Breaches
Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.
- GSM Hosting 2.6M accounts
In August 2016, breached data from the vBulletin forum for GSM-Hosting appeared for sale alongside dozens of other hacked services. The breach impacted 2.6M users of the service and included email and IP addresses, usernames and salted MD5 password hashes.
Email addresses · IP addresses · Passwords · Usernames
- SwordFantasy 2.7M accounts
In January 2019, the now defunct MMO and RPG game SwordFantasy suffered a data breach that exposed 2.7M unique email addresses. Other impacted data included username, IP address and salted MD5 password hashes.
Email addresses · IP addresses · Passwords · Usernames
- MediaWorks 163K accounts
In March 2024, millions of rows of data from the New Zealand media company MediaWorks was publicly posted to a popular hacking forum. The incident exposed 163k unique email addresses provided by visitors who filled out online competitions and included names, physical addresses, phone numbers, dates of birth, genders and the responses to questions in the competition. Some victims of the breach subsequently received ransom demands requesting payment to have their data deleted.
Dates of birth · Email addresses · Genders · Phone numbers · Physical addresses
- AT&T 49.1M accounts
In March 2024, tens of millions of records allegedly breached from AT&T were posted to a popular hacking forum. Dating back to August 2021, the data was originally posted for sale before later being freely released. At the time, AT&T maintained that there had not been a breach of their systems and that the data originated from elsewhere. 12 days later, AT&T acknowledged that data fields specific to them were in the breach and that it was not yet known whether the breach occurred at their end or that of a vendor. AT&T also proceeded to reset customer account passcodes, an indicator that there was sufficient belief passcodes had been compromised. The incident exposed names, email and physical addresses, dates of birth, phone numbers and US social security numbers.
Dates of birth · Email addresses · Government issued IDs · Names · Phone numbers · Physical addresses
- ClickASnap 3.3M accounts
In September 2022, the online photo sharing platform ClickASnap suffered a data breach. The incident exposed almost 3.3M personal records including email addresses, usernames and passwords stored as SHA-512 hashes. Further, a collection of paid subscriptions were also included and contained names, physical addresses and amounts paid.
Email addresses · Names · Passwords · Physical addresses · Purchases · Social media profiles · Usernames
- Misattributed Flipkart Data 552K accounts
In September 2022, over 500k customer records alleged to have been sourced from the Indian e-commerce service Flipkart appeared on a popular hacking forum. Flipkart subsequently reviewed the data and concluded there was minimal overlap with their subscriber base and was not sourced from their services. The data included email addresses, latitudes and longitudes, names and phone numbers.
Email addresses · Geographic locations · Latitude and longitude pairs · Names · Phone numbers
- Misattributed Habib's Data 3.5M accounts
In August 2021, an allegation was made that the Brazilian fast food company "Habib's" had suffered a data breach that was later redistributed as part of a larger corpus of data. Upon thorough investigation, parent company Gennius concluded that the information in the breach was not related to any databases that hold their customers' personal information and had been misattributed to Habib's. The corpus of data contained 3.5M unique email addresses along with IP addresses, names, phone numbers, dates of birth and links to social media profiles.
Dates of birth · Email addresses · IP addresses · Names · Phone numbers · Social media profiles
- APK.TW 2.5M accounts
In September 2022, the Taiwanese Android forum APK.TW suffered a data breach that was later redistributed as part of a larger corpus of data. The breach exposed 2.5M unique email addresses along with IP addresses, usernames and salted MD5 password hashes.
Email addresses · IP addresses · Passwords · Usernames
- Online Trade (Онлайн Трейд) 3.8M accounts
In September 2022, the Russian e-commerce website Online Trade (Онлайн Трейд) suffered a data breach that exposed 3.8M customer records. The data included email and IP addresses, names, phone numbers, dates of birth and MD5 password hashes.
Dates of birth · Email addresses · IP addresses · Names · Passwords · Phone numbers
- WoTLabs 22K accounts
In March 2024, WoTLabs (World of Tanks Statistics and Resources) suffered a data breach and website defacement attributed to "chromebook breachers". The breach exposed 22k forum members' personal data including email and IP addresses, usernames, dates of birth and time zones.
