{
  "query": {
    "page": "51"
  },
  "count": 20,
  "total": 1020,
  "page": 51,
  "limit": 20,
  "updated": {
    "cves": "2026-10-07T22:48:36.014Z",
    "kev": "2026-10-07T22:49:35.832Z",
    "epss": "2026-10-07T18:59:57.359Z",
    "breaches": "2026-10-07T18:47:59.596Z",
    "posts": "2026-10-07T22:48:36.006Z"
  },
  "links": {
    "web": "https://spydr.io/breaches?page=51"
  },
  "warnings": [],
  "results": [
    {
      "name": "Fridae",
      "title": "Fridae",
      "domain": "fridae.asia",
      "breach_date": "2014-05-02",
      "added": "2014-05-06T02:48:35.000Z",
      "accounts": 35368,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames",
        "Website activity"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In May 2014, over 25,000 user accounts were breached from the Asian lesbian, gay, bisexual and transgender website known as \"Fridae\". The attack which was announced on Twitter appears to have been orchestrated by Deletesec who claim that \"Digital weapons shall annihilate all secrecy within governments and corporations\". The exposed data included password stored in plain text.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Fridae"
    },
    {
      "name": "BigMoneyJobs",
      "title": "BigMoneyJobs",
      "domain": "bigmoneyjobs.com",
      "breach_date": "2014-04-03",
      "added": "2014-04-08T05:44:10.000Z",
      "accounts": 36789,
      "data_classes": [
        "Career levels",
        "Education levels",
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Salutations",
        "User website URLs",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In April 2014, the job site bigmoneyjobs.com was hacked by an attacker known as \"ProbablyOnion\". The attack resulted in the exposure of over 36,000 user accounts including email addresses, usernames and passwords which were stored in plain text. The attack was allegedly mounted by exploiting a SQL injection vulnerability.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BigMoneyJobs"
    },
    {
      "name": "Boxee",
      "title": "Boxee",
      "domain": "forums.boxee.com",
      "breach_date": "2014-03-29",
      "added": "2014-03-30T13:07:16.000Z",
      "accounts": 158093,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Geographic locations",
        "Historical passwords",
        "Instant messenger identities",
        "IP addresses",
        "Passwords",
        "Private messages",
        "User website URLs",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In March 2014, the home theatre PC software maker Boxee had their forums compromised in an attack. The attackers obtained the entire vBulletin MySQL database and promptly posted it for download on the Boxee forum itself. The data included 160k users, password histories, private messages and a variety of other data exposed across nearly 200 publicly exposed tables.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Boxee"
    },
    {
      "name": "Hemmelig",
      "title": "hemmelig.com",
      "domain": "hemmelig.com",
      "breach_date": "2011-12-21",
      "added": "2014-03-25T07:23:52.000Z",
      "accounts": 28641,
      "data_classes": [
        "Email addresses",
        "Genders",
        "Nicknames",
        "Partial dates of birth",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": true,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2011, Norway's largest online sex shop hemmelig.com was hacked by a collective calling themselves \"Team Appunity\". The attack exposed over 28,000 usernames and email addresses along with nicknames, gender, year of birth and unsalted MD5 password hashes.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Hemmelig"
    },
    {
      "name": "IGF",
      "title": "UN Internet Governance Forum",
      "domain": "intgovforum.org",
      "breach_date": "2014-02-20",
      "added": "2014-02-23T04:32:08.000Z",
      "accounts": 3200,
      "data_classes": [
        "Email addresses",
        "Names",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2014, the Internet Governance Forum (formed by the United Nations for policy dialogue on issues of internet governance) was attacked by hacker collective known as Deletesec. Although tasked with \"ensuring the security and stability of the Internet\", the IGF’s website was still breached and resulted in the leak of 3,200 email addresses, names, usernames and cryptographically stored passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#IGF"
    },
    {
      "name": "MuslimDirectory",
      "title": "Muslim Directory",
      "domain": "muslimdirectory.co.uk",
      "breach_date": "2014-02-17",
      "added": "2014-02-23T03:09:38.000Z",
      "accounts": 37784,
      "data_classes": [
        "Age groups",
        "Email addresses",
        "Employers",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Website activity"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2014, the UK guide to services and business known as the Muslim Directory was attacked by the hacker known as @th3inf1d3l. The data was consequently dumped publicly and included the web accounts of tens of thousands of users which contained data including their names, home address, age group, email, website activity and password in plain text.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#MuslimDirectory"
    },
    {
      "name": "Spirol",
      "title": "Spirol",
      "domain": "spirol.com",
