<html>

<head>
    <title>Have I Been Pwned: Check if your email has been compromised in a data breach</title>
</head>

<body>
    <div>
        <header>
            <div>
                <div>
                    <button type="button">
                    </button>
                    <a>';--</a>
                </div>
                <div>
                    <ul>
                        <li><a>Home</a></li>
                        <li><a>Notify me</a></li>
                        <li><a>Domain search</a></li>
                        <li><a>Who's been pwned</a></li>
                        <li><a>Passwords</a></li>
                        <li>
                            <a>API</a>
                            <ul>
                                <li><a>Overview</a></li>
                                <li><a>API key</a></li>
                                <li><a>Terms of use</a></li>
                            </ul>
                        </li>
                        <li>
                            <a>About</a>
                            <ul>
                                <li><a>Who, what &amp; why</a></li>
                                <li><a>Privacy</a></li>
                                <li><a>FAQs</a></li>
                                <li><a>Pastes</a></li>
                                <li><a>Opt-out</a></li>
                                <li><a>Twitter</a></li>
                                <li><a>Facebook</a></li>
                                <li><a>Mastodon</a></li>
                                <li><a>Suggest a feature</a></li>
                            </ul>
                        </li>
                        <li><a>Donate </a></li>
                    </ul>
                </div>
            </div>
        </header>
        <div>
            <div>
                <div>
                    <div>
                        <span>';--have i been pwned?</span>
                    </div>
                    <p>Check if your email or phone is in a data breach</p>
                </div>
            </div>
        </div>
        <div>
            <div>
                <form>
                    <div><iframe title="Widget containing a Cloudflare security challenge" /><input
                            name="cf-turnstile-response" /></div>
                    <div>
                        <input name="Account" placeholder="email address" type="email" />
                        <input name="apiEndpoint" value="https://haveibeenpwned.com/unifiedsearch/" />
                        <span>
                            <button type="submit">pwned?</button>
                        </span>
                    </div>
                    <div>
                        <div role="progressbar">
                        </div>
                    </div>
                </form>
            </div>
        </div>
        <div>
            <div>
                <p>
                    <img alt="1Password Logo" />
                    <span>Generate secure, unique passwords for every account</span>
                    <a>Learn more at 1Password.com</a>
                </p>
                <p><a>Why 1Password?</a></p>
            </div>
        </div>
    </div>
    <div>
        <div>
            <div>
                <div>
                    <h2>Good news — no pwnage found!</h2>
                    <p>
                        No <a>breached accounts</a>
                        <span>and no <a>pastes</a> (<a>subscribe</a> to search sensitive breaches)</span>
                    </p>
                </div>
                <div>
                    <div>
                        <div>
                            <img alt="1Password Logo" />
                            <h3>3 Steps to better security</h3>
                        </div>
                        <div>
                            <a>Start using 1Password.com</a>
                        </div>
                    </div>
                    <div>
                        <div>
                            <p>
                                <a>
                                    <img alt="Step 1" /><strong>Step 1</strong> Protect yourself using 1Password to
                                    generate and save strong passwords for each website.
                                </a>
                            </p>
                        </div>
                        <div>
                            <p>
                                <a>
                                    <img alt="Step 2" /><strong>Step 2</strong> Enable 2 factor authentication and store
                                    the codes inside your 1Password account.
                                </a>
                            </p>
                        </div>
                        <div>
                            <p>
                                <a>
                                    <img alt="Step 3" /><strong>Step 3</strong> <span>Subscribe</span> to notifications
                                    for any other breaches. Then just change that unique password.
                                </a>
                            </p>
                        </div>
                    </div>
                    <div>
                        <div>
                            <p><a>Why 1Password?</a></p>
                        </div>
                    </div>
                </div>
            </div>
        </div>
    </div>
    <div>
        <div>
            <div>
                <div>
                    <div>
                        <h2>
                            Oh no — pwned!
                        </h2>
                        <p>Pwned in 3 <a>data breaches</a> and found no <a>pastes</a> (<a>subscribe</a> to search
                            sensitive breaches)</p>
                    </div>
                    <div>
                        <div>
                            <div>
                                <img alt="1Password Logo" />
                                <h3>3 Steps to better security</h3>
                            </div>
                            <div>
                                <a>Start using 1Password.com</a>
                            </div>
                        </div>
                        <div>
                            <div>
                                <p>
                                    <a>
                                        <img alt="Step 1" /><strong>Step 1</strong> Protect yourself using 1Password to
                                        generate and save strong passwords for each website.
                                    </a>
                                </p>
                            </div>
                            <div>
                                <p>
                                    <a>
                                        <img alt="Step 2" /><strong>Step 2</strong> Enable 2 factor authentication and
                                        store the codes inside your 1Password account.
                                    </a>
                                </p>
                            </div>
                            <div>
                                <p>
                                    <a>
                                        <img alt="Step 3" /><strong>Step 3</strong> <span>Subscribe</span> to
                                        notifications for any other breaches. Then just change that unique password.
                                    </a>
                                </p>
                            </div>
                        </div>
                        <div>
                            <div>
                                <p><a>Why 1Password?</a></p>
                            </div>
                        </div>
                    </div>
                </div>
            </div>
        </div>
        <div>
            <div>
                <div>
                    <h3>Breaches you were pwned in</h3>
                    <p>
                        A "breach" is an incident where data has been unintentionally exposed to the
                        public. Using the <a>1Password password manager</a>
                        helps you ensure all your passwords are strong and unique such that a breach of one service
                        doesn't put your other services at risk.
                    </p>
                </div>
            </div>
            <div>
                <div>
                    <div>
                        <div>
                            <div><img alt="000webhost logo" /></div>
                            <div>
                                <p><span>000webhost</span>: In approximately March 2015, the free web hosting provider
                                    <a>000webhost suffered a major data breach</a> that exposed almost 15 million
                                    customer records. The data was sold and traded before 000webhost was alerted in
                                    October. The breach included names, email addresses and plain text passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Passwords
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="123RF logo" /></div>
                            <div>
                                <p><span>123RF</span>: In March 2020, the stock photo site <a>123RF suffered a data
                                        breach</a> which impacted over 8 million subscribers and was subsequently sold
                                    online. The breach included email, IP and physical addresses, names, phone numbers
                                    and passwords stored as MD5 hashes. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Passwords,
                                    Phone numbers, Physical addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="17 logo" /></div>
                            <div>
                                <p><span>17</span>: In April 2016, customer data obtained from the streaming app known
                                    as "17" <a>appeared listed for sale on a Tor hidden service marketplace</a>. The
                                    data contained over 4 million unique email addresses along with IP addresses,
                                    usernames and passwords stored as unsalted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Device information, Email addresses, IP addresses,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="2,844 Separate Data Breaches logo" /></div>
                            <div>
                                <p><span>2,844 Separate Data Breaches<span> (<a>unverified</a>)</span></span>: In
                                    February 2018, <a>a massive collection of almost 3,000 alleged data breaches was
                                        found online</a>. Whilst some of the data had previously been seen in Have I
                                    Been Pwned, 2,844 of the files consisting of more than 80 million unique email
                                    addresses had not previously been seen. Each file contained both an email address
                                    and plain text password and were consequently loaded as a single "unverified" data
                                    breach.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="500px logo" /></div>
                            <div>
                                <p><span>500px</span>: In mid-2018, the online photography community <a>500px suffered a
                                        data breach</a>. The incident exposed almost 15 million unique email addresses
                                    alongside names, usernames, genders, dates of birth and either an MD5 or bcrypt
                                    password hash. In 2019, <a>the data appeared listed for sale on a dark web
                                        marketplace</a> (along with several other large breaches) and subsequently began
                                    circulating more broadly. The data was provided to HIBP by a source who requested it
                                    to be attributed to "BenjaminBlue@exploit.im".</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders,
                                    Geographic locations, Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="8fit logo" /></div>
                            <div>
                                <p><span>8fit</span>: In July 2018, the health and fitness service <a>8fit suffered a
                                        data breach</a>. The data subsequently appeared for sale on a dark web
                                    marketplace in February 2019 and included over 15M unique email addresses alongside
                                    names, genders, IP addresses and passwords stored as bcrypt hashes. The data was
                                    provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Geographic locations, IP
                                    addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="8tracks logo" /></div>
                            <div>
                                <p><span>8tracks</span>: In June 2017, the online playlists service known as <a>8Tracks
                                        suffered a data breach</a> which impacted 18 million accounts. In their
                                    disclosure, 8Tracks advised that "the vector for the attack was an employee’s GitHub
                                    account, which was not secured using two-factor authentication". Salted SHA-1
                                    password hashes for users who <em>didn't</em> sign up with either Google or Facebook
                                    authentication were also included. The data was provided to HIBP by whitehat
                                    security researcher and data analyst Adam Davies and contained almost 8 million
                                    unique email addresses. The complete set of 18M records was later provided by
                                    JimScott.Sec@protonmail.com and updated in HIBP accordingly.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="AbuseWith.Us logo" /></div>
                            <div>
                                <p><span>AbuseWith.Us</span>: In 2016, the site dedicated to helping people hack email
                                    and online gaming accounts known as Abusewith.us suffered multiple data breaches.
                                    The site <a>allegedly had an administrator in common with the nefarious LeakedSource
                                        site</a>, both of which have since been shut down. The exposed data included
                                    more than 1.3 million unique email addresses, often accompanied by usernames, IP
                                    addresses and plain text or hashed passwords retrieved from various sources and
                                    intended to be used to compromise the victims' accounts.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Acne.org logo" /></div>
                            <div>
                                <p><span>Acne.org</span>: In November 2014, the acne website <a>acne.org</a> suffered a
                                    data breach that exposed over 430k forum members' accounts. The data was being
                                    actively traded on underground forums and included email addresses, birth dates and
                                    passwords.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ActMobile logo" /></div>
                            <div>
                                <p><span>ActMobile<span> (<a>unverified</a>)</span></span>: In October 2021, <a>security
                                        researcher Bob Diachenko discovered an exposed database he attributed to
                                        ActMobile, the operators of Dash VPN and FreeVPN</a>. The exposed data included
                                    1.6 million unique email addresses along with IP addresses and password hashes, all
                                    of which were subsequently leaked on a popular hacking forum. Although usage of the
                                    service was verified by HIBP subscribers, <a>ActMobile denied the data was sourced
                                        from them</a> and the breach has subsequently been flagged as "unverified".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Aditya Birla Fashion and Retail logo" /></div>
                            <div>
                                <p><span>Aditya Birla Fashion and Retail</span>: In December 2021, Indian retailer
                                    <a>Aditya Birla Fashion and Retail Ltd was breached and ransomed</a>. The ransom
                                    demand was allegedly rejected and data containing 5.4M unique email addresses was
                                    subsequently dumped publicly on a popular hacking forum the next month. The data
                                    contained extensive personal customer information including names, phone numbers,
                                    physical addresses, DoBs, order histories and passwords stored as MD5 hashes.
                                    Employee data was also dumped publicly and included salary grades, marital statuses
                                    and religions. The data was provided to HIBP by a source who requested it be
                                    attributed to "white_peacock@riseup.net".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Income levels, Job
                                    titles, Marital statuses, Names, Passwords, Phone numbers, Physical addresses,
                                    Purchases, Religions, Salutations</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Adobe logo" /></div>
                            <div>
                                <p><span>Adobe</span>: In October 2013, 153 million Adobe accounts were breached with
                                    each containing an internal ID, username, email, <em>encrypted</em> password and a
                                    password hint in plain text. The password cryptography was poorly done and many were
                                    quickly resolved back to plain text. The unencrypted hints also <a>disclosed much
                                        about the passwords</a> adding further to the risk that hundreds of millions of
                                    Adobe customers already faced.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Password hints, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Animal Jam logo" /></div>
                            <div>
                                <p><span>Animal Jam</span>: In October 2020, the online game for kids <a>Animal Jam
                                        suffered a data breach</a> which was subsequently shared through online hacking
                                    communities the following month. The data contained 46 million user accounts with
                                    over 7 million unique email addresses. Impacted data also included usernames, IP
                                    addresses and for some records, dates of birth (sometimes in partial form), physical
                                    addresses, parent names and passwords stored as PBKDF2 hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, IP
                                    addresses, Names, Passwords, Physical addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="AnimeGame logo" /></div>
                            <div>
                                <p><span>AnimeGame</span>: In February 2020, the gaming website <a>AnimeGame</a>
                                    suffered a data breach. The incident affected 1.4M subscribers and exposed email
                                    addresses, usernames and passwords stored as salted MD5 hashes. The data was
                                    subsequently shared on a popular hacking forum and was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Animoto logo" /></div>
                            <div>
                                <p><span>Animoto</span>: In July 2018, the cloud-based video making service <a>Animoto
                                        suffered a data breach</a>. The breach exposed 22 million unique email addresses
                                    alongside names, dates of birth, country of origin and salted password hashes. The
                                    data was provided to HIBP by a source who requested it be attributed to
                                    "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Geographic
                                    locations, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Apollo logo" /></div>
                            <div>
                                <p><span>Apollo</span>: In July 2018, the sales engagement startup <a>Apollo left a
                                        database containing billions of data points publicly exposed without a
                                        password</a>. The data was discovered by security researcher <a>Vinny Troia</a>
                                    who subsequently sent a subset of the data containing 126 million unique email
                                    addresses to Have I Been Pwned. The data left exposed by Apollo was used in their
                                    "revenue acceleration platform" and included personal information such as names and
                                    email addresses as well as professional information including places of employment,
                                    the roles people hold and where they're located. Apollo stressed that the exposed
                                    data did not include sensitive information such as passwords, social security
                                    numbers or financial data. <a>The Apollo website has a contact form</a> for those
                                    looking to get in touch with the organisation.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Employers, Geographic locations,
                                    Job titles, Names, Phone numbers, Salutations, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Appen logo" /></div>
                            <div>
                                <p><span>Appen</span>: In June 2020, the AI training data company <a>Appen suffered a
                                        data breach</a> exposing the details of almost 5.9 million users which were
                                    subsequently sold online. Included in the breach were names, email addresses and
                                    passwords stored as bcrypt hashes. Some records also contained phone numbers,
                                    employers and IP addresses. The data was provided to HIBP by <a>dehashed.com</a>.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, Employers, IP addresses, Names,
                                    Passwords, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Aptoide logo" /></div>
                            <div>
                                <p><span>Aptoide</span>: In April 2020, the independent Android app store <a>Aptoide
                                        suffered a data breach</a>. The incident resulted in the exposure of 20M
                                    customer records which were subsequently shared online via a popular hacking forum.
                                    Impacted data included email and IP addresses, names, IP addresses and passwords
                                    stored as SHA-1 hashes without a salt.</p>
                                <p><strong>Compromised data:</strong> Browser user agent details, Email addresses, IP
                                    addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Armor Games logo" /></div>
                            <div>
                                <p><span>Armor Games</span>: In January 2019, the game portal website <a>Armor Games
                                        suffered a data breach</a>. A total of 10.6 million email addresses were
                                    impacted by the breach which also exposed usernames, IP addresses, birthdays of
                                    administrator accounts and passwords stored as salted SHA-1 hashes. The data was
                                    provided to HIBP by a source who requested it be attributed to
                                    "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Bios, Dates of birth, Email addresses, Genders,
                                    Geographic locations, IP addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Army Force Online logo" /></div>
                            <div>
                                <p><span>Army Force Online</span>: In May 2016, the online gaming site <a>Army Force
                                        Online</a> suffered a data breach that exposed 1.5M accounts. The breached data
                                    was found being regularly traded online and included usernames, email and IP
                                    addresses and MD5 passwords.</p>
                                <p><strong>Compromised data:</strong> Avatars, Email addresses, Geographic locations, IP
                                    addresses, Names, Passwords, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Artsy logo" /></div>
                            <div>
                                <p><span>Artsy</span>: In April 2018, the online arts database <a>Artsy suffered a data
                                        breach which consequently appeared for sale on a dark web marketplace</a>. Over
                                    1M accounts were impacted and included IP and email addresses, names and passwords
                                    stored as salted SHA-512 hashes. The data was provided to HIBP by a source who
                                    requested it be attributed to "nano@databases.pw".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Passwords
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Audi logo" /></div>
                            <div>
                                <p><span>Audi</span>: In August 2019, <a>Audi USA suffered a data breach after a vendor
                                        left data unsecured and exposed on the internet</a>. The data contained 2.7M
                                    unique email addresses along with names, phone numbers, physical addresses and
                                    vehicle information including VIN. In <a>a disclosure statement from Audi</a>, they
                                    also advised some customers had driver's licenses, dates of birth, social security
                                    numbers and other personal information exposed.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Driver's licenses, Email
                                    addresses, Names, Phone numbers, Physical addresses, Social security numbers,
                                    Vehicle details</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="bigbasket logo" /></div>
                            <div>
                                <p><span>bigbasket</span>: In October 2020, the Indian grocery platform <a>bigbasket
                                        suffered a data breach that exposed over 20 million customer records</a>. The
                                    data was originally sold before being leaked publicly in April the following year
                                    and included email, IP and physical addresses, names, phones numbers, dates of birth
                                    passwords stored as Django(SHA-1) hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Names, Passwords, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bin Weevils logo" /></div>
                            <div>
                                <p><span>Bin Weevils</span>: In September 2014, the online game <a>Bin Weevils suffered
                                        a data breach</a>. Whilst originally stating that only usernames and passwords
                                    had been exposed, <a>a subsequent story on DataBreaches.net indicated that a more
                                        extensive set of personal attributes were impacted</a> (comments there also
                                    suggest the data may have come from a later breach). Data matching that pattern was
                                    later provided to Have I Been Pwned by <a>@akshayindia6</a> and included almost 1.3m
                                    unique email addresses, genders, ages and plain text passwords.</p>
                                <p><strong>Compromised data:</strong> Ages, Email addresses, Genders, IP addresses,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bitcoin Security Forum Gmail Dump logo" /></div>
                            <div>
                                <p><span>Bitcoin Security Forum Gmail Dump</span>: In September 2014, a large dump of
                                    nearly 5M usernames and passwords was <a>posted to a Russian Bitcoin forum</a>.
