "accounts": 7830195,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2011, data was allegedly obtained from the Chinese engineering website known as Civil Online and contained 7.8M accounts. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as \"unverified\". The data in the breach contains email and IP addresses, user names and MD5 password hashes. Read more about Chinese data breaches in Have I Been Pwned.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CivilOnline"
    },
    {
      "name": "Duowan",
      "title": "Duowan.com",
      "domain": "duowan.com",
      "breach_date": "2011-01-01",
      "added": "2016-11-07T12:53:19.000Z",
      "accounts": 2639894,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately 2011, data was allegedly obtained from the Chinese gaming website known as Duowan.com and contained 2.6M accounts. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as \"unverified\". The data in the breach contains email addresses, user names and plain text passwords. Read more about Chinese data breaches in Have I Been Pwned.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Duowan"
    },
    {
      "name": "WarInc",
      "title": "War Inc.",
      "domain": "thewarinc.com",
      "breach_date": "2012-07-04",
      "added": "2016-11-07T11:07:25.000Z",
      "accounts": 1020136,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2012, the real-time strategy game War Inc. suffered a data breach. The attack resulted in the exposure of over 1 million accounts including usernames, email addresses and salted MD5 hashes of passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#WarInc"
    },
    {
      "name": "EpicGames",
      "title": "Epic Games",
      "domain": "epicgames.com",
      "breach_date": "2016-08-11",
      "added": "2016-11-07T10:19:34.000Z",
      "accounts": 251661,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2016, the Epic Games forum suffered a data breach, allegedly due to a SQL injection vulnerability in vBulletin. The attack resulted in the exposure of 252k accounts including usernames, email addresses and salted MD5 hashes of passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#EpicGames"
    },
    {
      "name": "UnrealEngine",
      "title": "Unreal Engine",
      "domain": "unrealengine.com",
      "breach_date": "2016-08-11",
      "added": "2016-11-07T09:04:54.000Z",
      "accounts": 530147,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2016, the Unreal Engine Forum suffered a data breach, allegedly due to a SQL injection vulnerability in vBulletin. The attack resulted in the exposure of 530k accounts including usernames, email addresses and salted MD5 hashes of passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#UnrealEngine"
    },
    {
      "name": "HeroesOfGaia",
      "title": "Heroes of Gaia",
      "domain": "heroesofgaia.com",
      "breach_date": "2013-01-04",
      "added": "2016-11-07T08:11:03.000Z",
      "accounts": 179967,
      "data_classes": [
        "Browser user agent details",
        "Email addresses",
        "IP addresses",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In early 2013, the online fantasy multiplayer game Heroes of Gaia suffered a data breach. The newest records in the data set indicate a breach date of 4 January 2013 and include usernames, IP and email addresses but no passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#HeroesOfGaia"
    },
    {
      "name": "uTorrent",
      "title": "uTorrent",
      "domain": "utorrent.com",
      "breach_date": "2016-01-14",
      "added": "2016-11-05T22:32:39.000Z",
      "accounts": 395044,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In early 2016, the forum for the uTorrent BitTorrent client suffered a data breach which came to light later in the year. The database from the IP.Board based forum contained 395k accounts including usernames, email addresses and MD5 password hashes without a salt.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#uTorrent"
    },
    {
      "name": "Rambler",
      "title": "Rambler",
      "domain": "rambler.ru",
      "breach_date": "2014-03-01",
      "added": "2016-11-01T09:33:34.000Z",
      "accounts": 91436280,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In late 2016, a data dump of almost 100M accounts from Rambler, sometimes referred to as \"The Russian Yahoo\", was discovered being traded online. The data set provided to Have I Been Pwned included 91M unique usernames (which also form part of Rambler email addresses) and plain text passwords. According to Rambler, the data dates back to March 2014.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Rambler"
    },
    {
      "name": "ModernBusinessSolutions",
      "title": "Modern Business Solutions",
      "domain": "modbsolutions.com",
      "breach_date": "2016-10-08",
      "added": "2016-10-12T09:09:11.000Z",
      "accounts": 58843488,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "IP addresses",
        "Job titles",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2016, a large Mongo DB file containing tens of millions of accounts was shared publicly on Twitter (the file has since been removed). The database contained over 58M unique email addresses along with IP addresses, names, home addresses, genders, job titles, dates of birth and phone numbers. The data was subsequently attributed to \"Modern Business Solutions\", a company that provides data storage and database hosting solutions. They've yet to acknowledge the incident or explain how they came to be in possession of the data.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ModernBusinessSolutions"
    },
    {
      "name": "GFAN",
      "title": "GFAN",
      "domain": "gfan.com",
      "breach_date": "2016-10-10",
      "added": "2016-10-10T16:32:34.000Z",
      "accounts": 22526334,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2016, data surfaced that was allegedly obtained from the Chinese website known as GFAN and contained 22.5M accounts. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as \"unverified\". The data in the breach contains email and IP addresses, user names and salted and hashed passwords. Read more about Chinese data breaches in Have I Been Pwned.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GFAN"
    },
    {
      "name": "NetEase",
      "title": "NetEase",
