Breaches

Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.

1,020 breaches · updated 5 hours ago · data from Have I Been Pwned (CC BY 4.0)

1,020 breaches · page 46 of 51 Fabricated, spam-list and retired breaches are left out.
  • Trillian 3.8M accounts
    Added 15 Jul 2016 breached 27 Dec 2015 trillian.im

    In December 2015, the instant messaging application Trillian suffered a data breach. The breach became known in July 2016 and exposed various personal data attributes including names, email addresses and passwords stored as salted MD5 hashes.

    Dates of birth · Email addresses · IP addresses · Names · Passwords · Usernames

  • 17 4.0M accounts
    Added 8 Jul 2016 breached 19 Apr 2016 17app.co

    In April 2016, customer data obtained from the streaming app known as "17" appeared listed for sale on a Tor hidden service marketplace. The data contained over 4 million unique email addresses along with IP addresses, usernames and passwords stored as unsalted MD5 hashes.

    Device information · Email addresses · IP addresses · Passwords · Usernames

  • Neopets 26.9M accounts
    Added 7 Jul 2016 breached 5 May 2013 neopets.com

    In May 2016, a set of breached data originating from the virtual pet website "Neopets" was found being traded online. Allegedly hacked "several years earlier", the data contains sensitive personal information including birthdates, genders and names as well as almost 27 million unique email addresses. Passwords were stored in plain text and IP addresses were also present in the breach.

    Dates of birth · Email addresses · Genders · Geographic locations · IP addresses · Names · Passwords · Usernames

  • Badoo 112.0M accounts
    Added 6 Jul 2016 breached 1 Jun 2013 badoo.com sensitive unverified

    In June 2016, a data breach allegedly originating from the social website Badoo was found to be circulating amongst traders. Likely obtained several years earlier, the data contained 112 million unique email addresses with personal data including names, birthdates and passwords stored as MD5 hashes. Whilst there are many indicators suggesting Badoo did indeed suffer a data breach, the legitimacy of the data could not be emphatically proven so this breach has been categorised as "unverified".

    Dates of birth · Email addresses · Genders · Names · Passwords · Usernames

  • iMesh 49.5M accounts
    Added 2 Jul 2016 breached 22 Sept 2013 imesh.com

    In September 2013, the media and file sharing client known as iMesh was hacked and approximately 50M accounts were exposed. The data was later put up for sale on a dark market website in mid-2016 and included email and IP addresses, usernames and salted MD5 hashes.

    Email addresses · IP addresses · Passwords · Usernames

  • Tianya 29.0M accounts
    Added 30 Jun 2016 breached 26 Dec 2011 tianya.cn

    In December 2011, China's largest online forum known as Tianya was hacked and tens of millions of accounts were obtained by the attacker. The leaked data included names, usernames and email addresses.

    Email addresses · Names · Usernames

  • Muslim Match 150K accounts
    Added 29 Jun 2016 breached 24 Jun 2016 muslimmatch.com sensitive

    In June 2016, the Muslim Match dating website had 150k email addresses exposed. The data included private chats and messages between relationship seekers and numerous other personal attributes including passwords hashed with MD5.

    Chat logs · Email addresses · Geographic locations · IP addresses · Passwords · Private messages · User statuses · Usernames

  • WHMCS 134K accounts
    Added 28 Jun 2016 breached 21 May 2012 whmcs.com

    In May 2012, the web hosting, billing and automation company WHMCS suffered a data breach that exposed 134k email addresses. The breach included extensive information about customers and payment histories including partial credit card numbers.

    Email addresses · Email messages · Employers · IP addresses · Names · Partial credit card data · Passwords · Payment histories · Physical addresses · Website activity

  • Uiggy 2.7M accounts
    Added 27 Jun 2016 breached 1 Jun 2016 uiggy.com

    In June 2016, the Facebook application known as Uiggy was hacked and 4.3M accounts were exposed, 2.7M of which had email addresses against them. The leaked accounts also exposed names, genders and the Facebook ID of the owners.

    Email addresses · Genders · Names · Social connections · Website activity

  • VK 93.3M accounts
    Added 9 Jun 2016 breached 1 Jan 2012 vk.com

    In approximately 2012, the Russian social media site known as VK was hacked and almost 100 million accounts were exposed. The data emerged in June 2016 where it was being sold via a dark market website and included names, phone numbers email addresses and plain text passwords.