                                    Whilst commonly reported as 5M "Gmail passwords", the dump also contained 123k
                                    yandex.ru addresses. Whilst the origin of the breach remains unclear, the breached
                                    credentials were <a>confirmed by multiple source as correct</a>, albeit a number of
                                    years old.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bitly logo" /></div>
                            <div>
                                <p><span>Bitly</span>: In May 2014, the link management company <a>Bitly announced
                                        they'd suffered a data breach</a>. The breach contained over 9.3 million unique
                                    email addresses, usernames and hashed passwords, most using SHA1 with a small number
                                    using bcrypt.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="BlackSpigotMC logo" /></div>
                            <div>
                                <p><span>BlackSpigotMC</span>: In July 2019, the hacking website <a>BlackSpigotMC
                                        suffered a data breach</a>. The XenForo forum based site was allegedly
                                    compromised by a rival hacking website and resulted in 8.5GB of data being leaked
                                    including the database and website itself. The exposed data included 140k unique
                                    email addresses, usernames, IP addresses, genders, geographic locations and
                                    passwords stored as bcrypt hashes.</p>
                                <p><strong>Compromised data:</strong> Device information, Email addresses, Genders,
                                    Geographic locations, IP addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="BlankMediaGames logo" /></div>
                            <div>
                                <p><span>BlankMediaGames</span>: In December 2018, the Town of Salem website produced by
                                    <a>BlankMediaGames suffered a data breach</a>. Reported to HIBP by <a>DeHashed</a>,
                                    the data contained 7.6M unique user email addresses alongside usernames, IP
                                    addresses, purchase histories and passwords stored as phpass hashes. DeHashed made
                                    multiple attempts to contact BlankMediaGames over various channels and many days but
                                    had yet to receive a response at the time of publishing.</p>
                                <p><strong>Compromised data:</strong> Browser user agent details, Email addresses, IP
                                    addresses, Passwords, Purchases, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bombuj.eu logo" /></div>
                            <div>
                                <p><span>Bombuj.eu</span>: In December 2018, the Slovak website for watching movies
                                    online for free <a>Bombuj.eu</a> suffered a data breach. The incident exposed over
                                    575k unique email addresses and passwords stored as unsalted MD5 hashes. No response
                                    was received from Bombuj.eu when contacted about the incident.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bonobos logo" /></div>
                            <div>
                                <p><span>Bonobos</span>: In August 2020, the clothing store <a>Bonobos suffered a data
                                        breach</a> that exposed almost 70GB of data containing 2.8 million unique email
                                    addresses. The breach also exposed names, physical and IP addresses, phone numbers,
                                    order histories and passwords stored as salted SHA-512 hashes, including historical
                                    passwords. The breach also exposed partial credit card data including card type, the
                                    name on the card, expiry date and the last 4 digits of the card. The data was
                                    provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Historical passwords, IP
                                    addresses, Names, Partial credit card data, Passwords, Phone numbers, Physical
                                    addresses, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bookmate logo" /></div>
                            <div>
                                <p><span>Bookmate</span>: In mid-2018, the social ebook subscription service <a>Bookmate
                                        was among a raft of sites that were breached and their data then sold in
                                        early-2019</a>. The data included almost 4 million unique email addresses
                                    alongside names, genders, dates of birth and passwords stored as salted SHA-512
                                    hashes. The data was provided to HIBP by a source who requested it to be attributed
                                    to "BenjaminBlue@exploit.im".</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders,
                                    Geographic locations, Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bourse des Vols logo" /></div>
                            <div>
                                <p><span>Bourse des Vols</span>: In January 2021, the French travel company <a>Bourse
                                        des Vols suffered a data breach that exposed 1.46M unique email addresses</a>
                                    across more than 1.2k .sql files and over 9GB of data. The impacted data exposed
                                    personal information and travel histories including names, phone numbers, IP and
                                    physical addresses, dates of birth along with flights taken and purchases.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Flights taken, IP
                                    addresses, Names, Phone numbers, Physical addresses, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Bukalapak logo" /></div>
                            <div>
                                <p><span>Bukalapak</span>: In March 2019, the Indonesian e-commerce website <a>Bukalapak
                                        discovered a data breach of the organisation's backups dating back to October
                                        2017</a>. The incident exposed approximately 13 million unique email addresses
                                    alongside IP addresses, names and passwords stored as bcrypt and salted SHA-512
                                    hashes. The data was provided to HIBP by a source who requested it to be attributed
                                    to "Maxime Thalet".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="CafeMom logo" /></div>
                            <div>
                                <p><span>CafeMom</span>: In 2014, the social network for mothers <a>CafeMom</a> suffered
                                    a data breach. The data surfaced alongside a number of other historical breaches
                                    including Kickstarter, Bitly and Disqus and contained 2.6 million email addresses
                                    and plain text passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="CafePress logo" /></div>
                            <div>
                                <p><span>CafePress</span>: In February 2019, the custom merchandise retailer
                                    <a>CafePress</a> suffered a data breach. The exposed data included 23 million unique
                                    email addresses with some records also containing names, physical addresses, phone
                                    numbers and passwords stored as SHA-1 hashes. The data was provided to HIBP by a
                                    source who requested it be attributed to "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Phone numbers,
                                    Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Canva logo" /></div>
                            <div>
                                <p><span>Canva</span>: In May 2019, the graphic design tool website <a>Canva suffered a
                                        data breach</a> that impacted 137 million subscribers. The exposed data included
                                    email addresses, usernames, names, cities of residence and passwords stored as
                                    bcrypt hashes for users not using social logins. The data was provided to HIBP by a
                                    source who requested it be attributed to "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Names,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="CashCrate logo" /></div>
                            <div>
                                <p><span>CashCrate</span>: In June 2017, news broke that <a>CashCrate had suffered a
                                        data breach exposing 6.8 million records</a>. The breach of the cash-for-surveys
                                    site dated back to November 2016 and exposed names, physical addresses, email
                                    addresses and passwords stored in plain text for older accounts along with weak MD5
                                    hashes for newer ones.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Physical
                                    addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="CDEK logo" /></div>
                            <div>
                                <p><span>CDEK<span> (<a>unverified</a>)</span></span>: In early 2022, a collective known
                                    as <a>IT Army whose stated goal is to "completely de-anonymise most Russian users by
                                        leaking hundreds of gigabytes of databases"</a> published over 30GB of data
                                    allegedly sourced from Russian courier service CDEK. The data contained over 19M
                                    unique email addresses along with names and phone numbers. The authenticity of the
                                    breach could not be independently established and has been flagged as "unverfieid".
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Chegg logo" /></div>
                            <div>
                                <p><span>Chegg</span>: In April 2018, the textbook rental service <a>Chegg suffered a
                                        data breach</a> that impacted 40 million subscribers. The exposed data included
                                    email addresses, usernames, names and passwords stored as unsalted MD5 hashes. The
                                    data was provided to HIBP by a source who requested it be attributed to
                                    "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Cit0day logo" /></div>
                            <div>
                                <p><span>Cit0day<span> (<a>unverified</a>)</span></span>: In November 2020, <a>a
                                        collection of more than 23,000 allegedly breached websites known as Cit0day were
                                        made available for download on several hacking forums</a>. The data consisted of
                                    226M unique email address alongside password pairs, often represented as both
                                    password hashes and the cracked, plain text versions. Independent verification of
                                    the data established it contains many legitimate, previously undisclosed breaches.
                                    The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ClearVoice Surveys logo" /></div>
                            <div>
                                <p><span>ClearVoice Surveys</span>: In April 2021, the market research surveys company
                                    <a>ClearVoice Surveys</a> had a publicly facing database backup from 2015 taken and
                                    redistributed on a popular hacking forum. The data included 15M unique email
                                    addresses across more than 17M rows of data that also included names, physical and
                                    IP addresses, genders, dates of birth and plain text passwords. ClearVoice Surveys
                                    advised they were aware of the breach and confirmed its authenticity.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, IP
                                    addresses, Names, Passwords, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ClixSense logo" /></div>
                            <div>
                                <p><span>ClixSense</span>: In September 2016, the paid-to-click site <a>ClixSense
                                        suffered a data breach</a> which exposed 2.4 million subscriber identities. The
                                    breached data was then posted online by the attackers who claimed it was a subset of
                                    a larger data breach totalling 6.6 million records. The leaked data was extensive
                                    and included names, physical, email and IP addresses, genders and birth dates,
                                    account balances and passwords stored as plain text.</p>
                                <p><strong>Compromised data:</strong> Account balances, Dates of birth, Email addresses,
                                    Genders, IP addresses, Names, Passwords, Payment histories, Payment methods,
                                    Physical addresses, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="CloudPets logo" /></div>
                            <div>
                                <p><span>CloudPets</span>: In January, the maker of teddy bears that record children's
                                    voices and sends them to family and friends via the internet <a>CloudPets left their
                                        database publicly exposed and it was subsequently downloaded by external
                                        parties</a> (the data was also subject to 3 different ransom demands). 583k
                                    records were provided to HIBP via a data trader and included email addresses and
                                    bcrypt hashes, but the full extent of user data exposed by the system was over 821k
                                    records and also included children's names and references to portrait photos and
                                    voice recordings.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Family members' names, Passwords
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Club Penguin Rewritten (January 2018) logo" /></div>
                            <div>
                                <p><span>Club Penguin Rewritten (January 2018)</span>: In January 2018, the children's
                                    gaming site <a>Club Penguin Rewritten</a> (CPRewritten) suffered a data breach
                                    (note: CPRewritten is an independent recreation of Disney's Club Penguin game). The
                                    incident exposed almost 1.7 million unique email addresses alongside IP addresses,
                                    usernames and passwords stored as bcrypt hashes. When contacted, CPRewritten advised
                                    they were aware of the breach and had "contacted affected users".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Club Penguin Rewritten (July 2019) logo" /></div>
                            <div>
                                <p><span>Club Penguin Rewritten (July 2019)</span>: In July 2019, the children's gaming
                                    site <a>Club Penguin Rewritten</a> (CPRewritten) suffered a data breach (note:
                                    CPRewritten is an independent recreation of Disney's Club Penguin game). In addition
                                    to an earlier data breach that impacted 1.7 million accounts, the subsequent breach
                                    exposed 4 million unique email addresses alongside IP addresses, usernames and
                                    passwords stored as bcrypt hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Coinmama logo" /></div>
                            <div>
                                <p><span>Coinmama</span>: In August 2017, the crypto coin brokerage service <a>Coinmama
                                        suffered a data breach</a> that impacted 479k subscribers. The breach was
                                    discovered in February 2019 with exposed data including email addresses, usernames
                                    and passwords stored as MD5 WordPress hashes. The data was provided to HIBP by white
                                    hat security researcher and data analyst Adam Davies.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="CoinMarketCap logo" /></div>
                            <div>
                                <p><span>CoinMarketCap</span>: During October 2021, 3.1 million email addresses with
                                    accounts on the cryptocurrency market capitalisation website <a>CoinMarketCap</a>
                                    were discovered being traded on hacking forums. Whilst the email addresses were
                                    found to correlate with CoinMarketCap accounts, it's unclear precisely how they were
                                    obtained. CoinMarketCap has provided the following statement on the data:
                                    "CoinMarketCap has become aware that batches of data have shown up online purporting
                                    to be a list of user accounts. While the data lists we have seen are only email
                                    addresses (no passwords), we have found a correlation with our subscriber base. We
                                    have not found any evidence of a data leak from our own servers — we are actively
                                    investigating this issue and will update our subscribers as soon as we have any new
                                    information."</p>
                                <p><strong>Compromised data:</strong> Email addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Collection #1 logo" /></div>
                            <div>
                                <p><span>Collection #1<span> (<a>unverified</a>)</span></span>: In January 2019, a large
                                    collection of credential stuffing lists (combinations of email addresses and
                                    passwords used to hijack accounts on other services) was discovered being
                                    distributed on a popular hacking forum. The data contained almost 2.7
                                    <em>billion</em> records including 773 million unique email addresses alongside
                                    passwords those addresses had used on other breached services. Full details on the
                                    incident and how to search the breached passwords are provided in the blog post
                                    <a>The 773 Million Record "Collection #1" Data Breach</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Coupon Mom / Armor Games logo" /></div>
                            <div>
                                <p><span>Coupon Mom / Armor Games<span> (<a>unverified</a>)</span></span>: In 2014, a
                                    file allegedly containing data hacked from <a>Coupon Mom</a> was created and
                                    included 11 million email addresses and plain text passwords. On further
                                    investigation, the file was also found to contain data indicating it had been
                                    sourced from <a>Armor Games</a>. Subsequent verification with HIBP subscribers
                                    confirmed the passwords had previously been used and many subscribers had used
                                    either Coupon Mom or Armor Games in the past. On disclosure to both organisations,
                                    each found that the data did not represent their entire customer base and possibly
                                    includes records from other sources with common subscribers. The breach has
                                    subsequently been flagged as "unverified" as the source cannot be emphatically
                                    proven. In July 2020, <a>the data was also found to contain BeerAdvocate accounts
                                        sourced from a previously unknown breach</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Covve logo" /></div>
                            <div>
                                <p><span>Covve</span>: In February 2020, <a>a massive trove of personal information
                                        referred to as "db8151dd"</a> was provided to HIBP after being found left
                                    exposed on a publicly facing Elasticsearch server. Later identified as originating
                                    from the Covve contacts app, the exposed data included extensive personal
                                    information and interactions between Covve users and their contacts. The data was
                                    provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Job titles, Names, Phone numbers,
                                    Physical addresses, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Cracked.to logo" /></div>
                            <div>
                                <p><span>Cracked.to</span>: In July 2019, the hacking website <a>Cracked.to</a> suffered
                                    a data breach. There were 749k unique email addresses spread across 321k forum users
                                    and other tables in the database. A rival hacking website claimed responsibility for
                                    breaching the MyBB based forum which disclosed email and IP addresses, usernames,
                                    private messages and passwords stored as bcrypt hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords, Private
                                    messages, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="CrackingForum logo" /></div>
                            <div>
                                <p><span>CrackingForum</span>: In approximately mid-2016, the cracking community forum
                                    known as <a>CrackingForum</a> suffered a data breach. The vBulletin based forum
                                    exposed 660k email and IP addresses, usernames and salted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Daily Quiz logo" /></div>
                            <div>
                                <p><span>Daily Quiz</span>: In January 2021, the quiz website <a>Daily Quiz</a> suffered
                                    a data breach that exposed over 8 million unique email addresses. The data also
                                    included usernames, IP addresses and passwords stored in plain text.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Dailymotion logo" /></div>
                            <div>
                                <p><span>Dailymotion</span>: In October 2016, the video sharing platform <a>Dailymotion
                                        suffered a data breach</a>. The attack led to the exposure of more than 85
                                    million user accounts and included email addresses, usernames and bcrypt hashes of
                                    passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="DaniWeb logo" /></div>
                            <div>
                                <p><span>DaniWeb</span>: In late 2015, the technology and social site <a>DaniWeb</a>
                                    suffered a data breach. The attack resulted in the disclosure of 1.1 million
                                    accounts including email and IP addresses which were also accompanied by salted MD5
                                    hashes of passwords. However, DaniWeb have advised that "the breached password
                                    hashes and salts are incorrect" and that they have since switched to new
                                    infrastructure and software.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Data &amp; Leads logo" /></div>
                            <div>
                                <p><span>Data &amp; Leads</span>: In November 2018, <a>security researcher Bob Diachenko
                                        identified an unprotected database believed to be hosted by a data
                                        aggregator</a>. Upon further investigation, the data was linked to marketing
                                    company <a>Data &amp; Leads</a>. The exposed Elasticsearch instance contained over
                                    44M unique email addresses along with names, IP and physical addresses, phone
                                    numbers and employment information. No response was received from Data &amp; Leads
                                    when contacted by Bob and their site subsequently went offline.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Employers, IP addresses, Job
                                    titles, Names, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Data Enrichment Exposure From PDL Customer logo" /></div>
                            <div>
                                <p><span>Data Enrichment Exposure From PDL Customer</span>: In October 2019, <a>security
                                        researchers Vinny Troia and Bob Diachenko identified an unprotected
                                        Elasticsearch server holding 1.2 billion records of personal data</a>. The
                                    exposed data included an index indicating it was sourced from data enrichment
                                    company People Data Labs (PDL) and contained 622 million unique email addresses. The
                                    server was not owned by PDL and it's believed a customer failed to properly secure
                                    the database. Exposed information included email addresses, phone numbers, social
                                    media profiles and job history data.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Employers, Geographic locations,
                                    Job titles, Names, Phone numbers, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="DataCamp logo" /></div>
                            <div>
                                <p><span>DataCamp</span>: In December 2018, the data science website <a>DataCamp
                                        suffered a data breach</a> of records dating back to January 2017. The incident
                                    exposed 760k unique email and IP addresses along with names and passwords stored as
                                    bcrypt hashes. In 2019, <a>the data appeared listed for sale on a dark web
                                        marketplace</a> (along with several other large breaches) and subsequently began
                                    circulating more broadly. The data was provided to HIBP by a source who requested it
                                    to be attributed to "BenjaminBlue@exploit.im".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, IP
                                    addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="DatPiff logo" /></div>
                            <div>
                                <p><span>DatPiff</span>: In late 2021, <a>email address and plain text password pairs
                                        from the rap mixtape website DatPiff appeared for sale on a popular hacking
                                        forum</a>. The data allegedly dated back to an earlier breach and in total,
                                    contained almost 7.5M email addresses and cracked password pairs. The original data
                                    source allegedly contained usernames, security questions and answers and passwords
                                    stored as MD5 hashes with a static salt.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Security questions and
                                    answers, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Deezer logo" /></div>
                            <div>
                                <p><span>Deezer</span>: In late 2022, the music streaming service <a>Deezer disclosed a
                                        data breach that impacted over 240M customers</a>. The breach dated back to a
                                    mid-2019 backup exposed by a 3rd party partner which was subsequently sold and then
                                    broadly redistributed on a popular hacking forum. Impacted data included 229M unique
                                    email addresses, IP addresses, names, usernames, genders, DoBs and the geographic
                                    location of the customer.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders,
                                    Geographic locations, IP addresses, Names, Spoken languages, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Demon Forums logo" /></div>
                            <div>
                                <p><span>Demon Forums</span>: In February 2019, the hacking forum <a>Demon Forums</a>
                                    suffered a data breach. The compromise of the vBulletin forum exposed 52k unique
                                    email addresses alongside usernames and passwords stored as salted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Descomplica logo" /></div>
                            <div>
                                <p><span>Descomplica</span>: In March 2021, the Brazilian EdTech company <a>Descomplica
                                        suffered a data breach</a> which was subsequently posted to a popular hacking
                                    forum. The data included almost 5 million email addresses, names, the first 6 and
                                    last 4 digits and the expiry date of credit cards, purchase histories and password
                                    hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Partial credit card data,
                                    Passwords, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="diet.com logo" /></div>
                            <div>
                                <p><span>diet.com</span>: In August 2014, the diet and nutrition website <a>diet.com</a>
                                    suffered a data breach resulting in the exposure of 1.4 million unique user records
                                    dating back as far as 2004. The data contained email and IP addresses, usernames,
                                    plain text passwords and dietary information about the site members including eating
                                    habits, BMI and birth date. The site was previously reported as compromised on the
                                    <a>Vigilante.pw</a> breached database directory.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Eating habits, Email addresses, IP
                                    addresses, Names, Passwords, Physical attributes, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Digimon logo" /></div>
                            <div>
                                <p><span>Digimon<span> (<a>spam list</a>)</span></span>: In September 2016, over 16GB of
                                    logs from a service indicated to be digimon.co.in were obtained, most likely from an
                                    unprotected Mongo DB instance. The service ceased running shortly afterwards and no
                                    information remains about the precise nature of it. Based on <a>enquiries made via
                                        Twitter</a>, it appears to have been a mail service possibly based on PowerMTA
                                    and used for delivering spam. The logs contained information including 7.7M unique
                                    email recipients (names and addresses), mail server IP addresses, email subjects and
                                    tracking information including mail opens and clicks.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Email messages, IP addresses,
                                    Names</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Disqus logo" /></div>
                            <div>
                                <p><span>Disqus</span>: In October 2017, the blog commenting service <a>Disqus announced
                                        they'd suffered a data breach</a>. The breach dated back to July 2012 but wasn't
                                    identified until years later when the data finally surfaced. The breach contained
                                    over 17.5 million unique email addresses and usernames. Users who created logins on
                                    Disqus had salted SHA1 hashes of passwords whilst users who logged in via social
                                    providers only had references to those accounts.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="DLH.net logo" /></div>
                            <div>
                                <p><span>DLH.net</span>: In July 2016, the gaming news site <a>DLH.net suffered a data
                                        breach</a> which exposed 3.3M subscriber identities. Along with the keys used to
                                    redeem and activate games on the Steam platform, the breach also resulted in the
                                    exposure of email addresses, birth dates and salted MD5 password hashes. The data
                                    was donated to Have I Been Pwned by data breach monitoring service
                                    <a>Vigilante.pw</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Names, Passwords,
                                    Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Domino's India logo" /></div>
                            <div>
                                <p><span>Domino's India</span>: In April 2021, <a>13TB of compromised Domino's India
                                        appeared for sale on a hacking forum</a> after which the company acknowledged a
                                    major data breach they dated back to March. The compromised data included 22.5
                                    million unique email addresses, names, phone numbers, order histories and physical
                                    addresses.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Phone numbers, Physical
                                    addresses, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="DriveSure logo" /></div>
                            <div>
                                <p><span>DriveSure</span>: In December 2020, the car dealership service provider
                                    <a>DriveSure suffered a data breach</a>. The incident resulted in 26GB of data being
                                    downloaded and later shared on a hacking forum. Impacted personal information
                                    included 3.6 million unique email addresses, names, phone numbers and physical
                                    addresses. Vehicle data was also exposed and included makes, models, VIN numbers and
                                    odometer readings. A small number of passwords stored as bcrypt hashes were also
                                    included in the data set.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Phone numbers,
                                    Physical addresses, Vehicle details</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Drizly logo" /></div>
                            <div>
                                <p><span>Drizly</span>: In approximately July 2020, the US-based online alcohol delivery
                                    service <a>Drizly suffered a data breach</a>. The data was sold online before being
                                    extensively redistributed and contained 2.5 million unique email addresses alongside
                                    names, physical and IP addresses, phone numbers, dates of birth and passwords stored
                                    as bcrypt hashes. The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Device information, Email
                                    addresses, IP addresses, Names, Passwords, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Dropbox logo" /></div>
                            <div>
                                <p><span>Dropbox</span>: In mid-2012, Dropbox suffered a data breach which exposed the
                                    stored credentials of tens of millions of their customers. In August 2016, <a>they
                                        forced password resets for customers they believed may be at risk</a>. A large
                                    volume of data totalling over 68 million records <a>was subsequently traded
                                        online</a> and included email addresses and salted hashes of passwords (half of
                                    them SHA1, half of them bcrypt).</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Dubsmash logo" /></div>
                            <div>
                                <p><span>Dubsmash</span>: In December 2018, the video messaging service <a>Dubsmash
                                        suffered a data breach</a>. The incident exposed 162 million unique email
                                    addresses alongside usernames and PBKDF2 password hashes. In 2019, the data appeared
                                    listed for sale on a dark web marketplace (along with several other large breaches)
                                    and subsequently began circulating more broadly. The data was provided to HIBP by a
                                    source who requested it to be attributed to "BenjaminBlue@exploit.im".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Names,
                                    Passwords, Phone numbers, Spoken languages, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Dueling Network logo" /></div>
                            <div>
                                <p><span>Dueling Network</span>: In March 2017, the Flash game based on the Yu-Gi-Oh
                                    trading card game <a>Dueling Network suffered a data breach</a>. The site itself was
                                    taken offline in 2016 due to a cease-and-desist order but the forum remained online
                                    for another year. The data breach exposed usernames, IP and email addresses and
                                    passwords stored as MD5 hashes. The data was provided to HIBP by a source who
                                    requested it be attributed to "burger vault".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Dungeons &amp; Dragons Online logo" /></div>
                            <div>
                                <p><span>Dungeons &amp; Dragons Online</span>: In April 2013, the interactive video game
                                    <a>Dungeons &amp; Dragons Online</a> suffered a data breach that exposed almost 1.6M
                                    players' accounts. The data was being actively traded on underground forums and
                                    included email addresses, birth dates and password hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Passwords, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Dunzo logo" /></div>
                            <div>
                                <p><span>Dunzo</span>: In approximately June 2019, the Indian delivery service <a>Dunzo
                                        suffered a data breach</a>. Exposing 3.5 million unique email addresses, the
                                    Dunzo breach also included names, phone numbers and IP addresses which were all
                                    broadly distributed online via a hacking forum. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Device information, Email addresses, Geographic
                                    locations, IP addresses, Names, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Eatigo logo" /></div>
                            <div>
                                <p><span>Eatigo</span>: In October 2018, the restaurant reservation service <a>Eatigo
                                        suffered a data breach that exposed 2.8 million accounts</a>. The data included
                                    email addresses, names, phone numbers, social media profiles, genders and passwords
                                    stored as unsalted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Names, Passwords, Phone
                                    numbers, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="EatStreet logo" /></div>
                            <div>
                                <p><span>EatStreet</span>: In May 2019, the online food ordering service <a>EatStreet
                                        suffered a data breach affecting 6.4 million customers</a>. An extensive amount
                                    of personal data was obtained including names, phone numbers, addresses, partial
                                    credit card data and passwords stored as bcrypt hashes. The data was provided to
                                    HIBP by a source who requested it be attributed to "JimScott.Sec@protonmail.com".
