<html>

<head>
    <title>Have I Been Pwned: Check if your email has been compromised in a data breach</title>
</head>

<body>
    <div>
        <header>
            <div>
                <div>
                    <button type="button">
                    </button>
                    <a>';--</a>
                </div>
                <div>
                    <ul>
                        <li><a>Home</a></li>
                        <li><a>Notify me</a></li>
                        <li><a>Domain search</a></li>
                        <li><a>Who's been pwned</a></li>
                        <li><a>Passwords</a></li>
                        <li>
                            <a>API</a>
                            <ul>
                                <li><a>Overview</a></li>
                                <li><a>API key</a></li>
                                <li><a>Terms of use</a></li>
                            </ul>
                        </li>
                        <li>
                            <a>About</a>
                            <ul>
                                <li><a>Who, what &amp; why</a></li>
                                <li><a>Privacy</a></li>
                                <li><a>FAQs</a></li>
                                <li><a>Pastes</a></li>
                                <li><a>Opt-out</a></li>
                                <li><a>Twitter</a></li>
                                <li><a>Facebook</a></li>
                                <li><a>Mastodon</a></li>
                                <li><a>Suggest a feature</a></li>
                            </ul>
                        </li>
                        <li><a>Donate </a></li>
                    </ul>
                </div>
            </div>
        </header>
        <div>
            <div>
                <div>
                    <div>
                        <span>';--have i been pwned?</span>
                    </div>
                    <p>Check if your email or phone is in a data breach</p>
                </div>
            </div>
        </div>
        <div>
            <div>
                <form>
                    <div><iframe title="Widget containing a Cloudflare security challenge" /><input
                            name="cf-turnstile-response" /></div>
                    <div>
                        <input name="Account" placeholder="email address" type="email" />
                        <input name="apiEndpoint" value="https://haveibeenpwned.com/unifiedsearch/" />
                        <span>
                            <button type="submit">pwned?</button>
                        </span>
                    </div>
                    <div>
                        <div role="progressbar">
                        </div>
                    </div>
                </form>
            </div>
        </div>
        <div>
            <div>
                <p>
                    <img alt="1Password Logo" />
                    <span>Generate secure, unique passwords for every account</span>
                    <a>Learn more at 1Password.com</a>
                </p>
                <p><a>Why 1Password?</a></p>
            </div>
        </div>
    </div>
    <div>
        <div>
            <div>
                <div>
                    <h2>Good news — no pwnage found!</h2>
                    <p>
                        No <a>breached accounts</a>
                        <span>and no <a>pastes</a> (<a>subscribe</a> to search sensitive breaches)</span>
                    </p>
                </div>
                <div>
                    <div>
                        <div>
                            <img alt="1Password Logo" />
                            <h3>3 Steps to better security</h3>
                        </div>
                        <div>
                            <a>Start using 1Password.com</a>
                        </div>
                    </div>
                    <div>
                        <div>
                            <p>
                                <a>
                                    <img alt="Step 1" /><strong>Step 1</strong> Protect yourself using 1Password to
                                    generate and save strong passwords for each website.
                                </a>
                            </p>
                        </div>
                        <div>
                            <p>
                                <a>
                                    <img alt="Step 2" /><strong>Step 2</strong> Enable 2 factor authentication and store
                                    the codes inside your 1Password account.
                                </a>
                            </p>
                        </div>
                        <div>
                            <p>
                                <a>
                                    <img alt="Step 3" /><strong>Step 3</strong> <span>Subscribe</span> to notifications
                                    for any other breaches. Then just change that unique password.
                                </a>
                            </p>
                        </div>
                    </div>
                    <div>
                        <div>
                            <p><a>Why 1Password?</a></p>
                        </div>
                    </div>
                </div>
            </div>
        </div>
    </div>
    <div>
        <div>
            <div>
                <div>
                    <div>
                        <h2>
                            Oh no — pwned!
                        </h2>
                        <p>Pwned in 3 <a>data breaches</a> and found no <a>pastes</a> (<a>subscribe</a> to search
                            sensitive breaches)</p>
                    </div>
                    <div>
                        <div>
                            <div>
                                <img alt="1Password Logo" />
                                <h3>3 Steps to better security</h3>
                            </div>
                            <div>
                                <a>Start using 1Password.com</a>
                            </div>
                        </div>
                        <div>
                            <div>
                                <p>
                                    <a>
                                        <img alt="Step 1" /><strong>Step 1</strong> Protect yourself using 1Password to
                                        generate and save strong passwords for each website.
                                    </a>
                                </p>
                            </div>
                            <div>
                                <p>
                                    <a>
                                        <img alt="Step 2" /><strong>Step 2</strong> Enable 2 factor authentication and
                                        store the codes inside your 1Password account.
                                    </a>
                                </p>
                            </div>
                            <div>
                                <p>
                                    <a>
                                        <img alt="Step 3" /><strong>Step 3</strong> <span>Subscribe</span> to
                                        notifications for any other breaches. Then just change that unique password.
                                    </a>
                                </p>
                            </div>
                        </div>
                        <div>
                            <div>
                                <p><a>Why 1Password?</a></p>
                            </div>
                        </div>
                    </div>
                </div>
            </div>
        </div>
        <div>
            <div>
                <div>
                    <h3>Breaches you were pwned in</h3>
                    <p>
                        A "breach" is an incident where data has been unintentionally exposed to the
                        public. Using the <a>1Password password manager</a>
                        helps you ensure all your passwords are strong and unique such that a breach of one service
                        doesn't put your other services at risk.
                    </p>
                </div>
            </div>
            <div>
                <div>
                    <div>
                        <div>
                            <div><img alt="000webhost logo" /></div>
                            <div>
                                <p><span>000webhost</span>: In approximately March 2015, the free web hosting provider
                                    <a>000webhost suffered a major data breach</a> that exposed almost 15 million
                                    customer records. The data was sold and traded before 000webhost was alerted in
                                    October. The breach included names, email addresses and plain text passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Passwords
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="123RF logo" /></div>
                            <div>
                                <p><span>123RF</span>: In March 2020, the stock photo site <a>123RF suffered a data
                                        breach</a> which impacted over 8 million subscribers and was subsequently sold
                                    online. The breach included email, IP and physical addresses, names, phone numbers
                                    and passwords stored as MD5 hashes. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Passwords,
                                    Phone numbers, Physical addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="17 logo" /></div>
                            <div>
                                <p><span>17</span>: In April 2016, customer data obtained from the streaming app known
                                    as "17" <a>appeared listed for sale on a Tor hidden service marketplace</a>. The
                                    data contained over 4 million unique email addresses along with IP addresses,
                                    usernames and passwords stored as unsalted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Device information, Email addresses, IP addresses,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="2,844 Separate Data Breaches logo" /></div>
                            <div>
                                <p><span>2,844 Separate Data Breaches<span> (<a>unverified</a>)</span></span>: In
                                    February 2018, <a>a massive collection of almost 3,000 alleged data breaches was
                                        found online</a>. Whilst some of the data had previously been seen in Have I
                                    Been Pwned, 2,844 of the files consisting of more than 80 million unique email
                                    addresses had not previously been seen. Each file contained both an email address
                                    and plain text password and were consequently loaded as a single "unverified" data
                                    breach.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="500px logo" /></div>
                            <div>
                                <p><span>500px</span>: In mid-2018, the online photography community <a>500px suffered a
                                        data breach</a>. The incident exposed almost 15 million unique email addresses
                                    alongside names, usernames, genders, dates of birth and either an MD5 or bcrypt
                                    password hash. In 2019, <a>the data appeared listed for sale on a dark web
                                        marketplace</a> (along with several other large breaches) and subsequently began
                                    circulating more broadly. The data was provided to HIBP by a source who requested it
                                    to be attributed to "BenjaminBlue@exploit.im".</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders,
                                    Geographic locations, Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="8fit logo" /></div>
                            <div>
                                <p><span>8fit</span>: In July 2018, the health and fitness service <a>8fit suffered a
                                        data breach</a>. The data subsequently appeared for sale on a dark web
                                    marketplace in February 2019 and included over 15M unique email addresses alongside
                                    names, genders, IP addresses and passwords stored as bcrypt hashes. The data was
                                    provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Geographic locations, IP
                                    addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="8tracks logo" /></div>
                            <div>
                                <p><span>8tracks</span>: In June 2017, the online playlists service known as <a>8Tracks
                                        suffered a data breach</a> which impacted 18 million accounts. In their
                                    disclosure, 8Tracks advised that "the vector for the attack was an employee’s GitHub
                                    account, which was not secured using two-factor authentication". Salted SHA-1
                                    password hashes for users who <em>didn't</em> sign up with either Google or Facebook
                                    authentication were also included. The data was provided to HIBP by whitehat
                                    security researcher and data analyst Adam Davies and contained almost 8 million
                                    unique email addresses. The complete set of 18M records was later provided by
                                    JimScott.Sec@protonmail.com and updated in HIBP accordingly.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="AbuseWith.Us logo" /></div>
                            <div>
                                <p><span>AbuseWith.Us</span>: In 2016, the site dedicated to helping people hack email
                                    and online gaming accounts known as Abusewith.us suffered multiple data breaches.
