Breaches

Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.

1,020 breaches · updated 6 hours ago · data from Have I Been Pwned (CC BY 4.0)

1,020 breaches · page 41 of 51 Fabricated, spam-list and retired breaches are left out.
  • Dailymotion 85.2M accounts
    Added 7 Aug 2017 breached 20 Oct 2016 dailymotion.com

    In October 2016, the video sharing platform Dailymotion suffered a data breach. The attack led to the exposure of more than 85 million user accounts and included email addresses, usernames and bcrypt hashes of passwords.

    Email addresses · Passwords · Usernames

  • MCBans 120K accounts
    Added 23 Jul 2017 breached 27 Oct 2016 mcbans.com

    In October 2016, the Minecraft banning service known as MCBans suffered a data breach resulting in the exposure of 120k unique user records. The data contained email and IP addresses, usernames and password hashes of unknown format. The site was previously reported as compromised on the Vigilante.pw breached database directory.

    Email addresses · IP addresses · Passwords · Usernames · Website activity

  • Evermotion 436K accounts
    Added 2 Jul 2017 breached 7 May 2015 evermotion.org

    In May 2015, the Polish 3D modelling website known as Evermotion suffered a data breach resulting in the exposure of 435k unique user records. The data was sourced from a vBulletin forum and contained email addresses, usernames, dates of birth and salted MD5 hashes of passwords. The site was previously reported as compromised on the Vigilante.pw breached database directory.

    Dates of birth · Email addresses · Passwords · Usernames

  • Programming Forums 707K accounts
    Added 1 Jul 2017 breached 1 Dec 2015 programmingforums.org

    In approximately late 2015, the programming forum at programmingforums.org suffered a data breach resulting in the exposure of 707k unique user records. The data contained email and IP addresses, usernames and salted MD5 hashes of passwords. The site was previously reported as compromised on the Vigilante.pw breached database directory.

    Email addresses · IP addresses · Passwords · Usernames

  • Powerbot 504K accounts
    Added 1 Jul 2017 breached 1 Sept 2014 powerbot.org

    In approximately September 2014, the RuneScape bot website Powerbot suffered a data breach resulting in the exposure of over half a million unique user records. The data contained email and IP addresses, usernames and salted MD5 hashes of passwords. The site was previously reported as compromised on the Vigilante.pw breached database directory.

    Email addresses · IP addresses · Passwords · Usernames

  • XPG 890K accounts
    Added 1 Jul 2017 breached 1 Jan 2016 xpgamesaves.com

    In approximately early 2016, the gaming website Xpgamesaves (XPG) suffered a data breach resulting in the exposure of 890k unique user records. The data contained email and IP addresses, usernames and salted MD5 hashes of passwords. The site was previously reported as compromised on the Vigilante.pw breached database directory. This data was provided by security researcher and data analyst, Adam Davies.

    Email addresses · IP addresses · Passwords · Usernames

  • Coachella 600K accounts
    Added 27 Jun 2017 breached 22 Feb 2017 coachella.com

    In February 2017, hundreds of thousands of records from the Coachella music festival were discovered being sold online. Allegedly taken from a combination of the main Coachella website and their vBulletin-based message board, the data included almost 600k usernames, IP and email addresses and salted hashes of passwords (MD5 in the case of the message board).

    Email addresses · IP addresses · Passwords · Usernames

  • Exposed VINs 397K accounts
    Added 9 Jun 2017 breached 5 Jun 2017 unverified

    In June 2017, an unsecured database with more than 10 million VINs (vehicle identification numbers) was discovered by researchers. Believed to be sourced from US car dealerships, the data included a raft of personal information and vehicle data along with 397k unique email addresses.

    Dates of birth · Email addresses · Family structure · Genders · Names · Phone numbers · Physical addresses · Vehicle details

  • Added 8 Jun 2017 breached 23 Dec 2016 unverified

    In December 2016, more than 200 million "data enrichment profiles" were found for sale on the darknet. The seller claimed the data was sourced from Experian and whilst that claim was rejected by the company, the data itself was found to be legitimate suggesting it may have been sourced from other legitimate locations. In total, there were more than 8 million unique email addresses in the data which also contained a raft of other personal attributes including credit ratings, home ownership status, family structure and other fields described in the story linked to above. The email addresses alone were provided to HIBP.

    Buying preferences · Charitable donations · Credit status information · Dates of birth · Email addresses · Family structure · Financial investments · Home ownership statuses · Income levels · Job titles · Marital statuses · Names · Net worths · Phone numbers · Physical addresses · Political donations

  • Abandonia (2015) 776K accounts
    Added 5 Jun 2017 breached 1 Nov 2015 abandonia.com

    In November 2015, the gaming website dedicated to classic DOS games Abandonia suffered a data breach resulting in the exposure of 776k unique user records. The data contained email and IP addresses, usernames and salted MD5 hashes of passwords.

