{
  "query": {
    "page": "45"
  },
  "count": 20,
  "total": 1020,
  "page": 45,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T16:47:45.059Z",
    "kev": "2026-10-07T16:46:45.142Z",
    "epss": "2026-10-07T12:59:36.323Z",
    "breaches": "2026-10-07T12:47:35.891Z",
    "posts": "2026-10-07T16:47:45.059Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=45"
  },
  "warnings": [],
  "results": [
    {
      "name": "MoDaCo",
      "title": "MoDaCo",
      "domain": "modaco.com",
      "breach_date": "2016-01-01",
      "added": "2016-09-20T07:32:50.000Z",
      "accounts": 879703,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately January 2016, the UK based Android community known as MoDaCo suffered a data breach which exposed 880k subscriber identities. The data included email and IP addresses, usernames and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MoDaCo"
    },
    {
      "name": "eThekwiniMunicipality",
      "title": "eThekwini Municipality",
      "domain": "eservices.durban.gov.za",
      "breach_date": "2016-09-07",
      "added": "2016-09-15T00:01:47.000Z",
      "accounts": 81830,
      "data_classes": [
        "Dates of birth",
        "Deceased date",
        "Email addresses",
        "Genders",
        "Government issued IDs",
        "Names",
        "Passport numbers",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Utility bills"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2016, the new eThekwini eServices website in South Africa was launched with a number of security holes that lead to the leak of over 98k residents' personal information and utility bills across 82k unique email addresses. Emails were sent prior to launch containing passwords in plain text and the site allowed anyone to download utility bills without sufficient authentication. Various methods of customer data enumeration was possible and phishing attacks began appearing the day after launch.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#eThekwiniMunicipality"
    },
    {
      "name": "BlueSnapRegpack",
      "title": "Regpack",
      "domain": "bluesnap.com",
      "breach_date": "2016-05-20",
      "added": "2016-09-13T04:35:05.000Z",
      "accounts": 104977,
      "data_classes": [
        "Browser user agent details",
        "Credit card CVV",
        "Email addresses",
        "IP addresses",
        "Names",
        "Partial credit card data",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2016, a tweet was posted with a link to an alleged data breach of BlueSnap, a global payment gateway and merchant account provider. The data contained 324k payment records across 105k unique email addresses and included personal attributes such as name, home address and phone number. The data was verified with multiple Have I Been Pwned subscribers who confirmed it also contained valid transactions, partial credit card numbers, expiry dates and CVVs. A downstream consumer of BlueSnap services known as Regpack was subsequently identified as the source of the data after they identified human error had left the transactions exposed on a publicly facing server. A full investigation of the data and statement by Regpack is detailed in the post titled Someone just lost 324k payment records, complete with CVVs.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BlueSnapRegpack"
    },
    {
      "name": "ClixSense",
      "title": "ClixSense",
      "domain": "clixsense.com",
      "breach_date": "2016-09-04",
      "added": "2016-09-11T06:37:25.000Z",
      "accounts": 2424784,
      "data_classes": [
        "Account balances",
        "Dates of birth",
        "Email addresses",
        "Genders",
        "IP addresses",
        "Names",
        "Passwords",
        "Payment histories",
        "Payment methods",
        "Physical addresses",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2016, the paid-to-click site ClixSense suffered a data breach which exposed 2.4 million subscriber identities. The breached data was then posted online by the attackers who claimed it was a subset of a larger data breach totalling 6.6 million records. The leaked data was extensive and included names, physical, email and IP addresses, genders and birth dates, account balances and passwords stored as plain text.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ClixSense"
    },
    {
      "name": "Pokebip",
      "title": "Pokébip",
      "domain": "pokebip.com",
      "breach_date": "2015-07-28",
      "added": "2016-09-09T04:43:00.000Z",
      "accounts": 657001,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Time zones",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2015, the French Pokémon site Pokébip suffered a data breach which exposed 657k subscriber identities. The data included email and IP addresses, usernames and passwords stored as unsalted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Pokebip"
