Breaches

Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.

1,020 breaches · updated 2 hours ago · data from Have I Been Pwned (CC BY 4.0)

1,020 breaches · page 44 of 51 Fabricated, spam-list and retired breaches are left out.
  • Aipai.com 6.5M accounts
    Added 7 Nov 2016 breached 27 Sept 2016 aipai.com unverified

    In September 2016, data allegedly obtained from the Chinese gaming website known as Aipai.com and containing 6.5M accounts was leaked online. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains email addresses and MD5 password hashes. Read more about Chinese data breaches in Have I Been Pwned.

    Email addresses · Passwords

  • Civil Online 7.8M accounts
    Added 7 Nov 2016 breached 10 Jul 2011 co188.com unverified

    In mid-2011, data was allegedly obtained from the Chinese engineering website known as Civil Online and contained 7.8M accounts. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains email and IP addresses, user names and MD5 password hashes. Read more about Chinese data breaches in Have I Been Pwned.

    Email addresses · IP addresses · Passwords · Usernames · Website activity

  • Duowan.com 2.6M accounts
    Added 7 Nov 2016 breached 1 Jan 2011 duowan.com unverified

    In approximately 2011, data was allegedly obtained from the Chinese gaming website known as Duowan.com and contained 2.6M accounts. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains email addresses, user names and plain text passwords. Read more about Chinese data breaches in Have I Been Pwned.

    Email addresses · Passwords · Usernames

  • War Inc. 1.0M accounts
    Added 7 Nov 2016 breached 4 Jul 2012 thewarinc.com

    In mid-2012, the real-time strategy game War Inc. suffered a data breach. The attack resulted in the exposure of over 1 million accounts including usernames, email addresses and salted MD5 hashes of passwords.

    Email addresses · Passwords · Usernames · Website activity

  • Epic Games 252K accounts
    Added 7 Nov 2016 breached 11 Aug 2016 epicgames.com

    In August 2016, the Epic Games forum suffered a data breach, allegedly due to a SQL injection vulnerability in vBulletin. The attack resulted in the exposure of 252k accounts including usernames, email addresses and salted MD5 hashes of passwords.

    Email addresses · Passwords · Usernames

  • Unreal Engine 530K accounts
    Added 7 Nov 2016 breached 11 Aug 2016 unrealengine.com

    In August 2016, the Unreal Engine Forum suffered a data breach, allegedly due to a SQL injection vulnerability in vBulletin. The attack resulted in the exposure of 530k accounts including usernames, email addresses and salted MD5 hashes of passwords.

    Email addresses · Passwords · Usernames

  • Heroes of Gaia 180K accounts
    Added 7 Nov 2016 breached 4 Jan 2013 heroesofgaia.com

    In early 2013, the online fantasy multiplayer game Heroes of Gaia suffered a data breach. The newest records in the data set indicate a breach date of 4 January 2013 and include usernames, IP and email addresses but no passwords.

    Browser user agent details · Email addresses · IP addresses · Usernames · Website activity

  • uTorrent 395K accounts
    Added 5 Nov 2016 breached 14 Jan 2016 utorrent.com

    In early 2016, the forum for the uTorrent BitTorrent client suffered a data breach which came to light later in the year. The database from the IP.Board based forum contained 395k accounts including usernames, email addresses and MD5 password hashes without a salt.

    Email addresses · Passwords · Usernames

  • Rambler 91.4M accounts
    Added 1 Nov 2016 breached 1 Mar 2014 rambler.ru

    In late 2016, a data dump of almost 100M accounts from Rambler, sometimes referred to as "The Russian Yahoo", was discovered being traded online. The data set provided to Have I Been Pwned included 91M unique usernames (which also form part of Rambler email addresses) and plain text passwords. According to Rambler, the data dates back to March 2014.

    Email addresses · Passwords · Usernames

  • Added 12 Oct 2016 breached 8 Oct 2016 modbsolutions.com

    In October 2016, a large Mongo DB file containing tens of millions of accounts was shared publicly on Twitter (the file has since been removed). The database contained over 58M unique email addresses along with IP addresses, names, home addresses, genders, job titles, dates of birth and phone numbers. The data was subsequently attributed to "Modern Business Solutions", a company that provides data storage and database hosting solutions. They've yet to acknowledge the incident or explain how they came to be in possession of the data.

