Breaches

Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.

1,020 breaches · updated 1 hour ago · data from Have I Been Pwned (CC BY 4.0)

1,020 breaches · page 36 of 51 Fabricated, spam-list and retired breaches are left out.
  • Mappery 205K accounts
    Added 18 Dec 2018 breached 11 Dec 2018 mappery.com

    In December 2018, the mapping website Mappery suffered a data breach that exposed over 205k unique email addresses. The incident also exposed usernames, the geographic location of the user and passwords stored as unsalted SHA-1 hashes. No response was received from Mappery when contacted about the incident.

    Email addresses · Geographic locations · Passwords · Usernames

  • Bombuj.eu 575K accounts
    Added 10 Dec 2018 breached 7 Dec 2018 bombuj.eu

    In December 2018, the Slovak website for watching movies online for free Bombuj.eu suffered a data breach. The incident exposed over 575k unique email addresses and passwords stored as unsalted MD5 hashes. No response was received from Bombuj.eu when contacted about the incident.

    Email addresses · Passwords

  • Hub4Tech 37K accounts
    Added 9 Dec 2018 breached 1 Jan 2017 hub4tech.com

    On an unknown date in approximately 2017, the Indian training and assessment service known as Hub4Tech suffered a data breach via a SQL injection attack. The incident exposed almost 37k unique email addresses and passwords stored as unsalted MD5 hashes. No response was received from Hub4Tech when contacted about the incident.

    Email addresses · Passwords

  • You've Been Scraped 66.1M accounts
    Added 6 Dec 2018 breached 5 Oct 2018

    In October and November 2018, security researcher Bob Diachenko identified several unprotected MongoDB instances believed to be hosted by a data aggregator. Containing a total of over 66M records, the owner of the data couldn't be identified but it is believed to have been scraped from LinkedIn hence the title "You've Been Scraped". The exposed records included names, both work and personal email addresses, job titles and links to the individuals' LinkedIn profiles.

    Email addresses · Employers · Geographic locations · Job titles · Names · Social media profiles

  • AerServ 66K accounts
    Added 6 Dec 2018 breached 1 Apr 2018 aerserv.com

    In April 2018, the ad management platform known as AerServ suffered a data breach. Acquired by InMobi earlier in the year, the AerServ breach impacted over 66k unique email addresses and also included contact information and passwords stored as salted SHA-512 hashes. The data was publicly posted to Twitter later in 2018 after which InMobi was notified and advised they were aware of the incident.

    Email addresses · Employers · Job titles · Names · Passwords · Phone numbers · Physical addresses

  • ForumCommunity 777K accounts
    Added 5 Dec 2018 breached 1 Jun 2016 forumcommunity.net

    In approximately mid-2016, the Italian-based service for creating forums known as ForumCommunity suffered a data breach. The incident impacted over 776k unique email addresses along with usernames and unsalted MD5 password hashes. No response was received from ForumCommunity when contacted.

    Email addresses · Passwords · Usernames

  • Technic 265K accounts
    Added 4 Dec 2018 breached 30 Nov 2018 technicpack.net

    In November 2018, the Minecraft modpack platform known as Technic suffered a data breach. Technic promptly disclosed the breach and advised that the impacted data included over 265k unique users' email and IP addresses, chat logs, private messages and passwords stored as bcrypt hashes with a work factor of 13. Technic self-submitted the breach to HIBP.

    Chat logs · Email addresses · IP addresses · Passwords · Private messages · Time zones

  • Data & Leads 44.3M accounts
    Added 28 Nov 2018 breached 14 Nov 2018 datanleads.com

    In November 2018, security researcher Bob Diachenko identified an unprotected database believed to be hosted by a data aggregator. Upon further investigation, the data was linked to marketing company Data & Leads. The exposed Elasticsearch instance contained over 44M unique email addresses along with names, IP and physical addresses, phone numbers and employment information. No response was received from Data & Leads when contacted by Bob and their site subsequently went offline.

    Email addresses · Employers · IP addresses · Job titles · Names · Phone numbers · Physical addresses

  • Adapt 9.4M accounts
    Added 22 Nov 2018 breached 5 Nov 2018 adapt.io

    In November 2018, security researcher Bob Diachenko identified an unprotected database hosted by data aggregator "Adapt". A provider of "Fresh Quality Contacts", the service exposed over 9.3M unique records of individuals and employer information including their names, employers, job titles, contact information and data relating to the employer including organisation description, size and revenue. No response was received from Adapt when contacted.

    Email addresses · Employers · Job titles · Names · Phone numbers · Physical addresses · Social media profiles

  • HTH Studios 412K accounts
    Added 20 Nov 2018 breached 24 Aug 2018 hthstudios.com sensitive

    In August 2018, the adult furry interactive game creator HTH Studios suffered a data breach impacting multiple repositories of customer data. Several months later, the data surfaced on a popular hacking forum and included 411k unique email addresses along with physical and IP addresses, names, orders, salted SHA-1 and salted MD5 hashes. HTH Studios is aware of the incident.

