Breaches

Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.

1,018 breaches · updated 2 hours ago · data from Have I Been Pwned (CC BY 4.0)

1,018 breaches · page 23 of 51 Fabricated, spam-list and retired breaches are left out.
  • Aimware 305K accounts
    Added 2 May 2022 breached 28 Apr 2019 aimware.net

    In mid-2019, the video game cheats website "Aimware" suffered a data breach that exposed hundreds of thousands of subscribers' personal information. Data included email and IP addresses, usernames, forum posts, private messages, website activity and passwords stored as salted MD5 hashes.

    Email addresses · IP addresses · Passwords · Private messages · Usernames · Website activity

  • Devil-Torrents.pl 63K accounts
    Added 1 May 2022 breached 4 Jan 2021 devil-torrents.pl

    In early 2021, the Polish torrents website Devil-Torrents.pl suffered a data breach. A subset of the data including 63k unique email addresses and cracked passwords were subsequently socialised on a popular data breach sharing service.

    Email addresses · Passwords

  • Avvo 4.1M accounts
    Added 15 Apr 2022 breached 17 Dec 2019 avvo.com

    In approximately December 2019, an alleged data breach of the lawyer directory service Avvo was published to an online hacking forum and used in an extortion scam (it's possible the exposure dates back earlier than that). The data contained 4.1M unique email addresses alongside SHA-1 hashes, most likely representing user passwords. Multiple attempts at contacting Avvo over the course of a week were unsuccessful and the authenticity of the data was eventually verified with common Avvo and HIBP subscribers.

    Email addresses · Passwords

  • Travelio 471K accounts
    Added 8 Apr 2022 breached 23 Nov 2021 travelio.com

    In November 2021, the Indonesian real estate website Travelio suffered a data breach that exposed over 470k customer accounts. The data included email addresses, names, password hashes, phone numbers and for some accounts, dates of birth, physical address and Facebook auth tokens.

    Auth tokens · Dates of birth · Email addresses · Names · Passwords · Phone numbers · Physical addresses

  • Royal Enfield 421K accounts
    Added 31 Mar 2022 breached 1 Jan 2019 royalenfield.com

    In January 2020, motorcycle maker Royal Enfield left a database publicly exposed that resulted in the inadvertent publication of over 400k customers. The impacted data included email and physical addresses, names, motorcycle information, social media profiles, passwords, and other personal information.

    Dates of birth · Email addresses · Genders · Names · Passwords · Phone numbers · Physical addresses · Social media profiles · Vehicle details

  • ZAP-Hosting 747K accounts
    Added 19 Mar 2022 breached 22 Nov 2021 zap-hosting.com

    In November 2021, web host ZAP-Hosting suffered a data breach that exposed over 60GB of data containing 746k unique email addresses. The breach also contained support chat logs, IP addresses, names, purchases, physical addresses and phone numbers.

    Browser user agent details · Chat logs · Email addresses · IP addresses · Names · Phone numbers · Physical addresses · Purchases

  • CDEK 19.2M accounts
    Added 17 Mar 2022 breached 9 Mar 2022 cdek.ru unverified

    In early 2022, a collective known as IT Army whose stated goal is to "completely de-anonymise most Russian users by leaking hundreds of gigabytes of databases" published over 30GB of data allegedly sourced from Russian courier service CDEK. The data contained over 19M unique email addresses along with names and phone numbers. The authenticity of the breach could not be independently established and has been flagged as "unverified".

    Email addresses · Names · Phone numbers

  • Robinhood 5.0M accounts
    Added 3 Mar 2022 breached 3 Nov 2021 robinhood.com

    In November 2021, the online trading platform Robinhood suffered a data breach after a customer service representative was socially engineered. The incident exposed over 5M customer email addresses and 2M customer names.

    Email addresses

  • MacGeneration 101K accounts
    Added 3 Mar 2022 breached 29 Jan 2022 macg.co

    In January 2022, the French Apple news website MacGeneration suffered a data breach. The incident exposed over 100k usernames, email addresses and passwords stored as salted SHA-512 hashes. After discovering the incident, MacGeneration self-submitted data to HIBP.

    Email addresses · Passwords · Usernames

  • NVIDIA 71K accounts
    Added 2 Mar 2022 breached 23 Feb 2022 nvidia.com

    In February 2022, microchip company NVIDIA suffered a data breach that exposed employee credentials and proprietary code. Impacted data included over 70k employee email addresses and NTLM password hashes, many of which were subsequently cracked and circulated within the hacking community.

    Email addresses · Passwords

  • GiveSendGo 90K accounts
    Added 15 Feb 2022 breached 7 Feb 2022 givesendgo.com

    In February 2022, the Christian fundraising service GiveSendGo suffered a data breach which exposed the personal data of 90k donors to the Canadian "Freedom Convoy" protest against vaccine mandates. The breach exposed names, email addresses, post codes, donation amount and comments left at the time of donation.

