Breaches

Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.

1,018 breaches · updated 3 hours ago · data from Have I Been Pwned (CC BY 4.0)

1,018 breaches · page 31 of 51 Fabricated, spam-list and retired breaches are left out.
  • Added 16 Mar 2020 breached 27 Sept 2019 thehalloweenspot.com

    In September 2019, the Halloween costume store The Halloween Spot suffered a data breach. Originally misattributed to fancy dress store Smiffys, the breach contained 13GB of data with over 10k unique email addresses alongside names, physical and IP addresses, phone numbers and order histories. The Halloween Spot advised customers the breach was traced back to "an old shipping information database".

    Email addresses · IP addresses · Names · Phone numbers · Physical addresses · Purchases

  • AnimeGame 1.4M accounts
    Added 9 Mar 2020 breached 27 Feb 2020 animegame.me

    In February 2020, the gaming website AnimeGame suffered a data breach. The incident affected 1.4M subscribers and exposed email addresses, usernames and passwords stored as salted MD5 hashes. The data was subsequently shared on a popular hacking forum and was provided to HIBP by dehashed.com.

    Email addresses · Passwords · Usernames

  • Straffic 48.6M accounts
    Added 27 Feb 2020 breached 14 Feb 2020 straffic.io

    In February 2020, Israeli marketing company Straffic exposed a database with 140GB of personal data. The publicly accessible Elasticsearch database contained over 300M rows with 49M unique email addresses. Exposed data also included names, phone numbers, physical addresses and genders. In their breach disclosure message, Straffic stated that "it is impossible to create a totally immune system, and these things can occur".

    Email addresses · Genders · Names · Phone numbers · Physical addresses

  • Slickwraps 858K accounts
    Added 22 Feb 2020 breached 16 Feb 2020 slickwraps.com

    In February 2020, the online store for consumer electronics wraps Slickwraps suffered a data breach. The incident resulted in the exposure of 858k unique email addresses across customer records and newsletter subscribers. Additional impacted data included names, physical addresses, phone numbers and purchase histories.

    Email addresses · Names · Phone numbers · Physical addresses · Purchases

  • MGM Resorts 3.1M accounts
    Added 20 Feb 2020 breached 25 Jul 2019 mgmresorts.com

    In July 2019, MGM Resorts discovered a data breach of one of their cloud services. The breach included 10.6M guest records with 3.1M unique email addresses stemming back to 2017. The exposed data included email and physical addresses, names, phone numbers and dates of birth and was subsequently shared on a popular hacking forum in February 2020 where it was extensively redistributed. The data was provided to HIBP by Under The Breach.

    Dates of birth · Email addresses · Names · Phone numbers · Physical addresses

  • Added 6 Feb 2020 breached 16 Oct 2016 adultfriendfinder.com sensitive

    In October 2016, the adult entertainment company Friend Finder Networks suffered a massive data breach. The incident impacted multiple separate online assets owned by the company, the largest of which was the Adult FriendFinder website alleged to be "the world's largest sex & swinger community". Exposed data included usernames, passwords stored as SHA-1 hashes and 170 million unique email addresses. This incident is separate to the 2015 data breach Adult FriendFinder also suffered. The data was provided to HIBP by dehashed.com.

    Email addresses · Passwords · Spoken languages · Usernames

  • DailyObjects 464K accounts
    Added 28 Jan 2020 breached 1 Jan 2018 dailyobjects.com

    In approximately January 2018, a collection of more than 464k customer records from the Indian online retailer DailyObjects were leaked online. The data included names, physical and email addresses, phone numbers and "pincodes" stored in plain text. After multiple attempts to contact them, DailyObjects responded and received a copy of the data for verification, however failed to respond to multiple contact attempts following that.

    Email addresses · Names · Passwords · Phone numbers · Physical addresses

  • Tout 653K accounts
    Added 25 Jan 2020 breached 11 Sept 2014 tout.com

    In approximately September 2014, the now defunct social networking service Tout suffered a data breach. The breach subsequently appeared years later and included 653k unique email addresses, names, IP addresses, the location of the user, their bio and passwords stored as bcrypt hashes.

    Bios · Email addresses · Geographic locations · IP addresses · Names · Passwords · Usernames

  • europa.jobs 226K accounts
    Added 15 Jan 2020 breached 11 Aug 2019 europa.jobs

    In August 2019, the now defunct European jobs website europa.jobs (Google cache link) suffered a data breach. The incident exposed 226k unique email addresses alongside extensive personal information including names, dates of birth, job applications and passwords. The data was subsequently redistributed on a popular hacking forum.

    Dates of birth · Email addresses · Geographic locations · Job applications · Names · Passwords · Phone numbers · Spoken languages

  • Planet Calypso 62K accounts
    Added 12 Jan 2020 breached 1 Jul 2019 planetcalypsoforum.com

    In approximately July 2019, the forums for the Planet Calypso game suffered a data breach. The breach of the vBulletin based forum exposed email and IP addresses, usernames and passwords stored as salted MD5 hashes.