                                    The site <a>allegedly had an administrator in common with the nefarious LeakedSource
                                        site</a>, both of which have since been shut down. The exposed data included
                                    more than 1.3 million unique email addresses, often accompanied by usernames, IP
                                    addresses and plain text or hashed passwords retrieved from various sources and
                                    intended to be used to compromise the victims' accounts.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Acne.org logo" /></div>
                            <div>
                                <p><span>Acne.org</span>: In November 2014, the acne website <a>acne.org</a> suffered a
                                    data breach that exposed over 430k forum members' accounts. The data was being
                                    actively traded on underground forums and included email addresses, birth dates and
                                    passwords.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ActMobile logo" /></div>
                            <div>
                                <p><span>ActMobile<span> (<a>unverified</a>)</span></span>: In October 2021, <a>security
                                        researcher Bob Diachenko discovered an exposed database he attributed to
                                        ActMobile, the operators of Dash VPN and FreeVPN</a>. The exposed data included
                                    1.6 million unique email addresses along with IP addresses and password hashes, all
                                    of which were subsequently leaked on a popular hacking forum. Although usage of the
                                    service was verified by HIBP subscribers, <a>ActMobile denied the data was sourced
                                        from them</a> and the breach has subsequently been flagged as "unverified".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Aditya Birla Fashion and Retail logo" /></div>
                            <div>
                                <p><span>Aditya Birla Fashion and Retail</span>: In December 2021, Indian retailer
                                    <a>Aditya Birla Fashion and Retail Ltd was breached and ransomed</a>. The ransom
                                    demand was allegedly rejected and data containing 5.4M unique email addresses was
                                    subsequently dumped publicly on a popular hacking forum the next month. The data
                                    contained extensive personal customer information including names, phone numbers,
                                    physical addresses, DoBs, order histories and passwords stored as MD5 hashes.
                                    Employee data was also dumped publicly and included salary grades, marital statuses
                                    and religions. The data was provided to HIBP by a source who requested it be
                                    attributed to "white_peacock@riseup.net".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Income levels, Job
                                    titles, Marital statuses, Names, Passwords, Phone numbers, Physical addresses,
                                    Purchases, Religions, Salutations</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Adobe logo" /></div>
                            <div>
                                <p><span>Adobe</span>: In October 2013, 153 million Adobe accounts were breached with
                                    each containing an internal ID, username, email, <em>encrypted</em> password and a
                                    password hint in plain text. The password cryptography was poorly done and many were
                                    quickly resolved back to plain text. The unencrypted hints also <a>disclosed much
                                        about the passwords</a> adding further to the risk that hundreds of millions of
                                    Adobe customers already faced.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Password hints, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Animal Jam logo" /></div>
                            <div>
                                <p><span>Animal Jam</span>: In October 2020, the online game for kids <a>Animal Jam
                                        suffered a data breach</a> which was subsequently shared through online hacking
                                    communities the following month. The data contained 46 million user accounts with
                                    over 7 million unique email addresses. Impacted data also included usernames, IP
                                    addresses and for some records, dates of birth (sometimes in partial form), physical
                                    addresses, parent names and passwords stored as PBKDF2 hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, IP
                                    addresses, Names, Passwords, Physical addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="AnimeGame logo" /></div>
                            <div>
                                <p><span>AnimeGame</span>: In February 2020, the gaming website <a>AnimeGame</a>
                                    suffered a data breach. The incident affected 1.4M subscribers and exposed email
                                    addresses, usernames and passwords stored as salted MD5 hashes. The data was
                                    subsequently shared on a popular hacking forum and was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Animoto logo" /></div>
                            <div>
                                <p><span>Animoto</span>: In July 2018, the cloud-based video making service <a>Animoto
                                        suffered a data breach</a>. The breach exposed 22 million unique email addresses
                                    alongside names, dates of birth, country of origin and salted password hashes. The
                                    data was provided to HIBP by a source who requested it be attributed to
                                    "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Geographic
                                    locations, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Apollo logo" /></div>
                            <div>
                                <p><span>Apollo</span>: In July 2018, the sales engagement startup <a>Apollo left a
                                        database containing billions of data points publicly exposed without a
                                        password</a>. The data was discovered by security researcher <a>Vinny Troia</a>
                                    who subsequently sent a subset of the data containing 126 million unique email
                                    addresses to Have I Been Pwned. The data left exposed by Apollo was used in their
                                    "revenue acceleration platform" and included personal information such as names and
                                    email addresses as well as professional information including places of employment,
                                    the roles people hold and where they're located. Apollo stressed that the exposed
                                    data did not include sensitive information such as passwords, social security
                                    numbers or financial data. <a>The Apollo website has a contact form</a> for those
                                    looking to get in touch with the organisation.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Employers, Geographic locations,
                                    Job titles, Names, Phone numbers, Salutations, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Appen logo" /></div>
                            <div>
                                <p><span>Appen</span>: In June 2020, the AI training data company <a>Appen suffered a
                                        data breach</a> exposing the details of almost 5.9 million users which were
                                    subsequently sold online. Included in the breach were names, email addresses and
                                    passwords stored as bcrypt hashes. Some records also contained phone numbers,
                                    employers and IP addresses. The data was provided to HIBP by <a>dehashed.com</a>.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, Employers, IP addresses, Names,
                                    Passwords, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Aptoide logo" /></div>
                            <div>
                                <p><span>Aptoide</span>: In April 2020, the independent Android app store <a>Aptoide
                                        suffered a data breach</a>. The incident resulted in the exposure of 20M
                                    customer records which were subsequently shared online via a popular hacking forum.