                                </p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, Names,
                                    Partial credit card data, Passwords, Phone numbers, Physical addresses, Social media
                                    profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Elanic logo" /></div>
                            <div>
                                <p><span>Elanic</span>: In January 2020, the Indian fashion marketplace <a>Elanic</a>
                                    had 2.8M records with 2.3M unique email addresses posted publicly to a popular
                                    hacking forum. Elanic confirmed that they had "verified the data and it was pulled
                                    from one of our test servers where this data was exposed publicly" and that the data
                                    was "old" (the hacking forum reported it as being from 2016-2018). When asked about
                                    disclosure to impacted customers, Elanic advised that they had "decided to not have
                                    as such any communication and public disclosure". </p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Usernames
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="EpicBot logo" /></div>
                            <div>
                                <p><span>EpicBot</span>: In September 2019, the RuneScape bot provider <a>EpicBot
                                        suffered a data breach that impacted 817k subscribers</a>. Data from the breach
                                    was subsequently shared on a popular hacking forum and included usernames, email and
                                    IP addresses and passwords stored as either salted MD5 or bcrypt hashes. EpicBot did
                                    not respond when contacted about the incident.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Epik logo" /></div>
                            <div>
                                <p><span>Epik</span>: In September 2021, <a>the domain registrar and web host Epik
                                        suffered a significant data breach</a>, allegedly in retaliation for hosting
                                    alt-right websites. The breach exposed a huge volume of data not just of Epik
                                    customers, but also scraped WHOIS records belonging to individuals and organisations
                                    who were not Epik customers. The data included over 15 million unique email
                                    addresses (including anonymised versions for domain privacy), names, phone numbers,
                                    physical addresses, purchases and passwords stored in various formats.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Phone numbers, Physical
                                    addresses, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Everybody Edits logo" /></div>
                            <div>
                                <p><span>Everybody Edits</span>: In March 2019, the multiplayer platform game
                                    <a>Everybody Edits suffered a data breach</a>. The incident exposed 871k unique
                                    email addresses alongside usernames and IP addresses. The data was subsequently
                                    distributed online across a collection of files.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Evony logo" /></div>
                            <div>
                                <p><span>Evony</span>: In June 2016, the online multiplayer game <a>Evony was hacked</a>
                                    and over 29 million unique accounts were exposed. The attack led to the exposure of
                                    usernames, email and IP addresses and MD5 hashes of passwords (without salt).</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Experian (2015) logo" /></div>
                            <div>
                                <p><span>Experian (2015)<span> (<a>unverified</a>)</span></span>: In September 2015, the
                                    US based credit bureau and consumer data broker <a>Experian suffered a data
                                        breach</a> that impacted 15 million customers who had applied for financing from
                                    T-Mobile. An alleged data breach was subsequently circulated containing personal
                                    information including names, physical and email addresses, birth dates and various
                                    other personal attributes. Multiple Have I Been Pwned subscribers verified portions
                                    of the data as being accurate, but the actual source of it was inconclusive therefor
                                    this breach has been flagged as "unverified".</p>
                                <p><strong>Compromised data:</strong> Credit status information, Dates of birth, Email
                                    addresses, Ethnicities, Family structure, Genders, Home ownership statuses, Income
                                    levels, IP addresses, Names, Phone numbers, Physical addresses, Purchasing habits
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Exploit.In logo" /></div>
                            <div>
                                <p><span>Exploit.In<span> (<a>unverified</a>)</span></span>: In late 2016, a huge list
                                    of email address and password pairs appeared in a "combo list" referred to as
                                    "Exploit.In". The list contained 593 million unique email addresses, many with
                                    multiple different passwords hacked from various online systems. The list was
                                    broadly circulated and used for "credential stuffing", that is attackers employ it
                                    in an attempt to identify other online systems where the account owner had reused
                                    their password. For detailed background on this incident, read <a>Password reuse,
                                        credential stuffing and another billion records in Have I Been Pwned</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Eye4Fraud logo" /></div>
                            <div>
                                <p><span>Eye4Fraud</span>: In February 2023, <a>data alleged to have been taken from the
                                        fraud protection service Eye4Fraud was listed for sale on a popular hacking
                                        forum</a>. Spanning tens of millions of rows with 16M unique email addresses,
                                    the data was spread across 147 tables totalling 65GB and included both direct users
                                    of the service and what appears to be individuals who'd placed orders on other
                                    services that implemented Eye4Fraud to protect their sales. The data included names
                                    and bcrypt password hashes for users, and names, phone numbers, physical addresses
                                    and partial credit card data (card type and last 4 digits) for orders placed using
                                    the service. Eye4Fraud did not respond to multiple attempts to report the incident.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Partial
                                    credit card data, Passwords, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="EyeEm logo" /></div>
                            <div>
                                <p><span>EyeEm</span>: In February 2018, <a>photography website EyeEm suffered a data
                                        breach</a>. The breach was identified among a collection of other large
                                    incidents and exposed almost 20M unique email addresses, names, usernames, bios and
                                    password hashes. The data was provided to HIBP by a source who asked for it to be
                                    attributed to "Kuroi'sh or Gabriel Kimiaie-Asadi Bildstein".</p>
                                <p><strong>Compromised data:</strong> Bios, Email addresses, Names, Passwords, Usernames
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="FashionFantasyGame logo" /></div>
                            <div>
                                <p><span>FashionFantasyGame</span>: In late 2016, the fashion gaming website <a>Fashion
                                        Fantasy Game suffered a data breach</a>. The incident exposed 2.3 million unique
                                    user accounts and corresponding MD5 password hashes with no salt. The data was
                                    contributed to Have I Been Pwned courtesy of rip@creep.im.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Flash Flash Revolution (2016 breach) logo" /></div>
                            <div>
                                <p><span>Flash Flash Revolution (2016 breach)</span>: In February 2016, the music-based
                                    rhythm game known as <a>Flash Flash Revolution</a> was hacked and 1.8M accounts were
                                    exposed. Along with email and IP addresses, the vBulletin forum also exposed salted
                                    MD5 password hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Flash Flash Revolution (2019 breach) logo" /></div>
                            <div>
                                <p><span>Flash Flash Revolution (2019 breach)</span>: In July 2019, the music-based
                                    rhythm game <a>Flash Flash Revolution</a> suffered a data breach. The 2019 breach
                                    imapcted almost 1.9 million members and is <em>in addition to</em> <a>the 2016 data
                                        breach of the same service</a>. Email and IP addesses, usernames, dates of birth
                                    and salted MD5 hashes were all exposed in the breach. The data was provided with
                                    support from <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="FlexBooker logo" /></div>
                            <div>
                                <p><span>FlexBooker</span>: In December 2021, the online booking service
                                    <a>FlexBooker</a> suffered a data breach that exposed 3.7 million accounts. The data
                                    included email addresses, names, phone numbers and for a small number of accounts,
                                    password hashes and partial credit card data. FlexBooker has identified the breach
                                    as originating from a compromised account within their AWS infrastructure. The data
                                    was found being actively traded on a popular hacking forum and was provided to HIBP
                                    by a source who requested it be attributed to "white_peacock@riseup.net".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Partial credit card data,
                                    Passwords, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Funimation logo" /></div>
                            <div>
                                <p><span>Funimation</span>: In July 2016, the anime site <a>Funimation</a> suffered a
                                    data breach that impacted 2.5 million accounts. The data contained usernames, email
                                    addresses, dates of birth and salted SHA1 hashes of passwords.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Gaadi logo" /></div>
                            <div>
                                <p><span>Gaadi</span>: In May 2015, the Indian motoring website known as <a>Gaadi</a>
                                    had 4.3 million records exposed in a data breach. The data contained usernames,
                                    email and IP addresses, genders, the city of users as well as passwords stored in
                                    both plain text and as MD5 hashes. The site was previously reported as compromised
                                    on the <a>Vigilante.pw</a> breached database directory.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Geographic locations, IP
                                    addresses, Names, Passwords, Phone numbers, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Gamerzplanet logo" /></div>
                            <div>
                                <p><span>Gamerzplanet</span>: In approximately October 2015, the online gaming forum
                                    known as <a>Gamerzplanet</a> was hacked and more than 1.2M accounts were exposed.
                                    The vBulletin forum included IP addresses and passwords stored as salted hashes
                                    using a weak implementation enabling many to be rapidly cracked.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="GameSalad logo" /></div>
                            <div>
                                <p><span>GameSalad</span>: In February 2019, the education and game creation website
                                    <a>Game Salad suffered a data breach</a>. The incident impacted 1.5M accounts and
                                    exposed email addresses, usernames, IP addresses and passwords stored as SHA-256
                                    hashes. The data was provided to HIBP by a source who requested it be attributed to
                                    "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Gawker logo" /></div>
                            <div>
                                <p><span>Gawker</span>: In December 2010, Gawker was attacked by the hacker collective
                                    "Gnosis" in retaliation for what was reported to be a feud between Gawker and 4Chan.
                                    Information about Gawkers 1.3M users was published along with the data from Gawker's
                                    other web presences including Gizmodo and Lifehacker. Due to the prevalence of
                                    password reuse, many victims of the breach <a>then had their Twitter accounts
                                        compromised to send Acai berry spam</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Ge.tt logo" /></div>
                            <div>
                                <p><span>Ge.tt</span>: In May 2017, the file sharing platform <a>Ge.tt suffered a data
                                        breach</a>. The data was subsequently put up for sale on a dark web marketplace
                                    in February 2019 alongside a raft of other breaches. The Ge.tt breach included
                                    names, social media profile identifiers, SHA256 password hashes and almost 2.5M
                                    unique email addresses. The data was provided to HIBP by a source who requested it
                                    be attributed to <a>BreachDirectory</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Social media
                                    profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Gemini logo" /></div>
                            <div>
                                <p><span>Gemini</span>: In late 2022, <a>data allegedly taken from the Gemini crypto
                                        exchange was posted to a public hacking forum</a>. The data consisted of email
                                    addresses and partial phone numbers, which Gemini later attributed to <a>an incident
                                        at a third-party vendor</a> (the vendor was not named). The data was provided to
                                    HIBP by a source who requested it be attributed to "ZAN @ BF".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Partial phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="GeniusU logo" /></div>
                            <div>
                                <p><span>GeniusU</span>: In November 2020, <a>a collection of data breaches were made
                                        public including the "Entrepreneur Success Platform", GeniusU</a>. Dating back
                                    to the previous month, the data included 1.3M names, email and IP addresses,
                                    genders, links to social media profiles and passwords stored as bcrypt hashes. The
                                    data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, IP addresses, Names,
                                    Passwords, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="GFAN logo" /></div>
                            <div>
                                <p><span>GFAN<span> (<a>unverified</a>)</span></span>: In October 2016, data surfaced
                                    that was allegedly obtained from the Chinese website known as <a>GFAN</a> and
                                    contained 22.5M accounts. Whilst there is evidence that the data is legitimate, due
                                    to the difficulty of emphatically verifying the Chinese breach it has been flagged
                                    as "unverified". The data in the breach contains email and IP addresses, user names
                                    and salted and hashed passwords. <a>Read more about Chinese data breaches in Have I
                                        Been Pwned.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="GGCorp logo" /></div>
                            <div>
                                <p><span>GGCorp</span>: In August 2022, the MMORPG website <a>GGCorp suffered a data
                                        breach that exposed almost 2.4M unique email addresses</a>. The data also
                                    included IP addresses, usernames and MD5 password hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Glofox logo" /></div>
                            <div>
                                <p><span>Glofox</span>: In March 2020, the Irish gym management software company
                                    <a>Glofox suffered a data breach which exposed 2.3M membership records</a>. The data
                                    included email addresses, names, phone numbers, genders, dates of birth and
                                    passwords stored as unsalted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, Names,
                                    Passwords, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Go Games logo" /></div>
                            <div>
                                <p><span>Go Games</span>: In approximately October 2015, the manga website <a>Go
                                        Games</a> suffered a data breach. The exposed data included 3.4M customer
                                    records including email and IP addresses, usernames and passwords stored as salted
                                    MD5 hashes. Go Games did not respond when contacted about the incident. The data was
                                    provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="GPS Underground logo" /></div>
                            <div>
                                <p><span>GPS Underground</span>: In early 2017, <a>GPS Underground was amongst a
                                        collection of compromised vBulletin websites that were found being sold
                                        online</a>. The breach dated back to mid-2016 and included 670k records with
                                    usernames, email and IP addresses, dates of birth and salted MD5 password hashes.
                                </p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Gravatar logo" /></div>
                            <div>
                                <p><span>Gravatar</span>: In October 2020, <a>a security researcher published a
                                        technique for scraping large volumes of data from Gravatar, the service for
                                        providing globally unique avatars </a>. 167 million names, usernames and MD5
                                    hashes of email addresses used to reference users' avatars were subsequently scraped
                                    and distributed within the hacking community. 114 million of the MD5 hashes were
                                    cracked and distributed alongside the source hash, thus disclosing the original
                                    email address and accompanying data. Following the impacted email addresses being
                                    searchable in HIBP, <a>Gravatar release an FAQ detailing the incident</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="GTAGaming logo" /></div>
                            <div>
                                <p><span>GTAGaming</span>: In August 2016, the Grand Theft Auto forum <a>GTAGaming was
                                        hacked and nearly 200k user accounts were leaked</a>. The vBulletin based forum
                                    included usernames, email addresses and password hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Passwords, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="HauteLook logo" /></div>
                            <div>
                                <p><span>HauteLook</span>: In mid-2018, the fashion shopping site <a>HauteLook was among
                                        a raft of sites that were breached and their data then sold in early-2019</a>.
