Breaches
Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.
- 1win 96.2M accounts
In November 2024, the online betting platform 1win suffered a data breach that exposed 96M users. The exposed data included email and IP addresses, phone numbers, dates of birth, country and SHA-256 password hashes.
Dates of birth · Email addresses · Geographic locations · IP addresses · Passwords · Phone numbers
- DragonNest 511K accounts
In August 2013, the massively multiplayer online role-playing game (MMORGP) DragonNest suffered a data breach that was later redistributed as part of a larger corpus of data. The breach exposed over 500k unique email addresses along with usernames, IP addresses and plain text passwords. The service later suffered a massive data loss.
Email addresses · IP addresses · Passwords · Usernames
- 9Lives 110K accounts
In October 2014, the (now defunct) Belgian gaming news forum 9Lives suffered a data breach that was later redistributed as part of a larger corpus of data. The breach exposed 109k unique email addresses along with usernames and salted MD5 password hashes.
Email addresses · Passwords · Usernames
- Speedio 27.5M accounts
In December 2024, data alleged to have been taken from the Brazilian lead generation platform Speedio was posted for sale to a popular hacking forum. The data was allegedly obtained from an unsecured Elasticsearch instance and contained over 62M records of largely public business information including company names, phone numbers and physical addresses, along with 27M unique email addresses, predominantly from public services such as Gmail and Outlook. Speedio did not respond to multiple attempts to disclose the incident, and the origin of the data could not be independently verified.
Company names · Email addresses · Phone numbers · Physical addresses
- HeatGames 648K accounts
In June 2021, the (now defunct) gaming website HeatGames suffered a data breach that was later redistributed as part of a larger corpus of data. The breach exposed almost 650k unique email addresses along with IP addresses, country and salted MD5 password hashes.
Email addresses · Geographic locations · IP addresses · Passwords
- Doxbin Scrape 436K accounts
In January 2025, 435k email addresses were scraped from the "doxing" service Doxbin. Posts to the service are usually intended to disclose the personal information of non-consensually third parties.
Email addresses
- Frame & Optic 16K accounts
In January 2025, the eyewear seller Frame & Optic suffered a data breach. The incident exposed almost 16k unique email addresses along with names, phone numbers and geolocation data including country, state and postcode.
Email addresses · Geographic locations · Names · Phone numbers
- Welhof 107K accounts
In late 2023, the Dutch appliance store Welhof suffered a data breach. The incident exposed over 100k unique email addresses along with names, physical addresses and the value of purchases made.
Email addresses · Names · Physical addresses · Purchases
- Otelier 437K accounts
In July 2024, a threat actor gained access to the hotel management platform Otelier and retrieved customer data from well-known hotel brands including Marriott, Hilton, and Hyatt. The data included 437k customer email addresses (a further 868k generated email addresses from the booking.com and Expedia platforms were not loaded into HIBP), names, physical addresses, phone numbers, booking information related to travel plans, purchases recorded by the platform and in a small number of cases, partial credit card data.
Email addresses · Names · Partial credit card data · Phone numbers · Physical addresses · Purchases · Travel plans
- MSI 250K accounts
In July 2024, MSI inadvertently exposed hundreds of thousands of customer records related to RMA claims that were subsequently found to be publicly accessible. The data included 250k unique email addresses alongside names, phone numbers, physical addresses and warranty claims. When contacted about the incident, MSI advised that "there is no evidence the information was ever accessed" and that "the security incident we had did not trigger state data breach notification obligations" due to the absence of "(social security number, driver's license number….etc)".
Email addresses · Names · Phone numbers · Physical addresses · Warranty claims
- Le Coq Sportif Columbia 80K accounts
In January 2025, a data breach from the Columbian website for Le Coq Sportif was posted to a popular hacking forum. The data included almost 80k unique email addresses with the breach dating back to May 2023. Impacted data included physical and IP addresses, names, purchases, genders, dates of birth and bcrypt password hashes.
Dates of birth · Device information · Email addresses · Genders · IP addresses · Names · Passwords · Physical addresses · Purchases
- Stealer Logs, Jan 2025 71.0M accounts
In January 2025, stealer logs with 71M email addresses were added to HIBP. Consisting of email address, password and the website the credentials were entered against, this breach marks the launch of a new HIBP feature enabling the retrieval of the specific websites the logs were collected against. The incident also resulted in 106M more passwords being added to the Pwned Passwords service.
Email addresses · Passwords
- Scholastic 4.2M accounts
In January 2025, a data breach of the publishing company Scholastic surfaced. The breach contained 4.2M unique email addresses with many of the records also including name, phone number and physical address.
Email addresses · Names · Phone numbers · Physical addresses
- SuperDraft 300K accounts
In October 2024, the fantasy sports platform SuperDraft suffered a data breach that exposed over 300k customer records. The breach contained 24GB of data including email addresses, usernames, purchases, latitudes and longitudes, dates of birth and bcrypt password hashes.
Dates of birth · Email addresses · Geographic locations · Latitude and longitude pairs · Passwords · Purchases · Usernames
- GLAMIRA 875K accounts
In late 2023, the online jewellery store GLAMIRA suffered a data breach they attributed to "an unauthorised individual [who] briefly accessed one of our servers". The data was subsequently published on a popular hacking forum and included 875k email addresses, names, phone numbers and purchases.
Email addresses · Names · Phone numbers · Purchases
- French Citizens 28.4M accounts
In September 2024, over 90M rows of data on French Citizens was found left exposed in a publicly facing database. Compiled from various data breaches, the corpus contained 28M unique email addresses with the various source breaches each exposing different fields including name, physical and IP address, phone number and partial credit card data including payment type and last 4 digits.
Device information · Email addresses · IP addresses · Names · Partial credit card data · Phone numbers · Physical addresses
- Young Living Essential Oils 1.1M accounts
In December 2024, data claimed to be breached from the multi-level marketing company Young Living Essential Oils was posted to a popular hacking forum. The data contained 1.1M unique email addresses alongside names, the country of the account and in many cases, their date of birth. Young Living Essential Oils did not respond to multiple attempts to contact them about the data.
Dates of birth · Email addresses · Geographic locations · Names
- schenkYOU 237K accounts
In September 2024, data from the online German gift store schenkYOU was put up for sale on a popular hacking forum. Obtained the month before, the data included 237k unique email addresses alongside names, dates of birth and salted SHA-256 password hashes. The standalone store was subsequently shut down with all traffic redirected to their Amazon store.
Dates of birth · Email addresses · Names · Passwords
- BitView 63K accounts
In December 2024, the video sharing Community BitView suffered a data breach that exposed 63k customer records. Attributed to a backup taken by a previous administrator earlier in the year, the breach exposed email and IP addresses, bcrypt password hashes, usernames, bios, private messages, video comments and for some records, gender, date of birth and country of location.
Bios · Comments · Dates of birth · Email addresses · Genders · Geographic locations · IP addresses · Passwords · Private messages · Usernames
- Hopamedia 23.8M accounts
In 2024, data relating to an unknown service referred to as "Hopamedia" and dating back to 2020 appeared in a publicly exposed database. The data included almost 24M records of email address, name, phone number, the country of the individual and their telecommunications carrier.
Email addresses · Geographic locations · Names · Phone numbers · Telecommunications carrier