      "breach_date": "2014-02-22",
      "added": "2014-02-22T20:47:56.000Z",
      "accounts": 55622,
      "data_classes": [
        "Email addresses",
        "Employers",
        "Job titles",
        "Names",
        "Phone numbers",
        "Physical addresses"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2014, Connecticut based Spirol Fastening Solutions suffered a data breach that exposed over 70,000 customer records. The attack was allegedly mounted by exploiting a SQL injection vulnerability which yielded data from Spirol’s CRM system ranging from customers’ names, companies, contact information and over 55,000 unique email addresses.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Spirol"
    },
    {
      "name": "Forbes",
      "title": "Forbes",
      "domain": "forbes.com",
      "breach_date": "2014-02-15",
      "added": "2014-02-15T11:24:42.000Z",
      "accounts": 1057819,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "User website URLs",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2014, the Forbes website succumbed to an attack that leaked over 1 million user accounts. The attack was attributed to the Syrian Electronic Army, allegedly as retribution for a perceived \"Hate of Syria\". The attack not only leaked user credentials, but also resulted in the posting of fake news stories to forbes.com.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Forbes"
    },
    {
      "name": "Tesco",
      "title": "Tesco",
      "domain": "tesco.com",
      "breach_date": "2014-02-12",
      "added": "2014-02-13T21:19:24.000Z",
      "accounts": 2239,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Reward program balances"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2014, over 2,000 Tesco accounts with usernames, passwords and loyalty card balances appeared on Pastebin. Whilst the source of the breach is not clear, many confirmed the credentials were valid for Tesco and indeed they have a history of poor online security.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Tesco"
    },
    {
      "name": "Bell",
      "title": "Bell (2014 breach)",
      "domain": "bell.ca",
      "breach_date": "2014-02-01",
      "added": "2014-02-01T23:57:10.000Z",
      "accounts": 20902,
      "data_classes": [
        "Credit cards",
        "Genders",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In February 2014, Bell Canada suffered a data breach via the hacker collective known as NullCrew. The breach included data from multiple locations within Bell and exposed email addresses, usernames, user preferences and a number of unencrypted passwords and credit card data from 40,000 records containing just over 20,000 unique email addresses and usernames.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Bell"
    },
    {
      "name": "WPT",
      "title": "WPT Amateur Poker League",
      "domain": "wptapl.com",
      "breach_date": "2014-01-04",
      "added": "2014-02-01T02:57:21.000Z",
      "accounts": 148366,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2014, the World Poker Tour (WPT) Amateur Poker League website was hacked by the Twitter user @smitt3nz. The attack resulted in the public disclosure of 175,000 accounts including 148,000 email addresses. The plain text password for each account was also included in the breach.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#WPT"
    },
    {
      "name": "BattlefieldHeroes",
      "title": "Battlefield Heroes",
      "domain": "battlefieldheroes.com",
      "breach_date": "2011-06-26",
      "added": "2014-01-23T13:10:29.000Z",
      "accounts": 530270,
      "data_classes": [
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In June 2011 as part of a final breached data dump, the hacker collective \"LulzSec\" obtained and released over half a million usernames and passwords from the game Battlefield Heroes. The passwords were stored as MD5 hashes with no salt and many were easily converted back to their plain text versions.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#BattlefieldHeroes"
    },
    {
      "name": "Snapchat",
      "title": "Snapchat",
      "domain": "snapchat.com",
      "breach_date": "2014-01-01",
      "added": "2014-01-02T00:00:00.000Z",
      "accounts": 4609615,
      "data_classes": [
        "Geographic locations",
        "Phone numbers",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In January 2014 just one week after Gibson Security detailed vulnerabilities in the service, Snapchat had 4.6 million usernames and phone number exposed. The attack involved brute force enumeration of a large number of phone numbers against the Snapchat API in what appears to be a response to Snapchat's assertion that such an attack was \"theoretical\". Consequently, the breach enabled individual usernames (which are often used across other services) to be resolved to phone numbers which users usually wish to keep private.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Snapchat"
    },
    {
      "name": "PixelFederation",
      "title": "Pixel Federation",
      "domain": "pixelfederation.com",
      "breach_date": "2013-12-04",
      "added": "2013-12-06T00:00:00.000Z",
      "accounts": 38108,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2013, a breach of the web-based game community based in Slovakia exposed over 38,000 accounts which were promptly posted online. The breach included email addresses and unsalted MD5 hashed passwords, many of which were easily converted back to plain text.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#PixelFederation"