                                    Impacted data included email and IP addresses, names, IP addresses and passwords
                                    stored as SHA-1 hashes without a salt.</p>
                                <p><strong>Compromised data:</strong> Browser user agent details, Email addresses, IP
                                    addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Armor Games logo" /></div>
                            <div>
                                <p><span>Armor Games</span>: In January 2019, the game portal website <a>Armor Games
                                        suffered a data breach</a>. A total of 10.6 million email addresses were
                                    impacted by the breach which also exposed usernames, IP addresses, birthdays of
                                    administrator accounts and passwords stored as salted SHA-1 hashes. The data was
                                    provided to HIBP by a source who requested it be attributed to
                                    "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Bios, Dates of birth, Email addresses, Genders,
                                    Geographic locations, IP addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Army Force Online logo" /></div>
                            <div>
                                <p><span>Army Force Online</span>: In May 2016, the online gaming site <a>Army Force
                                        Online</a> suffered a data breach that exposed 1.5M accounts. The breached data
                                    was found being regularly traded online and included usernames, email and IP
                                    addresses and MD5 passwords.</p>
                                <p><strong>Compromised data:</strong> Avatars, Email addresses, Geographic locations, IP
                                    addresses, Names, Passwords, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Artsy logo" /></div>
                            <div>
                                <p><span>Artsy</span>: In April 2018, the online arts database <a>Artsy suffered a data
                                        breach which consequently appeared for sale on a dark web marketplace</a>. Over
                                    1M accounts were impacted and included IP and email addresses, names and passwords
                                    stored as salted SHA-512 hashes. The data was provided to HIBP by a source who
                                    requested it be attributed to "nano@databases.pw".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Passwords
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Audi logo" /></div>
                            <div>
                                <p><span>Audi</span>: In August 2019, <a>Audi USA suffered a data breach after a vendor
                                        left data unsecured and exposed on the internet</a>. The data contained 2.7M
                                    unique email addresses along with names, phone numbers, physical addresses and
                                    vehicle information including VIN. In <a>a disclosure statement from Audi</a>, they
                                    also advised some customers had driver's licenses, dates of birth, social security
                                    numbers and other personal information exposed.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Driver's licenses, Email
                                    addresses, Names, Phone numbers, Physical addresses, Social security numbers,
                                    Vehicle details</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="bigbasket logo" /></div>
                            <div>
                                <p><span>bigbasket</span>: In October 2020, the Indian grocery platform <a>bigbasket
                                        suffered a data breach that exposed over 20 million customer records</a>. The
                                    data was originally sold before being leaked publicly in April the following year
                                    and included email, IP and physical addresses, names, phones numbers, dates of birth
                                    passwords stored as Django(SHA-1) hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Names, Passwords, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bin Weevils logo" /></div>
                            <div>
                                <p><span>Bin Weevils</span>: In September 2014, the online game <a>Bin Weevils suffered
                                        a data breach</a>. Whilst originally stating that only usernames and passwords
                                    had been exposed, <a>a subsequent story on DataBreaches.net indicated that a more
                                        extensive set of personal attributes were impacted</a> (comments there also
                                    suggest the data may have come from a later breach). Data matching that pattern was
                                    later provided to Have I Been Pwned by <a>@akshayindia6</a> and included almost 1.3m
                                    unique email addresses, genders, ages and plain text passwords.</p>
                                <p><strong>Compromised data:</strong> Ages, Email addresses, Genders, IP addresses,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bitcoin Security Forum Gmail Dump logo" /></div>
                            <div>
                                <p><span>Bitcoin Security Forum Gmail Dump</span>: In September 2014, a large dump of
                                    nearly 5M usernames and passwords was <a>posted to a Russian Bitcoin forum</a>.
                                    Whilst commonly reported as 5M "Gmail passwords", the dump also contained 123k
                                    yandex.ru addresses. Whilst the origin of the breach remains unclear, the breached
                                    credentials were <a>confirmed by multiple source as correct</a>, albeit a number of
                                    years old.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bitly logo" /></div>
                            <div>
                                <p><span>Bitly</span>: In May 2014, the link management company <a>Bitly announced
                                        they'd suffered a data breach</a>. The breach contained over 9.3 million unique
                                    email addresses, usernames and hashed passwords, most using SHA1 with a small number
                                    using bcrypt.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="BlackSpigotMC logo" /></div>
                            <div>
                                <p><span>BlackSpigotMC</span>: In July 2019, the hacking website <a>BlackSpigotMC
                                        suffered a data breach</a>. The XenForo forum based site was allegedly
                                    compromised by a rival hacking website and resulted in 8.5GB of data being leaked
                                    including the database and website itself. The exposed data included 140k unique
                                    email addresses, usernames, IP addresses, genders, geographic locations and
                                    passwords stored as bcrypt hashes.</p>
                                <p><strong>Compromised data:</strong> Device information, Email addresses, Genders,
                                    Geographic locations, IP addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="BlankMediaGames logo" /></div>
                            <div>
                                <p><span>BlankMediaGames</span>: In December 2018, the Town of Salem website produced by
                                    <a>BlankMediaGames suffered a data breach</a>. Reported to HIBP by <a>DeHashed</a>,
                                    the data contained 7.6M unique user email addresses alongside usernames, IP
                                    addresses, purchase histories and passwords stored as phpass hashes. DeHashed made
                                    multiple attempts to contact BlankMediaGames over various channels and many days but
                                    had yet to receive a response at the time of publishing.</p>
                                <p><strong>Compromised data:</strong> Browser user agent details, Email addresses, IP
                                    addresses, Passwords, Purchases, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bombuj.eu logo" /></div>
                            <div>
                                <p><span>Bombuj.eu</span>: In December 2018, the Slovak website for watching movies
                                    online for free <a>Bombuj.eu</a> suffered a data breach. The incident exposed over
                                    575k unique email addresses and passwords stored as unsalted MD5 hashes. No response
                                    was received from Bombuj.eu when contacted about the incident.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bonobos logo" /></div>
                            <div>
                                <p><span>Bonobos</span>: In August 2020, the clothing store <a>Bonobos suffered a data
                                        breach</a> that exposed almost 70GB of data containing 2.8 million unique email
                                    addresses. The breach also exposed names, physical and IP addresses, phone numbers,
                                    order histories and passwords stored as salted SHA-512 hashes, including historical
                                    passwords. The breach also exposed partial credit card data including card type, the
                                    name on the card, expiry date and the last 4 digits of the card. The data was
                                    provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Historical passwords, IP
                                    addresses, Names, Partial credit card data, Passwords, Phone numbers, Physical
                                    addresses, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bookmate logo" /></div>
                            <div>
                                <p><span>Bookmate</span>: In mid-2018, the social ebook subscription service <a>Bookmate
                                        was among a raft of sites that were breached and their data then sold in
                                        early-2019</a>. The data included almost 4 million unique email addresses
                                    alongside names, genders, dates of birth and passwords stored as salted SHA-512
                                    hashes. The data was provided to HIBP by a source who requested it to be attributed
                                    to "BenjaminBlue@exploit.im".</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders,
                                    Geographic locations, Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bourse des Vols logo" /></div>
                            <div>
                                <p><span>Bourse des Vols</span>: In January 2021, the French travel company <a>Bourse
                                        des Vols suffered a data breach that exposed 1.46M unique email addresses</a>
                                    across more than 1.2k .sql files and over 9GB of data. The impacted data exposed
                                    personal information and travel histories including names, phone numbers, IP and
                                    physical addresses, dates of birth along with flights taken and purchases.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Flights taken, IP
                                    addresses, Names, Phone numbers, Physical addresses, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bukalapak logo" /></div>
                            <div>
