{
  "query": {
    "page": "46"
  },
  "count": 20,
  "total": 1020,
  "page": 46,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T16:47:45.059Z",
    "kev": "2026-10-07T17:46:46.967Z",
    "epss": "2026-10-07T12:59:36.323Z",
    "breaches": "2026-10-07T12:47:35.891Z",
    "posts": "2026-10-07T17:47:47.210Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=46"
  },
  "warnings": [],
  "results": [
    {
      "name": "Trillian",
      "title": "Trillian",
      "domain": "trillian.im",
      "breach_date": "2015-12-27",
      "added": "2016-07-15T11:14:44.000Z",
      "accounts": 3827238,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2015, the instant messaging application Trillian suffered a data breach. The breach became known in July 2016 and exposed various personal data attributes including names, email addresses and passwords stored as salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Trillian"
    },
    {
      "name": "17Media",
      "title": "17",
      "domain": "17app.co",
      "breach_date": "2016-04-19",
      "added": "2016-07-08T01:55:03.000Z",
      "accounts": 4009640,
      "data_classes": [
        "Device information",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2016, customer data obtained from the streaming app known as \"17\" appeared listed for sale on a Tor hidden service marketplace. The data contained over 4 million unique email addresses along with IP addresses, usernames and passwords stored as unsalted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#17Media"
    },
    {
      "name": "Neopets",
      "title": "Neopets",
      "domain": "neopets.com",
      "breach_date": "2013-05-05",
      "added": "2016-07-07T23:00:10.000Z",
      "accounts": 26892897,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Geographic locations",
        "IP addresses",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2016, a set of breached data originating from the virtual pet website \"Neopets\" was found being traded online. Allegedly hacked \"several years earlier\", the data contains sensitive personal information including birthdates, genders and names as well as almost 27 million unique email addresses. Passwords were stored in plain text and IP addresses were also present in the breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Neopets"
    },
    {
      "name": "Badoo",
      "title": "Badoo",
      "domain": "badoo.com",
      "breach_date": "2013-06-01",
      "added": "2016-07-06T08:16:03.000Z",
      "accounts": 112005531,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": false,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2016, a data breach allegedly originating from the social website Badoo was found to be circulating amongst traders. Likely obtained several years earlier, the data contained 112 million unique email addresses with personal data including names, birthdates and passwords stored as MD5 hashes. Whilst there are many indicators suggesting Badoo did indeed suffer a data breach, the legitimacy of the data could not be emphatically proven so this breach has been categorised as \"unverified\".",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Badoo"
    },
    {
      "name": "iMesh",
      "title": "iMesh",
      "domain": "imesh.com",
      "breach_date": "2013-09-22",
      "added": "2016-07-02T05:42:13.000Z",
      "accounts": 49467477,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2013, the media and file sharing client known as iMesh was hacked and approximately 50M accounts were exposed. The data was later put up for sale on a dark market website in mid-2016 and included email and IP addresses, usernames and salted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#iMesh"
    },
    {
      "name": "Tianya",
      "title": "Tianya",
      "domain": "tianya.cn",
      "breach_date": "2011-12-26",
      "added": "2016-06-30T03:39:05.000Z",
      "accounts": 29020808,
      "data_classes": [
        "Email addresses",
        "Names",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2011, China's largest online forum known as Tianya was hacked and tens of millions of accounts were obtained by the attacker. The leaked data included names, usernames and email addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Tianya"
    },
    {
      "name": "MuslimMatch",
      "title": "Muslim Match",
      "domain": "muslimmatch.com",
      "breach_date": "2016-06-24",
      "added": "2016-06-29T19:08:15.000Z",
      "accounts": 149830,
      "data_classes": [
        "Chat logs",
        "Email addresses",
        "Geographic locations",
        "IP addresses",
        "Passwords",
        "Private messages",
        "User statuses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2016, the Muslim Match dating website had 150k email addresses exposed. The data included private chats and messages between relationship seekers and numerous other personal attributes including passwords hashed with MD5.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MuslimMatch"
    },
    {
      "name": "WHMCS",
      "title": "WHMCS",
      "domain": "whmcs.com",
      "breach_date": "2012-05-21",
      "added": "2016-06-28T23:47:07.000Z",
      "accounts": 134047,
      "data_classes": [
        "Email addresses",
        "Email messages",
        "Employers",
        "IP addresses",
        "Names",
        "Partial credit card data",
        "Passwords",
        "Payment histories",
        "Physical addresses",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2012, the web hosting, billing and automation company WHMCS suffered a data breach that exposed 134k email addresses. The breach included extensive information about customers and payment histories including partial credit card numbers.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#WHMCS"
    },
    {
      "name": "Uiggy",
      "title": "Uiggy",
      "domain": "uiggy.com",
      "breach_date": "2016-06-01",
      "added": "2016-06-27T08:07:18.000Z",
      "accounts": 2682650,
      "data_classes": [
        "Email addresses",
        "Genders",
        "Names",
        "Social connections",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2016, the Facebook application known as Uiggy was hacked and 4.3M accounts were exposed, 2.7M of which had email addresses against them. The leaked accounts also exposed names, genders and the Facebook ID of the owners.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Uiggy"
    },
    {
      "name": "VK",
      "title": "VK",
      "domain": "vk.com",
      "breach_date": "2012-01-01",
      "added": "2016-06-09T09:16:36.000Z",
      "accounts": 93338602,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately 2012, the Russian social media site known as VK was hacked and almost 100 million accounts were exposed. The data emerged in June 2016 where it was being sold via a dark market website and included names, phone numbers email addresses and plain text passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#VK"
    },