    },
    {
      "name": "DLH",
      "title": "DLH.net",
      "domain": "dlh.net",
      "breach_date": "2016-07-31",
      "added": "2016-09-07T13:29:25.000Z",
      "accounts": 3264710,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2016, the gaming news site DLH.net suffered a data breach which exposed 3.3M subscriber identities. Along with the keys used to redeem and activate games on the Steam platform, the breach also resulted in the exposure of email addresses, birth dates and salted MD5 password hashes. The data was donated to Have I Been Pwned by data breach monitoring service Vigilante.pw.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#DLH"
    },
    {
      "name": "Experian",
      "title": "Experian (2015)",
      "domain": "experian.com",
      "breach_date": "2015-09-16",
      "added": "2016-09-06T23:49:00.000Z",
      "accounts": 7196890,
      "data_classes": [
        "Credit status information",
        "Dates of birth",
        "Email addresses",
        "Ethnicities",
        "Family structure",
        "Genders",
        "Home ownership statuses",
        "Income levels",
        "IP addresses",
        "Names",
        "Phone numbers",
        "Physical addresses",
        "Purchasing habits"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2015, the US based credit bureau and consumer data broker Experian suffered a data breach that impacted 15 million customers who had applied for financing from T-Mobile. An alleged data breach was subsequently circulated containing personal information including names, physical and email addresses, birth dates and various other personal attributes. Multiple Have I Been Pwned subscribers verified portions of the data as being accurate, but the actual source of it was inconclusive therefor this breach has been flagged as \"unverified\".",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Experian"
    },
    {
      "name": "FlashFlashRevolution",
      "title": "Flash Flash Revolution (2016 breach)",
      "domain": "flashflashrevolution.com",
      "breach_date": "2016-02-01",
      "added": "2016-09-06T08:08:29.000Z",
      "accounts": 1771845,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2016, the music-based rhythm game known as Flash Flash Revolution was hacked and 1.8M accounts were exposed. Along with email and IP addresses, the vBulletin forum also exposed salted MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#FlashFlashRevolution"
    },
    {
      "name": "Onverse",
      "title": "Onverse",
      "domain": "onverse.com",
      "breach_date": "2016-01-01",
      "added": "2016-09-06T06:28:30.000Z",
      "accounts": 800157,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2016, the online virtual world known as Onverse was hacked and 800k accounts were exposed. Along with email and IP addresses, the site also exposed salted MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Onverse"
    },
    {
      "name": "WIIUISO",
      "title": "WIIU ISO",
      "domain": "wiiuiso.com",
      "breach_date": "2015-09-25",
      "added": "2016-09-06T05:51:12.000Z",
      "accounts": 458155,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2015, the Nintendo Wii U forum known as WIIU ISO was hacked and 458k accounts were exposed. Along with email and IP addresses, the vBulletin forum also exposed salted MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#WIIUISO"
    },
    {
      "name": "ServerPact",
      "title": "ServerPact",
      "domain": "serverpact.com",
      "breach_date": "2016-01-01",
      "added": "2016-09-06T04:21:06.000Z",
      "accounts": 73587,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2015, the Dutch Minecraft site ServerPact was hacked and 73k accounts were exposed. Along with birth dates, email and IP addresses, the site also exposed SHA1 password hashes with the username as the salt.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ServerPact"
    },
    {
      "name": "Brazzers",
      "title": "Brazzers",
      "domain": "brazzers.com",
      "breach_date": "2013-04-01",
      "added": "2016-09-05T10:02:23.000Z",
      "accounts": 790724,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2013, the adult website known as Brazzers was hacked and 790k accounts were exposed publicly. Each record included a username, email address and password stored in plain text. The breach was brought to light by the Vigilante.pw data breach reporting site in September 2016.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Brazzers"
    },
    {
      "name": "Dropbox",
      "title": "Dropbox",
      "domain": "dropbox.com",
      "breach_date": "2012-07-01",
      "added": "2016-08-31T00:19:19.000Z",
