Breaches

Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.

1,020 breaches · updated 3 hours ago · data from Have I Been Pwned (CC BY 4.0)

1,020 breaches · page 38 of 51 Fabricated, spam-list and retired breaches are left out.
  • Light's Hope 30K accounts
    Added 4 Jul 2018 breached 25 Jun 2018 lightshope.org

    In June 2018, the World of Warcraft service Light's Hope suffered a data breach which they subsequently self-submitted to HIBP. Over 30K unique users were impacted and their exposed data included email addresses, dates of birth, private messages and passwords stored as bcrypt hashes.

    Dates of birth · Email addresses · Geographic locations · IP addresses · Passwords · Private messages · Usernames

  • Gaadi 4.3M accounts
    Added 1 Jul 2018 breached 14 May 2015 gaadi.com

    In May 2015, the Indian motoring website known as Gaadi had 4.3 million records exposed in a data breach. The data contained usernames, email and IP addresses, genders, the city of users as well as passwords stored in both plain text and as MD5 hashes. The site was previously reported as compromised on the Vigilante.pw breached database directory.

    Email addresses · Genders · Geographic locations · IP addresses · Names · Passwords · Phone numbers · Usernames

  • Added 11 Jun 2018 breached 7 Jun 2018

    In June 2018, the Cybercrime Bureau of the Estonian Central Criminal Police contacted HIBP and asked for assistance in making a data set of 655k email addresses searchable. The Estonian police suspected the email addresses and passwords they obtained were being used to access mailboxes, cryptocurrency exchanges, cloud service accounts and other similar online assets. They've requested that individuals who find themselves in the data set and also identify that cryptocurrency has been stolen contact them at cybercrime@politsei.ee.

    Email addresses · Passwords

  • Creative 483K accounts
    Added 7 Jun 2018 breached 1 May 2018 creative.com

    In May 2018, the forum for Singaporean hardware company Creative Technology suffered a data breach which resulted in the disclosure of 483k unique email addresses. Running on an old version of vBulletin, the breach also disclosed usernames, IP addresses and salted MD5 password hashes. After being notified of the incident, Creative permanently shut down the forum.

    Email addresses · IP addresses · Passwords · Usernames

  • Linux Forums 276K accounts
    Added 7 Jun 2018 breached 1 May 2018 linuxforums.org

    In May 2018, the Linux Forums website suffered a data breach which resulted in the disclosure of 276k unique email addresses. Running on an old version of vBulletin, the breach also disclosed usernames, IP addresses and salted MD5 password hashes. Linux Forums did not respond to multiple attempts to contact them about the breach.

    Email addresses · IP addresses · Passwords · Usernames

  • Ticketfly 26.2M accounts
    Added 3 Jun 2018 breached 31 May 2018 ticketfly.com

    In May 2018, the website for the ticket distribution service Ticketfly was defaced by an attacker and was subsequently taken offline. The attacker allegedly requested a ransom to share details of the vulnerability with Ticketfly but did not receive a reply and subsequently posted the breached data online to a publicly accessible location. The data included over 26 million unique email addresses along with names, physical addresses and phone numbers. Whilst there were no passwords in the publicly leaked data, Ticketfly later issued an incident update and stated that "It is possible, however, that hashed values of password credentials could have been accessed".

    Email addresses · Names · Phone numbers · Physical addresses

  • ViewFines 778K accounts
    Added 24 May 2018 breached 7 May 2018 viewfines.co.za

    In May 2018, the South African website for viewing traffic fines online known as ViewFines suffered a data breach. Over 934k records containing 778k unique email addresses were exposed and included names, phone numbers, government issued IDs and passwords stored in plain text.

    Email addresses · Government issued IDs · Names · Passwords · Phone numbers

  • VNG 24.9M accounts
    Added 28 Apr 2018 breached 19 May 2015 zing.vn

    In April 2018, news broke of a massive data breach impacting the Vietnamese company known as VNG after data was discovered being traded on a popular hacking forum where it was extensively redistributed. The breach dated back to an incident in May of 2015 and included of over 163 million customers. The data in the breach contained a wide range of personal attributes including usernames, birth dates, genders and home addresses along with unsalted MD5 hashes and 25 million unique email addresses. The data was provided to HIBP by dehashed.com.

    Dates of birth · Email addresses · Genders · IP addresses · Marital statuses · Names · Occupations · Passwords · Phone numbers · Physical addresses · Usernames

  • 17173 7.5M accounts
    Added 28 Apr 2018 breached 28 Dec 2011 17173.com unverified

    In late 2011, a series of data breaches in China affected up to 100 million users, including 7.5 million from the gaming site known as 17173. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains usernames, email addresses and salted MD5 password hashes and was provided with support from dehashed.com. Read more about Chinese data breaches in Have I Been Pwned.