    Email addresses · Names · Passwords · Phone numbers

  • BitTorrent 34K accounts
    Added 8 Jun 2016 breached 1 Jan 2016 bittorrent.com

    In January 2016, the forum for the popular torrent software BitTorrent was hacked. The IP.Board based forum stored passwords as weak SHA1 salted hashes and the breached data also included usernames, email and IP addresses.

    Email addresses · IP addresses · Passwords · Usernames

  • MySpace 359.4M accounts
    Added 31 May 2016 breached 1 Jul 2008 myspace.com

    In approximately 2008, MySpace suffered a data breach that exposed almost 360 million accounts. In May 2016 the data was offered up for sale on the "Real Deal" dark market website and included email addresses, usernames and SHA1 hashes of the first 10 characters of the password converted to lowercase and stored without a salt. The exact breach date is unknown, but analysis of the data suggests it was 8 years before being made public.

    Email addresses · Passwords · Usernames

  • tumblr 65.5M accounts
    Added 29 May 2016 breached 28 Feb 2013 tumblr.com

    In early 2013, tumblr suffered a data breach which resulted in the exposure of over 65 million accounts. The data was later put up for sale on a dark market website and included email addresses and passwords stored as salted SHA1 hashes.

    Email addresses · Passwords

  • Fling 40.8M accounts
    Added 28 May 2016 breached 10 Mar 2011 fling.com sensitive

    In 2011, the self-proclaimed "World's Best Adult Social Network" website known as Fling was hacked and more than 40 million accounts obtained by the attacker. The breached data included highly sensitive personal attributes such as sexual orientation and sexual interests as well as email addresses and passwords stored in plain text.

    Dates of birth · Email addresses · Genders · Geographic locations · IP addresses · Passwords · Phone numbers · Sexual fetishes · Sexual orientations · Usernames · Website activity

  • Fur Affinity 1.3M accounts
    Added 27 May 2016 breached 17 May 2016 furaffinity.net sensitive

    In May 2016, the Fur Affinity website for people with an interest in anthropomorphic animal characters (also known as "furries") was hacked. The attack exposed 1.2M email addresses (many accounts had a different "first" and "last" email against them) and hashed passwords.

    Email addresses · Passwords · Usernames

  • LinkedIn 164.6M accounts
    Added 21 May 2016 breached 5 May 2012 linkedin.com

    In May 2016, LinkedIn had 164 million email addresses and passwords exposed. Originally hacked in 2012, the data remained out of sight until being offered for sale on a dark market site 4 years later. The passwords in the breach were stored as SHA1 hashes without salt, the vast majority of which were quickly cracked in the days following the release of the data.

    Email addresses · Passwords

  • Rosebutt Board 107K accounts
    Added 10 May 2016 breached 9 May 2016 rosebuttboard.com sensitive

    Some time prior to May 2016, the forum known as "Rosebutt Board" was hacked and 107k accounts were exposed. The self-described "top one board for anal fisting, prolapse, huge insertions and rosebutt fans" had email and IP addresses, usernames and weakly stored salted MD5 password hashes hacked from the IP.Board based forum.

    Email addresses · IP addresses · Passwords · Usernames

  • Nulled.cr 599K accounts
    Added 9 May 2016 breached 6 May 2016 nulled.cr

    In May 2016, the cracking community forum known as Nulled.cr was hacked and 599k user accounts were leaked publicly. The compromised data included email and IP addresses, weak salted MD5 password hashes and hundreds of thousands of private messages between members.

    Dates of birth · Email addresses · IP addresses · Passwords · Private messages · Usernames · Website activity

  • Added 1 May 2016 breached 1 Jul 2015 qnb.com

    In July 2015, the Qatar National Bank suffered a data breach which exposed 15k documents totalling 1.4GB and detailing more than 100k accounts with passwords and PINs. The incident was made public some 9 months later in April 2016 when the documents appeared publicly on a file sharing site. Analysis of the breached data suggests the attack began by exploiting a SQL injection flaw in the bank's website.

    Bank account numbers · Customer feedback · Dates of birth · Financial transactions · Genders · Geographic locations · Government issued IDs · IP addresses · Marital statuses · Names · Passwords · Phone numbers · Physical addresses · PINs · Security questions and answers · Spoken languages

  • Lifeboat 7.1M accounts
    Added 25 Apr 2016 breached 1 Jan 2016 lbsg.net

    In January 2016, the Minecraft community known as Lifeboat was hacked and more than 7 million accounts leaked. Lifeboat knew of the incident for three months before the breach was made public but elected not to advise customers. The leaked data included usernames, email addresses and passwords stored as straight MD5 hashes.

    Email addresses · Passwords · Usernames