Breaches

Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.

1,018 breaches · updated 6 hours ago · data from Have I Been Pwned (CC BY 4.0)

1,018 breaches · page 3 of 51 Fabricated, spam-list and retired breaches are left out.
  • Atlas Menu 64K accounts
    Added 30 May 2026 breached 30 May 2026 atlasmenu.net

    In May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and published the service's database to a public GitHub repository. The incident exposed 64k unique email addresses along with usernames, IP addresses, support tickets and passwords stored as bcrypt hashes.

    Email addresses · IP addresses · Passwords · Support tickets · Usernames

  • Charter 4.9M accounts
    Added 28 May 2026 breached 23 May 2026 charter.com

    In May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group later published the data, which exposed 4.9M unique email addresses along with names, phone numbers and physical addresses. A subset of approximately 85k records originating from an internal employee directory also included job titles. Charter confirmed the incident, but stated that no sensitive personal information or customer proprietary network information (CPNI) was exfiltrated.

    Email addresses · Job titles · Names · Phone numbers · Physical addresses

  • Kemper 269K accounts
    Added 28 May 2026 breached 15 Apr 2026 kemper.com

    In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign. The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part of a broader campaign targeting hundreds of organisations using the same method. The group later published tens of gigabytes of data they claimed included internal directory data, Salesforce records and Stripe payment logs. Among the 269k unique email addresses were names, phone numbers, physical addresses and partial payment card data including the last 4 digits, expiry dates and card brands. Kemper confirmed the incident and stated they had engaged third-party cybersecurity experts and notified law enforcement.

    Email addresses · Names · Partial credit card data · Phone numbers · Physical addresses · Purchases

  • Mytheresa 84K accounts
    Added 27 May 2026 breached 12 Apr 2026 mytheresa.com

    In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters "pay or leak" extortion group. After the ransom deadline passed, the group publicly released the data which contained 84k unique email addresses. The exposed data also included names, phone numbers, physical addresses, purchases and partial credit card data including card type, last 4 digits and expiry date.

    Email addresses · Names · Partial credit card data · Phone numbers · Physical addresses · Purchases · Salutations

  • Ameriprise 503K accounts
    Added 26 May 2026 breached 2 Mar 2026 ameriprise.com

    In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group claimed possession of more than 200GB of compressed data exfiltrated from Ameriprise's Salesforce environment and internal SharePoint infrastructure, and subsequently published the data after negotiations allegedly failed. The published data contained 500k unique email addresses as well as names, phone numbers, physical addresses and employer information. In their disclosure to state attorneys general, Ameriprise reported 47,876 affected people; the larger email address population represents contacts from Ameriprise's broader operational systems, including internal staff. Ameriprise further advised that they have "implemented heightened monitoring of your account(s) to include enhanced identity verification procedures".

    Email addresses · Employers · Financial transactions · Job titles · Names · Phone numbers · Physical addresses

  • 7-Eleven 185K accounts
    Added 24 May 2026 breached 8 Apr 2026 7-eleven.com

    In April 2026, 7-Eleven was the victim of a "pay or leak" extortion campaign by ShinyHunters, with the data later published that month. The incident exposed 185k unique email addresses, along with names, physical addresses, dates of birth and phone numbers. A small number of records also contained additional exposed data fields. The company later advised the breach was limited to "certain 7-Eleven systems used to store franchisee documents", a statement consistent with the exposed data.

    Dates of birth · Email addresses · Names · Phone numbers · Physical addresses

  • Dragonica Lunaris 126K accounts
    Added 21 May 2026 breached 6 Dec 2025 playdragonica.eu

    In December 2025, the European Dragonica private server Dragonica Lunaris suffered a data breach. The incident exposed 126k email addresses, usernames, dates of birth and bcrypt password hashes. The service operator confirmed the breach and advised it has since been fixed.

    Dates of birth · Email addresses · Names · Passwords · Spoken languages · Usernames

  • Added 21 May 2026 breached 1 Jan 2021 windows93.net

    In January 2021, the parody site Windows93 suffered a data breach of the Myspace93 sub-site after a beta application was exploited to download server files. The compromised data was later leaked in June and included 46k Myspace93 accounts containing email and IP addresses, usernames and passwords stored in plain text.

    Email addresses · IP addresses · Passwords · Usernames

  • CTT 468K accounts
    Added 19 May 2026 breached 26 Apr 2026 ctt.pt

    In April 2026, data allegedly obtained from CTT, Portugal's national postal service, was posted to a public hacking forum. The data included 468k unique email addresses along with names, phone numbers and parcel tracking numbers which can be used to retrieve the tracking history of the parcel.

    Email addresses · Names · Phone numbers

  • Addi 34.5M accounts
    Added 18 May 2026 breached 25 Mar 2026 addi.com

    In March 2026, the Colombian fintech company Addi identified unauthorised activity on its platform and advised customers that "it is possible that your personal information may have been compromised". The "pay or leak" extortion group ShinyHunters subsequently claimed responsibility and published a large trove of personal data allegedly obtained from Addi. The data included 34M unique email addresses from credit scoring requests, credit bureau records, customer identity records and email validation logs. It also contained government issued IDs (Cédula de Ciudadanía), estimated income, socioeconomic levels, purchases and other credit-related data points.