Dates of birth · Email addresses · IP addresses · Time zones · Usernames
- Mr. Green Gaming 27K accounts
In March 2024, the online games community Mr. Green Gaming suffered a data breach that exposed 27k user records. Acknowledged on their Discord server, the incident exposed email and IP addresses, usernames, geographic locations and dates of birth.
Dates of birth · Email addresses · Geographic locations · IP addresses · Usernames
- Cutout.Pro 20.0M accounts
In February 2024, the AI-powered visual design platform Cutout.Pro suffered a data breach that exposed 20M records. The data included email and IP addresses, names and salted MD5 password hashes which were subsequently broadly distributed on a popular hacking forum and Telegram channels.
Email addresses · IP addresses · Names · Passwords
- Tangerine 243K accounts
In February 2024, the Australian Telco Tangerine suffered a data breach that exposed over 200k customer records. Attributed to a legacy customer database, the data included physical and email addresses, names, phone numbers and dates of birth. Whilst the Tangerine login process involves sending a one-time password after entering an email address and phone number, it previously used a traditional password which was also exposed as a bcrypt hash.
Dates of birth · Email addresses · Names · Passwords · Phone numbers · Physical addresses · Salutations
- Facebook Marketplace 77K accounts
In February 2024, 200k Facebook Marketplace records allegedly obtained from a Meta contractor in October 2023 were posted to a popular hacking forum. The data contained 77k unique email addresses alongside names, phone numbers, Facebook profile IDs and geographic locations. The data also contained bcrypt password hashes, although there is no indication these belong to the corresponding Facebook accounts.
Email addresses · Geographic locations · Names · Passwords · Phone numbers · Social media profiles
- Spoutible 207K accounts
In January 2024, Spoutible had 207k records scraped from a misconfigured API that inadvertently returned excessive personal information. The data included names, usernames, email and IP addresses, phone numbers (where provided to the platform), genders and bcrypt password hashes. The incident also exposed 2FA secrets and backup codes along with password reset tokens.
Email addresses · Genders · IP addresses · Names · Passwords · Phone numbers · Usernames
- MyPertamina 6.0M accounts
In November 2022, the Indonesian oil and gas company Pertamina suffered a data breach of their MyPertamina service. The incident exposed 44M records with 6M unique email addresses along with names, dates of birth, genders, physical addresses and purchases.
Dates of birth · Email addresses · Genders · Names · Phone numbers · Physical addresses · Purchases
- Trello 15.1M accounts
In January 2024, data was scraped from Trello and posted for sale on a popular hacking forum. Containing over 15M email addresses, names and usernames, the data was obtained by enumerating a publicly accessible resource using email addresses from previous breach corpuses. Trello advised that no unauthorised access had occurred.
Email addresses · Names · Usernames
- Naz.API 70.8M accounts
In September 2023, over 100GB of stealer logs and credential stuffing lists titled "Naz.API" was posted to a popular hacking forum. The incident contained a combination of email address and plain text password pairs alongside the service they were entered into, and standalone credential pairs obtained from unnamed sources. In total, the corpus of data included 71M unique email addresses and 100M unique passwords.
Email addresses · Passwords
- Hathway 4.7M accounts
In December 2023, hundreds of gigabytes of data allegedly taken from Indian ISP and digital TV provider Hathway appeared on a popular hacking website. The incident exposed extensive personal information including 4.7M unique email addresses along with names, physical and IP addresses, phone numbers, password hashes and support ticket logs.
Device information · Email addresses · IP addresses · Names · Passwords · Phone numbers · Physical addresses · Salutations · Support tickets
- Legendas.TV 3.9M accounts
In October 2017, the now defunct Brazilian service for retrieving subtitles in Portuguese Legendas.TV suffered a data breach that exposed nearly 4M customer records. The impacted data included names, usernames, email and IP addresses and unsalted SHA-1 hashes.
Email addresses · IP addresses · Names · Passwords · Usernames