    {
      "name": "BitTorrent",
      "title": "BitTorrent",
      "domain": "bittorrent.com",
      "breach_date": "2016-01-01",
      "added": "2016-06-08T10:49:24.000Z",
      "accounts": 34235,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2016, the forum for the popular torrent software BitTorrent was hacked. The IP.Board based forum stored passwords as weak SHA1 salted hashes and the breached data also included usernames, email and IP addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BitTorrent"
    },
    {
      "name": "MySpace",
      "title": "MySpace",
      "domain": "myspace.com",
      "breach_date": "2008-07-01",
      "added": "2016-05-31T00:12:29.000Z",
      "accounts": 359420698,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In approximately 2008, MySpace suffered a data breach that exposed almost 360 million accounts. In May 2016 the data was offered up for sale on the \"Real Deal\" dark market website and included email addresses, usernames and SHA1 hashes of the first 10 characters of the password converted to lowercase and stored without a salt. The exact breach date is unknown, but analysis of the data suggests it was 8 years before being made public.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MySpace"
    },
    {
      "name": "Tumblr",
      "title": "tumblr",
      "domain": "tumblr.com",
      "breach_date": "2013-02-28",
      "added": "2016-05-29T22:59:04.000Z",
      "accounts": 65469298,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In early 2013, tumblr suffered a data breach which resulted in the exposure of over 65 million accounts. The data was later put up for sale on a dark market website and included email addresses and passwords stored as salted SHA1 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Tumblr"
    },
    {
      "name": "Fling",
      "title": "Fling",
      "domain": "fling.com",
      "breach_date": "2011-03-10",
      "added": "2016-05-28T23:08:07.000Z",
      "accounts": 40767652,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Geographic locations",
        "IP addresses",
        "Passwords",
        "Phone numbers",
        "Sexual fetishes",
        "Sexual orientations",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In 2011, the self-proclaimed \"World's Best Adult Social Network\" website known as Fling was hacked and more than 40 million accounts obtained by the attacker. The breached data included highly sensitive personal attributes such as sexual orientation and sexual interests as well as email addresses and passwords stored in plain text.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Fling"
    },
    {
      "name": "FurAffinity",
      "title": "Fur Affinity",
      "domain": "furaffinity.net",
      "breach_date": "2016-05-17",
      "added": "2016-05-27T09:36:18.000Z",
      "accounts": 1270564,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2016, the Fur Affinity website for people with an interest in anthropomorphic animal characters (also known as \"furries\") was hacked. The attack exposed 1.2M email addresses (many accounts had a different \"first\" and \"last\" email against them) and hashed passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#FurAffinity"
    },
    {
      "name": "LinkedIn",
      "title": "LinkedIn",
      "domain": "linkedin.com",
      "breach_date": "2012-05-05",
      "added": "2016-05-21T21:35:40.000Z",
      "accounts": 164611595,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2016, LinkedIn had 164 million email addresses and passwords exposed. Originally hacked in 2012, the data remained out of sight until being offered for sale on a dark market site 4 years later. The passwords in the breach were stored as SHA1 hashes without salt, the vast majority of which were quickly cracked in the days following the release of the data.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#LinkedIn"
    },
    {
      "name": "RosebuttBoard",
      "title": "Rosebutt Board",
      "domain": "rosebuttboard.com",
      "breach_date": "2016-05-09",
      "added": "2016-05-10T07:37:46.000Z",
      "accounts": 107303,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "Some time prior to May 2016, the forum known as \"Rosebutt Board\" was hacked and 107k accounts were exposed. The self-described \"top one board for anal fisting, prolapse, huge insertions and rosebutt fans\" had email and IP addresses, usernames and weakly stored salted MD5 password hashes hacked from the IP.Board based forum.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#RosebuttBoard"
    },
    {
      "name": "Nulled",
      "title": "Nulled.cr",
      "domain": "nulled.cr",
      "breach_date": "2016-05-06",
      "added": "2016-05-09T11:28:01.000Z",
      "accounts": 599080,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Private messages",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2016, the cracking community forum known as Nulled.cr was hacked and 599k user accounts were leaked publicly. The compromised data included email and IP addresses, weak salted MD5 password hashes and hundreds of thousands of private messages between members.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Nulled"
    },
    {
      "name": "QatarNationalBank",
      "title": "Qatar National Bank",
      "domain": "qnb.com",
      "breach_date": "2015-07-01",
      "added": "2016-05-01T01:06:35.000Z",
      "accounts": 88678,
      "data_classes": [
        "Bank account numbers",
        "Customer feedback",
        "Dates of birth",
        "Financial transactions",
        "Genders",
        "Geographic locations",
        "Government issued IDs",
        "IP addresses",
        "Marital statuses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "PINs",
        "Security questions and answers",
        "Spoken languages"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2015, the Qatar National Bank suffered a data breach which exposed 15k documents totalling 1.4GB and detailing more than 100k accounts with passwords and PINs. The incident was made public some 9 months later in April 2016 when the documents appeared publicly on a file sharing site. Analysis of the breached data suggests the attack began by exploiting a SQL injection flaw in the bank's website.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#QatarNationalBank"
    },
    {
      "name": "Lifeboat",
      "title": "Lifeboat",
      "domain": "lbsg.net",
      "breach_date": "2016-01-01",
      "added": "2016-04-25T21:51:50.000Z",
      "accounts": 7089395,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2016, the Minecraft community known as Lifeboat was hacked and more than 7 million accounts leaked. Lifeboat knew of the incident for three months before the breach was made public but elected not to advise customers. The leaked data included usernames, email addresses and passwords stored as straight MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Lifeboat"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