                                    The data included over 28 million unique email addresses alongside names, genders,
                                    dates of birth and passwords stored as bcrypt hashes. The data was provided to HIBP
                                    by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders,
                                    Geographic locations, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Havenly logo" /></div>
                            <div>
                                <p><span>Havenly</span>: In June 2020, the interior design website <a>Havenly suffered a
                                        data breach</a> which impacted almost 1.4 million members of the service. The
                                    exposed data included email addresses, names, phone numbers, geographic locations
                                    and passwords stored as SHA-1 hashes, all of which was subsequently shared
                                    extensively throughout online hacking communities. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Names,
                                    Passwords, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Heroes of Gaia logo" /></div>
                            <div>
                                <p><span>Heroes of Gaia</span>: In early 2013, the online fantasy multiplayer game
                                    <a>Heroes of Gaia</a> suffered a data breach. The newest records in the data set
                                    indicate a breach date of 4 January 2013 and include usernames, IP and email
                                    addresses but no passwords.</p>
                                <p><strong>Compromised data:</strong> Browser user agent details, Email addresses, IP
                                    addresses, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Heroes of Newerth logo" /></div>
                            <div>
                                <p><span>Heroes of Newerth</span>: In December 2012, the multiplayer online battle arena
                                    game known as <a>Heroes of Newerth</a> <a> was hacked</a> and over 8 million
                                    accounts extracted from the system. The compromised data included usernames, email
                                    addresses and passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="HiAPK logo" /></div>
                            <div>
                                <p><span>HiAPK<span> (<a>unverified</a>)</span></span>: In approximately 2014, it's
                                    alleged that the Chinese Android store known as <a>HIAPK</a> suffered a data breach
                                    that impacted 13.8 million unique subscribers. Whilst there is evidence that the
                                    data is legitimate, due to the difficulty of emphatically verifying the Chinese
                                    breach it has been flagged as "unverified". The data in the breach contains
                                    usernames, email addresses and salted MD5 password hashes and was provided to HIBP
                                    by white hat security researcher and data analyst Adam Davies. <a>Read more about
                                        Chinese data breaches in Have I Been Pwned.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="HLTV logo" /></div>
                            <div>
                                <p><span>HLTV</span>: In June 2016, the "home of competitive Counter Strike" website
                                    <a>HLTV was hacked</a> and 611k accounts were exposed. The attack led to the
                                    exposure of names, usernames, email addresses and bcrypt hashes of passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Usernames,
                                    Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Home Chef logo" /></div>
                            <div>
                                <p><span>Home Chef</span>: In early 2020, the food delivery service <a>Home Chef
                                        suffered a data breach</a> which was subsequently sold online. The breach
                                    exposed the personal information of almost 9 million customers including names, IP
                                    addresses, post codes, the last 4 digits of credit card numbers and passwords stored
                                    as bcrypt hashes. The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, IP
                                    addresses, Names, Partial credit card data, Passwords, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Houzz logo" /></div>
                            <div>
                                <p><span>Houzz</span>: In mid-2018, the housing design website <a>Houzz suffered a data
                                        breach</a>. The company learned of the incident later that year then disclosed
                                    it to impacted members in February 2019. Almost 49 million unique email addresses
                                    were in the breach alongside names, IP addresses, geographic locations and either
                                    salted hashes of passwords or links to social media profiles used to authenticate to
                                    the service. The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, IP
                                    addresses, Names, Passwords, Social media profiles, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Hurb logo" /></div>
                            <div>
                                <p><span>Hurb</span>: In approximately March 2019, the online Brazilian travel agency
                                    <a>Hurb (formerly Hotel Urbano) suffered a data breach</a>. The data subsequently
                                    appeared online for download the following year and included over 20 million
                                    customer records with email and IP addresses, names, dates of birth, phone numbers
                                    and passwords stored as unsalted MD5 hashes. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Names, Passwords, Phone numbers, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="IDC Games logo" /></div>
                            <div>
                                <p><span>IDC Games</span>: In March 2021, <a>4 million records sourced from IDC Games
                                        were shared on a public hacking forum</a>. The data included usernames, email
                                    addresses and passwords stored as salted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="i-Dressup logo" /></div>
                            <div>
                                <p><span>i-Dressup</span>: In June 2016, the teen social site known as <a>i-Dressup was
                                        hacked</a> and over 2 million user accounts were exposed. At the time the hack
                                    was reported, the i-Dressup operators were not contactable and the underlying SQL
                                    injection flaw remained open, allegedly exposing a total of 5.5 million accounts.
                                    The breach included email addresses and passwords stored in plain text.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="IIMJobs logo" /></div>
                            <div>
                                <p><span>IIMJobs</span>: In December 2018, the Indian job portal <a>IIMJobs suffered a
                                        data breach that exposed 4.1 million unique email addresses</a>. The data also
                                    included names, phone numbers, geographic locations, dates of birth, job titles, job
                                    applications and cover letters plus passwords stored as unsalted MD5 hashes. The
                                    data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Geographic
                                    locations, IP addresses, Job applications, Job titles, Names, Passwords, Phone
                                    numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="iMesh logo" /></div>
                            <div>
                                <p><span>iMesh</span>: In September 2013, the media and file sharing client known as
                                    <a>iMesh was hacked and approximately 50M accounts were exposed</a>. The data was
                                    later put up for sale on a dark market website in mid-2016 and included email and IP
                                    addresses, usernames and salted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="IndiaMART logo" /></div>
                            <div>
                                <p><span>IndiaMART</span>: In August 2021, <a>38 million records from Indian e-commerce
                                        company IndiaMART were found being traded on a popular hacking forum</a>. Dated
                                    several months earlier, the data included over 20 million unique email addresses
                                    alongside names, phone numbers and physical addresses. It's unclear whether
                                    IndiaMART intentionally exposed the data attributes as part of the intended design
                                    of the platform or whether the data was obtained by exploiting a vulnerability in
                                    the service.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Phone numbers, Physical
                                    addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Instant Checkmate logo" /></div>
                            <div>
                                <p><span>Instant Checkmate</span>: In 2019, the public records search service <a>Instant
                                        Checkmate suffered a data breach that later came to light in early 2023</a>. The
                                    data included almost 12M unique customer email addresses, names, phone numbers and
                                    passwords stored as scrypt hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Phone numbers
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="InterPals logo" /></div>
                            <div>
                                <p><span>InterPals</span>: In late 2015, the online penpal site InterPals had their
                                    website hacked and 3.4 million accounts exposed. The compromised data included email
                                    addresses, geographical locations, birthdates and salted hashes of passwords.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Geographic
                                    locations, Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="iPmart logo" /></div>
                            <div>
                                <p><span>iPmart</span>: During 2015, the <a>iPmart forum</a> (now known as Mobi NUKE)
                                    was hacked and over 2 million forum members' details were exposed. The vBulletin
                                    forum included IP addresses, birth dates and passwords stored as salted hashes using
                                    a weak implementation enabling many to be rapidly cracked. A further 368k accounts
                                    were added to "Have I Been Pwned" in March 2016 bringing the total to over 2.4M.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ixigo logo" /></div>
                            <div>
                                <p><span>ixigo</span>: In January 2019, the travel and hotel booking site <a>ixigo
                                        suffered a data breach</a>. The data appeared for sale on a dark web marketplace
                                    the following month and included over 17M unique email addresses alongside names,
                                    genders, phone numbers, connections to Facebook profiles and passwords stored as MD5
                                    hashes. The data was provided to HIBP by a source who requested it to be attributed
                                    to "BenjaminBlue@exploit.im".</p>
                                <p><strong>Compromised data:</strong> Auth tokens, Device information, Email addresses,
                                    Genders, Names, Passwords, Phone numbers, Salutations, Social media profiles,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="JD logo" /></div>
                            <div>
                                <p><span>JD</span>: In 2013 (exact date unknown), the Chinese e-commerce service <a>JD
                                        suffered a data breach</a> that exposed 13GB of data containing 77 million
                                    unique email addresses. The data also included usernames, phone numbers and
                                    passwords stored as SHA-1 hashes. The data was provided to HIBP by a source who
                                    requested it be attributed to "white_peacock@riseup.net".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Phone numbers,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Jefit logo" /></div>
                            <div>
                                <p><span>Jefit</span>: In August 2020, the workout tracking app <a>Jefit suffered a data
                                        breach</a>. The data was subsequently sold within the hacking community and
                                    included over 9 million email and IP addresses, usernames and passwords stored as
                                    either vBulletin or argon2 hashes. Several million cracked passwords later appeared
                                    in broad circulation.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Jobandtalent logo" /></div>
                            <div>
                                <p><span>Jobandtalent</span>: In approximately February 2018, <a>the employment website
                                        Jobandtalent suffered a data breach which then appeared for sale alongside other
                                        breaches a year later</a>. The incident impacted 11 million subscribers and
                                    exposed their names, email and IP addresses and passwords stored as salted SHA-1
                                    hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Passwords
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="JukinMedia logo" /></div>
                            <div>
                                <p><span>JukinMedia</span>: In October 2021, the "global leader in user-generated
                                    entertainment" <a>Jukin Media suffered a data breach</a>. The breach exposed 13GB of
                                    code, configuration and data consisting of 314k unique email addresses along with
                                    names, phone numbers, IP addresses and bcrypt password hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Employers, IP addresses, Names,
                                    Occupations, Passwords, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Kayo.moe Credential Stuffing List logo" /></div>
                            <div>
                                <p><span>Kayo.moe Credential Stuffing List<span> (<a>unverified</a>)</span></span>: In
                                    September 2018, a collection of almost 42 million email address and plain text
                                    password pairs was uploaded to the anonymous file sharing service <a>kayo.moe</a>.
                                    The operator of the service contacted HIBP to report the data which, upon further
                                    investigation, turned out to be a large credential stuffing list. For more
                                    information, read about <a>The 42M Record kayo.moe Credential Stuffing Data</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Kickstarter logo" /></div>
                            <div>
                                <p><span>Kickstarter</span>: In February 2014, the crowdfunding platform <a>Kickstarter
                                        announced they'd suffered a data breach</a>. The breach contained almost 5.2
                                    million unique email addresses, usernames and salted SHA1 hashes of passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Knuddels logo" /></div>
                            <div>
                                <p><span>Knuddels</span>: In September 2018, the German social media website <a>Knuddels
                                        suffered a data breach</a>. The incident exposed 808k unique email addresses
                                    alongside usernames, real names, the city of the person and their password in plain
                                    text. Knuddels was <a>subsequently fined €20k for the breach</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Names,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Last.fm logo" /></div>
                            <div>
                                <p><span>Last.fm</span>: In March 2012, the music website <a>Last.fm was hacked</a> and
                                    43 million user accounts were exposed. Whilst <a>Last.fm knew of an incident back in
                                        2012</a>, the scale of the hack was not known until the data was released
                                    publicly in September 2016. The breach included 37 million unique email addresses,
                                    usernames and passwords stored as unsalted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames, Website
                                    activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Lazada RedMart logo" /></div>
                            <div>
                                <p><span>Lazada RedMart</span>: In October 2020, <a>news broke of Lazada RedMart data
                                        breach</a> containing records as recent as July 2020 and being sold via an
                                    online marketplace. In all, the data contained 1.1 million customer email addresses
                                    alongside names, phone numbers, physical addresses, partial credit card numbers and
                                    passwords stored as SHA-1 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Partial credit card data,
                                    Passwords, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Lead Hunter logo" /></div>
                            <div>
                                <p><span>Lead Hunter</span>: In March 2020, <a>a massive trove of personal information
                                        referred to as "Lead Hunter"</a> was provided to HIBP after being found left
                                    exposed on a publicly facing Elasticsearch server. The data contained 69 million
                                    unique email addresses across 110 million rows of data accompanied by additional
                                    personal information including names, phone numbers, genders and physical addresses.
                                    At the time of publishing, the breach could not be attributed to those responsible
                                    for obtaining and exposing it. The data was provided to HIBP by <a>dehashed.com</a>.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, IP addresses, Names,
                                    Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Leaked Reality logo" /></div>
                            <div>
                                <p><span>Leaked Reality</span>: In January 2022, <a>the now defunct uncensored video
                                        website Leaked Reality</a> suffered a data breach that exposed 115k unique email
                                    addresses. The data also included usernames, IP addresses and passwords stored as
                                    either MD5 or phpass hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Ledger logo" /></div>
                            <div>
                                <p><span>Ledger</span>: In June 2020, the hardware crypto wallet manufacturer <a>Ledger
                                        suffered a data breach that exposed over 1 million email addresses</a>. The data
                                    was initially sold before being dumped publicly in December 2020 and included names,
                                    physical addresses and phone numbers. The data was provided to HIBP by <a>Alon Gal,
                                        CTO of cybercrime intelligence firm Hudson Rock</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Phone numbers, Physical
                                    addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Leet logo" /></div>
                            <div>
                                <p><span>Leet</span>: In August 2016, the service for creating and running Pocket
                                    Minecraft edition servers known as <a>Leet was reported as having suffered a data
                                        breach that impacted 6 million subscribers</a>. The incident reported by
                                    Softpedia had allegedly taken place earlier in the year, although the data set sent
                                    to HIBP was dated as recently as early September but contained only 2 million
                                    subscribers. The data included usernames, email and IP addresses and SHA512 hashes.
                                    A further 3 million accounts were obtained and added to HIBP several days after the
                                    initial data was loaded bringing the total to over 5 million.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Lifeboat logo" /></div>
                            <div>
                                <p><span>Lifeboat</span>: In January 2016, the Minecraft community known as Lifeboat
                                    <a>was hacked and more than 7 million accounts leaked</a>. Lifeboat knew of the
                                    incident for three months before the breach was made public but elected not to
                                    advise customers. The leaked data included usernames, email addresses and passwords
                                    stored as straight MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="LinkedIn logo" /></div>
                            <div>
                                <p><span>LinkedIn</span>: In May 2016, <a>LinkedIn had 164 million email addresses and
                                        passwords exposed</a>. Originally hacked in 2012, the data remained out of sight
                                    until being offered for sale on a dark market site 4 years later. The passwords in
                                    the breach were stored as SHA1 hashes without salt, the vast majority of which were
                                    quickly cracked in the days following the release of the data.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="LinkedIn Scraped Data logo" /></div>
                            <div>
                                <p><span>LinkedIn Scraped Data</span>: During the first half of 2021, <a>LinkedIn was
                                        targeted by attackers who scraped data from hundreds of millions of public
                                        profiles and later sold them online</a>. Whilst the scraping did not constitute
                                    a data breach nor did it access any personal data not intended to be publicly
                                    accessible, the data was still monetised and later broadly circulated in hacking
                                    circles. The scraped data contains approximately 400M records with 125M unique email
                                    addresses, as well as names, geographic locations, genders and job titles. LinkedIn
                                    specifically addresses the incident in their post on <a>An update on report of
                                        scraped data</a>.</p>
                                <p><strong>Compromised data:</strong> Education levels, Email addresses, Genders,
                                    Geographic locations, Job titles, Names, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Little Monsters logo" /></div>
                            <div>
                                <p><span>Little Monsters</span>: In approximately January 2017, <a>the Lady Gaga fan
                                        site known as "Little Monsters" suffered a data breach that impacted 1 million
                                        accounts</a>. The data contained usernames, email addresses, dates of birth and
                                    bcrypt hashes of passwords.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="LiveAuctioneers logo" /></div>
                            <div>
                                <p><span>LiveAuctioneers</span>: In June 2020, the online antiques marketplace
                                    <a>LiveAuctioneers suffered a data breach</a> which was subsequently sold online
                                    then extensively redistributed in the hacking community. The data contained 3.4
                                    million records including names, email and IP addresses, physical addresses, phones
                                    numbers and passwords stored as unsalted MD5 hashes. The data was provided to HIBP
                                    by <a>breachbase.pw</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Passwords,
                                    Phone numbers, Physical addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="LiveJournal logo" /></div>
                            <div>
                                <p><span>LiveJournal</span>: In mid-2019, <a>news broke of an alleged LiveJournal data
                                        breach</a>. This followed <a>multiple reports of credential abuse against
                                        Dreamwidth beginning in 2018</a>, a fork of LiveJournal with a significant
                                    crossover in user base. The breach allegedly dates back to 2017 and contains 26M
                                    unique usernames and email addresses (both of which have been confirmed to exist on
                                    LiveJournal) alongside plain text passwords. An archive of the data was subsequently
                                    shared on a popular hacking forum in May 2020 and redistributed broadly. The data
                                    was provided to HIBP by a source who requested it be attributed to
                                    "nano@databases.pw".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Luxottica logo" /></div>
                            <div>
                                <p><span>Luxottica</span>: In March 2021, the world's largest eyewear company
                                    <a>Luxoticca suffered a data breach via one of their partners that exposed the
                                        personal information of more than 70M people</a>. The data was subsequently sold
                                    via a popular hacking forum in late 2022 and included email and physical addresses,
                                    names, genders, dates of birth and phone numbers. In a statement from Luxottica,
                                    they advised they were aware of the incident and are currently "considering other
                                    notification obligations".</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, Names,
                                    Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="MangaDex logo" /></div>
                            <div>
                                <p><span>MangaDex</span>: In March 2021, the manga fan site <a>MangaDex suffered a data
                                        breach</a> that resulted in the exposure of almost 3 million subscribers. The
                                    data included email and IP addresses, usernames and passwords stored as bcrypt
                                    hashes. The data was subsequently circulated within hacking groups.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Mangatoon logo" /></div>
                            <div>
                                <p><span>Mangatoon</span>: In May 2022, the Hong Kong based Manga service
                                    <a>Mangatoon</a> suffered a data breach that exposed 23M subscriber records. The
                                    breach exposed names, email addresses, genders, social media account identities,
                                    auth tokens from social logins and passwords stored as salted MD5 hashes. Mangatoon
                                    did not respond to multiple attempts to make contact regarding the breach.</p>
                                <p><strong>Compromised data:</strong> Auth tokens, Avatars, Email addresses, Genders,
                                    Names, Passwords, Social media profiles, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Mathway logo" /></div>
                            <div>
                                <p><span>Mathway</span>: In January 2020, the math solving website <a>Mathway suffered a
                                        data breach that exposed over 25M records</a>. The data was subsequently sold on
                                    a dark web marketplace and included names, Google and Facebook IDs, email addresses
                                    and salted password hashes.</p>
                                <p><strong>Compromised data:</strong> Device information, Email addresses, Names,
                                    Passwords, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Minehut logo" /></div>
                            <div>
                                <p><span>Minehut</span>: In May 2019, the Minecraft server website <a>Minehut</a>
                                    suffered a data breach. The company advised a database backup had been obtained
                                    after which they subsequently notified all impacted users. 397k email addresses from
                                    the incident were provided to HIBP. A data set with both email addresses and bcrypt
                                    password hashes was also later provided to HIBP.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Minted logo" /></div>
                            <div>
                                <p><span>Minted</span>: In May 2020, the online marketplace for independent artists
                                    <a>Minted suffered a data breach</a> that exposed 4.4M unique customer records
                                    subsequently sold on a dark web marketplace. Exposed data also included names,
                                    physical addresses, phone numbers and passwords stored as bcrypt hashes. The data
                                    was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Phone numbers,
                                    Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Modern Business Solutions logo" /></div>
                            <div>
                                <p><span>Modern Business Solutions</span>: In October 2016, a large Mongo DB file
                                    containing tens of millions of accounts <a>was shared publicly on Twitter</a> (the
                                    file has since been removed). The database contained over 58M unique email addresses
                                    along with IP addresses, names, home addresses, genders, job titles, dates of birth
                                    and phone numbers. The data was subsequently <a>attributed to "Modern Business
                                        Solutions"</a>, a company that provides data storage and database hosting
                                    solutions. They've yet to acknowledge the incident or explain how they came to be in
                                    possession of the data.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, IP
                                    addresses, Job titles, Names, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="MPGH logo" /></div>
                            <div>
                                <p><span>MPGH</span>: In October 2015, the multiplayer game hacking website <a>MPGH was
                                        hacked</a> and 3.1 million user accounts disclosed. The vBulletin forum breach
                                    contained usernames, email addresses, IP addresses and salted hashes of passwords.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="MyFitnessPal logo" /></div>
                            <div>
                                <p><span>MyFitnessPal</span>: In February 2018, the diet and exercise service
                                    <a>MyFitnessPal suffered a data breach</a>. The incident exposed 144 million unique
                                    email addresses alongside usernames, IP addresses and passwords stored as SHA-1 and
                                    bcrypt hashes (the former for earlier accounts, the latter for newer accounts). In
                                    2019, <a>the data appeared listed for sale on a dark web marketplace</a> (along with
                                    several other large breaches) and subsequently began circulating more broadly. The
                                    data was provided to HIBP by a source who requested it to be attributed to
                                    "BenjaminBlue@exploit.im".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="MyHeritage logo" /></div>
                            <div>
                                <p><span>MyHeritage</span>: In October 2017, the genealogy website <a>MyHeritage
                                        suffered a data breach</a>. The incident was reported 7 months later after a
                                    security researcher discovered the data and contacted MyHeritage. In total, more
                                    than 92M customer records were exposed and included email addresses and salted SHA-1
                                    password hashes. In 2019, <a>the data appeared listed for sale on a dark web
                                        marketplace</a> (along with several other large breaches) and subsequently began
                                    circulating more broadly. The data was provided to HIBP by a source who requested it
                                    be attributed to "BenjaminBlue@exploit.im".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="myRepoSpace logo" /></div>
                            <div>
                                <p><span>myRepoSpace</span>: In July 2015, the Cydia repository known as
                                    <a>myRepoSpace</a> was hacked and <a>user data leaked publicly</a>. Cydia is
                                    designed to facilitate the installation of apps on jailbroken iOS devices. The
                                    repository service was allegedly hacked by <a>@its_not_herpes</a> and
                                    <a>0x8badfl00d</a> in retaliation for the service refusing to remove pirated tweaks.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="MySpace logo" /></div>
                            <div>
                                <p><span>MySpace</span>: In approximately 2008, <a>MySpace suffered a data breach that
                                        exposed almost 360 million accounts</a>. In May 2016 the data was offered up for
                                    sale on the "Real Deal" dark market website and included email addresses, usernames
                                    and SHA1 hashes of the first 10 characters of the password converted to lowercase
                                    and stored without a salt. The exact breach date is unknown, but <a>analysis of the
                                        data suggests it was 8 years before being made public</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="NemoWeb logo" /></div>
                            <div>
                                <p><span>NemoWeb</span>: In September 2016, almost 21GB of data from the French website
                                    used for "standardised and decentralized means of exchange for publishing newsgroup
                                    articles" <a>NemoWeb</a> was leaked from what appears to have been an unprotected
                                    Mongo DB. The data consisted of a large volume of emails sent to the service and
                                    included almost 3.5M unique addresses, albeit many of them auto-generated. Multiple
                                    attempts were made to contact the operators of NemoWeb but no response was received.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, Names</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Neopets logo" /></div>
                            <div>
                                <p><span>Neopets</span>: In May 2016, <a>a set of breached data originating from the
                                        virtual pet website "Neopets" was found being traded online</a>. Allegedly
                                    hacked "several years earlier", the data contains sensitive personal information
                                    including birthdates, genders and names as well as almost 27 million unique email
                                    addresses. Passwords were stored in plain text and IP addresses were also present in
                                    the breach.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders,
                                    Geographic locations, IP addresses, Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="NetEase logo" /></div>
                            <div>
                                <p><span>NetEase<span> (<a>unverified</a>)</span></span>: In October 2015, the Chinese
                                    site known as <a>NetEase</a> (located at <a>163.com</a>) was <a>reported as having
                                        suffered a data breach that impacted hundreds of millions of subscribers</a>.