    Email addresses · IP addresses · Passwords · Usernames

  • Edmodo 43.4M accounts
    Added 1 Jun 2017 breached 11 May 2017 edmodo.com

    In May 2017, the education platform Edmodo was hacked resulting in the exposure of 77 million records comprised of over 43 million unique customer email addresses. The data was consequently published to a popular hacking forum and made freely available. The records in the breach included usernames, email addresses and bcrypt hashes of passwords.

    Email addresses · Passwords · Usernames

  • DaFont 637K accounts
    Added 18 May 2017 breached 16 May 2017 dafont.com

    In May 2017, font sharing site DaFont suffered a data breach resulting in the exposure of 637k records. Allegedly due to a SQL injection vulnerability exploited by multiple parties, the exposed data included usernames, email addresses and passwords stored as MD5 without a salt.

    Email addresses · Passwords · Usernames

  • Bell (2017 breach) 2.2M accounts
    Added 16 May 2017 breached 15 May 2017 bell.ca

    In May 2017, the Bell telecommunications company in Canada suffered a data breach resulting in the exposure of millions of customer records. The data was consequently leaked online with a message from the attacker stating that they were "releasing a significant portion of Bell.ca's data due to the fact that they have failed to cooperate with us" and included a threat to leak more. The impacted data included over 2 million unique email addresses and 153k survey results dating back to 2011 and 2012. There were also 162 Bell employee records with more comprehensive personal data including names, phone numbers and plain text "passcodes". Bell suffered another breach in 2014 which exposed 40k records.

    Email addresses · Geographic locations · IP addresses · Job titles · Names · Passwords · Phone numbers · Spoken languages · Survey results · Usernames

  • Exploit.In 593.4M accounts
    Added 6 May 2017 breached 13 Oct 2016 unverified

    In late 2016, a huge list of email address and password pairs appeared in a "combo list" referred to as "Exploit.In". The list contained 593 million unique email addresses, many with multiple different passwords hacked from various online systems. The list was broadly circulated and used for "credential stuffing", that is attackers employ it in an attempt to identify other online systems where the account owner had reused their password. For detailed background on this incident, read Password reuse, credential stuffing and another billion records in Have I Been Pwned.

    Email addresses · Passwords

  • Anti Public Combo List 458.0M accounts
    Added 4 May 2017 breached 16 Dec 2016 unverified

    In December 2016, a huge list of email address and password pairs appeared in a "combo list" referred to as "Anti Public". The list contained 458 million unique email addresses, many with multiple different passwords hacked from various online systems. The list was broadly circulated and used for "credential stuffing", that is attackers employ it in an attempt to identify other online systems where the account owner had reused their password. For detailed background on this incident, read Password reuse, credential stuffing and another billion records in Have I Been Pwned.

    Email addresses · Passwords

  • Retina-X 71K accounts
    Added 30 Apr 2017 breached 23 Feb 2017 retinax.com sensitive

    In February 2017, the mobile device monitoring software developer Retina-X was hacked and customer data downloaded before being wiped from their servers. The incident was covered in the Motherboard article titled Inside the 'Stalkerware' Surveillance Market, Where Ordinary People Tap Each Other's Phones. The service, used to monitor mobile devices, had 71k email addresses and MD5 hashes with no salt exposed. Retina-X disclosed the incident in a blog post on April 27, 2017.

    Email addresses · Passwords

  • Added 25 Apr 2017 breached 1 Jan 2017 r2games.com

    In early 2017, the forum for the gaming website R2 Games was hacked. R2 had previously appeared on HIBP in 2015 after a prior incident. This one exposed over 1 million unique user accounts and corresponding MD5 password hashes with no salt.

    Email addresses · Passwords · Usernames · Website activity

  • FashionFantasyGame 2.4M accounts
    Added 20 Apr 2017 breached 1 Dec 2016 fashionfantasygame.com

    In late 2016, the fashion gaming website Fashion Fantasy Game suffered a data breach. The incident exposed 2.3 million unique user accounts and corresponding MD5 password hashes with no salt. The data was contributed to Have I Been Pwned courtesy of rip@creep.im.

    Email addresses · Passwords

  • Youku 91.9M accounts
    Added 15 Apr 2017 breached 1 Dec 2016 youku.com

    In late 2016, the online Chinese video service Youku suffered a data breach. The incident exposed 92 million unique user accounts and corresponding MD5 password hashes. The data was contributed to Have I Been Pwned courtesy of rip@creep.im.

    Email addresses · Passwords

  • Health Now Networks 322K accounts
    Added 7 Apr 2017 breached 25 Mar 2017 healthnow.co

    In March 2017, the telemarketing service Health Now Networks left a database containing hundreds of thousands of medical records exposed. There were over 900,000 records in total containing significant volumes of personal information including names, dates of birth, various medical conditions and operator notes on the individuals' health. The data included over 320k unique email addresses.

    Dates of birth · Email addresses · Genders · Health insurance information · IP addresses · Names · Personal health data · Phone numbers · Physical addresses · Security questions and answers · Social connections