Breaches

Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.

1,018 breaches · updated 4 hours ago · data from Have I Been Pwned (CC BY 4.0)

1,018 breaches · page 26 of 51 Fabricated, spam-list and retired breaches are left out.
  • IIMJobs 4.2M accounts
    Added 21 May 2021 breached 31 Dec 2018 iimjobs.com

    In December 2018, the Indian job portal IIMJobs suffered a data breach that exposed 4.1 million unique email addresses. The data also included names, phone numbers, geographic locations, dates of birth, job titles, job applications and cover letters plus passwords stored as unsalted MD5 hashes. The data was provided to HIBP by dehashed.com.

    Dates of birth · Email addresses · Geographic locations · IP addresses · Job applications · Job titles · Names · Passwords · Phone numbers

  • WedMeGood 1.3M accounts
    Added 13 May 2021 breached 6 Jan 2021 wedmegood.com

    In January 2021, the Indian wedding planning platform WedMeGood suffered a data breach that exposed 1.3 million customers. The breach exposed 41.5GB of data including email and physical addresses, names, genders, phone numbers and password hashes. The data was provided to HIBP by dehashed.com.

    Email addresses · Genders · Names · Passwords · Phone numbers · Physical addresses

  • DriveSure 3.7M accounts
    Added 10 May 2021 breached 19 Dec 2020 drivesure.com

    In December 2020, the car dealership service provider DriveSure suffered a data breach. The incident resulted in 26GB of data being downloaded and later shared on a hacking forum. Impacted personal information included 3.6 million unique email addresses, names, phone numbers and physical addresses. Vehicle data was also exposed and included makes, models, VIN numbers and odometer readings. A small number of passwords stored as bcrypt hashes were also included in the data set.

    Email addresses · Names · Passwords · Phone numbers · Physical addresses · Vehicle details

  • ParkMobile 20.9M accounts
    Added 30 Apr 2021 breached 21 Mar 2021 parkmobile.io

    In March 2021, the mobile parking app service ParkMobile suffered a data breach which exposed 21 million customers' personal data. The impacted data included email addresses, names, phone numbers, vehicle licence plates and passwords stored as bcrypt hashes. The following month, the data appeared on a public hacking forum where it was extensively redistributed.

    Email addresses · Licence plates · Names · Passwords · Phone numbers

  • Descomplica 4.8M accounts
    Added 28 Apr 2021 breached 14 Mar 2021 descomplica.com.br

    In March 2021, the Brazilian EdTech company Descomplica suffered a data breach which was subsequently posted to a popular hacking forum. The data included almost 5 million email addresses, names, the first 6 and last 4 digits and the expiry date of credit cards, purchase histories and password hashes.

    Email addresses · Names · Partial credit card data · Passwords · Purchases

  • Jefit 9.1M accounts
    Added 27 Apr 2021 breached 11 Aug 2020 jefit.com

    In August 2020, the workout tracking app Jefit suffered a data breach. The data was subsequently sold within the hacking community and included over 9 million email and IP addresses, usernames and passwords stored as either vBulletin or argon2 hashes. Several million cracked passwords later appeared in broad circulation.

    Email addresses · IP addresses · Passwords · Usernames

  • Emotet 4.3M accounts
    Added 26 Apr 2021 breached 27 Jan 2021 sensitive malware

    In January 2021, the FBI in partnership with the Dutch NHTCU, German BKA and other international law enforcement agencies brought down the world's most dangerous malware: Emotet. The agencies obtained data collected by the malware and provided impacted email addresses to HIBP so that impacted individuals and domain owners could assess their exposure. Read more about the takedown and recommended actions.

    Email addresses · Passwords

  • bigbasket 24.5M accounts
    Added 26 Apr 2021 breached 14 Oct 2020 bigbasket.com

    In October 2020, the Indian grocery platform bigbasket suffered a data breach that exposed over 20 million customer records. The data was originally sold before being leaked publicly in April the following year and included email, IP and physical addresses, names, phones numbers, dates of birth passwords stored as Django(SHA-1) hashes.

    Dates of birth · Email addresses · IP addresses · Names · Passwords · Phone numbers · Physical addresses

  • MangaDex 3.0M accounts
    Added 25 Apr 2021 breached 22 Mar 2021 mangadex.org

    In March 2021, the manga fan site MangaDex suffered a data breach that resulted in the exposure of almost 3 million subscribers. The data included email and IP addresses, usernames and passwords stored as bcrypt hashes. The data was subsequently circulated within hacking groups.

    Email addresses · IP addresses · Passwords · Usernames

  • ShopBack 20.5M accounts
    Added 25 Apr 2021 breached 17 Sept 2020 shopback.com

    In September 2020, the cashback reward program ShopBack suffered a data breach. The incident exposed over 20 million unique email addresses along with names, phone numbers, country of residence and passwords stored as salted SHA-1 hashes. The data was provided to HIBP by dehashed.com.

    Email addresses · Geographic locations · Names · Passwords · Phone numbers

  • ClearVoice Surveys 15.1M accounts
    Added 23 Apr 2021 breached 23 Aug 2015 clearvoicesurveys.com

    In April 2021, the market research surveys company ClearVoice Surveys had a publicly facing database backup from 2015 taken and redistributed on a popular hacking forum. The data included 15M unique email addresses across more than 17M rows of data that also included names, physical and IP addresses, genders, dates of birth and plain text passwords. ClearVoice Surveys advised they were aware of the breach and confirmed its authenticity.