                                    Whilst there is evidence that the data itself is legitimate (multiple HIBP
                                    subscribers confirmed a password they use is in the data), due to the difficulty of
                                    emphatically verifying the Chinese breach it has been flagged as "unverified". The
                                    data in the breach contains email addresses and plain text passwords. <a>Read more
                                        about Chinese data breaches in Have I Been Pwned.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Netlog logo" /></div>
                            <div>
                                <p><span>Netlog</span>: In July 2018, the Belgian social networking site <a>Netlog
                                        identified a data breach of their systems dating back to November 2012
                                        (PDF)</a>. Although the service was discontinued in 2015, the data breach still
                                    impacted 49 million subscribers for whom email addresses and plain text passwords
                                    were exposed. The data was provided to HIBP by a source who requested it be
                                    attributed to "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="NextGenUpdate logo" /></div>
                            <div>
                                <p><span>NextGenUpdate</span>: Early in 2014, the video game website
                                    <a>NextGenUpdate</a> reportedly <a>suffered a data breach</a> that disclosed almost
                                    1.2 million accounts. Amongst the data breach was usernames, email addresses, IP
                                    addresses and salted and hashed passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Nihonomaru logo" /></div>
                            <div>
                                <p><span>Nihonomaru</span>: In late 2015, the anime community known as Nihonomaru had
                                    their vBulletin forum hacked and 1.7 million accounts exposed. The compromised data
                                    included email and IP addresses, usernames and salted hashes of passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Nitro logo" /></div>
                            <div>
                                <p><span>Nitro</span>: In September 2020, <a>the Nitro PDF service suffered a massive
                                        data breach which exposed over 70 million unique email addresses</a>. The breach
                                    also exposed names, bcrypt password hashes and the titles of converted documents.
                                    The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Nulled.cr logo" /></div>
                            <div>
                                <p><span>Nulled.cr</span>: In May 2016, the cracking community forum known as
                                    <a>Nulled.cr</a> was hacked and 599k user accounts were leaked publicly. The
                                    compromised data included email and IP addresses, weak salted MD5 password hashes
                                    and hundreds of thousands of private messages between members.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Passwords, Private messages, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="OGUsers (2019 breach) logo" /></div>
                            <div>
                                <p><span>OGUsers (2019 breach)</span>: In May 2019, the account hijacking and SIM
                                    swapping forum <a>OGusers suffered a data breach</a>. The breach exposed a database
                                    backup from December 2018 which was published on a rival hacking forum. There were
                                    161k unique email addresses spread across 113k forum users and other tables in the
                                    database. The exposed data also included usernames, IP addresses, private messages
                                    and passwords stored as salted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords, Private
                                    messages, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="OGUsers (2020 breach) logo" /></div>
                            <div>
                                <p><span>OGUsers (2020 breach)</span>: In April 2020, the account hijacking and SIM
                                    swapping forum <a>OGUsers suffered their second data breach in less than a year</a>.
                                    As with the previous breach, the exposed data included email and IP addresses,
                                    usernames, private messages and passwords stored as salted MD5 hashes. A total of
                                    263k email addresses across user accounts and other tables were posted to a rival
                                    hacking forum.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords, Private
                                    messages, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="OGUsers (2021 breach) logo" /></div>
                            <div>
                                <p><span>OGUsers (2021 breach)</span>: In April 2021, the account hijacking and SIM
                                    swapping forum <a>OGusers suffered a data breach</a>, the fourth since December
                                    2018. The breach was subsequently sold on a rival hacking forum and contained
                                    usernames, email and IP addresses and passwords stored as either salted MD5 or
                                    argon2 hashes. A total of 348k unique email addresses appeared in the breach.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="OGUsers (2022 breach) logo" /></div>
                            <div>
                                <p><span>OGUsers (2022 breach)</span>: In July 2022, the account hijacking and SIM
                                    swapping forum OGusers suffered a data breach, the fifth since December 2018. The
                                    breach contained usernames, email and IP addresses and passwords stored as argon2
                                    hashes. A total of 529k unique email addresses appeared in the breach.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Onliner Spambot logo" /></div>
                            <div>
                                <p><span>Onliner Spambot<span> (<a>spam list</a>)</span></span>: In August 2017, a
                                    spambot by the name of <a>Onliner Spambot was identified by security researcher
                                        Benkow moʞuƎq</a>. The malicious software contained a server-based component
                                    located on an IP address in the Netherlands which exposed a large number of files
                                    containing personal information. In total, there were 711 million unique email
                                    addresses, many of which were also accompanied by corresponding passwords. A full
                                    write-up on what data was found is in the blog post titled <a>Inside the Massive 711
                                        Million Record Onliner Spambot Dump</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Onverse logo" /></div>
                            <div>
                                <p><span>Onverse</span>: In January 2016, the online virtual world known as
                                    <a>Onverse</a> was hacked and 800k accounts were exposed. Along with email and IP
                                    addresses, the site also exposed salted MD5 password hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Open CS:GO logo" /></div>
                            <div>
                                <p><span>Open CS:GO</span>: In December 2017, the website for purchasing Counter-Strike
                                    skins known as <a>Open CS:GO</a> (Counter-Strike: Global Offensive) suffered a data
                                    breach (address since redirects to dropgun.com). The 10GB file contained an
                                    extensive amount of personal information including email and IP addresses, phone
                                    numbers, physical addresses and purchase histories. <a>Numerous attempts were made
                                        to contact Open CS:GO about the incident</a>, however no responses were
                                    received.</p>
                                <p><strong>Compromised data:</strong> Avatars, Email addresses, IP addresses, Phone
                                    numbers, Physical addresses, Purchases, Social media profiles, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="OwnedCore logo" /></div>
                            <div>
                                <p><span>OwnedCore</span>: In approximately August 2013, the World of Warcraft exploits
                                    forum known as <a>OwnedCore</a> was hacked and more than 880k accounts were exposed.
                                    The vBulletin forum included IP addresses and passwords stored as salted hashes
                                    using a weak implementation enabling many to be rapidly cracked.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Oxfam logo" /></div>
                            <div>
                                <p><span>Oxfam</span>: In January 2021, <a>Oxfam Australia was the victim of a data
                                        breach</a> which exposed 1.8M unique email addresses of supporters of the
                                    charity. The data was put up for sale on a popular hacking forum and also included
                                    names, phone numbers, addresses, genders and dates of birth. A small number of
                                    people also had partial credit card data exposed (the first 6 and last 3 digits of
                                    the card, plus card type and expiry) and in some cases the bank name, account number
                                    and BSB were also exposed. The data was subsequently made freely available on the
                                    hacking forum later the following month.</p>
                                <p><strong>Compromised data:</strong> Bank account numbers, Dates of birth, Email
                                    addresses, Genders, Names, Partial credit card data, Payment histories, Phone
                                    numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Paddy Power logo" /></div>
                            <div>
                                <p><span>Paddy Power</span>: In October 2010, the Irish bookmaker <a>Paddy Power
                                        suffered a data breach</a> that exposed 750,000 customer records with nearly
                                    600,000 unique email addresses. The breach was not disclosed until July 2014 and
                                    contained extensive personal information including names, addresses, phone numbers
                                    and plain text security questions and answers.</p>
                                <p><strong>Compromised data:</strong> Account balances, Dates of birth, Email addresses,
                                    IP addresses, Names, Phone numbers, Physical addresses, Security questions and
                                    answers, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Paragon Cheats logo" /></div>
                            <div>
                                <p><span>Paragon Cheats</span>: In May 2021, the Grand Theft Auto Online cheats website
                                    <a>Paragon Cheats suffered a data breach that lead to the shutdown of the
                                        service</a>. The breach exposed 188k customer records including usernames, email
                                    and IP addresses. The data was provided to HIBP by a source who requested it be
                                    attributed to "VRAirhead and xFueY".</p>
                                <p><strong>Compromised data:</strong> Browser user agent details, Email addresses, IP
                                    addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ParkMobile logo" /></div>
                            <div>
                                <p><span>ParkMobile</span>: In March 2021, the mobile parking app service <a>ParkMobile
                                        suffered a data breach which exposed 21 million customers' personal data</a>.
                                    The impacted data included email addresses, names, phone numbers, vehicle licence
                                    plates and passwords stored as bcrypt hashes. The following month, the data appeared
                                    on a public hacking forum where it was extensively redistributed.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Licence plates, Names, Passwords,
                                    Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="PayHere logo" /></div>
                            <div>
                                <p><span>PayHere</span>: In late March 2022, the Sri Lankan payment gateway <a>PayHere
                                        suffered a data breach that exposed more than 65GB of payment records</a>
                                    including over 1.5M unique email addresses. The data also included IP and physical
                                    addresses, names, phone numbers, purchase histories and partially obfuscated credit
                                    card data (card type, first 6 and last 4 digits plus expiry date). A month later,
                                    PayHere published a blog on the incident titled <a>Ensuring Integrity on PayHere
                                        Cybersecurity Incident</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Partial
                                    credit card data, Phone numbers, Physical addresses, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Peatix logo" /></div>
                            <div>
                                <p><span>Peatix</span>: In January 2019, the event organising platform <a>Peatix
                                        suffered a data breach</a>. The incident exposed 4.2M email addresses, names and
                                    salted password hashes. The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Pemiblanc logo" /></div>
                            <div>
                                <p><span>Pemiblanc<span> (<a>unverified</a>)</span></span>: In April 2018, a credential
                                    stuffing list containing 111 million email addresses and passwords known as
                                    <a>Pemiblanc</a> was discovered on a French server. The list contained email
                                    addresses and passwords collated from different data breaches and used to mount
                                    account takeover attacks against other services. <a>Read more about the
                                        incident.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="PetFlow logo" /></div>
                            <div>
                                <p><span>PetFlow</span>: In December 2017, the pet care delivery service <a>PetFlow
                                        suffered a data breach which consequently appeared for sale on a dark web
                                        marketplace</a>. Almost 1M accounts were impacted and exposed email addresses
                                    and passwords stored as unsalted MD5 hashes. The data was provided to HIBP by a
                                    source who requested it be attributed to "nano@databases.pw".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Pixlr logo" /></div>
                            <div>
                                <p><span>Pixlr</span>: In October 2020, the online photo editing application <a>Pixlr
                                        suffered a data breach</a> exposing 1.9 million subscribers. Impacted data
                                    included names, email addresses, social media profiles, the country signed up from
                                    and passwords stored as SHA-512 hashes. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Names,
                                    Passwords, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="piZap logo" /></div>
                            <div>
                                <p><span>piZap</span>: In approximately December 2017, the online photo editing site
                                    <a>piZap suffered a data breach</a>. The data was later placed up for sale on a dark
                                    web marketplace along with a collection of other data breaches in February 2019. A
                                    total of 42 million unique email addresses were included in the breach alongside
                                    names, genders and links to Facebook profiles when the social media platform was
                                    used to authenticate to piZap. When accounts were created directly on piZap without
                                    using Facebook for authentication, passwords stored as SHA-1 hashes were also
                                    exposed. The data was provided to HIBP by a source who requested it be attributed to
                                    "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Geographic locations,
                                    Names, Passwords, Social media profiles, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Planet Ice logo" /></div>
                            <div>
                                <p><span>Planet Ice</span>: In January 2023, the UK-based ice skating rink booking
                                    service <a>Planet Ice suffered a data breach</a>. The incident exposed the personal
                                    data of 240k people including email and physical addresses, phone numbers, genders,
                                    dates of birth and passwords stored as MD5 hashes. The data also included the names,
                                    genders and dates of birth of children having parties.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, IP
                                    addresses, Names, Passwords, Phone numbers, Physical addresses, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Pluto TV logo" /></div>
                            <div>
                                <p><span>Pluto TV</span>: In October 2018, the internet television service <a>Pluto TV
                                        suffered a data breach</a> which was then shared extensively in hacking
                                    communities. Pluto TV "decided not to proactively inform users of the breach" which
                                    contained 3.2M unique email and IP addresses, names, usernames, genders, dates of
                                    birth and passwords stored as bcrypt hashes. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Device information, Email
                                    addresses, Genders, IP addresses, Names, Passwords, Social media profiles, Usernames
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Pokébip logo" /></div>
                            <div>
                                <p><span>Pokébip</span>: In July 2015, the French Pokémon site <a>Pokébip suffered a
                                        data breach</a> which exposed 657k subscriber identities. The data included
                                    email and IP addresses, usernames and passwords stored as unsalted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords, Time
                                    zones, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Pokémon Creed logo" /></div>
                            <div>
                                <p><span>Pokémon Creed</span>: In August 2014, the Pokémon RPG website <a>Pokémon
                                        Creed</a> was hacked after a dispute with rival site, <a>Pokémon Dusk</a>. In a
                                    <a>post on Facebook</a>, "Cruz Dusk" announced the hack then pasted the dumped MySQL
                                    database on <a>pkmndusk.in</a>. The breached data included over 116k usernames,
                                    email addresses and plain text passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, IP addresses, Passwords,
                                    Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Poshmark logo" /></div>
                            <div>
                                <p><span>Poshmark</span>: In mid-2018, social commerce marketplace <a>Poshmark suffered
                                        a data breach</a> that exposed 36M user accounts. The compromised data included
                                    email addresses, names, usernames, genders, locations and passwords stored as bcrypt
                                    hashes. The data was provided to HIBP by a source who requested it be attributed to
                                    "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Geographic locations,
                                    Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Powerbot logo" /></div>
                            <div>
                                <p><span>Powerbot</span>: In approximately September 2014, the RuneScape bot website
                                    <a>Powerbot</a> suffered a data breach resulting in the exposure of over half a
                                    million unique user records. The data contained email and IP addresses, usernames
                                    and salted MD5 hashes of passwords. The site was previously reported as compromised
                                    on the <a>Vigilante.pw</a> breached database directory.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ProctorU logo" /></div>
                            <div>
                                <p><span>ProctorU</span>: In June 2020, the online exam service <a>ProctorU suffered a
                                        data breach</a> which was subsequently shared extensively across online hacking
                                    communities. The breach contained 444k user records including names, email and
                                    physical addresses, phones numbers and passwords stored as bcrypt hashes. The data
                                    was provided to HIBP by <a>breachbase.pw</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Phone numbers,
                                    Physical addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Promo logo" /></div>
                            <div>
                                <p><span>Promo</span>: In July 2020, the self-proclaimed "World's #1 Marketing Video
                                    Maker" <a>Promo suffered a data breach</a> which was then shared extensively on a
                                    hacking forum. The incident exposed 22 million records containing almost 15 million
                                    unique email addresses alongside IP addresses, genders, names and salted SHA-256
                                    password hashes. The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, IP addresses, Names,
                                    Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Promofarma logo" /></div>
                            <div>
                                <p><span>Promofarma</span>: In August 2019, <a>a data breach from the Spanish online
                                        pharmacy Promofarma appeared for sale on a dark web marketplace</a>. The breach
                                    exposed over 2.7M records and contained almost 1.3M unique customer email addresses.
                                    The data also included customer names and was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="PropTiger logo" /></div>
                            <div>
                                <p><span>PropTiger</span>: In January 2018, the Indian property website <a>PropTiger</a>
                                    suffered a data breach which resulted in a 3.46GB database file being exposed and
                                    subsequently shared extensively on a popular hacking forum 2 years later. The
                                    exposed data contained both user records and login histories with over 2M unique
                                    customer email addresses. Exposed data also included additional personal attributes
                                    such as names, dates of birth, genders, IP addresses and passwords stored as MD5
                                    hashes. PropTiger advised they believe the usability of the data is "limited" due to
                                    how certain data attributes were generated and stored. The data was provided to HIBP
                                    by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Device information, Email
                                    addresses, Genders, IP addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="QIP logo" /></div>
                            <div>
                                <p><span>QIP</span>: In mid-2011, the Russian instant messaging service known as <a>QIP
                                        (Quiet Internet Pager) suffered a data breach</a>. The attack resulted in the
                                    disclosure of over 26 million unique accounts including email addresses and
                                    passwords with the data eventually appearing in public years later.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames, Website
                                    activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="QuestionPro logo" /></div>
                            <div>
                                <p><span>QuestionPro</span>: In May 2022, <a>the survey website QuestionPro was the
                                        target of an extortion attempt relating to an alleged data breach</a>. Over
                                    100GB of data containing 22M unique email addresses (some of which appear to be
                                    generated by the platform), are alleged to have been extracted from the service
                                    along with IP addresses, browser user agents and results relating to surveys.
