Breaches

Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.

1,018 breaches · updated 2 hours ago · data from Have I Been Pwned (CC BY 4.0)

1,018 breaches · page 30 of 51 Fabricated, spam-list and retired breaches are left out.
  • Zoomcar 3.6M accounts
    Added 5 Jun 2020 breached 1 Jul 2018 zoomcar.com

    In July 2018, the Indian self-drive car rental company Zoomcar suffered a data breach which was subsequently sold on a dark web marketplace in 2020. The breach exposed over 3.5M records including names, email and IP addresses, phone numbers and passwords stored as bcrypt hashes. The data was provided to HIBP by dehashed.com.

    Email addresses · IP addresses · Names · Passwords · Phone numbers

  • Lead Hunter 68.7M accounts
    Added 3 Jun 2020 breached 4 Mar 2020

    In March 2020, a massive trove of personal information referred to as "Lead Hunter" was provided to HIBP after being found left exposed on a publicly facing Elasticsearch server. The data contained 69 million unique email addresses across 110 million rows of data accompanied by additional personal information including names, phone numbers, genders and physical addresses. At the time of publishing, the breach could not be attributed to those responsible for obtaining and exposing it. The data was provided to HIBP by dehashed.com.

    Email addresses · Genders · IP addresses · Names · Phone numbers · Physical addresses

  • Wishbone (2020) 9.7M accounts
    Added 28 May 2020 breached 27 Jan 2020 wishbone.io

    In January 2020, the mobile app to "compare anything" Wishbone suffered another data breach which followed their breach from 2016. An extensive amount of personal information including almost 10M unique email addresses alongside names, phone numbers geographic locations and other personal attributes were leaked online and extensively redistributed. Passwords stored as unsalted MD5 hashes were also included in the breach.

    Auth tokens · Dates of birth · Email addresses · Genders · Geographic locations · IP addresses · Names · Passwords · Phone numbers · Profile photos · Social media profiles · Usernames

  • LiveJournal 26.4M accounts
    Added 26 May 2020 breached 1 Jan 2017 livejournal.com

    In mid-2019, news broke of an alleged LiveJournal data breach. This followed multiple reports of credential abuse against Dreamwidth beginning in 2018, a fork of LiveJournal with a significant crossover in user base. The breach allegedly dates back to 2017 and contains 26M unique usernames and email addresses (both of which have been confirmed to exist on LiveJournal) alongside plain text passwords. An archive of the data was subsequently shared on a popular hacking forum in May 2020 and redistributed broadly.

    Email addresses · Passwords · Usernames

  • PetFlow 991K accounts
    Added 26 May 2020 breached 9 Dec 2017 petflow.com

    In December 2017, the pet care delivery service PetFlow suffered a data breach which consequently appeared for sale on a dark web marketplace. Almost 1M accounts were impacted and exposed email addresses and passwords stored as unsalted MD5 hashes.

    Email addresses · Passwords

  • Artsy 1.1M accounts
    Added 25 May 2020 breached 1 Apr 2018 artsy.net

    In April 2018, the online arts database Artsy suffered a data breach which consequently appeared for sale on a dark web marketplace. Over 1M accounts were impacted and included IP and email addresses, names and passwords stored as salted SHA-512 hashes.

    Email addresses · IP addresses · Names · Passwords

  • Lifebear 3.7M accounts
    Added 25 May 2020 breached 28 Feb 2019 lifebear.com

    In early 2019, the Japanese schedule app Lifebear appeared for sale on a dark web marketplace amongst a raft of other hacked websites. The breach exposed almost 3.7M unique email addresses, usernames and passwords stored as salted MD5 hashes.

    Email addresses · Passwords · Usernames

  • Nulled.ch 43K accounts
    Added 24 May 2020 breached 20 May 2020 nulled.ch

    In May 2020, the hacking forum Nulled.ch was breached and the data published to a rival hacking forum. Over 43k records were compromised and included IP and email addresses, usernames and passwords stored as salted MD5 hashes alongside the private message history of the website's admin.

    Email addresses · IP addresses · Passwords · Private messages · Usernames

  • Covve 22.8M accounts
    Added 15 May 2020 breached 20 Feb 2020 covve.com

    In February 2020, a massive trove of personal information referred to as "db8151dd" was provided to HIBP after being found left exposed on a publicly facing Elasticsearch server. Later identified as originating from the Covve contacts app, the exposed data included extensive personal information and interactions between Covve users and their contacts. The data was provided to HIBP by dehashed.com.

    Email addresses · Job titles · Names · Phone numbers · Physical addresses · Social media profiles

  • Ulmon 778K accounts
    Added 8 May 2020 breached 26 Jan 2020 ulmon.com

    In January 2020, the travel app creator Ulmon suffered a data breach. The service had almost 1.3M records with 777k unique email addresses, names, passwords stored as bcrypt hashes and in some cases, social media profile IDs, telephone numbers and bios. The data was subsequently posted to a popular hacking forum.