      "domain": "163.com",
      "breach_date": "2015-10-19",
      "added": "2016-10-09T06:13:31.000Z",
      "accounts": 234842089,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2015, the Chinese site known as NetEase (located at 163.com) was reported as having suffered a data breach that impacted hundreds of millions of subscribers. Whilst there is evidence that the data itself is legitimate (multiple HIBP subscribers confirmed a password they use is in the data), due to the difficulty of emphatically verifying the Chinese breach it has been flagged as \"unverified\". The data in the breach contains email addresses and plain text passwords. Read more about Chinese data breaches in Have I Been Pwned.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#NetEase"
    },
    {
      "name": "Taobao",
      "title": "Taobao",
      "domain": "taobao.com",
      "breach_date": "2012-01-01",
      "added": "2016-10-08T10:53:23.000Z",
      "accounts": 21149008,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately 2012, it's alleged that the Chinese shopping site known as Taobao suffered a data breach that impacted over 21 million subscribers. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as \"unverified\". The data in the breach contains email addresses and plain text passwords. Read more about Chinese data breaches in Have I Been Pwned.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Taobao"
    },
    {
      "name": "126",
      "title": "126",
      "domain": "126.com",
      "breach_date": "2012-01-01",
      "added": "2016-10-08T07:46:05.000Z",
      "accounts": 6414191,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately 2012, it's alleged that the Chinese email service known as 126 suffered a data breach that impacted 6.4 million subscribers. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as \"unverified\". The data in the breach contains email addresses and plain text passwords. Read more about Chinese data breaches in Have I Been Pwned.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#126"
    },
    {
      "name": "Aternos",
      "title": "Aternos",
      "domain": "aternos.org",
      "breach_date": "2015-12-06",
      "added": "2016-10-01T23:42:56.000Z",
      "accounts": 1436486,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2015, the service for creating and running free Minecraft servers known as Aternos suffered a data breach that impacted 1.4 million subscribers. The data included usernames, email and IP addresses and hashed passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Aternos"
    },
    {
      "name": "Leet",
      "title": "Leet",
      "domain": "leet.cc",
      "breach_date": "2016-09-10",
      "added": "2016-09-30T22:00:48.000Z",
      "accounts": 5081689,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2016, the service for creating and running Pocket Minecraft edition servers known as Leet was reported as having suffered a data breach that impacted 6 million subscribers. The incident reported by Softpedia had allegedly taken place earlier in the year, although the data set sent to HIBP was dated as recently as early September but contained only 2 million subscribers. The data included usernames, email and IP addresses and SHA512 hashes. A further 3 million accounts were obtained and added to HIBP several days after the initial data was loaded bringing the total to over 5 million.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Leet"
    },
    {
      "name": "iDressup",
      "title": "i-Dressup",
      "domain": "i-dressup.com",
      "breach_date": "2016-07-15",
      "added": "2016-09-26T20:14:51.000Z",
      "accounts": 2191565,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2016, the teen social site known as i-Dressup was hacked and over 2 million user accounts were exposed. At the time the hack was reported, the i-Dressup operators were not contactable and the underlying SQL injection flaw remained open, allegedly exposing a total of 5.5 million accounts. The breach included email addresses and passwords stored in plain text.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#iDressup"
    },
    {
      "name": "gPotato",
      "title": "gPotato",
      "domain": "gpotato.com",
      "breach_date": "2007-07-12",
      "added": "2016-09-24T21:37:43.000Z",
      "accounts": 2136520,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "IP addresses",
        "Names",
        "Passwords",
        "Physical addresses",
        "Security questions and answers",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2007, the multiplayer game portal known as gPotato (link to archive of the site at that time) suffered a data breach and over 2 million user accounts were exposed. The site later merged into the Webzen portal where the original accounts still exist today. The exposed data included usernames, email and IP addresses, MD5 hashes and personal attributes such as gender, birth date, physical address and security questions and answers stored in plain text.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#gPotato"
    },
    {
      "name": "GameTuts",
      "title": "GameTuts",
      "domain": "game-tuts.com",
      "breach_date": "2015-03-01",
      "added": "2016-09-23T23:59:38.000Z",
      "accounts": 2064274,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "Likely in early 2015, the video game website GameTuts suffered a data breach and over 2 million user accounts were exposed. The site later shut down in July 2016 but was identified as having been hosted on a vBulletin forum. The exposed data included usernames, email and IP addresses and salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GameTuts"
    },
    {
      "name": "Lastfm",
      "title": "Last.fm",
      "domain": "last.fm",
      "breach_date": "2012-03-22",
      "added": "2016-09-20T20:00:49.000Z",
      "accounts": 37217682,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2012, the music website Last.fm was hacked and 43 million user accounts were exposed. Whilst Last.fm knew of an incident back in 2012, the scale of the hack was not known until the data was released publicly in September 2016. The breach included 37 million unique email addresses, usernames and passwords stored as unsalted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Lastfm"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