    Email addresses · Passwords · Usernames

  • TGBUS 10.4M accounts
    Added 28 Apr 2018 breached 1 Sept 2017 tgbus.com unverified

    In approximately 2017, it's alleged that the Chinese gaming site known as TGBUS suffered a data breach that impacted over 10 million unique subscribers. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains usernames, email addresses and salted MD5 password hashes and was provided with support from dehashed.com. Read more about Chinese data breaches in Have I Been Pwned.

    Email addresses · Passwords · Usernames

  • ILikeCheats 189K accounts
    Added 22 Apr 2018 breached 18 Oct 2014 ilikecheats.net

    In October 2014, the game cheats website known as ILikeCheats suffered a data breach that exposed 189k accounts. The vBulletin based forum leaked usernames, IP and email addresses and weak MD5 hashes of passwords. The data was provided with support from dehashed.com.

    Email addresses · IP addresses · Passwords · Usernames

  • CashCrate 6.8M accounts
    Added 20 Apr 2018 breached 17 Nov 2016 cashcrate.com

    In June 2017, news broke that CashCrate had suffered a data breach exposing 6.8 million records. The breach of the cash-for-surveys site dated back to November 2016 and exposed names, physical addresses, email addresses and passwords stored in plain text for older accounts along with weak MD5 hashes for newer ones.

    Email addresses · Names · Passwords · Physical addresses

  • Taringa 28.0M accounts
    Added 19 Apr 2018 breached 1 Aug 2017 taringa.net

    In September 2017, news broke that Taringa had suffered a data breach exposing 28 million records. Known as "The Latin American Reddit", Taringa's breach disclosure notice indicated the incident dated back to August that year. The exposed data included usernames, email addresses and weak MD5 hashes of passwords.

    Email addresses · Passwords · Usernames

  • Smogon 386K accounts
    Added 11 Apr 2018 breached 10 Sept 2017 smogon.com

    In April 2018, the Pokémon website known as Smogon announced they'd suffered a data breach. The breach dated back to September 2017 and affected their XenForo based forum. The exposed data included usernames, email addresses, genders and both bcrypt and MD5 password hashes.

    Email addresses · Genders · Geographic locations · Passwords · Usernames · Website activity

  • HiAPK 13.9M accounts
    Added 1 Apr 2018 breached 1 Jan 2014 hiapk.com unverified

    In approximately 2014, it's alleged that the Chinese Android store known as HIAPK suffered a data breach that impacted 13.8 million unique subscribers. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains usernames, email addresses and salted MD5 password hashes and was provided to HIBP by white hat security researcher and data analyst Adam Davies. Read more about Chinese data breaches in Have I Been Pwned.

    Email addresses · Passwords · Usernames

  • Added 29 Mar 2018 breached 19 Mar 2018 bestialitysextaboo.com sensitive

    In March 2018, the animal bestiality website known as Bestialitysextaboo was hacked. A collection of various sites running on the same service were also compromised and details of the hack (including links to the data) were posted on a popular forum. In all, more than 3.2k unique email addresses were included alongside usernames, IP addresses, dates of birth, genders and bcrypt hashes of passwords.

    Dates of birth · Email addresses · Genders · Geographic locations · IP addresses · Passwords · Private messages · Usernames

  • MDPI 845K accounts
    Added 25 Mar 2018 breached 30 Aug 2016 mdpi.com

    In August 2016, the Swiss scholarly open access publisher known as MDPI had 17.5GB of data obtained from an unprotected Mongo DB instance. The data contained email exchanges between MDPI and their authors and reviewers which included 845k unique email addresses. MDPI have confirmed that the system has since been protected and that no data of a sensitive nature was impacted. As such, they concluded that notification to their subscribers was not necessary due to the fact that all their authors and reviewers are available online on their website.

    Email addresses · Email messages · IP addresses · Names

  • Added 18 Mar 2018 breached 12 Feb 2018 flvs.net sensitive

    In March 2018, the Florida Virtual School (FLVS) posted a data breach notification to their website. The school had identified a data breach which had occurred sometime between 6 May 2016 and 12 Feb 2018 and an XML file containing 368k student records was subsequently found circulating. Each record contained student name, date of birth, password, grade, email and parent email resulting in a total of 543k unique email addresses. Due to the prevalence of email addresses belonging to individuals who are still legally children, the data breach has been flagged as "sensitive".

    Dates of birth · Email addresses · Names · Passwords · School grades (class levels) · Usernames

  • MangaFox.me 1.3M accounts
    Added 17 Mar 2018 breached 1 Jun 2016 mangafox.me

    In approximately July 2016, the manga website known as mangafox.me suffered a data breach. The vBulletin based forum exposed 1.3 million accounts including usernames, email and IP addresses, dates of birth and salted MD5 password hashes.

    Dates of birth · Email addresses · IP addresses · Passwords · Usernames

  • xHamster 377K accounts
    Added 8 Mar 2018 breached 28 Nov 2016 xhamster.com sensitive

    In November 2016, news broke that hackers were trading hundreds of thousands of xHamster porn account details. In total, the data contained almost 380k unique user records including email addresses, usernames and unsalted MD5 password hashes.

    Email addresses · Passwords · Usernames