Breaches

Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.

1,020 breaches · updated 2 hours ago · data from Have I Been Pwned (CC BY 4.0)

1,020 breaches · page 37 of 51 Fabricated, spam-list and retired breaches are left out.
  • Apollo 125.9M accounts
    Added 5 Oct 2018 breached 23 Jul 2018 apollo.io

    In July 2018, the sales engagement startup Apollo left a database containing billions of data points publicly exposed without a password. The data was discovered by security researcher Vinny Troia who subsequently sent a subset of the data containing 126 million unique email addresses to Have I Been Pwned. The data left exposed by Apollo was used in their "revenue acceleration platform" and included personal information such as names and email addresses as well as professional information including places of employment, the roles people hold and where they're located. Apollo stressed that the exposed data did not include sensitive information such as passwords, social security numbers or financial data. The Apollo website has a contact form for those looking to get in touch with the organisation.

    Email addresses · Employers · Geographic locations · Job titles · Names · Phone numbers · Salutations · Social media profiles

  • Real Estate Mogul 308K accounts
    Added 24 Sept 2018 breached 6 Sept 2016 realestatemogul.com

    In September 2016, the real estate investment site Real Estate Mogul had a Mongo DB instance compromised and 5GB of data downloaded by an unauthorised party. The data contained real estate listings including addresses and the names, phone numbers and 308k unique email addresses of the sellers. Real Estate Mogul was advised of the incident in September 2018 and stated that they "found no instance of user account credentials like usernames and passwords nor billing information within this file".

    Email addresses · Names · Phone numbers · Physical addresses

  • Added 13 Sept 2018 breached 11 Sept 2018 unverified

    In September 2018, a collection of almost 42 million email address and plain text password pairs was uploaded to the anonymous file sharing service kayo.moe. The operator of the service contacted HIBP to report the data which, upon further investigation, turned out to be a large credential stuffing list. For more information, read about The 42M Record kayo.moe Credential Stuffing Data.

    Email addresses · Passwords

  • Russian America 183K accounts
    Added 13 Sept 2018 breached 1 Jan 2017 russianamerica.com

    In approximately 2017, the website for Russian speakers in America known as Russian America suffered a data breach. The incident exposed 183k unique records including names, email addresses, phone numbers and passwords stored in both plain text and as MD5 hashes. Russian America was contacted about the breach but did not respond.

    Email addresses · Names · Passwords · Phone numbers

  • FreshMenu 110K accounts
    Added 10 Sept 2018 breached 1 Jul 2016 freshmenu.com

    In July 2016, the India-based food delivery service FreshMenu suffered a data breach. The incident exposed the personal data of over 110k customers and included their names, email addresses, phone numbers, home addresses and order histories. When advised of the incident, FreshMenu acknowledged being already aware of the breach but stated they had decided not to notify impacted customers.

    Device information · Email addresses · Names · Phone numbers · Physical addresses · Purchases

  • NapsGear 287K accounts
    Added 10 Sept 2018 breached 21 Oct 2015 napsgear.org sensitive

    In October 2015, the anabolic steroids retailer NapsGear suffered a data breach. An extensive amount of personal information on 287k customers was exposed including email addresses, names, addresses, phone numbers, purchase histories and salted MD5 password hashes.

    Dates of birth · Email addresses · Genders · Names · Passwords · Phone numbers · Physical addresses · Purchases

  • Warmane 1.1M accounts
    Added 8 Sept 2018 breached 1 Dec 2016 warmane.com

    In approximately December 2016, the online service for World of Warcraft private servers Warmane suffered a data breach. The incident exposed over 1.1M accounts including usernames, email addresses, dates of birth and salted MD5 password hashes. The data was subsequently extensively circulated online and was later provided to HIBP by whitehat security researcher and data analyst Adam Davies.

    Dates of birth · Email addresses · Passwords · Usernames

  • Mortal Online 607K accounts
    Added 31 Aug 2018 breached 17 Jun 2018 mortalonline.com

    In June 2018, the massively multiplayer online role-playing game (MMORPG) Mortal Online suffered a data breach. A file containing 570k email addresses and cracked passwords was subsequently distributed online. A larger more complete file containing 607k email addresses with original unsalted MD5 password hashes along with names, usernames and physical addresses was later provided and the original breach in HIBP was updated accordingly. The data was provided to HIBP by whitehat security researcher and data analyst Adam Davies.

    Email addresses · Names · Passwords · Physical addresses · Usernames

  • SvenskaMagic 30K accounts
    Added 30 Aug 2018 breached 1 Jul 2015 svenskamagic.com

    Sometime in 2015, the Swedish magic website SvenskaMagic suffered a data breach that exposed over 30k records. The compromised data included usernames, email addresses and MD5 password hashes. The data was self-submitted to HIBP by SvenskaMagic.

    Email addresses · Passwords · Usernames

  • Atlas Quantum 261K accounts
    Added 27 Aug 2018 breached 25 Aug 2018 atlasquantum.com

    In August 2018, the cryptocurrency investment platform Atlas Quantum suffered a data breach. The breach leaked the personal data of 261k investors on the platform including their names, phone numbers, email addresses and account balances.

    Account balances · Email addresses · Names · Phone numbers

  • SpyFone 44K accounts
    Added 24 Aug 2018 breached 16 Aug 2018 spyfone.com sensitive

    In August 2018, the spyware company SpyFone left terabytes of data publicly exposed. Collected surreptitiously whilst the targets were using their devices, the data included photos, audio recordings, text messages and browsing history which were then exposed via a number of misconfigurations within SpyFone's systems. The data belonged the thousands of SpyFone customers and included 44k unique email addresses, many likely belonging to people the targeted phones had contact with.

