Breaches
Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.
- DC Health Link 48K accounts
In March 2023, DC Health Link discovered a data breach that was later publicly posted to a popular data breach forum. The impacted data included 48k unique email addresses alongside names, genders, dates of birth, home addresses, phone numbers and social security numbers.and "IntelBroker".
Citizenship statuses · Dates of birth · Email addresses · Employers · Ethnicities · Genders · Names · Phone numbers · Physical addresses · Purchases · Social security numbers
- InflateVids 13K accounts
In December 2023, the inflatable and balloon fetish videos website InflateVids suffered a data breach. The incident exposed over 13k unique email addresses alongside usernames, IP addresses, genders and SHA-1 password hashes.
Email addresses · Genders · IP addresses · Passwords · Usernames
- Kaneva 3.9M accounts
In July 2016, now defunct website Kaneva, the service to "build and explore virtual worlds", suffered a data breach that exposed 3.9M user records. The data included email addresses, usernames, dates of birth and salted MD5 password hashes.
Dates of birth · Email addresses · Passwords · Usernames
- Gemplex 4.6M accounts
In February 2021, the Indian streaming platform Gemplex suffered a data breach that exposed 4.6M user accounts. The impacted data included device information, names, phone numbers, email addresses and bcrypt password hashes.
Device information · Email addresses · Names · Passwords · Phone numbers
- Movie Forums 40K accounts
In December 2022, the Movie Forums website suffered a data breach that affected 40k users. The breach exposed email and IP addresses, usernames, dates of birth and passwords stored as easily crackable salted MD5 hashes. The data was subsequently posted a popular clear web hacking forum.
Dates of birth · Email addresses · IP addresses · Passwords · Usernames
- JoyGames 4.5M accounts
In December 2019, the forum for the JoyGames website suffered a data breach that exposed 4.5M unique email addresses. The impacted data also included usernames, IP addresses and salted MD5 password hashes.
Email addresses · IP addresses · Passwords · Usernames
- RailYatri 23.2M accounts
In December 2022, India’s government-approved online travel agency RailYatri suffered a data breach. The incident impacted over 31M customers and exposed 23M unique email addresses. Also impacted were names, genders, phone numbers and tickets purchased, including travel information and fares.
Email addresses · Genders · Names · Phone numbers · Purchases
- SoarGames 4.8M accounts
In December 2019, the now defunct gaming website SoarGames suffered a data breach that exposed 4.8M unique email addresses. The impacted data included usernames, email and IP addresses and salted MD5 password hashes. A significant number of the email addresses appeared to have been generated as opposed to organically provided by the user.
Email addresses · IP addresses · Passwords · Usernames
- Go Ninja 5.0M accounts
In December 2019, the now defunct German gaming website Go Ninja suffered a data breach that exposed 5M unique email addresses. The impacted data included usernames, email and IP addresses and salted MD5 password hashes. More than 4M of the email addresses appeared to have been generated as opposed to organically provided by the user.
Email addresses · IP addresses · Passwords · Usernames
- Estante Virtual 5.4M accounts
In February 2019, the Brazilian book store Estante Virtual suffered a data breach that impacted 5.4M customers. The exposed data included names, usernames, email and physical addresses, phone numbers, dates of birth and unsalted SHA-1 password hashes.
Dates of birth · Email addresses · Names · Passwords · Phone numbers · Physical addresses · Usernames
- Bleach Anime Forum 144K accounts
In 2015, the now defunct independent forum for the Bleach Anime series suffered a data breach that exposed 144k user records. The impacted data included usernames, email addresses and salted MD5 password hashes.
Email addresses · Passwords · Usernames
- IndiHome 12.6M accounts
In mid-2021, reports emerged of a data breach of Indonesia's telecommunications company, IndiHome. Over 26M rows of data alleged to have been sourced from the company was posted to a popular hacking forum and contained 12.6M unique email addresses alongside names, IP addresses, genders and geographic locations. The most recent data was stamped as being recorded in November 2019.
Device information · Email addresses · Genders · Geographic locations · IP addresses · Names
- Jam Tangan 435K accounts
In July 2021, the online Indonesian watch store, Jam Tangan (AKA Machtwatch), suffered a data breach that exposed over 400k customer records which were subsequently posted to a popular hacking forum. The data included email and IP addresses, names, phone numbers, physical addresses and passwords stored as either unsalted MD5 or bcrypt hashes.
Email addresses · IP addresses · Names · Passwords · Phone numbers · Physical addresses
- KitchenPal 99K accounts
In November 2023, the kitchen management application KitchenPal suffered a data breach that exposed 146k lines of data. When contacted about the incident, KitchenPal advised the corpus of data came from a staging environment, although acknowledged it contained a small number of users for debugging purposes and included passwords that could not be used. Impacted data included almost 100k email addresses, names, geolocations and incomplete data on dates of birth, genders, height and weight, social media profile identifiers and bcrypt password hashes.
Dates of birth · Email addresses · Genders · Geographic locations · Names · Passwords · Physical attributes · Social media profiles
- OMGPOP 7.1M accounts
In approximately 2013, the maker of the Draw Something game OMGPOP suffered a data breach. Formerly known as i'minlikewithyou or iilwy and later purchased by Zynga, the breach exposed over 7M email address and plain text password pairs which were later leaked in 2019.
Email addresses · Passwords
- Avito 2.7M accounts
In November 2022, the Moroccan e-commerce service Avito suffered a data breach that exposed the personal information of 2.7M customers. The data included name, email, phone, IP address and geographic location.
Email addresses · Geographic locations · IP addresses · Names · Phone numbers
- Chess.com (2023) 1.3M accounts
In November 2023, over 800k user records were scraped from the Chess.com website and posted to a popular hacking forum. The data included email address, name, username and the geographic location of the user. A further 446k scraped records were later provided and added to HIBP.
Email addresses · Geographic locations · Names · Usernames
- GamingMonk 655K accounts
In December 2020, India's "largest esports community" GamingMonk (since acquired by and redirected to MPL Esports), suffered a data breach. The incident exposed 655k unique email addresses along with names, usernames, phone numbers, dates of birth and bcrypt password hashes.
Dates of birth · Email addresses · Names · Passwords · Phone numbers · Usernames
- Fitmart 214K accounts
In October 2021, data from the German fitness supplies store Fitmart was obtained and later redistributed online. The data included 214k unique email addresses accompanied by plain text passwords, allegedly "dehashed" from the original stored version.
Email addresses · Passwords
- GameSprite 6.2M accounts
In December 2019, the now defunct gaming platform GameSprite suffered a data breach that exposed over 6M unique email addresses. The impacted data also included usernames, IP addresses and salted MD5 password hashes.
Email addresses · IP addresses · Passwords · Usernames