                                    QuestionPro would not confirm whether a breach had occurred (although they did
                                    confirm they were the target of an extortion attempt), so the data was initially
                                    flagged as "unverified". <a>Subsequent verification by impacted HIBP subscribers</a>
                                    later led to the removal of the unverified flag.</p>
                                <p><strong>Compromised data:</strong> Browser user agent details, Email addresses, IP
                                    addresses, Survey results</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Quidd logo" /></div>
                            <div>
                                <p><span>Quidd</span>: In 2019, online marketplace for trading stickers, cards, toys,
                                    and other collectibles <a>Quidd suffered a data breach</a>. The breach exposed
                                    almost 4 million users' email addresses, usernames and passwords stored as bcrypt
                                    hashes. The data was subsequently sold then redistributed extensively via hacking
                                    forums.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="R2Games logo" /></div>
                            <div>
                                <p><span>R2Games</span>: In late 2015, the gaming website <a>R2Games</a> was hacked and
                                    more than 2.1M personal records disclosed. The vBulletin forum included IP addresses
                                    and passwords stored as salted hashes using a weak implementation enabling many to
                                    be rapidly cracked. A further 11M accounts were added to "Have I Been Pwned" in
                                    March 2016 and another 9M in July 2016 bringing the total to over 22M.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Raychat logo" /></div>
                            <div>
                                <p><span>Raychat</span>: In January 2021, the now defunct Iranian social media platform
                                    <a>Raychat suffered a data breach that exposed 939 thousand unique email
                                        addresses</a>. The data included names, IP addresses, browser user agent strings
                                    and passwords stored as bcrypt hashes. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Browser user agent details, Email addresses, IP
                                    addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Rbx.Rocks logo" /></div>
                            <div>
                                <p><span>Rbx.Rocks</span>: In August 2018, the Roblox trading site <a>Rbx.Rocks</a>
                                    suffered a data breach. Almost 25k records were sent to HIBP in November and
                                    included names, email addresses and passwords stored as bcrypt hashes. In July 2019,
                                    a further 125k records emerged bringing the total size of the incident to 150k. The
                                    website has since gone offline with a message stating that "Rbx.Rocks v2.0 is
                                    currently under construction".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Read Novel logo" /></div>
                            <div>
                                <p><span>Read Novel<span> (<a>unverified</a>)</span></span>: In May 2019, the Chinese
                                    literature website <a>Read Novel</a> allegedly suffered a data breach that exposed
                                    22M unique email addresses. Data also included usernames, genders, phone numbers and
                                    passwords stored as salted MD5 hashes. The data was provided to HIBP by a source who
                                    requested it be attributed to "white_peacock@riseup.net". <a>Read more about Chinese
                                        data breaches in Have I Been Pwned.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Passwords, Phone
                                    numbers, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="RedDoorz logo" /></div>
                            <div>
                                <p><span>RedDoorz</span>: In September 2020, the hotel management &amp; booking platform
                                    <a>RedDoorz suffered a data breach that exposed over 5.8M user accounts</a>. The
                                    breached data included names, email addresses, phone numbers, genders, dates of
                                    birth and passwords stored as bcrypt hashes. The data was provided to HIBP by a
                                    source who requested it be attributed to "white_peacock@riseup.net".</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, Names,
                                    Occupations, Passwords, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Reincubate logo" /></div>
                            <div>
                                <p><span>Reincubate</span>: In October 2020, the app data company <a>Reincubate suffered
                                        a data breach</a> which exposed a backup from November 2017 (the newest record
                                    in the data appeared several months earlier). The data included over 616k unique
                                    email addresses, names and passwords stored as PBKDF2 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="RentoMojo logo" /></div>
                            <div>
                                <p><span>RentoMojo</span>: In April 2023, the Indian rental service <a>RentoMojo
                                        suffered a data breach</a>. The breach exposed over 2M unique email addresses
                                    along with names, phone, passport and Aadhaar numbers, genders, dates of birth,
                                    purchases and bcrypt password hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders,
                                    Government issued IDs, Names, Passport numbers, Passwords, Phone numbers, Purchases,
                                    Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Retina-X logo" /></div>
                            <div>
                                <p><span>Retina-X</span>: In February 2017, the mobile device monitoring software
                                    developer Retina-X was hacked and customer data downloaded before being wiped from
                                    their servers. The incident was covered in the Motherboard article titled <a>Inside
                                        the 'Stalkerware' Surveillance Market, Where Ordinary People Tap Each Other's
                                        Phones</a>. The service, used to monitor mobile devices, had 71k email addresses
                                    and MD5 hashes with no salt exposed. Retina-X <a>disclosed the incident in a blog
                                        post</a> on April 27, 2017.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="River City Media Spam List logo" /></div>
                            <div>
                                <p><span>River City Media Spam List<span> (<a>spam list</a>)</span></span>: In January
                                    2017, <a>a massive trove of data from River City Media was found exposed online</a>.
                                    The data was found to contain almost 1.4 billion records including email and IP
                                    addresses, names and physical addresses, all of which was used as part of an
                                    enormous spam operation. Once de-duplicated, there were 393 million unique email
                                    addresses within the exposed data.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Physical
                                    addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Roll20 logo" /></div>
                            <div>
                                <p><span>Roll20</span>: In December 2018, the tabletop role-playing games website
                                    <a>Roll20 suffered a data breach</a>. Almost 4 million customers were impacted by
                                    the breach and had email and IP addresses, names, bcrypt hashes of passwords and the
                                    last 4 digits of credit cards exposed. The data was provided to HIBP by a source who
                                    requested it be attributed to "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Partial
                                    credit card data, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Romwe logo" /></div>
                            <div>
                                <p><span>Romwe</span>: In mid-2018, the Hong Kong-based retailer <a>Romwe suffered a
                                        data breach which exposed almost 20 million customers</a>. The data was
                                    subsequently sold online and includes names, phone numbers, email and IP addresses,
                                    customer geographic locations and passwords stored as salted SHA-1 hashes. The data
                                    was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Geographic locations, IP addresses, Names,
                                    Passwords, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Scentbird logo" /></div>
                            <div>
                                <p><span>Scentbird</span>: In June 2020, the online fragrance service <a>Scentbird
                                        suffered a data breach</a> that exposed the personal information of over 5.8
                                    million customers. Personal information including names, email addresses, genders,
                                    dates of birth, passwords stored as bcrypt hashes and indicators of password
                                    strength were all exposed. The data was provided to HIBP by <a>breachbase.pw</a>.
                                </p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, Names,
                                    Password strengths, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ShareThis logo" /></div>
                            <div>
                                <p><span>ShareThis</span>: In July 2018, the social bookmarking and sharing service
                                    <a>ShareThis suffered a data breach</a>. The incident exposed 41 million unique
                                    email addresses alongside names and in some cases, dates of birth and password
                                    hashes. In 2019, <a>the data appeared listed for sale on a dark web marketplace</a>
                                    (along with several other large breaches) and subsequently began circulating more
                                    broadly. The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Names, Passwords
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="SHEIN logo" /></div>
                            <div>
                                <p><span>SHEIN</span>: In June 2018, online fashion retailer <a>SHEIN suffered a data
                                        breach</a>. The company discovered the breach 2 months later in August then
                                    disclosed the incident another month after that. A total of 39 million unique email
                                    addresses were found in the breach alongside MD5 password hashes. The data was
                                    provided to HIBP by a source who requested it be attributed to
                                    "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ShopBack logo" /></div>
                            <div>
                                <p><span>ShopBack</span>: In September 2020, the cashback reward program <a>ShopBack
                                        suffered a data breach</a>. The incident exposed over 20 million unique email
                                    addresses along with names, phone numbers, country of residence and passwords stored
                                    as salted SHA-1 hashes. The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Names,
                                    Passwords, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Shotbow logo" /></div>
                            <div>
                                <p><span>Shotbow</span>: In May 2016, the multiplayer server for Minecraft service
                                    <a>Shotbow announced they'd suffered a data breach</a>. The incident resulted in the
                                    exposure of over 1 million unique email addresses, usernames and salted SHA-256
                                    password hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="SirHurt logo" /></div>
                            <div>
                                <p><span>SirHurt</span>: In April 2021, the the Roblox cheats website <a>SirHurt
                                        suffered a data breach</a> that exposed over 90k customer records. The exposed
                                    data included email and IP addresses, usernames and passwords stored as MD5 hashes.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="SitePoint logo" /></div>
                            <div>
                                <p><span>SitePoint</span>: In June 2020, the web development site <a>SitePoint suffered
                                        a data breach that exposed over 1M customer records</a>. Impacted data included
                                    email and IP addresses, names, usernames, bios and passwords stored as bcrypt
                                    hashes.</p>
                                <p><strong>Compromised data:</strong> Bios, Email addresses, IP addresses, Names,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="SlideTeam logo" /></div>
                            <div>
                                <p><span>SlideTeam</span>: In April 2021, the "world’s largest collection of
                                    pre-designed presentation slides" <a>SlideTeam had 1.4M records breached and later
                                        published to a popular hacking forum the following year</a>. Allegedly sourced
                                    from a compromised Magento instance, the data included names, email addresses and
                                    passwords stored as salted hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Smogon logo" /></div>
                            <div>
                                <p><span>Smogon</span>: In April 2018, the Pokémon website known as <a>Smogon announced
                                        they'd suffered a data breach</a>. The breach dated back to September 2017 and
                                    affected their XenForo based forum. The exposed data included usernames, email
                                    addresses, genders and both bcrypt and MD5 password hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Geographic locations,
                                    Passwords, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Sonicbids logo" /></div>
                            <div>
                                <p><span>Sonicbids</span>: In December 2019, the booking website <a>Sonicbids suffered a
                                        data breach</a> which they attributed to "a data privacy event involving our
                                    third-party cloud hosting services". The breach contained 752k user records
                                    including names and usernames, email addresses and passwords stored as PBKDF2
                                    hashes. The data was provided to HIBP by <a>breachbase.pw</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="SpyFone logo" /></div>
                            <div>
                                <p><span>SpyFone</span>: In August 2018, the spyware company <a>SpyFone left terabytes
                                        of data publicly exposed</a>. Collected surreptitiously whilst the targets were
                                    using their devices, the data included photos, audio recordings, text messages and
                                    browsing history which were then exposed via a number of misconfigurations within
                                    SpyFone's systems. The data belonged the thousands of SpyFone customers and included
                                    44k unique email addresses, many likely belonging to people the targeted phones had
                                    contact with.</p>
                                <p><strong>Compromised data:</strong> Audio recordings, Browsing histories, Device
                                    information, Email addresses, Geographic locations, IMEI numbers, IP addresses,
                                    Names, Passwords, Photos, SMS messages</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="START logo" /></div>
                            <div>
                                <p><span>START</span>: In August 2022, <a>news broke of an attack against the Russian
                                        streaming service "START"</a>. The incident led to the exposure of 44M records
                                    containing 7.4M unique email addresses. The impacted data also included the
                                    subscriber's country and password hash. START subsequently <a>acknowledged the
                                        incident in a Telegram post</a> and stated that the data dated back to 2021.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Names,
                                    Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="StarTribune logo" /></div>
                            <div>
                                <p><span>StarTribune</span>: In October 2019, the Minnesota-based news service
                                    <a>StarTribune suffered a data breach</a> which was subsequently sold on the dark
                                    web. The breach exposed over 2 million unique email addresses alongside names,
                                    usernames, physical addresses, dates of birth, genders and passwords stored as
                                    bcrypt hashes. The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, Names,
                                    Passwords, Physical addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="StockX logo" /></div>
                            <div>
                                <p><span>StockX</span>: In July 2019, the fashion and sneaker trading platform <a>StockX
                                        suffered a data breach</a> which was subsequently sold via a dark
                                    webmarketplace. The exposed data included 6.8 million unique email addresses, names,
                                    physical addresses, purchases and passwords stored as salted MD5 hashes. The data
                                    was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Physical
                                    addresses, Purchases, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="StoryBird logo" /></div>
                            <div>
                                <p><span>StoryBird</span>: In August 2015, the storytelling service <a>StoryBird
                                        suffered a data breach</a> exposing 4 million records with 1 million unique
                                    email addresses. Impacted data also included names, usernames and passwords stored
                                    as PBKDF2 hashes. The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Straffic logo" /></div>
                            <div>
                                <p><span>Straffic</span>: In February 2020, Israeli marketing company <a>Straffic
                                        exposed a database with 140GB of personal data</a>. The publicly accessible
                                    Elasticsearch database contained over 300M rows with 49M unique email addresses.
                                    Exposed data also included names, phone numbers, physical addresses and genders. In
                                    <a>their breach disclosure message</a>, Straffic stated that "it is impossible to
                                    create a totally immune system, and these things can occur".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Names, Phone numbers,
                                    Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Stratfor logo" /></div>
                            <div>
                                <p><span>Stratfor</span>: In December 2011, "Anonymous" <a>attacked the global
                                        intelligence company known as "Stratfor"</a> and consequently disclosed a
                                    veritable treasure trove of data including hundreds of gigabytes of email and tens
                                    of thousands of credit card details which were promptly used by the attackers to
                                    make charitable donations (among other uses). The breach also included 860,000 user
                                    accounts complete with email address, time zone, some internal system data and MD5
                                    hashed passwords with no salt.</p>
                                <p><strong>Compromised data:</strong> Credit cards, Email addresses, Names, Passwords,
                                    Phone numbers, Physical addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="StreetEasy logo" /></div>
                            <div>
                                <p><span>StreetEasy</span>: In approximately June 2016, the real estate website
                                    <a>StreetEasy suffered a data breach</a>. In total, 988k unique email addresses were
                                    included in the breach alongside names, usernames and SHA-1 hashes of passwords, all
                                    of which appeared for sale on a dark web marketplace in February 2019. The data was
                                    provided to HIBP by a source who requested it be attributed to
                                    "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Stronghold Kingdoms logo" /></div>
                            <div>
                                <p><span>Stronghold Kingdoms</span>: In July 2018, the massive multiplayer online game
                                    <a>Stronghold Kingdoms suffered a data breach</a>. Almost 5.2 million accounts were
                                    impacted by the incident which exposed emails addresses, usernames and passwords
                                    stored as salted SHA-1 hashes. The data was provided to HIBP by a source who
                                    requested it be attributed to "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="SubaGames logo" /></div>
                            <div>
                                <p><span>SubaGames</span>: In November 2016, the game developer <a>Suba Games suffered a
                                        data breach</a> which led to the exposure of 6.1M unique email addresses.
                                    Impacted data also included usernames and passwords, most of which appeared
                                    circulating in the breached file in plain text after being cracked from salted MD5
                                    hashes. The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Sundry Files logo" /></div>
                            <div>
                                <p><span>Sundry Files</span>: In January 2022, the now defunct file upload service
                                    Sundry Files suffered a data breach that exposed 274k unique email addresses. The
                                    data also included usernames, IP addresses and passwords stored as salted SHA-256
                                    hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="SweClockers.com logo" /></div>
                            <div>
                                <p><span>SweClockers.com</span>: In early 2015, the Swedish tech news site
                                    <a>SweClockers was hacked</a> and 255k accounts were exposed. The attack led to the
                                    exposure of usernames, email addresses and salted hashes of passwords stored with a
                                    combination of MD5 and SHA512.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Swvl logo" /></div>
                            <div>
                                <p><span>Swvl</span>: In June 2020, the Egyptian bus operator <a>Swvl suffered a data
                                        breach</a> which impacted over 4 million members of the service. The exposed
                                    data included names, email addresses, phone numbers, profile photos, partial credit
                                    card data (type and last 4 digits) and passwords stored as bcrypt hashes, all of
                                    which was subsequently shared extensively throughout online hacking communities. The
                                    data was provided to HIBP by <a>breachbase.pw</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Partial credit card data,
                                    Passwords, Phone numbers, Profile photos</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="TaiLieu logo" /></div>
                            <div>
                                <p><span>TaiLieu</span>: In November 2019, the Vietnamese education website
                                    <a>TaiLieu</a> allegedly suffered a data breach exposing 7.3M customer records.
                                    Impacted data included names and usernames, email addresses, dates of birth, genders
                                    and passwords stored as unsalted MD5 hashes. The data was provided to HIBP by
                                    <a>dehashed.com</a> after being shared on a popular hacking forum. TaiLieu did not
                                    respond when contacted about the incident.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders,
                                    Geographic locations, Names, Passwords, Phone numbers, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="TAP Air Portugal logo" /></div>
                            <div>
                                <p><span>TAP Air Portugal</span>: In August 2022, the Portuguese airline <a>TAP Air
                                        Portugal was the target of a ransomware attack perpetrated by the Ragnar Locker
                                        gang</a> who later leaked the compromised data via a public dark web site. Over
                                    5M unique email addresses were exposed alongside other personal data including
                                    names, genders, DoBs, phone numbers and physical addresses.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, Names,
                                    Nationalities, Phone numbers, Physical addresses, Salutations, Spoken languages</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Teespring logo" /></div>
                            <div>
                                <p><span>Teespring</span>: In April 2020, the custom printed apparel website
                                    <a>Teespring suffered a data breach that exposed 8.2 million customer records</a>.