    Email addresses · IP addresses · Passwords · Usernames

  • BtoBet 444K accounts
    Added 11 Jan 2020 breached 26 Dec 2019 btobet.com

    In December 2019, a large collection of data from Nigerian gambling company Surebet247 was sent to HIBP. Alongside the Surebet247, database backups from gambling sites BetAlfa, BetWay, BongoBongo and TopBet was also included. Further investigation implicated betting platform provider BtoBet as being the common source of the data. Impacted data included user records and extensive information on gambling histories.

    Dates of birth · Email addresses · Financial transactions · Geographic locations · IP addresses · Names · Usernames

  • Go Games 3.4M accounts
    Added 11 Jan 2020 breached 24 Oct 2015 gogames.me

    In approximately October 2015, the manga website Go Games suffered a data breach. The exposed data included 3.4M customer records including email and IP addresses, usernames and passwords stored as salted MD5 hashes. Go Games did not respond when contacted about the incident. The data was provided to HIBP by dehashed.com.

    Email addresses · IP addresses · Passwords · Usernames

  • Indian Railways 583K accounts
    Added 10 Jan 2020 breached 28 Oct 2019 indianrails.in

    In November 2019, the website for Indian Rail left more than 2M records exposed on an unprotected Firebase database instance. The exposed data included 583k unique email addresses alongside usernames and passwords stored in plain text.

    Email addresses · Passwords · Usernames

  • Universarium 565K accounts
    Added 3 Jan 2020 breached 1 Nov 2019 universarium.org

    In approximately November 2019, the Russian "Remote preparatory faculty for IT specialties" Universarium suffered a data breach. The incident exposed 565k email addresses and passwords in plain text. Universarium did not respond to multiple attempts to make contact over a period of many weeks. The data was provided to HIBP by dehashed.com.

    Email addresses · Passwords

  • Factual 2.5M accounts
    Added 24 Dec 2019 breached 22 Mar 2017 factual.com

    In March 2017, a file containing 8M rows of data allegedly sourced from data aggregator Factual was compiled and later exchanged on the premise it was a "breach". The data contained 2.5M unique email addresses alongside business names, addresses and phone numbers. After consultation with Factual, they advised the data was "publicly available information about businesses and other points of interest that Factual makes available on its website and to customers".

    Email addresses · Employers · Phone numbers · Physical addresses

  • Zynga 172.9M accounts
    Added 19 Dec 2019 breached 1 Sept 2019 zynga.com

    In September 2019, game developer Zynga (the creator of Words with Friends) suffered a data breach. The incident exposed 173M unique email addresses alongside usernames and passwords stored as salted SHA-1 hashes. The data was provided to HIBP by dehashed.com.

    Email addresses · Passwords · Phone numbers · Usernames

  • Added 4 Dec 2019 breached 24 Sept 2019 agusiq-torrents.pl

    In September 2019, Polish torrent site AgusiQ-Torrents.pl suffered a data breach. The incident exposed 90k member records including email and IP addresses, usernames and passwords stored as MD5 hashes.

    Email addresses · IP addresses · Passwords · Usernames

  • Added 22 Nov 2019 breached 16 Oct 2019

    In October 2019, security researchers Vinny Troia and Bob Diachenko identified an unprotected Elasticsearch server holding 1.2 billion records of personal data. The exposed data included an index indicating it was sourced from data enrichment company People Data Labs (PDL) and contained 622 million unique email addresses. The server was not owned by PDL and it's believed a customer failed to properly secure the database. Exposed information included email addresses, phone numbers, social media profiles and job history data.

    Email addresses · Employers · Geographic locations · Job titles · Names · Phone numbers · Social media profiles

  • GateHub 1.4M accounts
    Added 20 Nov 2019 breached 4 Jun 2019 gatehub.net

    In October 2019, 1.4M accounts from the cryptocurrency wallet service GateHub were posted to a popular hacking forum. GateHub had previously acknowledged a data breach in June, albeit with a smaller number of impacted accounts. Data from the breach included email addresses, mnemonic phrases, encrypted master keys, encrypted recovery keys and passwords stored as bcrypt hashes.

    Email addresses · Encrypted keys · Mnemonic phrases · Passwords

  • EpicBot 817K accounts
    Added 19 Nov 2019 breached 1 Sept 2019 epicbot.com

    In September 2019, the RuneScape bot provider EpicBot suffered a data breach that impacted 817k subscribers. Data from the breach was subsequently shared on a popular hacking forum and included usernames, email and IP addresses and passwords stored as either salted MD5 or bcrypt hashes. EpicBot did not respond when contacted about the incident.

    Email addresses · IP addresses · Passwords · Usernames