                                <p><span>Bukalapak</span>: In March 2019, the Indonesian e-commerce website <a>Bukalapak
                                        discovered a data breach of the organisation's backups dating back to October
                                        2017</a>. The incident exposed approximately 13 million unique email addresses
                                    alongside IP addresses, names and passwords stored as bcrypt and salted SHA-512
                                    hashes. The data was provided to HIBP by a source who requested it to be attributed
                                    to "Maxime Thalet".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="CafeMom logo" /></div>
                            <div>
                                <p><span>CafeMom</span>: In 2014, the social network for mothers <a>CafeMom</a> suffered
                                    a data breach. The data surfaced alongside a number of other historical breaches
                                    including Kickstarter, Bitly and Disqus and contained 2.6 million email addresses
                                    and plain text passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="CafePress logo" /></div>
                            <div>
                                <p><span>CafePress</span>: In February 2019, the custom merchandise retailer
                                    <a>CafePress</a> suffered a data breach. The exposed data included 23 million unique
                                    email addresses with some records also containing names, physical addresses, phone
                                    numbers and passwords stored as SHA-1 hashes. The data was provided to HIBP by a
                                    source who requested it be attributed to "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Phone numbers,
                                    Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Canva logo" /></div>
                            <div>
                                <p><span>Canva</span>: In May 2019, the graphic design tool website <a>Canva suffered a
                                        data breach</a> that impacted 137 million subscribers. The exposed data included
                                    email addresses, usernames, names, cities of residence and passwords stored as
                                    bcrypt hashes for users not using social logins. The data was provided to HIBP by a
                                    source who requested it be attributed to "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Names,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="CashCrate logo" /></div>
                            <div>
                                <p><span>CashCrate</span>: In June 2017, news broke that <a>CashCrate had suffered a
                                        data breach exposing 6.8 million records</a>. The breach of the cash-for-surveys
                                    site dated back to November 2016 and exposed names, physical addresses, email
                                    addresses and passwords stored in plain text for older accounts along with weak MD5
                                    hashes for newer ones.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Physical
                                    addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="CDEK logo" /></div>
                            <div>
                                <p><span>CDEK<span> (<a>unverified</a>)</span></span>: In early 2022, a collective known
                                    as <a>IT Army whose stated goal is to "completely de-anonymise most Russian users by
                                        leaking hundreds of gigabytes of databases"</a> published over 30GB of data
                                    allegedly sourced from Russian courier service CDEK. The data contained over 19M
                                    unique email addresses along with names and phone numbers. The authenticity of the
                                    breach could not be independently established and has been flagged as "unverfieid".
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Chegg logo" /></div>
                            <div>
                                <p><span>Chegg</span>: In April 2018, the textbook rental service <a>Chegg suffered a
                                        data breach</a> that impacted 40 million subscribers. The exposed data included
                                    email addresses, usernames, names and passwords stored as unsalted MD5 hashes. The
                                    data was provided to HIBP by a source who requested it be attributed to
                                    "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        
                     
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Cit0day logo" /></div>
                            <div>
                                <p><span>Cit0day<span> (<a>unverified</a>)</span></span>: In November 2020, <a>a
                                        collection of more than 23,000 allegedly breached websites known as Cit0day were
                                        made available for download on several hacking forums</a>. The data consisted of
                                    226M unique email address alongside password pairs, often represented as both
                                    password hashes and the cracked, plain text versions. Independent verification of
                                    the data established it contains many legitimate, previously undisclosed breaches.
                                    The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ClearVoice Surveys logo" /></div>
                            <div>
                                <p><span>ClearVoice Surveys</span>: In April 2021, the market research surveys company
                                    <a>ClearVoice Surveys</a> had a publicly facing database backup from 2015 taken and
                                    redistributed on a popular hacking forum. The data included 15M unique email
                                    addresses across more than 17M rows of data that also included names, physical and
                                    IP addresses, genders, dates of birth and plain text passwords. ClearVoice Surveys
                                    advised they were aware of the breach and confirmed its authenticity.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, IP
                                    addresses, Names, Passwords, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ClixSense logo" /></div>
                            <div>
                                <p><span>ClixSense</span>: In September 2016, the paid-to-click site <a>ClixSense
                                        suffered a data breach</a> which exposed 2.4 million subscriber identities. The
                                    breached data was then posted online by the attackers who claimed it was a subset of
                                    a larger data breach totalling 6.6 million records. The leaked data was extensive
                                    and included names, physical, email and IP addresses, genders and birth dates,
                                    account balances and passwords stored as plain text.</p>
                                <p><strong>Compromised data:</strong> Account balances, Dates of birth, Email addresses,
                                    Genders, IP addresses, Names, Passwords, Payment histories, Payment methods,
                                    Physical addresses, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="CloudPets logo" /></div>
                            <div>
                                <p><span>CloudPets</span>: In January, the maker of teddy bears that record children's
                                    voices and sends them to family and friends via the internet <a>CloudPets left their
                                        database publicly exposed and it was subsequently downloaded by external
                                        parties</a> (the data was also subject to 3 different ransom demands). 583k
                                    records were provided to HIBP via a data trader and included email addresses and
                                    bcrypt hashes, but the full extent of user data exposed by the system was over 821k
                                    records and also included children's names and references to portrait photos and
                                    voice recordings.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Family members' names, Passwords
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Club Penguin Rewritten (January 2018) logo" /></div>
                            <div>
                                <p><span>Club Penguin Rewritten (January 2018)</span>: In January 2018, the children's
                                    gaming site <a>Club Penguin Rewritten</a> (CPRewritten) suffered a data breach
                                    (note: CPRewritten is an independent recreation of Disney's Club Penguin game). The
                                    incident exposed almost 1.7 million unique email addresses alongside IP addresses,
                                    usernames and passwords stored as bcrypt hashes. When contacted, CPRewritten advised
                                    they were aware of the breach and had "contacted affected users".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Club Penguin Rewritten (July 2019) logo" /></div>
                            <div>
                                <p><span>Club Penguin Rewritten (July 2019)</span>: In July 2019, the children's gaming
                                    site <a>Club Penguin Rewritten</a> (CPRewritten) suffered a data breach (note:
                                    CPRewritten is an independent recreation of Disney's Club Penguin game). In addition
                                    to an earlier data breach that impacted 1.7 million accounts, the subsequent breach
                                    exposed 4 million unique email addresses alongside IP addresses, usernames and
                                    passwords stored as bcrypt hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Coinmama logo" /></div>
                            <div>
                                <p><span>Coinmama</span>: In August 2017, the crypto coin brokerage service <a>Coinmama
                                        suffered a data breach</a> that impacted 479k subscribers. The breach was
                                    discovered in February 2019 with exposed data including email addresses, usernames
                                    and passwords stored as MD5 WordPress hashes. The data was provided to HIBP by white
                                    hat security researcher and data analyst Adam Davies.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="CoinMarketCap logo" /></div>
                            <div>
                                <p><span>CoinMarketCap</span>: During October 2021, 3.1 million email addresses with
                                    accounts on the cryptocurrency market capitalisation website <a>CoinMarketCap</a>
                                    were discovered being traded on hacking forums. Whilst the email addresses were
                                    found to correlate with CoinMarketCap accounts, it's unclear precisely how they were
                                    obtained. CoinMarketCap has provided the following statement on the data:
                                    "CoinMarketCap has become aware that batches of data have shown up online purporting
                                    to be a list of user accounts. While the data lists we have seen are only email
                                    addresses (no passwords), we have found a correlation with our subscriber base. We