                                    The data included email addresses, names, geographic locations and social media IDs.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Names,
                                    Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="TGBUS logo" /></div>
                            <div>
                                <p><span>TGBUS<span> (<a>unverified</a>)</span></span>: In approximately 2017, it's
                                    alleged that the Chinese gaming site known as <a>TGBUS</a> suffered a data breach
                                    that impacted over 10 million unique subscribers. Whilst there is evidence that the
                                    data is legitimate, due to the difficulty of emphatically verifying the Chinese
                                    breach it has been flagged as "unverified". The data in the breach contains
                                    usernames, email addresses and salted MD5 password hashes and was provided with
                                    support from <a>dehashed.com</a>. <a>Read more about Chinese data breaches in Have I
                                        Been Pwned.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="TheTVDB.com logo" /></div>
                            <div>
                                <p><span>TheTVDB.com</span>: In November 2017, the open television database known as
                                    <a>TheTVDB.com suffered a data breach</a>. The breached data was posted to a hacking
                                    forum and included 182k records with usernames, email addresses and MySQL password
                                    hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ThisHabbo Forum logo" /></div>
                            <div>
                                <p><span>ThisHabbo Forum</span>: In 2014, the ThisHabbo forum (a fan site for Habbo.com,
                                    a Finnish social networking site) <a>appeared among a list of compromised sites</a>
                                    which has subsequently been removed from the internet. Whilst the actual date of the
                                    exploit is not clear, the breached data includes usernames, email addresses, IP
                                    addresses and salted hashes of passwords. A further 584k records were added from a
                                    more comprehensive breach file provided in October 2016.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Tianya logo" /></div>
                            <div>
                                <p><span>Tianya</span>: In December 2011, <a>China's largest online forum known as
                                        Tianya was hacked</a> and tens of millions of accounts were obtained by the
                                    attacker. The leaked data included names, usernames and email addresses.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Ticketfly logo" /></div>
                            <div>
                                <p><span>Ticketfly</span>: In May 2018, the website for the ticket distribution service
                                    <a>Ticketfly was defaced by an attacker and was subsequently taken offline</a>. The
                                    attacker allegedly requested a ransom to share details of the vulnerability with
                                    Ticketfly but did not receive a reply and subsequently posted the breached data
                                    online to a publicly accessible location. The data included over 26 million unique
                                    email addresses along with names, physical addresses and phone numbers. Whilst there
                                    were no passwords in the publicly leaked data, <a>Ticketfly later issued an incident
                                        update</a> and stated that "It is possible, however, that hashed values of
                                    password credentials could have been accessed".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Phone numbers, Physical
                                    addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Tokopedia logo" /></div>
                            <div>
                                <p><span>Tokopedia</span>: In April 2020, Indonesia's largest online store <a>Tokopedia
                                        suffered a data breach</a>. The incident resulted in 15M rows of data being
                                    posted to a popular hacking forum. An additional 76M rows were later provided to
                                    HIBP in July 2020. In total, the data included over 71M unique email addresses
                                    alongside names, genders, birth dates and passwords stored as SHA2-384 hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, Names,
                                    Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ToonDoo logo" /></div>
                            <div>
                                <p><span>ToonDoo</span>: In August 2019, the comic strip creation website <a>ToonDoo
                                        suffered a data breach</a>. The data was subsequently redistributed on a popular
                                    hacking forum in November where the personal information of over 6M subscribers was
                                    shared. Impacted data included email and IP addresses, usernames, genders, the
                                    location of the individual and salted password hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Geographic locations, IP
                                    addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Tout logo" /></div>
                            <div>
                                <p><span>Tout</span>: In approximately September 2014, the now defunct social networking
                                    service <a>Tout</a> suffered a data breach. The breach subsequently appeared years
                                    later and included 653k unique email addresses, names, IP addresses, the location of
                                    the user, their bio and passwords stored as bcrypt hashes. The data was provided to
                                    HIBP by a source who requested it to be attributed to "nmapthis@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Bios, Email addresses, Geographic locations, IP
                                    addresses, Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Trillian logo" /></div>
                            <div>
                                <p><span>Trillian</span>: In December 2015, the instant messaging application
                                    <a>Trillian suffered a data breach</a>. The breach became known in July 2016 and
                                    exposed various personal data attributes including names, email addresses and
                                    passwords stored as salted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Truth Finder logo" /></div>
                            <div>
                                <p><span>Truth Finder</span>: In 2019, the public records search service <a>TruthFinder
                                        suffered a data breach that later came to light in early 2023</a>. The data
                                    included over 8M unique customer email addresses, names, phone numbers and passwords
                                    stored as scrypt hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Phone numbers
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="tumblr logo" /></div>
                            <div>
                                <p><span>tumblr</span>: In early 2013, <a>tumblr suffered a data breach</a> which
                                    resulted in the exposure of over 65 million accounts. The data was later put up for
                                    sale on a dark market website and included email addresses and passwords stored as
                                    salted SHA1 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Tuned Global logo" /></div>
                            <div>
                                <p><span>Tuned Global</span>: In January 2021, <a>data from a number of breached
                                        services including Tuned Global were released to a public hacking forum</a>. The
                                    breach appears to date back to 2016 and includes 985k records containing email
                                    addresses, names, a small number of physical addresses and phone numbers and
                                    passwords stored in plain text.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Phone numbers,
                                    Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Twitter (200M) logo" /></div>
                            <div>
                                <p><span>Twitter (200M)</span>: In early 2023, <a>over 200M records scraped from Twitter
                                        appeared on a popular hacking forum</a>. The data was obtained sometime in 2021
                                    by abusing an API that enabled email addresses to be resolved to Twitter profiles.
                                    The subsequent results were then composed into a corpus of data containing email
                                    addresses alongside public Twitter profile information including names, usernames
                                    and follower counts.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Social media profiles,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Unverified Data Source logo" /></div>
                            <div>
                                <p><span>Unverified Data Source<span> (<a>unverified</a>)</span></span>: In January
                                    2021, over 11M unique email addresses were discovered by Night Lion Security
                                    alongside an extensive amount of personal information including names, physical and
                                    IP addresses, phone numbers and dates of birth. Some records also contained social
                                    security numbers, driver's license details, personal financial information and
                                    health-related data, depending on where the information was sourced from. Initially
                                    attributed to Astoria Company, <a>they subsequently investigated the incident and
                                        confirmed the data did not originate from their services</a>.</p>
                                <p><strong>Compromised data:</strong> Bank account numbers, Credit status information,
                                    Dates of birth, Email addresses, Employers, Health insurance information, Income
                                    levels, IP addresses, Names, Personal health data, Phone numbers, Physical
                                    addresses, Smoking habits, Social security numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Vakinha logo" /></div>
                            <div>
                                <p><span>Vakinha</span>: In June 2020, the Brazilian fund raising service <a>Vakinha
                                        suffered a data breach</a> which impacted almost 4.8 million members. The
                                    exposed data included email addresses, names, phone numbers, geographic locations
                                    and passwords stored as bcrypt hashes, all of which was subsequently shared
                                    extensively throughout online hacking communities. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Names, Passwords, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="vBulletin logo" /></div>
                            <div>
                                <p><span>vBulletin</span>: In November 2015, the forum software maker <a>vBulletin
                                        suffered a serious data breach</a>. The attack lead to the release of both forum
                                    user and customer accounts totalling almost 519k records. The breach included email
                                    addresses, birth dates, security questions and answers for customers and salted
                                    hashes of passwords for both sources.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Homepage URLs,
                                    Instant messenger identities, IP addresses, Passwords, Security questions and
                                    answers, Spoken languages, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Vedantu logo" /></div>
                            <div>
                                <p><span>Vedantu</span>: In mid-2019, the Indian interactive online tutoring platform
                                    <a>Vedantu</a> suffered a data breach which exposed the personal data of 687k users.
                                    The JSON formatted database dump exposed extensive personal information including
                                    email and IP address, names, phone numbers, genders and passwords stored as bcrypt
                                    hashes. When contacted about the incident, Vedantu advised that they were aware of
                                    the breach and were in the process of informing their customers.</p>
                                <p><strong>Compromised data:</strong> Browser user agent details, Email addresses,
                                    Genders, IP addresses, Names, Passwords, Phone numbers, Spoken languages, Time
                                    zones, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Verifications.io logo" /></div>
                            <div>
                                <p><span>Verifications.io</span>: In February 2019, the email address validation service
                                    <a>verifications.io suffered a data breach</a>. Discovered by <a>Bob Diachenko</a>
                                    and <a>Vinny Troia</a>, the breach was due to the data being stored in a MongoDB
                                    instance left publicly facing without a password and resulted in 763 million unique
                                    email addresses being exposed. Many records within the data also included additional
                                    personal attributes such as names, phone numbers, IP addresses, dates of birth and
                                    genders. No passwords were included in the data. The Verifications.io website went
                                    offline during the disclosure process, although <a>an archived copy remains
                                        viewable</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Employers,
                                    Genders, Geographic locations, IP addresses, Job titles, Names, Phone numbers,
                                    Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="VK logo" /></div>
                            <div>
                                <p><span>VK</span>: In approximately 2012, the Russian social media site known as <a>VK
                                        was hacked</a> and almost 100 million accounts were exposed. The data emerged in
                                    June 2016 where it was being sold via a dark market website and included names,
                                    phone numbers email addresses and plain text passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Phone numbers
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="VNG logo" /></div>
                            <div>
                                <p><span>VNG</span>: In April 2018, <a>news broke of a massive data breach impacting the
                                        Vietnamese company known as VNG</a> after data was discovered being traded on a
                                    popular hacking forum where it was extensively redistributed. The breach dated back
                                    to an incident in May of 2015 and included of over 163 million customers. The data
                                    in the breach contained a wide range of personal attributes including usernames,
                                    birth dates, genders and home addresses along with unsalted MD5 hashes and 25
                                    million unique email addresses. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, IP
                                    addresses, Marital statuses, Names, Occupations, Passwords, Phone numbers, Physical
                                    addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Void.to logo" /></div>
                            <div>
                                <p><span>Void.to</span>: In June 2019, the hacking website <a>Void.to</a> suffered a
                                    data breach. There were 95k unique email addresses spread across 86k forum users and
                                    other tables in the database. A rival hacking website claimed responsibility for
                                    breaching the MyBB based forum which disclosed email and IP addresses, usernames,
                                    private messages and passwords stored as either salted MD5 or bcrypt hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords, Private
                                    messages, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Wakanim logo" /></div>
                            <div>
                                <p><span>Wakanim</span>: In August 2022, the European streaming service <a>Wakanim
                                        suffered a data breach which was subsequently advertised and sold on a popular
                                        hacking forum</a>. The breach exposed 6.7M customer records including email, IP
                                    and physical addresses, names and usernames.</p>
                                <p><strong>Compromised data:</strong> Browser user agent details, Email addresses, IP
                                    addresses, Names, Physical addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Wanelo logo" /></div>
                            <div>
                                <p><span>Wanelo</span>: In approximately December 2018, the digital mall <a>Wanelo
                                        suffered a data breach</a>. The data was later placed up for sale on a dark web
                                    marketplace along with a collection of other data breaches in April 2019. A total of
                                    23 million unique email addresses were included in the breach alongside passwords
                                    stored as either MD5 or bcrypt hashes. After the initial HIBP load, further data
                                    containing names, shipping addresses and IP addresses were also provided to HIBP,
                                    albeit without direct association to the email addresses and passwords. The data was
                                    provided to HIBP by a source who requested it be attributed to
                                    "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Passwords,
                                    Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="War Inc. logo" /></div>
                            <div>
                                <p><span>War Inc.</span>: In mid-2012, the real-time strategy game <a>War Inc.</a>
                                    suffered a data breach. The attack resulted in the exposure of over 1 million
                                    accounts including usernames, email addresses and salted MD5 hashes of passwords.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames, Website
                                    activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Wattpad logo" /></div>
                            <div>
                                <p><span>Wattpad</span>: In June 2020, the user-generated stories website <a>Wattpad
                                        suffered a huge data breach that exposed almost 270 million records</a>. The
                                    data was initially sold then published on a public hacking forum where it was
                                    broadly shared. The incident exposed extensive personal information including names
                                    and usernames, email and IP addresses, genders, birth dates and passwords stored as
                                    bcrypt hashes.</p>
                                <p><strong>Compromised data:</strong> Bios, Dates of birth, Email addresses, Genders,
                                    Geographic locations, IP addresses, Names, Passwords, Social media profiles, User
                                    website URLs, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="We Heart It logo" /></div>
                            <div>
                                <p><span>We Heart It</span>: In November 2013, the image-based social network <a>We
                                        Heart It suffered a data breach</a>. The incident wasn't discovered until
                                    October 2017 when 8.6 million user records were sent to HIBP. The data contained
                                    user names, email addresses and password hashes, 80% of which were salted SHA-256
                                    with the remainder being MD5 with no salt.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="WedMeGood logo" /></div>
                            <div>
                                <p><span>WedMeGood</span>: In January 2021, the Indian wedding planning platform
                                    <a>WedMeGood suffered a data breach that exposed 1.3 million customers</a>. The
                                    breach exposed 41.5GB of data including email and physical addresses, names,
                                    genders, phone numbers and password hashes. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Names, Passwords, Phone
                                    numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Whitepages logo" /></div>
                            <div>
                                <p><span>Whitepages</span>: In mid-2016, the telephone and address directory service
                                    <a>Whitepages was among a raft of sites that were breached and their data then sold
                                        in early-2019</a>. The data included over 11 million unique email addresses
                                    alongside names and passwords stored as either a SHA-1 or bcrypt hash. The data was
                                    provided to HIBP by a source who requested it to be attributed to
                                    "BenjaminBlue@exploit.im".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="WIIU ISO logo" /></div>
                            <div>
                                <p><span>WIIU ISO</span>: In September 2015, the Nintendo Wii U forum known as <a>WIIU
                                        ISO</a> was hacked and 458k accounts were exposed. Along with email and IP
                                    addresses, the vBulletin forum also exposed salted MD5 password hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Wishbone (2016) logo" /></div>
                            <div>
                                <p><span>Wishbone (2016)</span>: In August 2016, the mobile app to "compare anything"
                                    known as <a>Wishbone suffered a data breach</a>. The data contained 9.4 million
                                    records with 2.2 million unique email addresses and was allegedly a subset of the
                                    complete data set. The exposed data included genders, birthdates, email addresses
                                    and phone numbers for an audience predominantly composed of teenagers and young
                                    adults.</p>
                                <p><strong>Compromised data:</strong> Auth tokens, Dates of birth, Email addresses,
                                    Genders, Names, Phone numbers, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Wishbone (2020) logo" /></div>
                            <div>
                                <p><span>Wishbone (2020)</span>: In January 2020, the mobile app to "compare anything"
                                    <a>Wishbone suffered another data breach</a> which followed their breach from 2016.
                                    An extensive amount of personal information including almost 10M unique email
                                    addresses alongside names, phone numbers geographic locations and other personal
                                    attributes were leaked online and extensively redistributed. Passwords stored as
                                    unsalted MD5 hashes were also included in the breach. The data was provided to HIBP
                                    by a source who requested it be attributed to "All3in".</p>
                                <p><strong>Compromised data:</strong> Auth tokens, Dates of birth, Email addresses,
                                    Genders, Geographic locations, IP addresses, Names, Passwords, Phone numbers,
                                    Profile photos, Social media profiles, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Wongnai logo" /></div>
                            <div>
                                <p><span>Wongnai</span>: In October 2020, <a>17 previously undisclosed data breaches
                                        appeared for sale</a> including the Thai restaurant, hotel and attraction
                                    finding service, Wongnai. The breach exposed almost 4M unique customer records from
                                    some time during 2020 along with names, phone numbers, links to social media
                                    profiles and passwords stored as MD5 hashes. The data was self-submitted to HIBP by
                                    Wongnai.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Geographic
                                    locations, IP addresses, Names, Passwords, Phone numbers, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Xbox 360 ISO logo" /></div>
                            <div>
                                <p><span>Xbox 360 ISO</span>: In approximately September 2015, the XBOX 360 forum known
                                    as <a>XBOX360 ISO</a> was hacked and 1.2 million accounts were exposed. Along with
                                    email and IP addresses, the vBulletin forum also exposed salted MD5 password hashes.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="XPG logo" /></div>
                            <div>
                                <p><span>XPG</span>: In approximately early 2016, the gaming website <a>Xpgamesaves</a>
                                    (XPG) suffered a data breach resulting in the exposure of 890k unique user records.
                                    The data contained email and IP addresses, usernames and salted MD5 hashes of
                                    passwords. The site was previously reported as compromised on the
                                    <a>Vigilante.pw</a> breached database directory. This data was provided by security
                                    researcher and data analyst, Adam Davies.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="XSplit logo" /></div>
                            <div>
                                <p><span>XSplit</span>: In November 2013, the makers of gaming live streaming and
                                    recording software <a>XSplit was compromised in an online attack</a>. The data
                                    breach leaked almost 3M names, email addresses, usernames and hashed passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Yahoo logo" /></div>
                            <div>
                                <p><span>Yahoo</span>: In July 2012, Yahoo! had their online publishing service "Voices"
                                    compromised via a SQL injection attack. The breach resulted in the disclosure of
                                    nearly half a million usernames and passwords stored in plain text. The breach
                                    showed that of the compromised accounts, a staggering <a>59% of people who also had
                                        accounts in the Sony breach reused their passwords across both services</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Yatra logo" /></div>
                            <div>
                                <p><span>Yatra</span>: In September 2013, the Indian bookings website known as
                                    <a>Yatra</a> had 5 million records exposed in a data breach. The data contained
                                    email and physical addresses, dates of birth and phone numbers along with both PINs
                                    and passwords stored in plain text. The site was previously reported as compromised
                                    on the <a>Vigilante.pw</a> breached database directory.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Names, Passwords,
                                    Phone numbers, Physical addresses, PINs</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Youku logo" /></div>
                            <div>
                                <p><span>Youku</span>: In late 2016, the online Chinese video service <a>Youku</a>
                                    suffered a data breach. The incident exposed 92 million unique user accounts and
                                    corresponding MD5 password hashes. The data was contributed to Have I Been Pwned
                                    courtesy of rip@creep.im.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="YouNow logo" /></div>
                            <div>
                                <p><span>YouNow</span>: In February 2019, <a>data from the live broadcasting service
                                        YouNow appeared for sale on a dark web marketplace</a>. Whilst it's not clear
                                    what date the actual breach occurred on, the impacted data included 18M unique email
                                    addresses, IP addresses, names, usernames and links to social media profiles. As
                                    authentication is performed via social providers, no passwords were exposed in the
                                    breach. Many records didn't have associated email addresses thus the unique number
                                    is lower than the reported total number of accounts. The data was provided to HIBP
                                    by a source who requested it be attributed to "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Social media
                                    profiles, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Zomato logo" /></div>
                            <div>
                                <p><span>Zomato</span>: In May 2017, the restaurant guide website <a>Zomato was
                                        hacked</a> resulting in the exposure of almost 17 million accounts. The data was
                                    consequently redistributed online and contains email addresses, usernames and salted
                                    MD5 hashes of passwords (the password hash was not present on all accounts). This
                                    data was provided to HIBP by whitehat security researcher and data analyst Adam
                                    Davies.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Zoomcar logo" /></div>
                            <div>
                                <p><span>Zoomcar</span>: In July 2018, the Indian self-drive car rental company
                                    <a>Zoomcar suffered a data breach which was subsequently sold on a dark web
                                        marketplace in 2020</a>. The breach exposed over 3.5M records including names,
                                    email and IP addresses, phone numbers and passwords stored as bcrypt hashes. The
                                    data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Passwords,
                                    Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Zynga logo" /></div>
                            <div>
                                <p><span>Zynga</span>: In September 2019, game developer <a>Zynga (the creator of Words
                                        with Friends) suffered a data breach</a>. The incident exposed 173M unique email
                                    addresses alongside usernames and passwords stored as salted SHA-1 hashes. The data
                                    was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Phone numbers,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="17173 logo" /></div>
                            <div>
                                <p><span>17173<span> (<a>unverified</a>)</span></span>: In late 2011, <a>a series of
                                        data breaches in China affected up to 100 million users</a>, including 7.5
                                    million from the gaming site known as 17173. Whilst there is evidence that the data
                                    is legitimate, due to the difficulty of emphatically verifying the Chinese breach it
                                    has been flagged as "unverified". The data in the breach contains usernames, email
                                    addresses and salted MD5 password hashes and was provided with support from
                                    <a>dehashed.com</a>. <a>Read more about Chinese data breaches in Have I Been
                                        Pwned.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Adapt logo" /></div>
                            <div>
                                <p><span>Adapt</span>: In November 2018, <a>security researcher Bob Diachenko identified
                                        an unprotected database hosted by data aggregator "Adapt"</a>. A provider of
                                    "Fresh Quality Contacts", the service exposed over 9.3M unique records of
                                    individuals and employer information including their names, employers, job titles,
                                    contact information and data relating to the employer including organisation
                                    description, size and revenue. No response was received from Adapt when contacted.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, Employers, Job titles, Names,
                                    Phone numbers, Physical addresses, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="AerServ logo" /></div>
                            <div>
                                <p><span>AerServ</span>: In April 2018, the ad management platform known as
                                    <a>AerServ</a> suffered a data breach. Acquired by InMobi earlier in the year, the
                                    AerServ breach impacted over 66k unique email addresses and also included contact
                                    information and passwords stored as salted SHA-512 hashes. The data was publicly
                                    posted to Twitter later in 2018 after which InMobi was notified and advised they
                                    were aware of the incident.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Employers, Job titles, Names,
                                    Passwords, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Aipai.com logo" /></div>
                            <div>
                                <p><span>Aipai.com<span> (<a>unverified</a>)</span></span>: In September 2016, data
                                    allegedly obtained from the Chinese gaming website known as <a>Aipai.com</a> and
                                    containing 6.5M accounts was leaked online. Whilst there is evidence that the data
                                    is legitimate, due to the difficulty of emphatically verifying the Chinese breach it
                                    has been flagged as "unverified". The data in the breach contains email addresses
                                    and MD5 password hashes. <a>Read more about Chinese data breaches in Have I Been
                                        Pwned.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Anti Public Combo List logo" /></div>
                            <div>
                                <p><span>Anti Public Combo List<span> (<a>unverified</a>)</span></span>: In December
                                    2016, a huge list of email address and password pairs appeared in a "combo list"
                                    referred to as "Anti Public". The list contained 458 million unique email addresses,
                                    many with multiple different passwords hacked from various online systems. The list
                                    was broadly circulated and used for "credential stuffing", that is attackers employ
                                    it in an attempt to identify other online systems where the account owner had reused
                                    their password. For detailed background on this incident, read <a>Password reuse,
                                        credential stuffing and another billion records in Have I Been Pwned</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Civil Online logo" /></div>
                            <div>
                                <p><span>Civil Online<span> (<a>unverified</a>)</span></span>: In mid-2011, data was
                                    allegedly obtained from the Chinese engineering website known as <a>Civil Online</a>
                                    and contained 7.8M accounts. Whilst there is evidence that the data is legitimate,
                                    due to the difficulty of emphatically verifying the Chinese breach it has been
                                    flagged as "unverified". The data in the breach contains email and IP addresses,
                                    user names and MD5 password hashes. <a>Read more about Chinese data breaches in Have
                                        I Been Pwned.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Dodonew.com logo" /></div>
                            <div>
                                <p><span>Dodonew.com<span> (<a>unverified</a>)</span></span>: In late 2011, data was
                                    allegedly obtained from the Chinese website known as <a>Dodonew.com</a> and
                                    contained 8.7M accounts. Whilst there is evidence that the data is legitimate, due
                                    to the difficulty of emphatically verifying the Chinese breach it has been flagged
                                    as "unverified". The data in the breach contains email addresses and user names.
