{
  "query": {
    "page": "50"
  },
  "count": 20,
  "total": 1020,
  "page": 50,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T20:48:31.249Z",
    "kev": "2026-10-07T21:49:33.076Z",
    "epss": "2026-10-07T18:59:57.359Z",
    "breaches": "2026-10-07T18:47:59.596Z",
    "posts": "2026-10-07T21:48:33.240Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=50"
  },
  "warnings": [],
  "results": [
    {
      "name": "QuantumBooter",
      "title": "Quantum Booter",
      "domain": "quantumbooter.net",
      "breach_date": "2014-03-18",
      "added": "2015-04-04T06:40:05.000Z",
      "accounts": 48592,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Private messages",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2014, the booter service Quantum Booter (also referred to as Quantum Stresser) suffered a breach which lead to the disclosure of their internal database. The leaked data included private discussions relating to malicious activity Quantum Booter users were performing against online adversaries, including the IP addresses of those using the service to mount DDoS attacks.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#QuantumBooter"
    },
    {
      "name": "ThisHabboForum",
      "title": "ThisHabbo Forum",
      "domain": "thishabboforum.com",
      "breach_date": "2014-01-01",
      "added": "2015-03-28T05:35:28.000Z",
      "accounts": 612414,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In 2014, the ThisHabbo forum (a fan site for Habbo.com, a Finnish social networking site) appeared among a list of compromised sites which has subsequently been removed from the internet. Whilst the actual date of the exploit is not clear, the breached data includes usernames, email addresses, IP addresses and salted hashes of passwords. A further 584k records were added from a more comprehensive breach file provided in October 2016.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#ThisHabboForum"
    },
    {
      "name": "Flashback",
      "title": "Flashback",
      "domain": "flashback.se",
      "breach_date": "2015-02-11",
      "added": "2015-02-12T05:42:12.000Z",
      "accounts": 40256,
      "data_classes": [
        "Email addresses",
        "Government issued IDs",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2015, the Swedish forum known as Flashback had sensitive internal data on 40k members published via the tabloid newspaper Aftonbladet. The data was allegedly sold to them via Researchgruppen (The Research Group) who have a history of exposing otherwise anonymous users, primarily those who they believe participate in \"troll like\" behaviour. The compromised data includes social security numbers, home and email addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Flashback"
    },
    {
      "name": "CrackCommunity",
      "title": "Crack Community",
      "domain": "crackcommunity.com",
      "breach_date": "2013-09-09",
      "added": "2015-02-03T06:30:05.000Z",
      "accounts": 19210,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In late 2013, the Crack Community forum specialising in cracks for games was compromised and over 19k accounts published online. Built on the MyBB forum platform, the compromised data included email addresses, IP addresses and salted MD5 passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CrackCommunity"
    },
    {
      "name": "LizardSquad",
      "title": "Lizard Squad",
      "domain": "lizardstresser.su",
      "breach_date": "2015-01-16",
      "added": "2015-01-18T01:24:24.000Z",
      "accounts": 13451,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2015, the hacker collective known as \"Lizard Squad\" created a DDoS service by the name of \"Lizard Stresser\" which could be procured to mount attacks against online targets. Shortly thereafter, the service suffered a data breach which resulted in the public disclosure of over 13k user accounts including passwords stored in plain text.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#LizardSquad"
    },
    {
      "name": "Dominos",
      "title": "Domino's",
      "domain": "pizza.dominos.be",
      "breach_date": "2014-06-13",
      "added": "2015-01-04T03:03:34.000Z",
      "accounts": 648231,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2014, Domino's Pizza in France and Belgium was hacked by a group going by the name \"Rex Mundi\" and their customer data held to ransom. Domino's refused to pay the ransom and six months later, the attackers released the data along with troves of other hacked accounts. Amongst the customer data was passwords stored with a weak MD5 hashing algorithm and no salt.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Dominos"
    },
    {
      "name": "AhaShare",
      "title": "AhaShare.com",
      "domain": "ahashare.com",
      "breach_date": "2013-05-30",
      "added": "2014-11-06T21:47:52.000Z",
      "accounts": 180468,
      "data_classes": [
        "Email addresses",
        "Genders",
        "Geographic locations",
        "IP addresses",