                                    have not found any evidence of a data leak from our own servers — we are actively
                                    investigating this issue and will update our subscribers as soon as we have any new
                                    information."</p>
                                <p><strong>Compromised data:</strong> Email addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Collection #1 logo" /></div>
                            <div>
                                <p><span>Collection #1<span> (<a>unverified</a>)</span></span>: In January 2019, a large
                                    collection of credential stuffing lists (combinations of email addresses and
                                    passwords used to hijack accounts on other services) was discovered being
                                    distributed on a popular hacking forum. The data contained almost 2.7
                                    <em>billion</em> records including 773 million unique email addresses alongside
                                    passwords those addresses had used on other breached services. Full details on the
                                    incident and how to search the breached passwords are provided in the blog post
                                    <a>The 773 Million Record "Collection #1" Data Breach</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Coupon Mom / Armor Games logo" /></div>
                            <div>
                                <p><span>Coupon Mom / Armor Games<span> (<a>unverified</a>)</span></span>: In 2014, a
                                    file allegedly containing data hacked from <a>Coupon Mom</a> was created and
                                    included 11 million email addresses and plain text passwords. On further
                                    investigation, the file was also found to contain data indicating it had been
                                    sourced from <a>Armor Games</a>. Subsequent verification with HIBP subscribers
                                    confirmed the passwords had previously been used and many subscribers had used
                                    either Coupon Mom or Armor Games in the past. On disclosure to both organisations,
                                    each found that the data did not represent their entire customer base and possibly
                                    includes records from other sources with common subscribers. The breach has
                                    subsequently been flagged as "unverified" as the source cannot be emphatically
                                    proven. In July 2020, <a>the data was also found to contain BeerAdvocate accounts
                                        sourced from a previously unknown breach</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Covve logo" /></div>
                            <div>
                                <p><span>Covve</span>: In February 2020, <a>a massive trove of personal information
                                        referred to as "db8151dd"</a> was provided to HIBP after being found left
                                    exposed on a publicly facing Elasticsearch server. Later identified as originating
                                    from the Covve contacts app, the exposed data included extensive personal
                                    information and interactions between Covve users and their contacts. The data was
                                    provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Job titles, Names, Phone numbers,
                                    Physical addresses, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Cracked.to logo" /></div>
                            <div>
                                <p><span>Cracked.to</span>: In July 2019, the hacking website <a>Cracked.to</a> suffered
                                    a data breach. There were 749k unique email addresses spread across 321k forum users
                                    and other tables in the database. A rival hacking website claimed responsibility for
                                    breaching the MyBB based forum which disclosed email and IP addresses, usernames,
                                    private messages and passwords stored as bcrypt hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords, Private
                                    messages, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="CrackingForum logo" /></div>
                            <div>
                                <p><span>CrackingForum</span>: In approximately mid-2016, the cracking community forum
                                    known as <a>CrackingForum</a> suffered a data breach. The vBulletin based forum
                                    exposed 660k email and IP addresses, usernames and salted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Daily Quiz logo" /></div>
                            <div>
                                <p><span>Daily Quiz</span>: In January 2021, the quiz website <a>Daily Quiz</a> suffered
                                    a data breach that exposed over 8 million unique email addresses. The data also
                                    included usernames, IP addresses and passwords stored in plain text.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Dailymotion logo" /></div>
                            <div>
                                <p><span>Dailymotion</span>: In October 2016, the video sharing platform <a>Dailymotion
                                        suffered a data breach</a>. The attack led to the exposure of more than 85
                                    million user accounts and included email addresses, usernames and bcrypt hashes of
                                    passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="DaniWeb logo" /></div>
                            <div>
                                <p><span>DaniWeb</span>: In late 2015, the technology and social site <a>DaniWeb</a>
                                    suffered a data breach. The attack resulted in the disclosure of 1.1 million
                                    accounts including email and IP addresses which were also accompanied by salted MD5
                                    hashes of passwords. However, DaniWeb have advised that "the breached password
                                    hashes and salts are incorrect" and that they have since switched to new
                                    infrastructure and software.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Data &amp; Leads logo" /></div>
                            <div>
                                <p><span>Data &amp; Leads</span>: In November 2018, <a>security researcher Bob Diachenko
                                        identified an unprotected database believed to be hosted by a data
                                        aggregator</a>. Upon further investigation, the data was linked to marketing
                                    company <a>Data &amp; Leads</a>. The exposed Elasticsearch instance contained over
                                    44M unique email addresses along with names, IP and physical addresses, phone
                                    numbers and employment information. No response was received from Data &amp; Leads
                                    when contacted by Bob and their site subsequently went offline.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Employers, IP addresses, Job
                                    titles, Names, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Data Enrichment Exposure From PDL Customer logo" /></div>
                            <div>
                                <p><span>Data Enrichment Exposure From PDL Customer</span>: In October 2019, <a>security
                                        researchers Vinny Troia and Bob Diachenko identified an unprotected
                                        Elasticsearch server holding 1.2 billion records of personal data</a>. The
                                    exposed data included an index indicating it was sourced from data enrichment
                                    company People Data Labs (PDL) and contained 622 million unique email addresses. The
                                    server was not owned by PDL and it's believed a customer failed to properly secure
                                    the database. Exposed information included email addresses, phone numbers, social
                                    media profiles and job history data.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Employers, Geographic locations,
                                    Job titles, Names, Phone numbers, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="DataCamp logo" /></div>
                            <div>
                                <p><span>DataCamp</span>: In December 2018, the data science website <a>DataCamp
                                        suffered a data breach</a> of records dating back to January 2017. The incident
                                    exposed 760k unique email and IP addresses along with names and passwords stored as
                                    bcrypt hashes. In 2019, <a>the data appeared listed for sale on a dark web
                                        marketplace</a> (along with several other large breaches) and subsequently began
                                    circulating more broadly. The data was provided to HIBP by a source who requested it
                                    to be attributed to "BenjaminBlue@exploit.im".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, IP
                                    addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="DatPiff logo" /></div>
                            <div>
                                <p><span>DatPiff</span>: In late 2021, <a>email address and plain text password pairs
                                        from the rap mixtape website DatPiff appeared for sale on a popular hacking
                                        forum</a>. The data allegedly dated back to an earlier breach and in total,
                                    contained almost 7.5M email addresses and cracked password pairs. The original data
                                    source allegedly contained usernames, security questions and answers and passwords
                                    stored as MD5 hashes with a static salt.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Security questions and
                                    answers, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Deezer logo" /></div>
                            <div>
                                <p><span>Deezer</span>: In late 2022, the music streaming service <a>Deezer disclosed a
                                        data breach that impacted over 240M customers</a>. The breach dated back to a
                                    mid-2019 backup exposed by a 3rd party partner which was subsequently sold and then
                                    broadly redistributed on a popular hacking forum. Impacted data included 229M unique
                                    email addresses, IP addresses, names, usernames, genders, DoBs and the geographic
                                    location of the customer.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders,
                                    Geographic locations, IP addresses, Names, Spoken languages, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Demon Forums logo" /></div>
                            <div>
                                <p><span>Demon Forums</span>: In February 2019, the hacking forum <a>Demon Forums</a>
                                    suffered a data breach. The compromise of the vBulletin forum exposed 52k unique
                                    email addresses alongside usernames and passwords stored as salted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Descomplica logo" /></div>
