Breaches
Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.
- MoDaCo 880K accounts
In approximately January 2016, the UK based Android community known as MoDaCo suffered a data breach which exposed 880k subscriber identities. The data included email and IP addresses, usernames and passwords stored as salted MD5 hashes.
Email addresses · IP addresses · Passwords · Usernames
- eThekwini Municipality 82K accounts
In September 2016, the new eThekwini eServices website in South Africa was launched with a number of security holes that lead to the leak of over 98k residents' personal information and utility bills across 82k unique email addresses. Emails were sent prior to launch containing passwords in plain text and the site allowed anyone to download utility bills without sufficient authentication. Various methods of customer data enumeration was possible and phishing attacks began appearing the day after launch.
Dates of birth · Deceased date · Email addresses · Genders · Government issued IDs · Names · Passport numbers · Passwords · Phone numbers · Physical addresses · Utility bills
- Regpack 105K accounts
In July 2016, a tweet was posted with a link to an alleged data breach of BlueSnap, a global payment gateway and merchant account provider. The data contained 324k payment records across 105k unique email addresses and included personal attributes such as name, home address and phone number. The data was verified with multiple Have I Been Pwned subscribers who confirmed it also contained valid transactions, partial credit card numbers, expiry dates and CVVs. A downstream consumer of BlueSnap services known as Regpack was subsequently identified as the source of the data after they identified human error had left the transactions exposed on a publicly facing server. A full investigation of the data and statement by Regpack is detailed in the post titled Someone just lost 324k payment records, complete with CVVs.
Browser user agent details · Credit card CVV · Email addresses · IP addresses · Names · Partial credit card data · Phone numbers · Physical addresses · Purchases
- ClixSense 2.4M accounts
In September 2016, the paid-to-click site ClixSense suffered a data breach which exposed 2.4 million subscriber identities. The breached data was then posted online by the attackers who claimed it was a subset of a larger data breach totalling 6.6 million records. The leaked data was extensive and included names, physical, email and IP addresses, genders and birth dates, account balances and passwords stored as plain text.
Account balances · Dates of birth · Email addresses · Genders · IP addresses · Names · Passwords · Payment histories · Payment methods · Physical addresses · Usernames · Website activity
- Pokébip 657K accounts
In July 2015, the French Pokémon site Pokébip suffered a data breach which exposed 657k subscriber identities. The data included email and IP addresses, usernames and passwords stored as unsalted MD5 hashes.
Email addresses · IP addresses · Passwords · Time zones · Usernames · Website activity
- DLH.net 3.3M accounts
In July 2016, the gaming news site DLH.net suffered a data breach which exposed 3.3M subscriber identities. Along with the keys used to redeem and activate games on the Steam platform, the breach also resulted in the exposure of email addresses, birth dates and salted MD5 password hashes. The data was donated to Have I Been Pwned by data breach monitoring service Vigilante.pw.
Dates of birth · Email addresses · Names · Passwords · Usernames · Website activity
- Experian (2015) 7.2M accounts
In September 2015, the US based credit bureau and consumer data broker Experian suffered a data breach that impacted 15 million customers who had applied for financing from T-Mobile. An alleged data breach was subsequently circulated containing personal information including names, physical and email addresses, birth dates and various other personal attributes. Multiple Have I Been Pwned subscribers verified portions of the data as being accurate, but the actual source of it was inconclusive therefor this breach has been flagged as "unverified".
Credit status information · Dates of birth · Email addresses · Ethnicities · Family structure · Genders · Home ownership statuses · Income levels · IP addresses · Names · Phone numbers · Physical addresses · Purchasing habits
- Flash Flash Revolution (2016 breach) 1.8M accounts
In February 2016, the music-based rhythm game known as Flash Flash Revolution was hacked and 1.8M accounts were exposed. Along with email and IP addresses, the vBulletin forum also exposed salted MD5 password hashes.
Email addresses · Passwords · Usernames
- Onverse 800K accounts
In January 2016, the online virtual world known as Onverse was hacked and 800k accounts were exposed. Along with email and IP addresses, the site also exposed salted MD5 password hashes.
Email addresses · IP addresses · Passwords · Usernames
- WIIU ISO 458K accounts
In September 2015, the Nintendo Wii U forum known as WIIU ISO was hacked and 458k accounts were exposed. Along with email and IP addresses, the vBulletin forum also exposed salted MD5 password hashes.
Email addresses · IP addresses · Passwords · Usernames
- ServerPact 74K accounts
In mid-2015, the Dutch Minecraft site ServerPact was hacked and 73k accounts were exposed. Along with birth dates, email and IP addresses, the site also exposed SHA1 password hashes with the username as the salt.
Dates of birth · Email addresses · IP addresses · Passwords · Usernames
- Brazzers 791K accounts
In April 2013, the adult website known as Brazzers was hacked and 790k accounts were exposed publicly. Each record included a username, email address and password stored in plain text. The breach was brought to light by the Vigilante.pw data breach reporting site in September 2016.
Email addresses · Passwords · Usernames
- Dropbox 68.6M accounts
In mid-2012, Dropbox suffered a data breach which exposed the stored credentials of tens of millions of their customers. In August 2016, they forced password resets for customers they believed may be at risk. A large volume of data totalling over 68 million records was subsequently traded online and included email addresses and salted hashes of passwords (half of them SHA1, half of them bcrypt).
Email addresses · Passwords
- InterPals 3.4M accounts
In late 2015, the online penpal site InterPals had their website hacked and 3.4 million accounts exposed. The compromised data included email addresses, geographical locations, birthdates and salted hashes of passwords.
Dates of birth · Email addresses · Geographic locations · Names · Passwords · Usernames
- Nihonomaru 1.7M accounts
In late 2015, the anime community known as Nihonomaru had their vBulletin forum hacked and 1.7 million accounts exposed. The compromised data included email and IP addresses, usernames and salted hashes of passwords.
Email addresses · IP addresses · Passwords · Usernames
- Minecraft World Map 71K accounts
In approximately January 2016, the Minecraft World Map site designed for sharing maps created for the game was hacked and over 71k user accounts were exposed. The data included usernames, email and IP addresses along with salted and hashed passwords.
Email addresses · IP addresses · Passwords · Usernames
- GTAGaming 197K accounts
In August 2016, the Grand Theft Auto forum GTAGaming was hacked and nearly 200k user accounts were leaked. The vBulletin based forum included usernames, email addresses and password hashes.
Dates of birth · Email addresses · IP addresses · Passwords · Usernames · Website activity
- Teracod 97K accounts
In May 2015, almost 100k user records were extracted from the Hungarian torrent site known as Teracod. The data was later discovered being torrented itself and included email addresses, passwords, private messages between members and the peering history of IP addresses using the service.
Avatars · Email addresses · IP addresses · Passwords · Payment histories · Private messages · Usernames · Website activity
- xat 6.0M accounts
In November 2015, the online chatroom known as "xat" was hacked and 6 million user accounts were exposed. Used as a chat engine on websites, the leaked data included usernames, email and IP addresses along with hashed passwords.
Email addresses · IP addresses · Passwords · Usernames · Website activity
- Warframe 819K accounts
In November 2014, the online game Warframe was hacked and 819k unique email addresses were exposed. Allegedly due to a SQL injection flaw in Drupal, the attack exposed usernames, email addresses and data in a "pass" column which adheres to the salted SHA12 password hashing pattern used by Drupal 7. Digital Extremes (the developers of Warframe), asserts the salted hashes are of "alias names" rather than passwords.
Email addresses · Usernames · Website activity