    },
    {
      "name": "Adobe",
      "title": "Adobe",
      "domain": "adobe.com",
      "breach_date": "2013-10-04",
      "added": "2013-12-04T00:00:00.000Z",
      "accounts": 152445165,
      "data_classes": [
        "Email addresses",
        "Password hints",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In October 2013, 153 million Adobe accounts were breached with each containing an internal ID, username, email, encrypted password and a password hint in plain text. The password cryptography was poorly done and many were quickly resolved back to plain text. The unencrypted hints also disclosed much about the passwords adding further to the risk that hundreds of millions of Adobe customers already faced.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Adobe"
    },
    {
      "name": "Gawker",
      "title": "Gawker",
      "domain": "gawker.com",
      "breach_date": "2010-12-11",
      "added": "2013-12-04T00:00:00.000Z",
      "accounts": 1247574,
      "data_classes": [
        "Email addresses",
        "Passwords",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2010, Gawker was attacked by the hacker collective \"Gnosis\" in retaliation for what was reported to be a feud between Gawker and 4Chan. Information about Gawkers 1.3M users was published along with the data from Gawker's other web presences including Gizmodo and Lifehacker. Due to the prevalence of password reuse, many victims of the breach then had their Twitter accounts compromised to send Acai berry spam.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Gawker"
    },
    {
      "name": "Sony",
      "title": "Sony",
      "domain": "sony.com",
      "breach_date": "2011-06-02",
      "added": "2013-12-04T00:00:00.000Z",
      "accounts": 37103,
      "data_classes": [
        "Dates of birth",
        "Email addresses",
        "Genders",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In 2011, Sony suffered breach after breach after breach — it was a very bad year for them. The breaches spanned various areas of the business ranging from the PlayStation network all the way through to the motion picture arm, Sony Pictures. A SQL Injection vulnerability in sonypictures.com lead to tens of thousands of accounts across multiple systems being exposed complete with plain text passwords.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Sony"
    },
    {
      "name": "Stratfor",
      "title": "Stratfor",
      "domain": "stratfor.com",
      "breach_date": "2011-12-24",
      "added": "2013-12-04T00:00:00.000Z",
      "accounts": 859777,
      "data_classes": [
        "Credit cards",
        "Email addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In December 2011, \"Anonymous\" attacked the global intelligence company known as \"Stratfor\" and consequently disclosed a veritable treasure trove of data including hundreds of gigabytes of email and tens of thousands of credit card details which were promptly used by the attackers to make charitable donations (among other uses). The breach also included 860,000 user accounts complete with email address, time zone, some internal system data and MD5 hashed passwords with no salt.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Stratfor"
    },
    {
      "name": "Yahoo",
      "title": "Yahoo",
      "domain": "yahoo.com",
      "breach_date": "2012-07-11",
      "added": "2013-12-04T00:00:00.000Z",
      "accounts": 453427,
      "data_classes": [
        "Email addresses",
        "Passwords"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In July 2012, Yahoo! had their online publishing service \"Voices\" compromised via a SQL injection attack. The breach resulted in the disclosure of nearly half a million usernames and passwords stored in plain text. The breach showed that of the compromised accounts, a staggering 59% of people who also had accounts in the Sony breach reused their passwords across both services.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Yahoo"
    },
    {
      "name": "Vodafone",
      "title": "Vodafone",
      "domain": "vodafone.is",
      "breach_date": "2013-11-30",
      "added": "2013-11-30T00:00:00.000Z",
      "accounts": 56021,
      "data_classes": [
        "Credit cards",
        "Email addresses",
        "Government issued IDs",
        "IP addresses",
        "Names",
        "Passwords",
        "Phone numbers",
        "Physical addresses",
        "Purchases",
        "SMS messages",
        "Usernames"
      ],
      "verified": true,
      "sensitive": false,
      "malware": false,
      "stealer_log": false,
      "description": "In November 2013, Vodafone in Iceland suffered an attack attributed to the Turkish hacker collective \"Maxn3y\". The data was consequently publicly exposed and included user names, email addresses, social security numbers, SMS message, server logs and passwords from a variety of different internal sources.",
      "source": "Have I Been Pwned (haveibeenpwned.com), CC BY 4.0",
      "source_url": "https://haveibeenpwned.com/PwnedWebsites#Vodafone"
    }
  ],
  "attribution": [
    {
      "source": "Have I Been Pwned",
      "url": "https://haveibeenpwned.com",
      "notice": "Breach data from Have I Been Pwned (haveibeenpwned.com), licensed under CC BY 4.0."
    }
  ]
}