        "Partial dates of birth",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2013, the torrent site AhaShare.com suffered a breach which resulted in more than 180k user accounts being published publicly. The breach included a raft of personal information on registered users plus despite assertions of not distributing personally identifiable information, the site also leaked the IP addresses used by the registered identities.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#AhaShare"
    },
    {
      "name": "Yandex",
      "title": "Yandex Dump",
      "domain": "forum.btcsec.com",
      "breach_date": "2014-09-07",
      "added": "2014-09-12T04:50:32.000Z",
      "accounts": 1186564,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2014, news broke of a massive leak of accounts from Yandex, the Russian search engine giants who also provides email services. The purported million \"breached\" accounts were disclosed at the same time as nearly 5M mail.ru accounts with both companies claiming the credentials were acquired via phishing scams rather than being obtained as a result of direct attacks against their services.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Yandex"
    },
    {
      "name": "MailRu",
      "title": "mail.ru Dump",
      "domain": "mail.ru",
      "breach_date": "2014-09-10",
      "added": "2014-09-12T04:50:22.000Z",
      "accounts": 16630988,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": false,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2014, several large dumps of user accounts appeared on the Russian Bitcoin Security Forum including one with nearly 5M email addresses and passwords, predominantly on the mail.ru domain. Whilst unlikely to be the result of a direct attack against mail.ru, the credentials were confirmed by many as legitimate for other services they had subscribed to. Further data allegedly valid for mail.ru and containing email addresses and plain text passwords was added in January 2018 bringing to total to more than 16M records. The incident was also then flagged as \"unverified\", a concept that was introduced after the initial data load in 2014.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MailRu"
    },
    {
      "name": "BTSec",
      "title": "Bitcoin Security Forum Gmail Dump",
      "domain": "forum.btcsec.com",
      "breach_date": "2014-01-09",
      "added": "2014-09-10T20:30:11.000Z",
      "accounts": 4789599,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2014, a large dump of nearly 5M usernames and passwords was posted to a Russian Bitcoin forum. Whilst commonly reported as 5M \"Gmail passwords\", the dump also contained 123k yandex.ru addresses. Whilst the origin of the breach remains unclear, the breached credentials were confirmed by multiple source as correct, albeit a number of years old.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BTSec"
    },
    {
      "name": "PokemonCreed",
      "title": "Pokémon Creed",
      "domain": "pokemoncreed.net",
      "breach_date": "2014-08-08",
      "added": "2014-08-10T00:03:59.000Z",
      "accounts": 116465,
      "data_classes": [
        "Email addresses",
        "Genders",
        "IP addresses",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In August 2014, the Pokémon RPG website Pokémon Creed was hacked after a dispute with rival site, Pokémon Dusk. In a post on Facebook, \"Cruz Dusk\" announced the hack then pasted the dumped MySQL database on pkmndusk.in. The breached data included over 116k usernames, email addresses and plain text passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#PokemonCreed"
    },
    {
      "name": "Insanelyi",
      "title": "Insanelyi",
      "domain": "insanelyi.com",
      "breach_date": "2014-07-22",
      "added": "2014-07-22T22:56:15.000Z",
      "accounts": 104097,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2014, the iOS forum Insanelyi was hacked by an attacker known as Kim Jong-Cracks. A popular source of information for users of jailbroken iOS devices running Cydia, the Insanelyi breach disclosed over 104k users' emails addresses, user names and weakly hashed passwords (salted MD5).",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Insanelyi"
    },
    {
      "name": "LoungeBoard",
      "title": "Lounge Board",
      "domain": "loungeboard.net",
      "breach_date": "2013-08-01",
      "added": "2014-07-06T10:22:01.000Z",
      "accounts": 45018,
      "data_classes": [
        "Email addresses",
        "IP addresses",
        "Names",
        "Passwords",
        "Private messages",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "At some point in 2013, 45k accounts were breached from the Lounge Board \"General Discussion Forum\" and then dumped publicly. Lounge Board was a MyBB forum launched in 2012 and discontinued in mid 2013 (the last activity in the logs was from August 2013).",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#LoungeBoard"
    },
    {
      "name": "Verified",
      "title": "Verified",
      "domain": "verified.cm",
      "breach_date": "2014-01-10",
      "added": "2014-07-06T04:16:37.000Z",
      "accounts": 16919,
      "data_classes": [
        "Email addresses",