    Browser user agent details · Dates of birth · Email addresses · IP addresses · Names · Phone numbers · Physical addresses · Purchases · Usernames

  • Added 17 Nov 2018 breached 29 Oct 2018

    In October 2018, security researcher Bob Diachenko identified multiple exposed databases with hundreds of millions of records. One of those datasets was an Elasticsearch instance on AWS containing sales lead data and 5.8M unique email addresses. The data contained information relating to individuals and the companies they worked for including their names, email addresses and company name and contact information. Despite best efforts, it was not possible to identify the owner of the data hence this breach as been titled "Elasticsearch Sales Leads".

    Email addresses · Employers · Names · Physical addresses

  • KnownCircle 2.0M accounts
    Added 17 Nov 2018 breached 12 Apr 2016 knowncircle.com

    In approximately April 2016, the "marketing automation for agents and professional service providers" company KnownCircle had a large volume of data obtained by an external party. The data belonging to the now defunct service appeared in JSON format and contained gigabytes of data related to the real estate and insurance sectors. The personal data in the breach appears to have primarily been used for marketing purposes, including logs of emails sent and tracking of gift cards. A small number of passwords for KnownCircle staff were also present and were stored as bcrypt hashes.

    Email addresses · Email messages · Genders · Names · Passwords · Phone numbers · Physical addresses

  • Rbx.Rocks 150K accounts
    Added 7 Nov 2018 breached 6 Aug 2018 rbx.rocks

    In August 2018, the Roblox trading site Rbx.Rocks suffered a data breach. Almost 25k records were sent to HIBP in November and included names, email addresses and passwords stored as bcrypt hashes. In July 2019, a further 125k records emerged bringing the total size of the incident to 150k. The website has since gone offline with a message stating that "Rbx.Rocks v2.0 is currently under construction".

    Email addresses · Names · Passwords

  • Added 7 Nov 2018 breached 3 Nov 2018 siae.it

    In November 2018, the Società Italiana degli Autori ed Editori (Italian Society of Authors and Publishers, or SIAE) was hacked, defaced and almost 4GB of data leaked publicly via Twitter. The data included over 14k registered users' names, email addresses and passwords.

    Email addresses · IP addresses · Names · Passwords · Phone numbers

  • WPSandbox 858 accounts
    Added 6 Nov 2018 breached 4 Nov 2018 wpsandbox.io

    In November 2018, the WordPress sandboxing service that allows people to create temporary websites WP Sandbox discovered their service was being used to host a phishing site attempting to collect Microsoft OneDrive accounts. After identifying the malicious site, WP Sandbox took it offline, contacted the 858 people who provided information to it then self-submitted their addresses to HIBP. The phishing page requested both email addresses and passwords.

    Email addresses · Passwords

  • JoomlArt 22K accounts
    Added 1 Nov 2018 breached 30 Jan 2018 joomlart.com

    In January 2018, the Joomla template website JoomlArt inadvertently exposed more than 22k unique customer records in a Jira ticket. The exposed data was from iJoomla and JomSocial, both services that JoomlArt acquired the previous year. The data included usernames, email addresses, purchases and passwords stored as MD5 hashes. When contacted, JoomlArt advised they were aware of the incident and had previously notified impacted parties.

    Email addresses · Names · Passwords · Payment histories · Usernames

  • Mac Forums 327K accounts
    Added 29 Oct 2018 breached 3 Jul 2016 mac-forums.com

    In July 2016, the self-proclaimed "Ultimate Source For Your Mac" website Mac Forums suffered a data breach. The vBulletin-based system exposed over 326k usernames, email and IP addresses, dates of birth and passwords stored as salted MD5 hashes. The data was later discovered being traded on a popular hacking forum. Mac Forums did not respond when contacted about the incident via their contact us form.

    Dates of birth · Email addresses · IP addresses · Passwords · Usernames

  • Baby Names 847K accounts
    Added 24 Oct 2018 breached 24 Oct 2008 babynames.com

    In approximately 2008, the site to help parents name their children known as Baby Names suffered a data breach. The incident exposed 846k email addresses and passwords stored as salted MD5 hashes. When contacted in October 2018, Baby Names advised that "the breach happened at least ten years ago" and that members were notified at the time.

    Email addresses · Passwords

  • Wife Lovers 1.3M accounts
    Added 20 Oct 2018 breached 7 Oct 2018 wifelovers.com sensitive

    In October 2018, the site dedicated to posting naked photos and other erotica of wives Wife Lovers suffered a data breach. The underlying database supported a total of 8 different adult websites and contained over 1.2M unique email addresses. Wife Lovers acknowledged the breach which impacted names, usernames, email and IP addresses and passwords hashed using the weak DEScrypt algorithm. The breach has been marked as "sensitive" due to the nature of the site.

    Email addresses · IP addresses · Names · Passwords · Usernames

  • Facepunch 343K accounts
    Added 17 Oct 2018 breached 3 Jun 2016 facepunch.com

    In June 2016, the game development studio Facepunch suffered a data breach that exposed 343k users. The breached data included usernames, email and IP addresses, dates of birth and salted MD5 password hashes. Facepunch advised they were aware of the incident and had notified people at the time. The data was provided to HIBP by whitehat security researcher and data analyst Adam Davies.

    Dates of birth · Email addresses · IP addresses · Passwords · Usernames