{
  "query": {
    "page": "5"
  },
  "count": 20,
  "total": 1018,
  "page": 5,
  "limit": 20,
  "updated": {
    "cves": "2026-10-06T00:45:13.875Z",
    "kev": "2026-10-06T01:44:15.693Z",
    "epss": "2026-10-06T00:57:13.818Z",
    "breaches": "2026-10-06T00:45:13.561Z",
    "posts": "2026-10-06T01:45:15.769Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=5"
  },
  "warnings": [],
  "results": [
    {
      "name": "Provecho",
      "title": "Provecho",
      "domain": "provecho.bio",
      "breach_date": "2026-01-30",
      "added": "2026-03-03T06:40:50.000Z",
      "accounts": 712904,
      "data_classes": [
        "Email addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In early 2026, data purportedly sourced from the recipe and meal planning service Provecho was alleged to have been obtained in a breach. The exposed data included 713k unique email address along with username and the creator account holders followed. Provecho has been notified and is aware of the claims surrounding the incident.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Provecho"
    },
    {
      "name": "Lovora",
      "title": "Lovora",
      "domain": null,
      "breach_date": "2026-02-25",
      "added": "2026-03-02T07:23:06.000Z",
      "accounts": 495556,
      "data_classes": [
        "Display names",
        "Email addresses",
        "Profile photos"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2026, the couples and relationship app Lovora allegedly suffered a data breach that exposed 496k unique email addresses. The data also included users’ display names and profile photos, along with other personal information collected through use of the app. The app’s maker, Plantake, did not respond to multiple attempts to contact them about the incident.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Lovora"
    },
    {
      "name": "Quitbro",
      "title": "Quitbro",
      "domain": "quitbro.app",
      "breach_date": "2026-02-17",
      "added": "2026-03-02T05:27:11.000Z",
      "accounts": 22874,
      "data_classes": [
        "Email addresses",
        "Partial dates of birth",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2026, the porn addiction app Quitbro allegedly suffered a data breach that exposed 23k unique email addresses. The data also included users’ years of birth, responses to questions within the app and their last recorded relapse time. The app’s maker, Plantake, did not respond to multiple attempts to contact them about the incident.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Quitbro"
    },
    {
      "name": "KomikoAI",
      "title": "KomikoAI",
      "domain": "komiko.app",
      "breach_date": "2026-02-25",
      "added": "2026-03-02T01:31:29.000Z",
      "accounts": 1060191,
      "data_classes": [
        "AI prompts",
        "Email addresses",
        "Forum posts",
        "Names"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February, the AI-powered comic generation platform KomikoAI suffered a data breach. The incident exposed 1M unique email addresses along with names, user posts and the AI prompts used to generate content. The exposed data enables the mapping of individual AI prompts to specific email addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#KomikoAI"
    },
    {
      "name": "Odido",
      "title": "Odido",
      "domain": "odido.nl",
      "breach_date": "2026-02-12",
      "added": "2026-02-26T23:25:29.000Z",
      "accounts": 6077025,
      "data_classes": [
        "Bank account numbers",
        "Customer service records",
        "Dates of birth",
        "Driver's licenses",
        "Email addresses",
        "Genders",
        "Government issued IDs",
        "Names",
        "Passport numbers",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2026, Dutch telco Odido was the victim of a data breach and subsequent extortion attempt. Shortly after, a total of 6M unique email addresses were published across four separate data releases over consecutive days. The exposed data includes names, physical addresses, phone numbers, bank account numbers, dates of birth, customer service notes and passport, driver’s licence and European national ID numbers. Odido has published a disclosure notice including an FAQ to support affected customers.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Odido"
    },
    {
      "name": "CanadianTire",
      "title": "Canadian Tire",
      "domain": "canadiantire.ca",
      "breach_date": "2025-10-02",
      "added": "2026-02-25T06:53:25.000Z",
      "accounts": 38306562,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Partial credit card data",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2025, retailer Canadian Tire was the victim of a data breach that exposed almost 42M records. The data contained 38M unique email addresses along with names, phone numbers and physical addresses. Passwords were stored as PBKDF2 hashes and for a subset of records, dates of birth and partial credit card data were also included (card type, expiry and masked card number). In its disclosure notice, Canadian Tire advised that the incident did not impact bank account information or loyalty program data.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CanadianTire"
    },
    {
      "name": "CarGurus",
      "title": "CarGurus",
      "domain": "cargurus.com",
      "breach_date": "2026-02-14",
      "added": "2026-02-22T04:43:54.000Z",
