Breaches
Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.
- Ticketcounter 1.9M accounts
In August 2020, the Dutch ticketing service Ticketcounter inadvertently published a database backup to a publicly accessible location where it was then found and downloaded in February 2021. The data contained 1.9M unique email addresses which were offered for sale on a hacking forum and in some cases included names, physical and IP addresses, genders, dates of birth, payment histories and bank account numbers. Ticketcounter was later held to ransom with the threat of the breached being released publicly.
Bank account numbers · Dates of birth · Email addresses · Genders · IP addresses · Names · Payment histories · Phone numbers · Physical addresses
- SuperVPN & GeckoVPN 20.3M accounts
In February 2021, a series of "free" VPN services were breached including SuperVPN and GeckoVPN, exposing over 20M records. The data appeared together in a single file with a small number of records also included from FlashVPN, suggesting that all three brands may share the same platform. Impacted data also included email addresses, the country logged in from and the date and time each login occurred alongside device information including the make and model, IMSI number and serial number.
Device information · Device serial numbers · Email addresses · Geographic locations · IMSI numbers · Login histories
- Filmai.in 646K accounts
In approximately 2019 or 2020, the Lithuanian movie streaming service Filmai.in suffered a data breach exposing 645k email addresses, usernames and plain text passwords.
Email addresses · Passwords · Usernames
- NurseryCam 11K accounts
In February 2021, a series of egregiously bad security flaws were identified in the NurseryCam system designed for parents to remotely monitor their children whilst attending nursery. The flaws led to the exposure of over 10k parent records before the service was shut down. The email addresses alone were provided to Have I Been Pwned to ensure parents were properly notified of the incident.
Email addresses
- People's Energy 359K accounts
In December 2020, the UK power company People's Energy suffered a data breach. The breach exposed almost 7GB of files containing 359k unique email addresses along with names, phones numbers, physical addresses and dates of birth. The incident also included People's Energy staff email addresses and bcrypt password hashes (no customer passwords were exposed).
Dates of birth · Email addresses · Names · Passwords · Phone numbers · Physical addresses
- NetGalley 1.4M accounts
In December 2020, the book promotion site NetGalley suffered a data breach. The incident exposed 1.4 million unique email addresses alongside names, usernames, physical and IP addresses, phone numbers, dates of birth and passwords stored as salted SHA-1 hashes.
Dates of birth · Email addresses · IP addresses · Names · Passwords · Phone numbers · Physical addresses · Usernames
- CityBee 110K accounts
In February 2021, the Lithuanian car-sharing service CityBee announced they'd suffered a data breach that exposed 110k customers' personal information. The breach exposed names, email addresses, government issued IDs and passwords stored as unsalted SHA-1 hashes.
Email addresses · Government issued IDs · Names · Passwords
- Ge.tt 2.5M accounts
In May 2017, the file sharing platform Ge.tt suffered a data breach. The data was subsequently put up for sale on a dark web marketplace in February 2019 alongside a raft of other breaches. The Ge.tt breach included names, social media profile identifiers, SHA256 password hashes and almost 2.5M unique email addresses.
Email addresses · Names · Passwords · Social media profiles
- StoryBird 1.0M accounts
In August 2015, the storytelling service StoryBird suffered a data breach exposing 4 million records with 1 million unique email addresses. Impacted data also included names, usernames and passwords stored as PBKDF2 hashes. The data was provided to HIBP by dehashed.com.
Email addresses · Names · Passwords · Usernames
- Pixlr 1.9M accounts
In October 2020, the online photo editing application Pixlr suffered a data breach exposing 1.9 million subscribers. Impacted data included names, email addresses, social media profiles, the country signed up from and passwords stored as SHA-512 hashes. The data was provided to HIBP by dehashed.com.
