Breaches

Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.

1,020 breaches · updated 5 hours ago · data from Have I Been Pwned (CC BY 4.0)

1,020 breaches · page 40 of 51 Fabricated, spam-list and retired breaches are left out.
  • Added 9 Nov 2017 breached 8 Feb 2014 unverified

    In 2014, a file allegedly containing data hacked from Coupon Mom was created and included 11 million email addresses and plain text passwords. On further investigation, the file was also found to contain data indicating it had been sourced from Armor Games. Subsequent verification with HIBP subscribers confirmed the passwords had previously been used and many subscribers had used either Coupon Mom or Armor Games in the past. On disclosure to both organisations, each found that the data did not represent their entire customer base and possibly includes records from other sources with common subscribers. The breach has subsequently been flagged as "unverified" as the source cannot be emphatically proven. In July 2020, the data was also found to contain BeerAdvocate accounts sourced from a previously unknown breach.

    Email addresses · Passwords

  • CafeMom 2.6M accounts
    Added 9 Nov 2017 breached 10 Apr 2014 cafemom.com

    In 2014, the social network for mothers CafeMom suffered a data breach. The data surfaced alongside a number of other historical breaches including Kickstarter, Bitly and Disqus and contained 2.6 million email addresses and plain text passwords.

    Email addresses · Passwords

  • JobStreet 3.9M accounts
    Added 30 Oct 2017 breached 7 Mar 2012 jobstreet.com

    In October 2017, the Malaysian website lowyat.net ran a story on a massive set of breached data affecting millions of Malaysians after someone posted it for sale on their forums. The data spanned multiple separate breaches including the JobStreet jobs website which contained almost 4 million unique email addresses. The dates in the breach indicate the incident occurred in March 2012. The data later appeared freely downloadable on a Tor hidden service and contained extensive information on job seekers including names, genders, birth dates, phone numbers, physical addresses and passwords.

    Dates of birth · Email addresses · Genders · Geographic locations · Government issued IDs · Marital statuses · Names · Nationalities · Passwords · Phone numbers · Physical addresses · Usernames

  • Shotbow 1.1M accounts
    Added 29 Oct 2017 breached 9 May 2016 shotbow.net

    In May 2016, the multiplayer server for Minecraft service Shotbow announced they'd suffered a data breach. The incident resulted in the exposure of over 1 million unique email addresses, usernames and salted SHA-256 password hashes.

    Email addresses · Passwords · Usernames

  • Master Deeds 2.3M accounts
    Added 18 Oct 2017 breached 14 Mar 2017

    In March 2017, a 27GB database backup file named "Master Deeds" was sent to HIBP by a supporter of the project. Upon detailed analysis later that year, the file was found to contain the personal data of tens of millions of living and deceased South African residents. The data included extensive personal attributes such as names, addresses, ethnicities, genders, birth dates, government issued personal identification numbers and 2.2 million email addresses. At the time of publishing, it's alleged the data was sourced from Dracore Data Sciences (Dracore is yet to publicly confirm or deny the data was sourced from their systems). On 18 October 2017, the file was found to have been published to a publicly accessible web server where it was located at the root of an IP address with directory listing enabled. The file was dated 8 April 2015.

    Dates of birth · Deceased statuses · Email addresses · Employers · Ethnicities · Genders · Government issued IDs · Home ownership statuses · Job titles · Names · Nationalities · Phone numbers · Physical addresses

  • We Heart It 8.6M accounts
    Added 14 Oct 2017 breached 3 Nov 2013 weheartit.com

    In November 2013, the image-based social network We Heart It suffered a data breach. The incident wasn't discovered until October 2017 when 8.6 million user records were sent to HIBP. The data contained user names, email addresses and password hashes, 80% of which were salted SHA-256 with the remainder being MD5 with no salt.

    Email addresses · Passwords · Usernames

  • diet.com 1.4M accounts
    Added 13 Oct 2017 breached 10 Aug 2014 diet.com

    In August 2014, the diet and nutrition website diet.com suffered a data breach resulting in the exposure of 1.4 million unique user records dating back as far as 2004. The data contained email and IP addresses, usernames, plain text passwords and dietary information about the site members including eating habits, BMI and birth date. The site was previously reported as compromised on the Vigilante.pw breached database directory.

    Dates of birth · Eating habits · Email addresses · IP addresses · Names · Passwords · Physical attributes · Usernames

  • Victory Phones 166K accounts
    Added 11 Oct 2017 breached 1 Jan 2017 victoryphones.com

    In January 2017, the automated telephony services company Victory Phones left a Mongo DB database publicly facing without a password. Subsequently, 213GB of data was downloaded by an unauthorised party including names, addresses, phone numbers and over 166k unique email addresses.

    Dates of birth · Email addresses · IP addresses · Names · Phone numbers · Physical addresses

  • AbuseWith.Us 1.4M accounts
    Added 9 Oct 2017 breached 1 Jul 2016 abusewith.us

    In 2016, the site dedicated to helping people hack email and online gaming accounts known as Abusewith.us suffered multiple data breaches. The site allegedly had an administrator in common with the nefarious LeakedSource site, both of which have since been shut down. The exposed data included more than 1.3 million unique email addresses, often accompanied by usernames, IP addresses and plain text or hashed passwords retrieved from various sources and intended to be used to compromise the victims' accounts.