      "accounts": 12461887,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2026, the automotive marketplace CarGurus was the target of a data breach attributed to the threat actor ShinyHunters. Following an attempted extortion, the data was published publicly and contained more than 12M email addresses across multiple files including user account ID mappings, finance pre-qualification application data and dealer account and subscription information. Impacted data also included names, phone numbers, physical and IP addresses, and auto finance application outcomes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CarGurus"
    },
    {
      "name": "CarMax",
      "title": "CarMax",
      "domain": "carmax.com",
      "breach_date": "2026-01-24",
      "added": "2026-02-20T03:48:30.000Z",
      "accounts": 431371,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2026, data allegedly sourced from US automotive retailer CarMax was published online following a failed extortion attempt. The data included 431k unique email addresses along with names, phone numbers and physical addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CarMax"
    },
    {
      "name": "Figure",
      "title": "Figure",
      "domain": "figure.com",
      "breach_date": "2026-01-28",
      "added": "2026-02-18T01:11:11.000Z",
      "accounts": 967178,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2026, data obtained from the fintech lending platform Figure was publicly posted online. The exposed data, dating back to January 2026, contained over 900k unique email addresses along with names, phone numbers, physical addresses and dates of birth. Figure confirmed the incident and attributed it to a social engineering attack in which an employee was tricked into providing access.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Figure"
    },
    {
      "name": "CanadaGoose",
      "title": "Canada Goose",
      "domain": "canadagoose.com",
      "breach_date": "2025-07-04",
      "added": "2026-02-17T00:19:51.000Z",
      "accounts": 581877,
      "data_classes": [
        "Device information",
        "Email addresses",
        "IP addresses",
        "Names",
        "Partial credit card data",
        "Phone numbers",
        "Physical addresses",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2026, a data breach allegedly containing data relating to Canada Goose customers was published publicly. The data contained 920k records with 582k unique email addresses and included names, phone numbers, IP addresses, physical addresses and partial credit card data, specifically card type and last 4 digits. Canada Goose advised that the data \"appears to relate to past customer transactions\" and stated that it originated from a breach at a third party in August 2025. The most recent transaction date in the data is July 2025.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CanadaGoose"
    },
    {
      "name": "UniversityOfPennsylvania",
      "title": "University of Pennsylvania",
      "domain": "upenn.edu",
      "breach_date": "2025-10-30",
      "added": "2026-02-16T21:57:51.000Z",
      "accounts": 623750,
      "data_classes": [
        "Charitable donations",
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Income levels",
        "Job titles",
        "Names",
        "Physical addresses",
        "Religions",
        "Salutations",
        "Spouses names"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2025, the University of Pennsylvania was the victim of a data breach followed by a ransom demand, largely affecting its donor database. After the incident, the attackers sent inflammatory emails to some victims. The data was later published online in February 2026 and included 624k unique email addresses alongside names and physical addresses. For some donor records, additional personal information was exposed, including gender and date of birth. A small subset of records also contained religion, spouse name, estimated income and donation history.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#UniversityOfPennsylvania"
    },
    {
      "name": "APOIAse",
      "title": "APOIA.se",
      "domain": "apoia.se",
      "breach_date": "2025-12-16",
      "added": "2026-02-16T07:31:43.000Z",
      "accounts": 450764,
      "data_classes": [
        "Email addresses",
        "Names",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2025, a database of the Brazilian crowdfunding platform APOIA.se was posted to an online forum. In January 2026, the company confirmed it had suffered a data breach. The incident exposed 451k unique email addresses along with names and physical addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#APOIAse"
    },
    {
      "name": "ToyBattles",
      "title": "Toy Battles",
      "domain": "toybattles.net",
      "breach_date": "2026-02-06",
      "added": "2026-02-10T02:44:47.000Z",
      "accounts": 1017,
      "data_classes": [
        "Chat logs",
        "Email addresses",
        "IP addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2026, the online gaming community Toy Battles suffered a data breach. The incident exposed 1k unique email addresses alongside usernames, IP addresses and chat logs. Following the breach, Toy Battles self-submitted the data to Have I Been Pwned.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ToyBattles"
    },
    {
      "name": "ANPS",
      "title": "Association Nationale des Premiers Secours",
      "domain": "anps.fr",
      "breach_date": "2026-01-30",
      "added": "2026-02-10T01:27:25.000Z",
      "accounts": 5600,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Names",
        "Places of birth",