    Dates of birth · Email addresses · Genders · IP addresses · Names · Passwords · Phone numbers · Physical addresses

  • Phone House España 5.2M accounts
    Added 22 Apr 2021 breached 8 Apr 2021 phonehouse.es

    In April 2021, the Spanish retailer Phone House allegedly suffered a ransomware attack that also exposed significant volumes of customer data. Attributed to the Babuk ransomware, a collection of data alleged to be a subset of a larger corpus was posted to a dark web site and contained 5.2M email addresses along with names, nationalities, genders, dates of birth, phone numbers and physical addresses. Phone House has been threatened with further releases if a ransom is not paid.

    Dates of birth · Email addresses · Genders · Names · Nationalities · Phone numbers · Physical addresses

  • Facebook 509.5M accounts
    Added 4 Apr 2021 breached 1 Aug 2019 facebook.com

    In April 2021, a large data set of over 500 million Facebook users was made freely available for download. Encompassing approximately 20% of Facebook's subscribers, the data was allegedly obtained by exploiting a vulnerability Facebook advises they rectified in August 2019. The primary value of the data is the association of phone numbers to identities; whilst each record included phone, only 2.5 million contained an email address. Most records contained names and genders with many also including dates of birth, location, relationship status and employer.

    Dates of birth · Email addresses · Employers · Genders · Geographic locations · Names · Phone numbers · Relationship statuses

  • Added 24 Mar 2021 breached 26 Jan 2021 astoriacompany.com unverified

    In January 2021, over 11M unique email addresses were discovered by Night Lion Security alongside an extensive amount of personal information including names, physical and IP addresses, phone numbers and dates of birth. Some records also contained social security numbers, driver's license details, personal financial information and health-related data, depending on where the information was sourced from. Initially attributed to Astoria Company, they subsequently investigated the incident and confirmed the data did not originate from their services.

    Bank account numbers · Credit status information · Dates of birth · Email addresses · Employers · Health insurance information · Income levels · IP addresses · Names · Personal health data · Phone numbers · Physical addresses · Smoking habits · Social security numbers

  • Added 23 Mar 2021 breached 18 Mar 2021 cardmafia.cc sensitive

    In March 2021, the Carding Mafia forum suffered a data breach that exposed almost 300k members' email addresses. Dedicated to the theft and trading of stolen credit cards, the forum breach also exposed usernames, IP addresses and passwords stored as salted MD5 hashes.

    Email addresses · IP addresses · Passwords · Usernames

  • WeLeakInfo 12K accounts
    Added 15 Mar 2021 breached 8 Mar 2021 weleakinfo.com sensitive

    In March 2021, the Stripe account of the now-defunct WeLeakInfo service was taken over by "pompompurin" after acquiring an expired domain name with an email address used to manage the account. Access to Stripe then exposed almost 12k unique email addresses from customers who'd made credit card payments in order to obtain breached data hosted by WeLeakInfo. The data was subsequently leaked publicly and also included names, payment histories, IP addresses, billing addresses, partial credit card data and the organisation making the purchase.

    Browser user agent details · Email addresses · Employers · IP addresses · Names · Partial credit card data · Physical addresses · Purchases

  • Liker 465K accounts
    Added 13 Mar 2021 breached 8 Mar 2021 liker.com

    In March 2021, the self-proclaimed "kinder, smarter social network" Liker suffered a data breach, allegedly in retaliation for the Gab data breach and scraping of data from Parler. The site remained offline after the breach which exposed 465k email addresses in addition to names, dates of birth, education levels, private messages, security questions and answers in plain text, passwords stored as bcrypt hashes and other personal data attributes. Liker did not respond when contacted about the breach.

    Auth tokens · Dates of birth · Education levels · Email addresses · Geographic locations · IP addresses · Names · Passwords · Phone numbers · Private messages · Security questions and answers · Social media profiles · Usernames

  • Travel Oklahoma 637K accounts
    Added 10 Mar 2021 breached 17 Dec 2020 travelok.com

    In December 2020, the Oklahoma state Tourism and Recreation Department suffered a data breach. The incident exposed 637k email addresses across a variety of tables including age ranges against brochure orders and dates of birth against contest entries. Genders, names and physical addresses were also exposed.

    Age groups · Dates of birth · Email addresses · Genders · Names · Physical addresses

  • Gab 67K accounts
    Added 3 Mar 2021 breached 26 Feb 2021 gab.com sensitive

    In February 2021, the alt-tech social network service Gab suffered a data breach. The incident exposed almost 70GB of data including 4M user accounts, a small number of private chat logs and a list of public groups and public posts made to the service. Only a small number of accounts included email addresses and / or passwords stored as bcrypt hashes with a total of 66.5k unique email addresses being exposed across the corpus of data.

    Avatars · Email addresses · Names · Passwords · Private messages · Usernames

  • Oxfam 1.8M accounts
    Added 2 Mar 2021 breached 20 Jan 2021 oxfam.org.au

    In January 2021, Oxfam Australia was the victim of a data breach which exposed 1.8M unique email addresses of supporters of the charity. The data was put up for sale on a popular hacking forum and also included names, phone numbers, addresses, genders and dates of birth. A small number of people also had partial credit card data exposed (the first 6 and last 3 digits of the card, plus card type and expiry) and in some cases the bank name, account number and BSB were also exposed. The data was subsequently made freely available on the hacking forum later the following month.

    Bank account numbers · Dates of birth · Email addresses · Genders · Names · Partial credit card data · Payment histories · Phone numbers · Physical addresses