Email addresses · Geographic locations · Names · Passwords · Social media profiles
- MeetMindful 1.4M accounts
In early 2020, the online dating service MeetMindful suffered a data breach that exposed 1.4 million unique customer email addresses. Included in the data was an extensive array of personal information used to find romantic matches including physical attributes, use of alcohol, drugs and cigarettes, marital statuses, birthdates, genders and the gender being sought. Additional personal information such as names, geographical locations and IP addresses were also exposed, along with passwords stored as bcrypt hashes.
Dates of birth · Drinking habits · Drug habits · Email addresses · Genders · Geographic locations · IP addresses · Marital statuses · Names · Passwords · Physical attributes · Religions · Sexual orientations · Smoking habits · Social media profiles · Usernames
- Bonobos 2.8M accounts
In August 2020, the clothing store Bonobos suffered a data breach that exposed almost 70GB of data containing 2.8 million unique email addresses. The breach also exposed names, physical and IP addresses, phone numbers, order histories and passwords stored as salted SHA-512 hashes, including historical passwords. The breach also exposed partial credit card data including card type, the name on the card, expiry date and the last 4 digits of the card. The data was provided to HIBP by dehashed.com.
Email addresses · Historical passwords · IP addresses · Names · Partial credit card data · Passwords · Phone numbers · Physical addresses · Purchases
- Nitro 77.2M accounts
In September 2020, the Nitro PDF service suffered a massive data breach which exposed over 70 million unique email addresses. The breach also exposed names, bcrypt password hashes and the titles of converted documents. The data was provided to HIBP by dehashed.com.
Email addresses · Names · Passwords
- Romwe 19.5M accounts
In mid-2018, the Hong Kong-based retailer Romwe suffered a data breach which exposed almost 20 million customers. The data was subsequently sold online and includes names, phone numbers, email and IP addresses, customer geographic locations and passwords stored as salted SHA-1 hashes. The data was provided to HIBP by dehashed.com.
Geographic locations · IP addresses · Names · Passwords · Phone numbers · Physical addresses
- Jobandtalent 11.0M accounts
In approximately February 2018, the employment website Jobandtalent suffered a data breach which then appeared for sale alongside other breaches a year later. The incident impacted 11 million subscribers and exposed their names, email and IP addresses and passwords stored as salted SHA-1 hashes.
Email addresses · IP addresses · Names · Passwords
- Glofox 2.3M accounts
In March 2020, the Irish gym management software company Glofox suffered a data breach which exposed 2.3M membership records. The data included email addresses, names, phone numbers, genders, dates of birth and passwords stored as unsalted MD5 hashes.
Dates of birth · Email addresses · Genders · Names · Passwords · Phone numbers
- GeniusU 1.3M accounts
In November 2020, a collection of data breaches were made public including the "Entrepreneur Success Platform", GeniusU. Dating back to the previous month, the data included 1.3M names, email and IP addresses, genders, links to social media profiles and passwords stored as bcrypt hashes. The data was provided to HIBP by dehashed.com.
Email addresses · Genders · IP addresses · Names · Passwords · Social media profiles
- Ledger 1.1M accounts
In June 2020, the hardware crypto wallet manufacturer Ledger suffered a data breach that exposed over 1 million email addresses. The data was initially sold before being dumped publicly in December 2020 and included names, physical addresses and phone numbers. The data was provided to HIBP by Alon Gal, CTO of cybercrime intelligence firm Hudson Rock.
Email addresses · Names · Phone numbers · Physical addresses
- Peatix 4.2M accounts
In January 2019, the event organising platform Peatix suffered a data breach. The incident exposed 4.2M email addresses, names and salted password hashes. The data was provided to HIBP by dehashed.com.
Email addresses · Names · Passwords
- Pluto TV 3.2M accounts
In October 2018, the internet television service Pluto TV suffered a data breach which was then shared extensively in hacking communities. Pluto TV "decided not to proactively inform users of the breach" which contained 3.2M unique email and IP addresses, names, usernames, genders, dates of birth and passwords stored as bcrypt hashes. The data was provided to HIBP by dehashed.com.
Dates of birth · Device information · Email addresses · Genders · IP addresses · Names · Passwords · Social media profiles · Usernames