    Email addresses · Geographic locations · Names · Purchases

  • RedDoorz 5.9M accounts
    Added 28 Jan 2022 breached 4 Sept 2020 reddoorz.com

    In September 2020, the hotel management & booking platform RedDoorz suffered a data breach that exposed over 5.8M user accounts. The breached data included names, email addresses, phone numbers, genders, dates of birth and passwords stored as bcrypt hashes.

    Dates of birth · Email addresses · Genders · Names · Occupations · Passwords · Phone numbers

  • BTC-Alpha 362K accounts
    Added 27 Jan 2022 breached 2 Nov 2021 btc-alpha.com

    In November 2021, the crypto exchange platform BTC-Alpha suffered a ransomware attack data breach after which customer data was publicly dumped. The impacted data included 362k email and IP addresses, usernames and passwords stored as PBKDF2 hashes.

    Email addresses · IP addresses · Passwords · Usernames

  • ShockGore 74K accounts
    Added 20 Jan 2022 breached 11 Aug 2020 shockgore.com sensitive

    In August 2020, the website for sharing graphic videos and images of gore and animal cruelty suffered a data breach. The breach exposed 74k unique email addresses alongside usernames, IP addresses, genders and unsalted SHA-1 password hashes. Private messages were also exposed, many containing requests for material of a depraved nature.

    Email addresses · Genders · IP addresses · Passwords · Private messages · Usernames

  • Open Subtitles 6.8M accounts
    Added 19 Jan 2022 breached 1 Aug 2021 opensubtitles.org

    In August 2021, the subtitling website Open Subtitles suffered a data breach and subsequent ransom demand. The breach exposed almost 7M subscribers' personal data including email and IP addresses, usernames, the country of the user and passwords stored as unsalted MD5 hashes.

    Email addresses · Geographic locations · IP addresses · Passwords · Usernames

  • Upstox 111K accounts
    Added 19 Jan 2022 breached 8 Apr 2021 upstox.com

    In April 2021, Indian brokerage firm Upstox suffered a data breach. The incident exposed extensive personal information on over 100k customers including names, genders, dates of birth, physical addresses, banking information and passwords stored as bcrypt hashes. Extensive "know your customer" information was also exposed including scans of bank statements, cheques and identity documents complete with Aadhaar numbers.

    Bank account numbers · Dates of birth · Email addresses · Family members' names · Genders · Government issued IDs · Income levels · Marital statuses · Nationalities · Occupations · Passwords · Phone numbers · Physical addresses

  • Added 16 Jan 2022 breached 28 Dec 2021 cardmafia.cc sensitive

    In December 2021, the Carding Mafia forum suffered a data breach that exposed over 300k members' email addresses. Dedicated to the theft and trading of stolen credit cards, the forum breach also exposed usernames, IP addresses and passwords stored as salted MD5 hashes. This breach came only 9 months after another breach of the forum in March 2021.

    Email addresses · IP addresses · Passwords · Usernames

  • Added 15 Jan 2022 breached 1 Dec 2021 abfrl.com

    In December 2021, Indian retailer Aditya Birla Fashion and Retail Ltd was breached and ransomed. The ransom demand was allegedly rejected and data containing 5.4M unique email addresses was subsequently dumped publicly on a popular hacking forum the next month. The data contained extensive personal customer information including names, phone numbers, physical addresses, DoBs, order histories and passwords stored as MD5 hashes. Employee data was also dumped publicly and included salary grades, marital statuses and religions.

    Email addresses · Genders · Income levels · Job titles · Marital statuses · Names · Passwords · Phone numbers · Physical addresses · Purchases · Religions · Salutations

  • Guns.com 376K accounts
    Added 13 Jan 2022 breached 12 Jan 2021 guns.com sensitive

    In January 2021, the firearms website guns.com suffered a data breach. The breach exposed 376k unique email addresses along with names, phone numbers, physical addresses, gun purchases, partial credit card data, dates of birth and passwords stored as bcrypt hashes.

    Dates of birth · Email addresses · Names · Partial credit card data · Passwords · Phone numbers · Physical addresses · Purchases

  • Doxbin 371K accounts
    Added 8 Jan 2022 breached 5 Jan 2022 doxbin.com sensitive

    In January 2022, the "doxing" website designed to disclose the personal information of targeted individuals ("doxes") Doxbin suffered a data breach. The breach was subsequently leaked online and included over 370k unique email addresses across user accounts and doxes. User accounts also included usernames, password hashes and browser user agents. The personal information disclosed in the doxes was often extensive including names, physical addresses, phone numbers and more.

    Browser user agent details · Email addresses · Passwords · Usernames