      "accounts": 68648009,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In mid-2012, Dropbox suffered a data breach which exposed the stored credentials of tens of millions of their customers. In August 2016, they forced password resets for customers they believed may be at risk. A large volume of data totalling over 68 million records was subsequently traded online and included email addresses and salted hashes of passwords (half of them SHA1, half of them bcrypt).",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Dropbox"
    },
    {
      "name": "Interpals",
      "title": "InterPals",
      "domain": "interpals.net",
      "breach_date": "2015-11-04",
      "added": "2016-08-30T11:22:42.000Z",
      "accounts": 3439414,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Geographic locations",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In late 2015, the online penpal site InterPals had their website hacked and 3.4 million accounts exposed. The compromised data included email addresses, geographical locations, birthdates and salted hashes of passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Interpals"
    },
    {
      "name": "Nihonomaru",
      "title": "Nihonomaru",
      "domain": "nihonomaru.net",
      "breach_date": "2015-12-01",
      "added": "2016-08-30T09:54:55.000Z",
      "accounts": 1697282,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In late 2015, the anime community known as Nihonomaru had their vBulletin forum hacked and 1.7 million accounts exposed. The compromised data included email and IP addresses, usernames and salted hashes of passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Nihonomaru"
    },
    {
      "name": "MinecraftWorldMap",
      "title": "Minecraft World Map",
      "domain": "minecraftworldmap.com",
      "breach_date": "2016-01-15",
      "added": "2016-08-29T01:07:38.000Z",
      "accounts": 71081,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately January 2016, the Minecraft World Map site designed for sharing maps created for the game was hacked and over 71k user accounts were exposed. The data included usernames, email and IP addresses along with salted and hashed passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MinecraftWorldMap"
    },
    {
      "name": "GTAGaming",
      "title": "GTAGaming",
      "domain": "gtagaming.com",
      "breach_date": "2016-08-01",
      "added": "2016-08-23T20:41:17.000Z",
      "accounts": 197184,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2016, the Grand Theft Auto forum GTAGaming was hacked and nearly 200k user accounts were leaked. The vBulletin based forum included usernames, email addresses and password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#GTAGaming"
    },
    {
      "name": "Teracod",
      "title": "Teracod",
      "domain": "teracod.org",
      "breach_date": "2016-05-28",
      "added": "2016-08-22T11:21:27.000Z",
      "accounts": 97151,
      "data_classes": [
        "Avatars",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Payment histories",
        "Private messages",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2015, almost 100k user records were extracted from the Hungarian torrent site known as Teracod. The data was later discovered being torrented itself and included email addresses, passwords, private messages between members and the peering history of IP addresses using the service.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Teracod"
    },
    {
      "name": "xat",
      "title": "xat",
      "domain": "xat.com",
      "breach_date": "2015-11-04",
      "added": "2016-08-05T06:53:35.000Z",
      "accounts": 5968783,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2015, the online chatroom known as \"xat\" was hacked and 6 million user accounts were exposed. Used as a chat engine on websites, the leaked data included usernames, email and IP addresses along with hashed passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#xat"
    },
    {
      "name": "Warframe",
      "title": "Warframe",
      "domain": "warframe.com",
      "breach_date": "2014-11-24",
      "added": "2016-07-21T02:25:49.000Z",
      "accounts": 819478,
      "data_classes": [
        "Email addresses",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2014, the online game Warframe was hacked and 819k unique email addresses were exposed. Allegedly due to a SQL injection flaw in Drupal, the attack exposed usernames, email addresses and data in a \"pass\" column which adheres to the salted SHA12 password hashing pattern used by Drupal 7. Digital Extremes (the developers of Warframe), asserts the salted hashes are of \"alias names\" rather than passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Warframe"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