    Email addresses · IP addresses · Passwords · Usernames

  • Disqus 17.6M accounts
    Added 6 Oct 2017 breached 1 Jul 2012 disqus.com

    In October 2017, the blog commenting service Disqus announced they'd suffered a data breach. The breach dated back to July 2012 but wasn't identified until years later when the data finally surfaced. The breach contained over 17.5 million unique email addresses and usernames. Users who created logins on Disqus had salted SHA1 hashes of passwords whilst users who logged in via social providers only had references to those accounts.

    Email addresses · Passwords · Usernames

  • Kickstarter 5.2M accounts
    Added 6 Oct 2017 breached 16 Feb 2014 kickstarter.com

    In February 2014, the crowdfunding platform Kickstarter announced they'd suffered a data breach. The breach contained almost 5.2 million unique email addresses, usernames and salted SHA1 hashes of passwords.

    Email addresses · Passwords

  • Bitly 9.3M accounts
    Added 6 Oct 2017 breached 8 May 2014 bitly.com

    In May 2014, the link management company Bitly announced they'd suffered a data breach. The breach contained over 9.3 million unique email addresses, usernames and hashed passwords, most using SHA1 with a small number using bcrypt.

    Email addresses · Passwords · Usernames

  • ReverbNation 7.0M accounts
    Added 5 Oct 2017 breached 1 Jan 2014 reverbnation.com

    In January 2014, the online service for assisting musicians to build their careers ReverbNation suffered a data breach which wasn't identified until September the following year. The breach contained over 7 million accounts with unique email addresses and salted SHA1 passwords.

    Email addresses · Passwords

  • Staminus 27K accounts
    Added 5 Oct 2017 breached 11 Mar 2016 staminus.net

    In March 2016, the DDoS protection service Staminus was "massively hacked" resulting in an outage of more than 20 hours and the disclosure of customer credentials (with unsalted MD5 hashes), support tickets, credit card numbers and other sensitive data. 27k unique email addresses were found in the data which was subsequently released to the public. Staminus is no longer in operation.

    Credit cards · Email addresses · IP addresses · Passwords · Support tickets · Usernames

  • AKP Emails 917K accounts
    Added 1 Oct 2017 breached 19 Jul 2016 akparti.org.tr

    In July 2016, a hacker known as Phineas Fisher hacked Turkey's ruling party (Justice and Development Party or "AKP") and gained access to 300k emails. The full contents of the emails were subsequently published by WikiLeaks and made searchable. HIBP identified over 917k unique email address patterns in the data set, including message IDs and a number of other non-user addresses.

    Email addresses · Email messages

  • 7k7k 9.1M accounts
    Added 26 Sept 2017 breached 1 Jan 2011 7k7k.com unverified

    In approximately 2011, it's alleged that the Chinese gaming site known as 7k7k suffered a data breach that impacted 9.1 million subscribers. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains usernames, email addresses and plain text passwords. Read more about Chinese data breaches in Have I Been Pwned.

    Email addresses · Passwords · Usernames

  • Zomato 16.5M accounts
    Added 4 Sept 2017 breached 17 May 2017 zomato.com

    In May 2017, the restaurant guide website Zomato was hacked resulting in the exposure of almost 17 million accounts. The data was consequently redistributed online and contains email addresses, usernames and salted MD5 hashes of passwords (the password hash was not present on all accounts). This data was provided to HIBP by whitehat security researcher and data analyst Adam Davies.

    Email addresses · Passwords · Usernames

  • MALL.cz 735K accounts
    Added 4 Sept 2017 breached 27 Jul 2017 mall.cz

    In July 2017, the Czech Republic e-commerce site MALL.cz suffered a data breach after which 735k unique accounts including email addresses, names, phone numbers and passwords were later posted online. Whilst passwords were stored as hashes, a number of different algorithms of varying strength were used over time. All passwords included in the publicly distributed data were in plain text and were likely just those that had been successfully cracked (members with strong passwords don't appear to be included). According to MALL.cz, the breach only impacted accounts created before 2015.

    Email addresses · Names · Passwords · Phone numbers

  • Biohack.me 3K accounts
    Added 23 Aug 2017 breached 2 Dec 2016 biohack.me

    In December 2016, the forum for the biohacking website Biohack.me suffered a data breach that exposed 3.4k accounts. The data included usernames, email addresses and hashed passwords along with the private messages of forum members. The data was self-submitted to HIBP by the Biohack.me operators.

    Email addresses · Passwords · Private messages · Usernames

  • Bin Weevils 1.3M accounts
    Added 18 Aug 2017 breached 1 Sept 2014 binweevils.com

    In September 2014, the online game Bin Weevils suffered a data breach. Whilst originally stating that only usernames and passwords had been exposed, a subsequent story on DataBreaches.net indicated that a more extensive set of personal attributes were impacted (comments there also suggest the data may have come from a later breach). Data matching that pattern was later provided to Have I Been Pwned by @akshayindia6 and included almost 1.3m unique email addresses, genders, ages and plain text passwords.

    Ages · Email addresses · Genders · IP addresses · Passwords · Usernames