                                    <a>Read more about Chinese data breaches in Have I Been Pwned.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Edmodo logo" /></div>
                            <div>
                                <p><span>Edmodo</span>: In May 2017, the education platform <a>Edmodo was hacked</a>
                                    resulting in the exposure of 77 million records comprised of over 43 million unique
                                    customer email addresses. The data was consequently published to a popular hacking
                                    forum and made freely available. The records in the breach included usernames, email
                                    addresses and bcrypt hashes of passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Elance logo" /></div>
                            <div>
                                <p><span>Elance</span>: Sometime in 2009, staffing platform <a>Elance suffered a data
                                        breach that impacted 1.3 million accounts</a>. Appearing online 8 years later,
                                    the data contained usernames, email addresses, phone numbers and SHA1 hashes of
                                    passwords, amongst other personal data.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Employers, Geographic locations,
                                    Passwords, Phone numbers, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Elasticsearch Instance of Sales Leads on AWS logo" /></div>
                            <div>
                                <p><span>Elasticsearch Instance of Sales Leads on AWS</span>: In October 2018,
                                    <a>security researcher Bob Diachenko identified multiple exposed databases with
                                        hundreds of millions of records</a>. One of those datasets was an Elasticsearch
                                    instance on AWS containing sales lead data and 5.8M unique email addresses. The data
                                    contained information relating to individuals and the companies they worked for
                                    including their names, email addresses and company name and contact information.
                                    Despite best efforts, it was not possible to identify the owner of the data hence
                                    this breach as been titled "Elasticsearch Sales Leads".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Employers, Names, Physical
                                    addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Evite logo" /></div>
                            <div>
                                <p><span>Evite</span>: In April 2019, the social planning website for managing online
                                    invitations <a>Evite identified a data breach of their systems</a>. Upon
                                    investigation, they found unauthorised access to a database archive dating back to
                                    2013. The exposed data included a total of 101 million unique email addresses, most
                                    belonging to recipients of invitations. Members of the service also had names, phone
                                    numbers, physical addresses, dates of birth, genders and passwords stored in plain
                                    text exposed. The data was provided to HIBP by a source who requested it be
                                    attributed to "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, Names,
                                    Passwords, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="GeekedIn logo" /></div>
                            <div>
                                <p><span>GeekedIn</span>: In August 2016, the technology recruitment site GeekedIn left
                                    a MongoDB database exposed and over 8M records were extracted by an unknown third
                                    party. The breached data was originally scraped from GitHub in violation of their
                                    terms of use and contained information exposed in public profiles, including over 1
                                    million members' email addresses. Full details on the incident (including how
                                    impacted members can see their leaked data) are covered in the blog post on <a>8
                                        million GitHub profiles were leaked from GeekedIn's MongoDB - here's how to see
                                        yours</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Names,
                                    Professional skills, Usernames, Years of professional experience</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="gPotato logo" /></div>
                            <div>
                                <p><span>gPotato</span>: In July 2007, the multiplayer game portal known as
                                    <a>gPotato</a> (link to archive of the site at that time) suffered a data breach and
                                    over 2 million user accounts were exposed. The site later merged into the <a>Webzen
                                        portal</a> where the original accounts still exist today. The exposed data
                                    included usernames, email and IP addresses, MD5 hashes and personal attributes such
                                    as gender, birth date, physical address and security questions and answers stored in
                                    plain text.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, IP
                                    addresses, Names, Passwords, Physical addresses, Security questions and answers,
                                    Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Lizard Squad logo" /></div>
                            <div>
                                <p><span>Lizard Squad</span>: In January 2015, the hacker collective known as "Lizard
                                    Squad" created a DDoS service by the name of "Lizard Stresser" which could be
                                    procured to mount attacks against online targets. Shortly thereafter, the service
                                    <a>suffered a data breach</a> which resulted in the public disclosure of over 13k
                                    user accounts including passwords stored in plain text.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Lounge Board logo" /></div>
                            <div>
                                <p><span>Lounge Board</span>: At some point in 2013, 45k accounts were <a>breached from
                                        the Lounge Board "General Discussion Forum" and then dumped publicly</a>. Lounge
                                    Board was a MyBB forum launched in 2012 and discontinued in mid 2013 (the last
                                    activity in the logs was from August 2013).</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Passwords,
                                    Private messages, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="MangaFox.me logo" /></div>
                            <div>
                                <p><span>MangaFox.me</span>: In approximately July 2016, the manga website known as
                                    <a>mangafox.me</a> suffered a data breach. The vBulletin based forum exposed 1.3
                                    million accounts including usernames, email and IP addresses, dates of birth and
                                    salted MD5 password hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="MGM Resorts (2022 Update) logo" /></div>
                            <div>
                                <p><span>MGM Resorts (2022 Update)</span>: In July 2019, <a>MGM Resorts discovered a
                                        data breach of one of their cloud services</a>. The breach included 10.6M guest
                                    records with 3.1M unique email addresses stemming back to 2017. In May 2022, <a>a
                                        superset of the data totalling almost 25M unique email addresses across 142M
                                        rows was extensively shared on Telegram</a>. On analysis, it's highly likely the
                                    data stems from the same incident <a>with 142M records having been discovered for
                                        sale on a dark web marketplace in mid-2020</a>. The exposed data included email
                                    and physical addresses, names, phone numbers and dates of birth.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Names, Phone
                                    numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Not Acxiom logo" /></div>
                            <div>
                                <p><span>Not Acxiom<span> (<a>unverified</a>)</span></span>: In 2020, <a>a corpus of
                                        data containing almost a quarter of a billion records spanning over 400
                                        different fields was misattributed to database marketing company Acxiom</a> and
                                    subsequently circulated within the hacking community. On review, Acxiom concluded
                                    that "the claims are indeed false and that the data, which has been readily
                                    available across multiple environments, does not come from Acxiom and is in no way
                                    the subject of an Acxiom breach". The data contained almost 52M unique email
                                    addresses.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Phone
                                    numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="QuinStreet logo" /></div>
                            <div>
                                <p><span>QuinStreet</span>: In approximately late 2015, the maker of "performance
                                    marketing products" <a>QuinStreet</a> had a number of their online assets
                                    compromised. The attack impacted 28 separate sites, predominantly technology forums
                                    such as <a>flashkit.com</a>, <a>codeguru.com</a> and <a>webdeveloper.com</a>
                                    (<a>view a full list of sites</a>). QuinStreet advised that impacted users have been
                                    notified and passwords reset. The data contained details on over 4.9 million people
                                    and included email addresses, dates of birth and salted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Passwords, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="RedLine Stealer logo" /></div>
                            <div>
                                <p><span>RedLine Stealer</span>: In December 2021, <a>logs from the RedLine Stealer
                                        malware were left publicly exposed and were then obtained by security researcher
                                        Bob Diachenko</a>. The data included 441 thousand unique email addresses,
                                    usernames and plain text passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Slickwraps logo" /></div>
                            <div>
                                <p><span>Slickwraps</span>: In February 2020, the online store for consumer electronics
                                    wraps <a>Slickwraps suffered a data breach</a>. The incident resulted in the
                                    exposure of 858k unique email addresses across customer records and newsletter
                                    subscribers. Additional impacted data included names, physical addresses, phone
                                    numbers and purchase histories.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Phone numbers, Physical
                                    addresses, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Taobao logo" /></div>
                            <div>
                                <p><span>Taobao<span> (<a>unverified</a>)</span></span>: In approximately 2012, it's
                                    alleged that the Chinese shopping site known as <a>Taobao</a> suffered a data breach
                                    that impacted over 21 million subscribers. Whilst there is evidence that the data is
                                    legitimate, due to the difficulty of emphatically verifying the Chinese breach it
                                    has been flagged as "unverified". The data in the breach contains email addresses
                                    and plain text passwords. <a>Read more about Chinese data breaches in Have I Been
                                        Pwned.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Trik Spam Botnet logo" /></div>
                            <div>
                                <p><span>Trik Spam Botnet<span> (<a>spam list</a>)</span></span>: In June 2018, the
                                    command and control server of a malicious botnet known as the "Trik Spam Botnet"
                                    <a>was misconfigured such that it exposed the email addresses of more than 43
                                        million people</a>. The researchers who discovered the exposed Russian server
                                    believe the list of addresses was used to distribute various malware strains via
                                    malspam campaigns (emails designed to deliver malware).</p>
                                <p><strong>Compromised data:</strong> Email addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="uuu9 logo" /></div>
                            <div>
                                <p><span>uuu9<span> (<a>unverified</a>)</span></span>: In September 2016, data was
                                    allegedly obtained from the Chinese website known as <a>uuu9.com</a> and contained
                                    7.5M accounts. Whilst there is evidence that the data is legitimate, due to the
                                    difficulty of emphatically verifying the Chinese breach it has been flagged as
                                    "unverified". The data in the breach contains email addresses and user names.
                                    <a>Read more about Chinese data breaches in Have I Been Pwned.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Yam logo" /></div>
                            <div>
                                <p><span>Yam</span>: In June 2013, the Taiwanese website <a>Yam.com suffered a data
                                        breach which was shared to a popular hacking forum in 2021</a>. The data
                                    included 13 million unique email addresses alongside names, usernames, phone
                                    numbers, physical addresses, dates of birth and unsalted MD5 password hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Names, Passwords,
                                    Phone numbers, Physical addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Black Hat World logo" /></div>
                            <div>
                                <p><span>Black Hat World</span>: In June 2014, the search engine optimisation forum
                                    <a>Black Hat World</a> had three quarters of a million accounts breached from their
                                    system. The breach included various personally identifiable attributes which were
                                    publicly released in a MySQL database script.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Instant messenger
                                    identities, IP addresses, Passwords, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Evermotion logo" /></div>
                            <div>
                                <p><span>Evermotion</span>: In May 2015, the Polish 3D modelling website known as
                                    <a>Evermotion</a> suffered a data breach resulting in the exposure of 435k unique
                                    user records. The data was sourced from a vBulletin forum and contained email
                                    addresses, usernames, dates of birth and salted MD5 hashes of passwords. The site
                                    was previously reported as compromised on the <a>Vigilante.pw</a> breached database
                                    directory.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Light's Hope logo" /></div>
                            <div>
                                <p><span>Light's Hope</span>: In June 2018, the World of Warcraft service <a>Light's
                                        Hope suffered a data breach</a> which they subsequently self-submitted to HIBP.
                                    Over 30K unique users were impacted and their exposed data included email addresses,
                                    dates of birth, private messages and passwords stored as bcrypt hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Geographic
                                    locations, IP addresses, Passwords, Private messages, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="PSP ISO logo" /></div>
                            <div>
                                <p><span>PSP ISO</span>: In approximately September 2015, the PlayStation PSP forum
                                    known as <a>PSP ISO</a> was hacked and almost 1.3 million accounts were exposed.
                                    Along with email and IP addresses, the vBulletin forum also exposed salted MD5
                                    password hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Social Engineered logo" /></div>
                            <div>
                                <p><span>Social Engineered</span>: In June 2019, the "Art of Human Hacking" site
                                    <a>Social Engineered</a> suffered a data breach. The breach of the MyBB forum was
                                    published on a rival hacking forum and included 89k unique email addresses spread
                                    across 55k forum users and other tables in the database. The exposed data also
                                    included usernames, IP addresses, private messages and passwords stored as salted
                                    MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords, Private
                                    messages, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Weee logo" /></div>
                            <div>
                                <p><span>Weee</span>: In February 2023, <a>data belonging to the Asian and Hispanic food
                                        delivery service Weee appeared on a popular hacking forum</a>. Dating back to
                                    mid-2022, the data included 1.1M unique email addresses from 11M rows of orders
                                    containing names, phone numbers and delivery instructions.</p>
                                <p><strong>Compromised data:</strong> Delivery instructions, Email addresses, Names,
                                    Phone numbers, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
            </div>
        </div>
        <div>
            <div>
                <div>
                    <h3>Pastes you were found in</h3>
                    <p>
                        A <a>paste</a> is information that has been published to a
                        publicly facing website designed to share content and is often an early indicator of a data
                        breach. Pastes are automatically imported and often removed shortly after having been
                        posted. Using the <a>1Password password manager</a>
                        helps you ensure all your passwords are strong and unique such that a breach of one service
                        doesn't put your other services at risk.
                    </p>
                </div>
            </div>
        </div>
    </div>
    <div role="dialog">
        <div>
            <div>
                <div>
                    <button type="button">×</button>
                </div>
            </div>
        </div>
    </div>
    <div>
        <div>
            <div><span>674</span></div>
            <div><span>12,576,062,746</span></div>
            <div><span>115,747</span></div>
            <div><span>228,723,401</span></div>
        </div>
        <div>
            <div>
                <h3>Largest breaches</h3>
                <div>
                    <table>
                        <tbody>
                            <tr>
                                <td><img alt="Collection #1 logo" /></td>
                                <td>772,904,991</td>
                                <td><a>Collection #1 accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Verifications.io logo" /></td>
                                <td>763,117,241</td>
                                <td><a>Verifications.io accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Onliner Spambot logo" /></td>
                                <td>711,477,622</td>
                                <td><a>Onliner Spambot accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Data Enrichment Exposure From PDL Customer logo" /></td>
                                <td>622,161,052</td>
                                <td><a>Data Enrichment Exposure From PDL Customer accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Exploit.In logo" /></td>
                                <td>593,427,119</td>
                                <td><a>Exploit.In accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Facebook logo" /></td>
                                <td>509,458,528</td>
                                <td><a>Facebook accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Anti Public Combo List logo" /></td>
                                <td>457,962,538</td>
                                <td><a>Anti Public Combo List accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="River City Media Spam List logo" /></td>
                                <td>393,430,309</td>
                                <td><a>River City Media Spam List accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="MySpace logo" /></td>
                                <td>359,420,698</td>
                                <td><a>MySpace accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Wattpad logo" /></td>
                                <td>268,765,495</td>
                                <td><a>Wattpad accounts</a></td>
                            </tr>
                        </tbody>
                    </table>
                </div>
            </div>
            <div>
                <h3>Recently added breaches</h3>
                <div>
                    <table>
                        <tbody>
                            <tr>
                                <td><img alt="Luxottica logo" /></td>
                                <td>77,093,812</td>
                                <td><a>Luxottica accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="RentoMojo logo" /></td>
                                <td>2,185,697</td>
                                <td><a>RentoMojo accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="CityJerks logo" /></td>
                                <td>177,554</td>
                                <td><a>CityJerks accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="MEO logo" /></td>
                                <td>8,227</td>
                                <td><a>MEO accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Terravision logo" /></td>
                                <td>2,075,625</td>
                                <td><a>Terravision accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="OGUsers (2022 breach) logo" /></td>
                                <td>529,020</td>
                                <td><a>OGUsers (2022 breach) accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="The Kodi Foundation logo" /></td>
                                <td>400,635</td>
                                <td><a>The Kodi Foundation accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Genesis Market logo" /></td>
                                <td>8,000,000</td>
                                <td><a>Genesis Market accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Sundry Files logo" /></td>
                                <td>274,461</td>
                                <td><a>Sundry Files accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Leaked Reality logo" /></td>
                                <td>114,907</td>
                                <td><a>Leaked Reality accounts</a></td>
                            </tr>
                        </tbody>
                    </table>
                </div>
            </div>
        </div>
    </div>
    <div role="dialog">
        <div>
            <div>
                <div>
                    <button type="button">×</button>
                    <h4>Notify me</h4>
                </div>
                <div>
                    <div>
                        <form role="form">
                            <p>
                                Get notified when future pwnage occurs and your account is compromised.
                            </p>
                            <div>
                                <div>
                                    <input name="NotifyEmail" placeholder="enter your email address" type="email" />
                                </div>
                            </div>
                            <div>
                                <div>
                                    <div>
                                        <div><iframe name="a-264q2ixba10l" title="reCAPTCHA" /></div><textarea
                                            name="g-recaptcha-response" />
                                    </div>
                                </div>
                            </div>
                            <div>
                                <input type="submit" value="notify me of pwnage" />
                            </div>
                        </form>
                    </div>
                    <div>
                        <p>
                            You've just been sent a verification email, all you need to do now is confirm your
                            address by clicking on the link when it hits your mailbox and you'll be automatically
                            notified of future pwnage. In case it doesn't show up, check your junk mail and if
                            you <em>still</em> can't find it, you can always repeat this process.
                        </p>
                        <p>
                            <a>add another address</a>
                        </p>
                    </div>
                </div>
            </div>
        </div>
    </div>
    <footer>
        <div>
            <p>
                <a>A troyhunt.com project</a>
            </p>
        </div>
    </footer>
    <div>
        <div><iframe name="c-264q2ixba10l" title="recaptcha challenge expires in two minutes" /></div>
    </div>
</body>

</html>