        "Salutations"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2026, a data breach impacting the French non-profit Association Nationale des Premiers Secours (ANPS) was posted to a hacking forum. The breach exposed 5.6k unique email addresses along with names, dates of birth and places of birth. ANPS self-submitted the data to HIBP and advised the incident was traced back to a legacy system and did not impact health data, financial information or passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ANPS"
    },
    {
      "name": "Substack",
      "title": "Substack",
      "domain": "substack.com",
      "breach_date": "2025-10-23",
      "added": "2026-02-06T23:33:22.000Z",
      "accounts": 663121,
      "data_classes": [
        "Email addresses",
        "Phone numbers"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2025, the publishing platform Substack suffered a data breach that was subsequently circulated more widely in February 2026. The breach exposed 663k account holder records containing email addresses along with publicly visible profile information from Substack accounts, such as publication names and bios. A subset of records also included phone numbers.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Substack"
    },
    {
      "name": "Betterment",
      "title": "Betterment",
      "domain": "betterment.com",
      "breach_date": "2026-01-09",
      "added": "2026-02-05T00:29:45.000Z",
      "accounts": 1435174,
      "data_classes": [
        "Dates of birth",
        "Device information",
        "Email addresses",
        "Employers",
        "Geographic locations",
        "Job titles",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2026, the automated investment platform Betterment confirmed it had suffered a data breach attributed to a social engineering attack. As part of the incident, Betterment customers received fraudulent crypto-related messages promising high returns if funds were sent to an attacker-controlled cryptocurrency wallet. The breach exposed 1.4M unique email addresses, along with names and geographic location data. A subset of records also included dates of birth, phone numbers, and physical addresses. In its disclosure notice, Betterment stated that the incident did not provide attackers with access to customer accounts and did not expose passwords or other login credentials.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Betterment"
    },
    {
      "name": "PaneraBread",
      "title": "Panera Bread",
      "domain": "panerabread.com",
      "breach_date": "2026-01-07",
      "added": "2026-01-31T03:19:30.000Z",
      "accounts": 5112502,
      "data_classes": [
        "Email addresses",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2026, Panera Bread suffered a data breach that exposed 14M records. After an attempted extortion failed, the attackers published the data publicly, which included 5.1M unique email addresses along with associated account information such as names, phone numbers and physical addresses. Panera Bread subsequently confirmed that \"the data involved is contact information\" and that authorities were notified.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#PaneraBread"
    },
    {
      "name": "SoundCloud",
      "title": "SoundCloud",
      "domain": "soundcloud.com",
      "breach_date": "2025-12-15",
      "added": "2026-01-27T01:13:16.000Z",
      "accounts": 29815722,
      "data_classes": [
        "Avatars",
        "Email addresses",
        "Geographic locations",
        "Names",
        "Profile statistics",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2025, SoundCloud announced it had discovered unauthorised activity on its platform. The incident allowed an attacker to map publicly available SoundCloud profile data to email addresses for approximately 20% of its users. The impacted data included 30M unique email addresses, names, usernames, avatars, follower and following counts and, in some cases, the user’s country. The attackers later attempted to extort SoundCloud before publicly releasing the data the following month.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#SoundCloud"
    },
    {
      "name": "UnderArmour",
      "title": "Under Armour",
      "domain": "underarmour.com",
      "breach_date": "2025-11-17",
      "added": "2026-01-21T06:34:18.000Z",
      "accounts": 72742892,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Geographic locations",
        "Names",
        "Purchases"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2025, the Everest ransomware group claimed Under Armour as a victim and attempted to extort a ransom, alleging they had obtained access to 343GB of data. In January 2026, customer data from the incident was published publicly on a popular hacking forum, including 72M email addresses. Many records also contained additional personal information such as names, dates of birth, genders, geographic locations and purchase information.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#UnderArmour"
    },
    {
      "name": "Raaga",
      "title": "Raaga",
      "domain": "raaga.com",
      "breach_date": "2025-12-15",
      "added": "2026-01-19T17:33:46.000Z",
      "accounts": 10225145,
      "data_classes": [
        "Ages",
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Geographic locations",
        "Names",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2025, data allegedly breached from the Indian streaming music service \"Raaga\" was posted for sale to a popular hacking forum. The data contained 10M unique email addresses along with names, genders, ages (in some cases, full date of birth), postcodes and passwords stored as unsalted MD5 hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Raaga"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