    Age groups · Credit scores · Device information · Email addresses · Government issued IDs · Income levels · IP addresses · Latitude and longitude pairs · Names · Phone numbers · Physical addresses · Purchases · Socioeconomic levels

  • Abrigo 711K accounts
    Added 14 May 2026 breached 14 Apr 2026 abrigo.com

    In April 2026, the fintech software company Abrigo was targeted in a "pay or leak" extortion attempt by the ShinyHunters group. Shortly after, data allegedly taken from the company's Salesforce instance was published publicly and contained over 700k unique email addresses belonging to both Abrigo staff and external contacts. Whilst separate from Abrigo's Salesforce compromise via the Drift application connector the previous year, the data fields described in that incident are consistent with the ShinyHunters data, namely that it was "business contact information" including "institution name, employee name, email addresses, and phone numbers".

    Email addresses · Employers · Job titles · Names · Phone numbers · Physical addresses

  • Canada Life 238K accounts
    Added 13 May 2026 breached 20 Apr 2026 canadalife.com

    In April 2026, Canada Life was the victim of a "pay or leak" extortion campaign by the ShinyHunters group. The group subsequently published the data which contained over 200k unique email addresses along with names, phone numbers, physical addresses and, in some cases, customer support tickets. In their disclosure notice, Canada Life advised that "it is a small proportion of our customers who may have been impacted". In the wake of the incident, Canada Life also published an alert cautioning customers to be wary of phishing attacks, a pattern often seen after the public release of breached data.

    Email addresses · Job titles · Names · Phone numbers · Physical addresses · Salutations · Support tickets

  • Cushman & Wakefield 310K accounts
    Added 12 May 2026 breached 5 May 2026 cushmanwakefield.com

    In May 2026, the real estate services firm Cushman & Wakefield was the target of a "pay or leak" extortion campaign by the ShinyHunters group. Following the threat, the group publicly published data they alleged had been obtained from the firm, consisting mostly of C&W email addresses along with tens of thousands of external email addresses and corporate contact records. The exposed data was primarily business information, including names, job titles, company addresses and phone numbers.

    Email addresses · Job titles · Names · Phone numbers · Physical addresses · Salutations

  • Zara 197K accounts
    Added 8 May 2026 breached 15 Apr 2026 zara.com

    In April 2026, the fashion brand Zara was among a number of organisations targeted by the ShinyHunters extortion group as part of their "pay or leak" campaign. The group claimed the breach was related to a compromise of the Anodot analytics platform and subsequently published a terabyte of data allegedly including 95M support ticket records. The data contained 197k unique email addresses alongside product SKUs, order IDs and the market the support ticket originated in. Zara's parent company Inditex advised that the incident didn't affect passwords or payment information.

    Email addresses · Geographic locations · Purchases · Support tickets

  • Woflow 448K accounts
    Added 7 May 2026 breached 4 Mar 2026 woflow.com

    In March 2026, the AI-driven merchant data platform Woflow was named as a victim by the ShinyHunters data extortion group. The group subsequently published tens of thousands of files allegedly obtained from the company, comprising more than 2TB of data. The trove included hundreds of thousands of email addresses, names, phone numbers and physical addresses, with the data indicating it related to Woflow customers and, in turn, the customers of merchants using their platform.

    Email addresses · Names · Phone numbers · Physical addresses

  • LegionProxy 10K accounts
    Added 6 May 2026 breached 6 Apr 2026 legionproxy.io

    In April 2026, the commercial residential and ISP proxy network LegionProxy suffered a data breach. The incident exposed 10k email addresses, bcrypt password hashes, names and purchases.

    Email addresses · Names · Passwords · Purchases

  • Vimeo 119K accounts
    Added 5 May 2026 breached 28 Apr 2026 vimeo.com

    In April 2026, the ShinyHunters extortion group listed Vimeo on their extortion portal as part of their "pay or leak" campaign. They subsequently published hundreds of gigabytes of data, predominantly consisting of video titles, technical data and metadata. The data also included 119k unique email addresses, sometimes accompanied by names. Vimeo attributed the exposure to a breach of Anodot, a third-party analytics vendor, and advised the incident does not include "Vimeo video content, valid user login credentials, or payment card information".

    Email addresses · Names

  • Reborn Gaming 126 accounts
    Added 4 May 2026 breached 30 Apr 2026 reborngaming.net

    In April 2026, the gaming community Reborn Gaming suffered a data breach due to a vulnerability in cPanel and WebHost Manager (WHM). The breach exposed 126 unique email addresses along with IP addresses and Steam IDs. Reborn Gaming self-submitted the data to Have I Been Pwned.

    Email addresses · IP addresses

  • Marcus & Millichap 1.8M accounts
    Added 3 May 2026 breached 12 Apr 2026 marcusmillichap.com

    In April 2026, the commercial real estate brokerage firm Marcus & Millichap was named as one of multiple alleged victims of the ShinyHunters hacking and extortion group. Data alleged to have been obtained from the company was subsequently released publicly and included 1.8M unique email addresses, along with names, phone numbers and employment-related information including employer, job title and physical company address. In their disclosure notice, Marcus & Millichap advised that data which may have been accessed appeared limited to "company forms, templates, marketing materials, and general contact information".

    Email addresses · Employers · Job titles · Names · Phone numbers · Physical addresses

  • ZenBusiness 5.1M accounts
    Added 2 May 2026 breached 27 Mar 2026 zenbusiness.com

    In March 2026, the hacker and extortion group "ShinyHunters" claimed to have obtained a substantial corpus of data from ZenBusiness, a business formation and compliance platform. The group claimed the data had been exfiltrated from platforms including Snowflake, Mixpanel and Salesforce, and threatened to publish it if a ransom was not paid. The following month, after claiming payment had not been made, ShinyHunters publicly released the data. The collection amounted to many terabytes across thousands of files that appeared to originate from multiple systems and business functions, including leads, support records and other CRM-related data. The data contained approximately 5M unique email addresses, often accompanied by name and phone number depending on the source file.

    Email addresses · Names · Phone numbers