                            <div>
                                <p><span>Descomplica</span>: In March 2021, the Brazilian EdTech company <a>Descomplica
                                        suffered a data breach</a> which was subsequently posted to a popular hacking
                                    forum. The data included almost 5 million email addresses, names, the first 6 and
                                    last 4 digits and the expiry date of credit cards, purchase histories and password
                                    hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Partial credit card data,
                                    Passwords, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="diet.com logo" /></div>
                            <div>
                                <p><span>diet.com</span>: In August 2014, the diet and nutrition website <a>diet.com</a>
                                    suffered a data breach resulting in the exposure of 1.4 million unique user records
                                    dating back as far as 2004. The data contained email and IP addresses, usernames,
                                    plain text passwords and dietary information about the site members including eating
                                    habits, BMI and birth date. The site was previously reported as compromised on the
                                    <a>Vigilante.pw</a> breached database directory.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Eating habits, Email addresses, IP
                                    addresses, Names, Passwords, Physical attributes, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Digimon logo" /></div>
                            <div>
                                <p><span>Digimon<span> (<a>spam list</a>)</span></span>: In September 2016, over 16GB of
                                    logs from a service indicated to be digimon.co.in were obtained, most likely from an
                                    unprotected Mongo DB instance. The service ceased running shortly afterwards and no
                                    information remains about the precise nature of it. Based on <a>enquiries made via
                                        Twitter</a>, it appears to have been a mail service possibly based on PowerMTA
                                    and used for delivering spam. The logs contained information including 7.7M unique
                                    email recipients (names and addresses), mail server IP addresses, email subjects and
                                    tracking information including mail opens and clicks.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Email messages, IP addresses,
                                    Names</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Disqus logo" /></div>
                            <div>
                                <p><span>Disqus</span>: In October 2017, the blog commenting service <a>Disqus announced
                                        they'd suffered a data breach</a>. The breach dated back to July 2012 but wasn't
                                    identified until years later when the data finally surfaced. The breach contained
                                    over 17.5 million unique email addresses and usernames. Users who created logins on
                                    Disqus had salted SHA1 hashes of passwords whilst users who logged in via social
                                    providers only had references to those accounts.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="DLH.net logo" /></div>
                            <div>
                                <p><span>DLH.net</span>: In July 2016, the gaming news site <a>DLH.net suffered a data
                                        breach</a> which exposed 3.3M subscriber identities. Along with the keys used to
                                    redeem and activate games on the Steam platform, the breach also resulted in the
                                    exposure of email addresses, birth dates and salted MD5 password hashes. The data
                                    was donated to Have I Been Pwned by data breach monitoring service
                                    <a>Vigilante.pw</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Names, Passwords,
                                    Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Domino's India logo" /></div>
                            <div>
                                <p><span>Domino's India</span>: In April 2021, <a>13TB of compromised Domino's India
                                        appeared for sale on a hacking forum</a> after which the company acknowledged a
                                    major data breach they dated back to March. The compromised data included 22.5
                                    million unique email addresses, names, phone numbers, order histories and physical
                                    addresses.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Phone numbers, Physical
                                    addresses, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="DriveSure logo" /></div>
                            <div>
                                <p><span>DriveSure</span>: In December 2020, the car dealership service provider
                                    <a>DriveSure suffered a data breach</a>. The incident resulted in 26GB of data being
                                    downloaded and later shared on a hacking forum. Impacted personal information
                                    included 3.6 million unique email addresses, names, phone numbers and physical
                                    addresses. Vehicle data was also exposed and included makes, models, VIN numbers and
                                    odometer readings. A small number of passwords stored as bcrypt hashes were also
                                    included in the data set.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Phone numbers,
                                    Physical addresses, Vehicle details</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Drizly logo" /></div>
                            <div>
                                <p><span>Drizly</span>: In approximately July 2020, the US-based online alcohol delivery
                                    service <a>Drizly suffered a data breach</a>. The data was sold online before being
                                    extensively redistributed and contained 2.5 million unique email addresses alongside
                                    names, physical and IP addresses, phone numbers, dates of birth and passwords stored
                                    as bcrypt hashes. The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Device information, Email
                                    addresses, IP addresses, Names, Passwords, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Dropbox logo" /></div>
                            <div>
                                <p><span>Dropbox</span>: In mid-2012, Dropbox suffered a data breach which exposed the
                                    stored credentials of tens of millions of their customers. In August 2016, <a>they
                                        forced password resets for customers they believed may be at risk</a>. A large
                                    volume of data totalling over 68 million records <a>was subsequently traded
                                        online</a> and included email addresses and salted hashes of passwords (half of
                                    them SHA1, half of them bcrypt).</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Dubsmash logo" /></div>
                            <div>
                                <p><span>Dubsmash</span>: In December 2018, the video messaging service <a>Dubsmash
                                        suffered a data breach</a>. The incident exposed 162 million unique email
                                    addresses alongside usernames and PBKDF2 password hashes. In 2019, the data appeared
                                    listed for sale on a dark web marketplace (along with several other large breaches)
                                    and subsequently began circulating more broadly. The data was provided to HIBP by a
                                    source who requested it to be attributed to "BenjaminBlue@exploit.im".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Names,
                                    Passwords, Phone numbers, Spoken languages, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Dueling Network logo" /></div>
                            <div>
                                <p><span>Dueling Network</span>: In March 2017, the Flash game based on the Yu-Gi-Oh
                                    trading card game <a>Dueling Network suffered a data breach</a>. The site itself was
                                    taken offline in 2016 due to a cease-and-desist order but the forum remained online
                                    for another year. The data breach exposed usernames, IP and email addresses and
                                    passwords stored as MD5 hashes. The data was provided to HIBP by a source who
                                    requested it be attributed to "burger vault".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Dungeons &amp; Dragons Online logo" /></div>
                            <div>
                                <p><span>Dungeons &amp; Dragons Online</span>: In April 2013, the interactive video game
                                    <a>Dungeons &amp; Dragons Online</a> suffered a data breach that exposed almost 1.6M
                                    players' accounts. The data was being actively traded on underground forums and
                                    included email addresses, birth dates and password hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Passwords, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Dunzo logo" /></div>
                            <div>
                                <p><span>Dunzo</span>: In approximately June 2019, the Indian delivery service <a>Dunzo
                                        suffered a data breach</a>. Exposing 3.5 million unique email addresses, the
                                    Dunzo breach also included names, phone numbers and IP addresses which were all
                                    broadly distributed online via a hacking forum. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Device information, Email addresses, Geographic
                                    locations, IP addresses, Names, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Eatigo logo" /></div>
                            <div>
                                <p><span>Eatigo</span>: In October 2018, the restaurant reservation service <a>Eatigo
                                        suffered a data breach that exposed 2.8 million accounts</a>. The data included
                                    email addresses, names, phone numbers, social media profiles, genders and passwords
                                    stored as unsalted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Names, Passwords, Phone
                                    numbers, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="EatStreet logo" /></div>
                            <div>
                                <p><span>EatStreet</span>: In May 2019, the online food ordering service <a>EatStreet
                                        suffered a data breach affecting 6.4 million customers</a>. An extensive amount
                                    of personal data was obtained including names, phone numbers, addresses, partial
                                    credit card data and passwords stored as bcrypt hashes. The data was provided to
                                    HIBP by a source who requested it be attributed to "JimScott.Sec@protonmail.com".