        "Historical passwords",
        "IP addresses",
        "Passwords",
        "Private messages",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2014, one of the largest communities of Eastern Europe cybercriminals known as \"Verified\" was hacked. The breach exposed nearly 17k users of the vBulletin forum including their personal messages and other potentially personally identifiable information.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Verified"
    },
    {
      "name": "AstroPID",
      "title": "Astropid",
      "domain": "astropid.com",
      "breach_date": "2013-12-19",
      "added": "2014-07-06T03:49:45.000Z",
      "accounts": 5788,
      "data_classes": [
        "Email addresses",
        "Instant messenger identities",
        "IP addresses",
        "Names",
        "Passwords",
        "Private messages",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2013, the vBulletin forum for the social engineering site known as \"AstroPID\" was breached and leaked publicly. The site provided tips on fraudulently obtaining goods and services, often by providing a legitimate \"PID\" or Product Information Description. The breach resulted in nearly 6k user accounts and over 220k private messages between forum members being exposed.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#AstroPID"
    },
    {
      "name": "MangaTraders",
      "title": "Manga Traders",
      "domain": "mangatraders.com",
      "breach_date": "2014-06-09",
      "added": "2014-06-10T03:49:45.000Z",
      "accounts": 855249,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2014, the Manga trading website Mangatraders.com had the usernames and passwords of over 900k users leaked on the internet (approximately 855k of the emails were unique). The passwords were weakly hashed with a single iteration of MD5 leaving them vulnerable to being easily cracked.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MangaTraders"
    },
    {
      "name": "Win7Vista",
      "title": "Win7Vista Forum",
      "domain": "win7vista.com",
      "breach_date": "2013-09-03",
      "added": "2014-06-01T10:01:32.000Z",
      "accounts": 202683,
      "data_classes": [
        "Email addresses",
        "Instant messenger identities",
        "IP addresses",
        "Names",
        "Passwords",
        "Private messages",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In September 2013, the Win7Vista Windows forum (since renamed to the \"Beyond Windows 9\" forum) was hacked and later had its internal database dumped. The dump included over 200k members’ personal information and other internal data extracted from the forum.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Win7Vista"
    },
    {
      "name": "CannabisForum",
      "title": "Cannabis.com",
      "domain": "cannabis.com",
      "breach_date": "2014-02-05",
      "added": "2014-06-01T07:55:24.000Z",
      "accounts": 227746,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Geographic locations",
        "Historical passwords",
        "Instant messenger identities",
        "IP addresses",
        "Passwords",
        "Private messages",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2014, the vBulletin forum for the Marijuana site cannabis.com was breached and leaked publicly. Whilst there has been no public attribution of the breach, the leaked data included over 227k accounts and nearly 10k private messages between users of the forum.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#CannabisForum"
    },
    {
      "name": "HackForums",
      "title": "hackforums.net",
      "domain": "hackforums.net",
      "breach_date": "2011-06-25",
      "added": "2014-05-11T10:30:43.000Z",
      "accounts": 191540,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Instant messenger identities",
        "IP addresses",
        "Passwords",
        "Social connections",
        "Spoken languages",
        "Time zones",
        "User website URLs",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2011, the hacktivist group known as \"LulzSec\" leaked one final large data breach they titled \"50 days of lulz\". The compromised data came from sources such as AT&T, Battlefield Heroes and the hackforums.net website. The leaked Hack Forums data included credentials and personal information of nearly 200,000 registered forum users.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#HackForums"
    },
    {
      "name": "BusinessAcumen",
      "title": "Business Acumen Magazine",
      "domain": "businessacumen.biz",
      "breach_date": "2014-04-25",
      "added": "2014-05-11T04:25:48.000Z",
      "accounts": 26596,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2014, the Australian \"Business Acumen Magazine\" website was hacked by an attacker known as 1337MiR. The breach resulted in over 26,000 accounts being exposed including usernames, email addresses and password stored with a weak cryptographic hashing algorithm (MD5 with no salt).",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BusinessAcumen"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
