Breaches
Data breaches as they’re disclosed and verified, newest additions first — who was breached, how many accounts, and what was exposed.
- Final Fantasy Shrine 621K accounts
In September 2015, the Final Fantasy discussion forum known as FFShrine was breached and the data dumped publicly. Approximately 620k records were released containing email addresses, IP addresses and salted hashes of passwords.
Email addresses · Passwords · Usernames · Website activity
- PHP Freaks 174K accounts
In October 2015, the PHP discussion board PHP Freaks was hacked and 173k user accounts were publicly leaked. The breach included multiple personal data attributes as well as salted and hashed passwords.
Dates of birth · Email addresses · IP addresses · Passwords · Usernames · Website activity
- 000webhost 14.9M accounts
In approximately March 2015, the free web hosting provider 000webhost suffered a major data breach that exposed almost 15 million customer records. The data was sold and traded before 000webhost was alerted in October. The breach included names, email addresses and plain text passwords.
Email addresses · IP addresses · Names · Passwords
- MPGH 3.1M accounts
In October 2015, the multiplayer game hacking website MPGH was hacked and 3.1 million user accounts disclosed. The vBulletin forum breach contained usernames, email addresses, IP addresses and salted hashes of passwords.
Email addresses · IP addresses · Passwords · Usernames
- Paddy Power 591K accounts
In October 2010, the Irish bookmaker Paddy Power suffered a data breach that exposed 750,000 customer records with nearly 600,000 unique email addresses. The breach was not disclosed until July 2014 and contained extensive personal information including names, addresses, phone numbers and plain text security questions and answers.
Account balances · Dates of birth · Email addresses · IP addresses · Names · Phone numbers · Physical addresses · Security questions and answers · Usernames · Website activity
- MyVidster (2015) 20K accounts
In August 2015, the social video sharing and bookmarking site MyVidster was hacked and nearly 20,000 accounts were dumped online. The dump included usernames, email addresses and hashed passwords.
Email addresses · Passwords · Usernames
- Patreon 2.3M accounts
In October 2015, the crowdfunding site Patreon was hacked and over 16GB of data was released publicly. The dump included almost 14GB of database records with more than 2.3M unique email addresses, millions of personal messages and passwords stored as bcrypt hashes.
Email addresses · Passwords · Payment histories · Physical addresses · Private messages · Website activity
- Ashley Madison 30.8M accounts
In July 2015, the infidelity website Ashley Madison suffered a serious data breach. The attackers threatened Ashley Madison with the full disclosure of the breach unless the service was shut down. One month later, the database was dumped including more than 30M unique email addresses. This breach has been classed as "sensitive" and is not publicly searchable, although individuals may discover if they've been impacted by registering for notifications. Read about this approach in detail.
Dates of birth · Email addresses · Ethnicities · Genders · Names · Passwords · Payment histories · Phone numbers · Physical addresses · Security questions and answers · Sexual orientations · Usernames · Website activity
- XSplit 3.0M accounts
In November 2013, the makers of gaming live streaming and recording software XSplit was compromised in an online attack. The data breach leaked almost 3M names, email addresses, usernames and hashed passwords.
Email addresses · Names · Passwords · Usernames
- YouPorn 1.3M accounts
In February 2012, the adult website YouPorn had over 1.3M user accounts exposed in a data breach. The publicly released data included both email addresses and plain text passwords.
Email addresses · Passwords
- Hacking Team 32K accounts
In July 2015, the Italian security firm Hacking Team suffered a major data breach that resulted in over 400GB of their data being posted online via a torrent. The data searchable on "Have I Been Pwned?" is from 189GB worth of PST mail folders in the dump. The contents of the PST files is searchable on Wikileaks.
Email addresses · Email messages
- Hemmakväll 47K accounts
In July 2015, the Swedish video store chain Hemmakväll was hacked and nearly 50k records dumped publicly. The disclosed data included various attributes of their customers including email and physical addresses, names and phone numbers. Passwords were also leaked, stored with a weak MD5 hashing algorithm.
Email addresses · Names · Passwords · Phone numbers · Physical addresses
- myRepoSpace 253K accounts
In July 2015, the Cydia repository known as myRepoSpace was hacked and user data leaked publicly. Cydia is designed to facilitate the installation of apps on jailbroken iOS devices. The repository service was allegedly hacked by @its_not_herpes and 0x8badfl00d in retaliation for the service refusing to remove pirated tweaks.
Email addresses · IP addresses · Passwords · Usernames
- Minecraft Pocket Edition Forum 16K accounts
In May 2015, the Minecraft Pocket Edition forum was hacked and over 16k accounts were dumped public. Allegedly hacked by @rmsg0d, the forum data included numerous personal pieces of data for each user. The forum has subsequently been decommissioned.
Email addresses · IP addresses · Passwords · Usernames
- NextGenUpdate 1.2M accounts
Early in 2014, the video game website NextGenUpdate reportedly suffered a data breach that disclosed almost 1.2 million accounts. Amongst the data breach was usernames, email addresses, IP addresses and salted and hashed passwords.
Email addresses · IP addresses · Passwords · Usernames
- mSpy 700K accounts
In May 2015, the "monitoring" software known as mSpy suffered a major data breach. The software (allegedly often used to spy on unsuspecting victims), stored extensive personal information within their online service which after being breached, was made freely available on the internet.
Device usage tracking data
- Adult FriendFinder (2015) 3.9M accounts
In May 2015, the adult hookup site Adult FriendFinder was hacked and nearly 4 million records dumped publicly. The data dump included extremely sensitive personal information about individuals and their relationship statuses and sexual preferences combined with personally identifiable information.
Dates of birth · Email addresses · Genders · Geographic locations · IP addresses · Races · Relationship statuses · Sexual orientations · Spoken languages · Usernames
- Спрашивай.ру 3.5M accounts
In May 2015, Спрашивай.ру (a the Russian website for anonymous reviews) was reported to have had 6.7 million user details exposed by a hacker known as "w0rm". Intended to be a site for expressing anonymous opinions, the leaked data included email addresses, birth dates and other personally identifiable data about almost 3.5 million unique email addresses found in the leak.
Dates of birth · Email addresses · Genders · Geographic locations · IP addresses · Passwords · Spoken languages
- Telecom Regulatory Authority of India 108K accounts
In April 2015, the Telecom Regulatory Authority of India (TRAI) published tens of thousand of emails sent by Indian citizens supporting net neutrality as part of the SaveTheInternet campaign. The published data included lists of emails including the sender's name and email address as well as the contents of the email as well, often with signatures including other personal data.
Email addresses · Email messages
- StarNet 139K accounts
In February 2015, the Moldavian ISP "StarNet" had it's database published online. The dump included nearly 140k email addresses, many with personal details including contact information, usage patterns of the ISP and even passport numbers.
Customer interactions · Dates of birth · Email addresses · Genders · IP addresses · MAC addresses · Names · Passport numbers · Passwords · Phone numbers