    Dates of birth · Email addresses · Genders · IP addresses · Job titles · Names · Phone numbers · Physical addresses

  • GFAN 22.5M accounts
    Added 10 Oct 2016 breached 10 Oct 2016 gfan.com unverified

    In October 2016, data surfaced that was allegedly obtained from the Chinese website known as GFAN and contained 22.5M accounts. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains email and IP addresses, user names and salted and hashed passwords. Read more about Chinese data breaches in Have I Been Pwned.

    Email addresses · IP addresses · Passwords · Usernames

  • NetEase 234.8M accounts
    Added 9 Oct 2016 breached 19 Oct 2015 163.com unverified

    In October 2015, the Chinese site known as NetEase (located at 163.com) was reported as having suffered a data breach that impacted hundreds of millions of subscribers. Whilst there is evidence that the data itself is legitimate (multiple HIBP subscribers confirmed a password they use is in the data), due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains email addresses and plain text passwords. Read more about Chinese data breaches in Have I Been Pwned.

    Email addresses · Passwords

  • Taobao 21.1M accounts
    Added 8 Oct 2016 breached 1 Jan 2012 taobao.com unverified

    In approximately 2012, it's alleged that the Chinese shopping site known as Taobao suffered a data breach that impacted over 21 million subscribers. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains email addresses and plain text passwords. Read more about Chinese data breaches in Have I Been Pwned.

    Email addresses · Passwords

  • 126 6.4M accounts
    Added 8 Oct 2016 breached 1 Jan 2012 126.com unverified

    In approximately 2012, it's alleged that the Chinese email service known as 126 suffered a data breach that impacted 6.4 million subscribers. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains email addresses and plain text passwords. Read more about Chinese data breaches in Have I Been Pwned.

    Email addresses · Passwords

  • Aternos 1.4M accounts
    Added 1 Oct 2016 breached 6 Dec 2015 aternos.org

    In December 2015, the service for creating and running free Minecraft servers known as Aternos suffered a data breach that impacted 1.4 million subscribers. The data included usernames, email and IP addresses and hashed passwords.

    Email addresses · IP addresses · Passwords · Usernames · Website activity

  • Leet 5.1M accounts
    Added 30 Sept 2016 breached 10 Sept 2016 leet.cc

    In August 2016, the service for creating and running Pocket Minecraft edition servers known as Leet was reported as having suffered a data breach that impacted 6 million subscribers. The incident reported by Softpedia had allegedly taken place earlier in the year, although the data set sent to HIBP was dated as recently as early September but contained only 2 million subscribers. The data included usernames, email and IP addresses and SHA512 hashes. A further 3 million accounts were obtained and added to HIBP several days after the initial data was loaded bringing the total to over 5 million.

    Email addresses · IP addresses · Passwords · Usernames · Website activity

  • i-Dressup 2.2M accounts
    Added 26 Sept 2016 breached 15 Jul 2016 i-dressup.com

    In June 2016, the teen social site known as i-Dressup was hacked and over 2 million user accounts were exposed. At the time the hack was reported, the i-Dressup operators were not contactable and the underlying SQL injection flaw remained open, allegedly exposing a total of 5.5 million accounts. The breach included email addresses and passwords stored in plain text.

    Email addresses · Passwords

  • gPotato 2.1M accounts
    Added 24 Sept 2016 breached 12 Jul 2007 gpotato.com

    In July 2007, the multiplayer game portal known as gPotato (link to archive of the site at that time) suffered a data breach and over 2 million user accounts were exposed. The site later merged into the Webzen portal where the original accounts still exist today. The exposed data included usernames, email and IP addresses, MD5 hashes and personal attributes such as gender, birth date, physical address and security questions and answers stored in plain text.

    Dates of birth · Email addresses · Genders · IP addresses · Names · Passwords · Physical addresses · Security questions and answers · Usernames · Website activity

  • GameTuts 2.1M accounts
    Added 23 Sept 2016 breached 1 Mar 2015 game-tuts.com

    Likely in early 2015, the video game website GameTuts suffered a data breach and over 2 million user accounts were exposed. The site later shut down in July 2016 but was identified as having been hosted on a vBulletin forum. The exposed data included usernames, email and IP addresses and salted MD5 hashes.

    Email addresses · IP addresses · Passwords · Usernames

  • Last.fm 37.2M accounts
    Added 20 Sept 2016 breached 22 Mar 2012 last.fm

    In March 2012, the music website Last.fm was hacked and 43 million user accounts were exposed. Whilst Last.fm knew of an incident back in 2012, the scale of the hack was not known until the data was released publicly in September 2016. The breach included 37 million unique email addresses, usernames and passwords stored as unsalted MD5 hashes.

    Email addresses · Passwords · Usernames · Website activity