    Bios · Email addresses · Names · Passwords · Phone numbers · Social media profiles

  • Elanic 2.3M accounts
    Added 4 May 2020 breached 1 Jan 2018 elanic.in

    In January 2020, the Indian fashion marketplace Elanic had 2.8M records with 2.3M unique email addresses posted publicly to a popular hacking forum. Elanic confirmed that they had "verified the data and it was pulled from one of our test servers where this data was exposed publicly" and that the data was "old" (the hacking forum reported it as being from 2016-2018). When asked about disclosure to impacted customers, Elanic advised that they had "decided to not have as such any communication and public disclosure".

    Email addresses · Geographic locations · Usernames

  • TaiLieu 7.3M accounts
    Added 3 May 2020 breached 24 Nov 2019 tailieu.vn

    In November 2019, the Vietnamese education website TaiLieu allegedly suffered a data breach exposing 7.3M customer records. Impacted data included names and usernames, email addresses, dates of birth, genders and passwords stored as unsalted MD5 hashes. The data was provided to HIBP by dehashed.com after being shared on a popular hacking forum. TaiLieu did not respond when contacted about the incident.

    Dates of birth · Email addresses · Genders · Geographic locations · Names · Passwords · Phone numbers · Usernames

  • Tokopedia 71.4M accounts
    Added 2 May 2020 breached 17 Apr 2020 tokopedia.com

    In April 2020, Indonesia's largest online store Tokopedia suffered a data breach. The incident resulted in 15M rows of data being posted to a popular hacking forum. An additional 76M rows were later provided to HIBP in July 2020. In total, the data included over 71M unique email addresses alongside names, genders, birth dates and passwords stored as SHA2-384 hashes.

    Dates of birth · Email addresses · Genders · Names · Passwords

  • Vianet 94K accounts
    Added 22 Apr 2020 breached 8 Apr 2020 vianet.com.np

    In April 2020, the Nepalese internet service provider Vianet suffered a data breach. The attack on the ISP led to the exposure of 177k customer records including 94k unique email addresses. Also exposed were names, phone numbers and physical addresses.

    Email addresses · Names · Phone numbers · Physical addresses

  • Aptoide 20.0M accounts
    Added 19 Apr 2020 breached 13 Apr 2020 aptoide.com

    In April 2020, the independent Android app store Aptoide suffered a data breach. The incident resulted in the exposure of 20M customer records which were subsequently shared online via a popular hacking forum. Impacted data included email and IP addresses, names, IP addresses and passwords stored as SHA-1 hashes without a salt.

    Browser user agent details · Email addresses · IP addresses · Names · Passwords

  • HTC Mania 1.5M accounts
    Added 6 Apr 2020 breached 4 Jan 2020 htcmania.com

    In January 2020, the Spanish mobile phone forum HTC Mania suffered a data breach of the vBulletin based site. The incident exposed 1.5M member email addresses, usernames, IP addresses, dates of birth and salted MD5 password hashes and password histories. Data from the breach was subsequently redistributed on popular hacking websites.

    Dates of birth · Email addresses · Historical passwords · IP addresses · Passwords · Usernames

  • Added 4 Apr 2020 breached 2 Apr 2020 ogusers.com

    In April 2020, the account hijacking and SIM swapping forum OGUsers suffered their second data breach in less than a year. As with the previous breach, the exposed data included email and IP addresses, usernames, private messages and passwords stored as salted MD5 hashes. A total of 263k email addresses across user accounts and other tables were posted to a rival hacking forum.

    Email addresses · IP addresses · Passwords · Private messages · Usernames

  • Dueling Network 6.5M accounts
    Added 30 Mar 2020 breached 29 Mar 2017 duelingnetwork.com

    In March 2017, the Flash game based on the Yu-Gi-Oh trading card game Dueling Network suffered a data breach. The site itself was taken offline in 2016 due to a cease-and-desist order but the forum remained online for another year. The data breach exposed usernames, IP and email addresses and passwords stored as MD5 hashes.

    Email addresses · IP addresses · Passwords · Usernames

  • Tamodo 495K accounts
    Added 24 Mar 2020 breached 28 Feb 2020 tamodo.com

    In February 2020, the affiliate marketing network Tamodo suffered a data breach which was subsequently shared on a popular hacking forum. The incident exposed almost 500k accounts including names, email addresses, dates of birth and passwords stored as bcrypt hashes. Tamodo failed to respond to multiple attempts to report the breach via published communication channels.

    Dates of birth · Email addresses · Genders · Geographic locations · IP addresses · Names · Passwords

  • PropTiger 2.2M accounts
    Added 24 Mar 2020 breached 30 Jan 2018 proptiger.com

    In January 2018, the Indian property website PropTiger suffered a data breach which resulted in a 3.46GB database file being exposed and subsequently shared extensively on a popular hacking forum 2 years later. The exposed data contained both user records and login histories with over 2M unique customer email addresses. Exposed data also included additional personal attributes such as names, dates of birth, genders, IP addresses and passwords stored as MD5 hashes. PropTiger advised they believe the usability of the data is "limited" due to how certain data attributes were generated and stored. The data was provided to HIBP by dehashed.com.

    Dates of birth · Device information · Email addresses · Genders · IP addresses · Names · Passwords