                                </p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, Names,
                                    Partial credit card data, Passwords, Phone numbers, Physical addresses, Social media
                                    profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Elanic logo" /></div>
                            <div>
                                <p><span>Elanic</span>: In January 2020, the Indian fashion marketplace <a>Elanic</a>
                                    had 2.8M records with 2.3M unique email addresses posted publicly to a popular
                                    hacking forum. Elanic confirmed that they had "verified the data and it was pulled
                                    from one of our test servers where this data was exposed publicly" and that the data
                                    was "old" (the hacking forum reported it as being from 2016-2018). When asked about
                                    disclosure to impacted customers, Elanic advised that they had "decided to not have
                                    as such any communication and public disclosure". </p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Usernames
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="EpicBot logo" /></div>
                            <div>
                                <p><span>EpicBot</span>: In September 2019, the RuneScape bot provider <a>EpicBot
                                        suffered a data breach that impacted 817k subscribers</a>. Data from the breach
                                    was subsequently shared on a popular hacking forum and included usernames, email and
                                    IP addresses and passwords stored as either salted MD5 or bcrypt hashes. EpicBot did
                                    not respond when contacted about the incident.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Epik logo" /></div>
                            <div>
                                <p><span>Epik</span>: In September 2021, <a>the domain registrar and web host Epik
                                        suffered a significant data breach</a>, allegedly in retaliation for hosting
                                    alt-right websites. The breach exposed a huge volume of data not just of Epik
                                    customers, but also scraped WHOIS records belonging to individuals and organisations
                                    who were not Epik customers. The data included over 15 million unique email
                                    addresses (including anonymised versions for domain privacy), names, phone numbers,
                                    physical addresses, purchases and passwords stored in various formats.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Phone numbers, Physical
                                    addresses, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Everybody Edits logo" /></div>
                            <div>
                                <p><span>Everybody Edits</span>: In March 2019, the multiplayer platform game
                                    <a>Everybody Edits suffered a data breach</a>. The incident exposed 871k unique
                                    email addresses alongside usernames and IP addresses. The data was subsequently
                                    distributed online across a collection of files.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Evony logo" /></div>
                            <div>
                                <p><span>Evony</span>: In June 2016, the online multiplayer game <a>Evony was hacked</a>
                                    and over 29 million unique accounts were exposed. The attack led to the exposure of
                                    usernames, email and IP addresses and MD5 hashes of passwords (without salt).</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Experian (2015) logo" /></div>
                            <div>
                                <p><span>Experian (2015)<span> (<a>unverified</a>)</span></span>: In September 2015, the
                                    US based credit bureau and consumer data broker <a>Experian suffered a data
                                        breach</a> that impacted 15 million customers who had applied for financing from
                                    T-Mobile. An alleged data breach was subsequently circulated containing personal
                                    information including names, physical and email addresses, birth dates and various
                                    other personal attributes. Multiple Have I Been Pwned subscribers verified portions
                                    of the data as being accurate, but the actual source of it was inconclusive therefor
                                    this breach has been flagged as "unverified".</p>
                                <p><strong>Compromised data:</strong> Credit status information, Dates of birth, Email
                                    addresses, Ethnicities, Family structure, Genders, Home ownership statuses, Income
                                    levels, IP addresses, Names, Phone numbers, Physical addresses, Purchasing habits
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Exploit.In logo" /></div>
                            <div>
                                <p><span>Exploit.In<span> (<a>unverified</a>)</span></span>: In late 2016, a huge list
                                    of email address and password pairs appeared in a "combo list" referred to as
                                    "Exploit.In". The list contained 593 million unique email addresses, many with
                                    multiple different passwords hacked from various online systems. The list was
                                    broadly circulated and used for "credential stuffing", that is attackers employ it
                                    in an attempt to identify other online systems where the account owner had reused
                                    their password. For detailed background on this incident, read <a>Password reuse,
                                        credential stuffing and another billion records in Have I Been Pwned</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Eye4Fraud logo" /></div>
                            <div>
                                <p><span>Eye4Fraud</span>: In February 2023, <a>data alleged to have been taken from the
                                        fraud protection service Eye4Fraud was listed for sale on a popular hacking
                                        forum</a>. Spanning tens of millions of rows with 16M unique email addresses,
                                    the data was spread across 147 tables totalling 65GB and included both direct users
                                    of the service and what appears to be individuals who'd placed orders on other
                                    services that implemented Eye4Fraud to protect their sales. The data included names
                                    and bcrypt password hashes for users, and names, phone numbers, physical addresses
                                    and partial credit card data (card type and last 4 digits) for orders placed using
                                    the service. Eye4Fraud did not respond to multiple attempts to report the incident.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Partial
                                    credit card data, Passwords, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="EyeEm logo" /></div>
                            <div>
                                <p><span>EyeEm</span>: In February 2018, <a>photography website EyeEm suffered a data
                                        breach</a>. The breach was identified among a collection of other large
                                    incidents and exposed almost 20M unique email addresses, names, usernames, bios and
                                    password hashes. The data was provided to HIBP by a source who asked for it to be
                                    attributed to "Kuroi'sh or Gabriel Kimiaie-Asadi Bildstein".</p>
                                <p><strong>Compromised data:</strong> Bios, Email addresses, Names, Passwords, Usernames
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="FashionFantasyGame logo" /></div>
                            <div>
                                <p><span>FashionFantasyGame</span>: In late 2016, the fashion gaming website <a>Fashion
                                        Fantasy Game suffered a data breach</a>. The incident exposed 2.3 million unique
                                    user accounts and corresponding MD5 password hashes with no salt. The data was
                                    contributed to Have I Been Pwned courtesy of rip@creep.im.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Flash Flash Revolution (2016 breach) logo" /></div>
                            <div>
                                <p><span>Flash Flash Revolution (2016 breach)</span>: In February 2016, the music-based
                                    rhythm game known as <a>Flash Flash Revolution</a> was hacked and 1.8M accounts were
                                    exposed. Along with email and IP addresses, the vBulletin forum also exposed salted
                                    MD5 password hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Flash Flash Revolution (2019 breach) logo" /></div>
                            <div>
                                <p><span>Flash Flash Revolution (2019 breach)</span>: In July 2019, the music-based
                                    rhythm game <a>Flash Flash Revolution</a> suffered a data breach. The 2019 breach
                                    imapcted almost 1.9 million members and is <em>in addition to</em> <a>the 2016 data
                                        breach of the same service</a>. Email and IP addesses, usernames, dates of birth
                                    and salted MD5 hashes were all exposed in the breach. The data was provided with
                                    support from <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="FlexBooker logo" /></div>
                            <div>
                                <p><span>FlexBooker</span>: In December 2021, the online booking service
                                    <a>FlexBooker</a> suffered a data breach that exposed 3.7 million accounts. The data
                                    included email addresses, names, phone numbers and for a small number of accounts,
                                    password hashes and partial credit card data. FlexBooker has identified the breach
                                    as originating from a compromised account within their AWS infrastructure. The data
                                    was found being actively traded on a popular hacking forum and was provided to HIBP
                                    by a source who requested it be attributed to "white_peacock@riseup.net".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Partial credit card data,
                                    Passwords, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Funimation logo" /></div>
                            <div>
                                <p><span>Funimation</span>: In July 2016, the anime site <a>Funimation</a> suffered a
                                    data breach that impacted 2.5 million accounts. The data contained usernames, email
                                    addresses, dates of birth and salted SHA1 hashes of passwords.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Gaadi logo" /></div>
                            <div>
                                <p><span>Gaadi</span>: In May 2015, the Indian motoring website known as <a>Gaadi</a>
                                    had 4.3 million records exposed in a data breach. The data contained usernames,
                                    email and IP addresses, genders, the city of users as well as passwords stored in
                                    both plain text and as MD5 hashes. The site was previously reported as compromised
                                    on the <a>Vigilante.pw</a> breached database directory.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Geographic locations, IP
                                    addresses, Names, Passwords, Phone numbers, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Gamerzplanet logo" /></div>
                            <div>
                                <p><span>Gamerzplanet</span>: In approximately October 2015, the online gaming forum
                                    known as <a>Gamerzplanet</a> was hacked and more than 1.2M accounts were exposed.