    Audio recordings · Browsing histories · Device information · Email addresses · Geographic locations · IMEI numbers · IP addresses · Names · Passwords · Photos · SMS messages

  • MyFHA 973K accounts
    Added 9 Aug 2018 breached 18 Feb 2015 myfha.net

    In approximately February 2015, the home financing website MyFHA suffered a data breach which disclosed the personal information of nearly 1 million people. The data included extensive personal information relating to home financing including personal contact info, credit statuses, household incomes, loan amounts and notes on personal circumstances, often referring to legal issues, divorces and health conditions. Multiple parties contacted HIBP with the data after which MyFHA was alerted in mid-July and acknowledged the legitimacy of the breach then took the site offline.

    Credit status information · Email addresses · Income levels · IP addresses · Loan information · Names · Passwords · Personal descriptions · Physical addresses

  • Lanwar 45K accounts
    Added 8 Aug 2018 breached 28 Jul 2018 lanwar.com

    In July 2018, staff of the Lanwar gaming site discovered a data breach they believe dates back to sometime over the previous several months. The data contained 45k names, email addresses, usernames and plain text passwords. A Lanwar staff member self-submitted the breach to HIBP and has also contacted the relevant authorities about the incident after identifying a phishing attempt to extort Bitcoin from a user.

    Email addresses · Names · Passwords · Physical addresses · Usernames

  • Added 6 Aug 2018 breached 30 May 2018 adult-fanfiction.org sensitive

    In May 2018, the website for sharing adult-orientated works of fiction known as Adult-FanFiction.Org had 186k records exposed in a data breach. The data contained names, email addresses, dates of birth and passwords stored as both MD5 hashes and plain text. AFF did not respond when contacted about the breach and the site was previously reported as compromised on the Vigilante.pw breached database directory.

    Dates of birth · Email addresses · Names · Passwords

  • Fashion Nexus 1.3M accounts
    Added 31 Jul 2018 breached 9 Jul 2018 fashionnexus.co.uk

    In July 2018, UK-based ecommerce company Fashion Nexus suffered a data breach which exposed 1.4 million records. Multiple websites developed by sister company White Room Solutions were impacted in the breach amongst which were sites including Jaded London and AX Paris. The various sites exposed in the incident included a range of different data types including names, phone numbers, addresses and passwords stored as a mix of salted MD5 and SHA-1 as well as unsalted MD5 passwords. When asked by reporter Graham Cluley if a public statement on the incident was available, a one-word response of "No" was received.

    Browser user agent details · Dates of birth · Email addresses · Genders · IP addresses · Names · Passwords · Phone numbers · Physical addresses · Purchases

  • League of Legends 339K accounts
    Added 28 Jul 2018 breached 11 Jun 2012 leagueoflegends.com

    In June 2012, the multiplayer online game League of Legends suffered a data breach. At the time, the service had more than 32 million registered accounts and the breach affected various personal data attributes including "encrypted" passwords. In 2018, a 339k record subset of the data emerged with email addresses, usernames and plain text passwords, likely cracked from the original cryptographically protected ones.

    Email addresses · Passwords · Usernames

  • Exactis 131.6M accounts
    Added 25 Jul 2018 breached 1 Jun 2018 exactis.com

    In June 2018, the marketing firm Exactis inadvertently publicly leaked 340 million records of personal data. Security researcher Vinny Troia of Night Lion Security discovered the leak contained multiple terabytes of personal information spread across hundreds of separate fields including addresses, phone numbers, family structures and extensive profiling data. The data was collected as part of Exactis' service as a "compiler and aggregator of premium business & consumer data" which they then sell for profiling and marketing purposes. A small subset of the exposed fields were provided to Have I Been Pwned and contained 132 million unique email addresses.

    Credit status information · Dates of birth · Education levels · Email addresses · Ethnicities · Family structure · Financial investments · Genders · Home ownership statuses · Income levels · IP addresses · Marital statuses · Names · Net worths · Occupations · Personal interests · Phone numbers · Physical addresses · Religions · Spoken languages

  • Funny Games 764K accounts
    Added 24 Jul 2018 breached 28 Apr 2018 funny-games.biz

    In April 2018, the online entertainment site Funny Games suffered a data breach that disclosed 764k records including usernames, email and IP addresses and salted MD5 password hashes. The incident was disclosed to Funny Games in July who acknowledged the breach and identified it had been caused by legacy code no longer in use. The record count in the breach constitute approximately half of the user base.

    Email addresses · IP addresses · Passwords · Usernames

  • Pemiblanc 111.0M accounts
    Added 9 Jul 2018 breached 2 Apr 2018 pemiblanc.com unverified

    In April 2018, a credential stuffing list containing 111 million email addresses and passwords known as Pemiblanc was discovered on a French server. The list contained email addresses and passwords collated from different data breaches and used to mount account takeover attacks against other services. Read more about the incident.

    Email addresses · Passwords

  • Yatra 5.0M accounts
    Added 4 Jul 2018 breached 1 Sept 2013 yatra.com

    In September 2013, the Indian bookings website known as Yatra had 5 million records exposed in a data breach. The data contained email and physical addresses, dates of birth and phone numbers along with both PINs and passwords stored in plain text. The site was previously reported as compromised on the Vigilante.pw breached database directory.

    Dates of birth · Email addresses · Names · Passwords · Phone numbers · Physical addresses · PINs