                                    The vBulletin forum included IP addresses and passwords stored as salted hashes
                                    using a weak implementation enabling many to be rapidly cracked.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="GameSalad logo" /></div>
                            <div>
                                <p><span>GameSalad</span>: In February 2019, the education and game creation website
                                    <a>Game Salad suffered a data breach</a>. The incident impacted 1.5M accounts and
                                    exposed email addresses, usernames, IP addresses and passwords stored as SHA-256
                                    hashes. The data was provided to HIBP by a source who requested it be attributed to
                                    "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Gawker logo" /></div>
                            <div>
                                <p><span>Gawker</span>: In December 2010, Gawker was attacked by the hacker collective
                                    "Gnosis" in retaliation for what was reported to be a feud between Gawker and 4Chan.
                                    Information about Gawkers 1.3M users was published along with the data from Gawker's
                                    other web presences including Gizmodo and Lifehacker. Due to the prevalence of
                                    password reuse, many victims of the breach <a>then had their Twitter accounts
                                        compromised to send Acai berry spam</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Weee logo" /></div>
                            <div>
                                <p><span>Weee</span>: In February 2023, <a>data belonging to the Asian and Hispanic food
                                        delivery service Weee appeared on a popular hacking forum</a>. Dating back to
                                    mid-2022, the data included 1.1M unique email addresses from 11M rows of orders
                                    containing names, phone numbers and delivery instructions.</p>
                                <p><strong>Compromised data:</strong> Delivery instructions, Email addresses, Names,
                                    Phone numbers, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
            </div>
        </div>
        <div>
            <div>
                <div>
                    <h3>Pastes you were found in</h3>
                    <p>
                        A <a>paste</a> is information that has been published to a
                        publicly facing website designed to share content and is often an early indicator of a data
                        breach. Pastes are automatically imported and often removed shortly after having been
                        posted. Using the <a>1Password password manager</a>
                        helps you ensure all your passwords are strong and unique such that a breach of one service
                        doesn't put your other services at risk.
                    </p>
                </div>
            </div>
        </div>
    </div>
    <div role="dialog">
        <div>
            <div>
                <div>
                    <button type="button">×</button>
                </div>
            </div>
        </div>
    </div>
    <div>
        <div>
            <div><span>674</span></div>
            <div><span>12,576,062,746</span></div>
            <div><span>115,747</span></div>
            <div><span>228,723,401</span></div>
        </div>
        <div>
            <div>
                <h3>Largest breaches</h3>
                <div>
                    <table>
                        <tbody>
                            <tr>
                                <td><img alt="Collection #1 logo" /></td>
                                <td>772,904,991</td>
                                <td><a>Collection #1 accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Verifications.io logo" /></td>
                                <td>763,117,241</td>
                                <td><a>Verifications.io accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Onliner Spambot logo" /></td>
                                <td>711,477,622</td>
                                <td><a>Onliner Spambot accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Data Enrichment Exposure From PDL Customer logo" /></td>
                                <td>622,161,052</td>
                                <td><a>Data Enrichment Exposure From PDL Customer accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Exploit.In logo" /></td>
                                <td>593,427,119</td>
                                <td><a>Exploit.In accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Facebook logo" /></td>
                                <td>509,458,528</td>
                                <td><a>Facebook accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Anti Public Combo List logo" /></td>
                                <td>457,962,538</td>
                                <td><a>Anti Public Combo List accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="River City Media Spam List logo" /></td>
                                <td>393,430,309</td>
                                <td><a>River City Media Spam List accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="MySpace logo" /></td>
                                <td>359,420,698</td>
                                <td><a>MySpace accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Wattpad logo" /></td>
                                <td>268,765,495</td>
                                <td><a>Wattpad accounts</a></td>
                            </tr>
                        </tbody>
                    </table>
                </div>
            </div>
            <div>
                <h3>Recently added breaches</h3>
                <div>
                    <table>
                        <tbody>
                            <tr>
                                <td><img alt="Luxottica logo" /></td>
                                <td>77,093,812</td>
                                <td><a>Luxottica accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="RentoMojo logo" /></td>
                                <td>2,185,697</td>
                                <td><a>RentoMojo accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="CityJerks logo" /></td>
                                <td>177,554</td>
                                <td><a>CityJerks accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="MEO logo" /></td>
                                <td>8,227</td>
                                <td><a>MEO accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Terravision logo" /></td>
                                <td>2,075,625</td>
                                <td><a>Terravision accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="OGUsers (2022 breach) logo" /></td>
                                <td>529,020</td>
                                <td><a>OGUsers (2022 breach) accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="The Kodi Foundation logo" /></td>
                                <td>400,635</td>
                                <td><a>The Kodi Foundation accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Genesis Market logo" /></td>
                                <td>8,000,000</td>
                                <td><a>Genesis Market accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Sundry Files logo" /></td>
                                <td>274,461</td>
                                <td><a>Sundry Files accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Leaked Reality logo" /></td>
                                <td>114,907</td>
                                <td><a>Leaked Reality accounts</a></td>
                            </tr>
                        </tbody>
                    </table>
                </div>
            </div>
        </div>
    </div>
    <div role="dialog">
        <div>
            <div>
                <div>
                    <button type="button">×</button>
                    <h4>Notify me</h4>
                </div>
                <div>
                    <div>
                        <form role="form">
                            <p>
                                Get notified when future pwnage occurs and your account is compromised.
                            </p>
                            <div>
                                <div>
                                    <input name="NotifyEmail" placeholder="enter your email address" type="email" />
                                </div>
                            </div>
                            <div>
                                <div>
                                    <div>
                                        <div><iframe name="a-264q2ixba10l" title="reCAPTCHA" /></div><textarea
                                            name="g-recaptcha-response" />
                                    </div>
                                </div>
                            </div>
                            <div>
                                <input type="submit" value="notify me of pwnage" />
                            </div>
                        </form>
                    </div>
                    <div>
                        <p>
                            You've just been sent a verification email, all you need to do now is confirm your
                            address by clicking on the link when it hits your mailbox and you'll be automatically
                            notified of future pwnage. In case it doesn't show up, check your junk mail and if
                            you <em>still</em> can't find it, you can always repeat this process.
                        </p>
                        <p>
                            <a>add another address</a>
                        </p>
                    </div>
                </div>
            </div>
        </div>
    </div>
    <footer>
        <div>
            <p>
                <a>A troyhunt.com project</a>
            </p>
        </div>
    </footer>
    <div>
        <div><iframe name="c-264q2ixba10l" title="recaptcha challenge expires in two minutes" /></div>
    </div>
</body>

</html>