<html>

<head>
    <title>Have I Been Pwned: Check if your email has been compromised in a data breach</title>
</head>

<body>
    <div>
        <header>
            <div>
                <div>
                    <button type="button">
                    </button>
                    <a>';--</a>
                </div>
                <div>
                    <ul>
                        <li><a>Home</a></li>
                        <li><a>Notify me</a></li>
                        <li><a>Domain search</a></li>
                        <li><a>Who's been pwned</a></li>
                        <li><a>Passwords</a></li>
                        <li>
                            <a>API</a>
                            <ul>
                                <li><a>Overview</a></li>
                                <li><a>API key</a></li>
                                <li><a>Terms of use</a></li>
                            </ul>
                        </li>
                        <li>
                            <a>About</a>
                            <ul>
                                <li><a>Who, what &amp; why</a></li>
                                <li><a>Privacy</a></li>
                                <li><a>FAQs</a></li>
                                <li><a>Pastes</a></li>
                                <li><a>Opt-out</a></li>
                                <li><a>Twitter</a></li>
                                <li><a>Facebook</a></li>
                                <li><a>Mastodon</a></li>
                                <li><a>Suggest a feature</a></li>
                            </ul>
                        </li>
                        <li><a>Donate </a></li>
                    </ul>
                </div>
            </div>
        </header>
        <div>
            <div>
                <div>
                    <div>
                        <span>';--have i been pwned?</span>
                    </div>
                    <p>Check if your email or phone is in a data breach</p>
                </div>
            </div>
        </div>
        <div>
            <div>
                <form>
                    <div><iframe title="Widget containing a Cloudflare security challenge" /><input
                            name="cf-turnstile-response" /></div>
                    <div>
                        <input name="Account" placeholder="email address" type="email" />
                        <input name="apiEndpoint" value="https://haveibeenpwned.com/unifiedsearch/" />
                        <span>
                            <button type="submit">pwned?</button>
                        </span>
                    </div>
                    <div>
                        <div role="progressbar">
                        </div>
                    </div>
                </form>
            </div>
        </div>
        <div>
            <div>
                <p>
                    <img alt="1Password Logo" />
                    <span>Generate secure, unique passwords for every account</span>
                    <a>Learn more at 1Password.com</a>
                </p>
                <p><a>Why 1Password?</a></p>
            </div>
        </div>
    </div>
    <div>
        <div>
            <div>
                <div>
                    <h2>Good news — no pwnage found!</h2>
                    <p>
                        No <a>breached accounts</a>
                        <span>and no <a>pastes</a> (<a>subscribe</a> to search sensitive breaches)</span>
                    </p>
                </div>
                <div>
                    <div>
                        <div>
                            <img alt="1Password Logo" />
                            <h3>3 Steps to better security</h3>
                        </div>
                        <div>
                            <a>Start using 1Password.com</a>
                        </div>
                    </div>
                    <div>
                        <div>
                            <p>
                                <a>
                                    <img alt="Step 1" /><strong>Step 1</strong> Protect yourself using 1Password to
                                    generate and save strong passwords for each website.
                                </a>
                            </p>
                        </div>
                        <div>
                            <p>
                                <a>
                                    <img alt="Step 2" /><strong>Step 2</strong> Enable 2 factor authentication and store
                                    the codes inside your 1Password account.
                                </a>
                            </p>
                        </div>
                        <div>
                            <p>
                                <a>
                                    <img alt="Step 3" /><strong>Step 3</strong> <span>Subscribe</span> to notifications
                                    for any other breaches. Then just change that unique password.
                                </a>
                            </p>
                        </div>
                    </div>
                    <div>
                        <div>
                            <p><a>Why 1Password?</a></p>
                        </div>
                    </div>
                </div>
            </div>
        </div>
    </div>
    <div>
        <div>
            <div>
                <div>
                    <div>
                        <h2>
                            Oh no — pwned!
                        </h2>
                        <p>Pwned in 3 <a>data breaches</a> and found no <a>pastes</a> (<a>subscribe</a> to search
                            sensitive breaches)</p>
                    </div>
                    <div>
                        <div>
                            <div>
                                <img alt="1Password Logo" />
                                <h3>3 Steps to better security</h3>
                            </div>
                            <div>
                                <a>Start using 1Password.com</a>
                            </div>
                        </div>
                        <div>
                            <div>
                                <p>
                                    <a>
                                        <img alt="Step 1" /><strong>Step 1</strong> Protect yourself using 1Password to
                                        generate and save strong passwords for each website.
                                    </a>
                                </p>
                            </div>
                            <div>
                                <p>
                                    <a>
                                        <img alt="Step 2" /><strong>Step 2</strong> Enable 2 factor authentication and
                                        store the codes inside your 1Password account.
                                    </a>
                                </p>
                            </div>
                            <div>
                                <p>
                                    <a>
                                        <img alt="Step 3" /><strong>Step 3</strong> <span>Subscribe</span> to
                                        notifications for any other breaches. Then just change that unique password.
                                    </a>
                                </p>
                            </div>
                        </div>
                        <div>
                            <div>
                                <p><a>Why 1Password?</a></p>
                            </div>
                        </div>
                    </div>
                </div>
            </div>
        </div>
        <div>
            <div>
                <div>
                    <h3>Breaches you were pwned in</h3>
                    <p>
                        A "breach" is an incident where data has been unintentionally exposed to the
                        public. Using the <a>1Password password manager</a>
                        helps you ensure all your passwords are strong and unique such that a breach of one service
                        doesn't put your other services at risk.
                    </p>
                </div>
            </div>
            <div>
                <div>
                    <div>
                        
                            
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Covve logo" /></div>
                            <div>
                                <p><span>Covve</span>: In February 2020, <a>a massive trove of personal information
                                        referred to as "db8151dd"</a> was provided to HIBP after being found left
                                    exposed on a publicly facing Elasticsearch server. Later identified as originating
                                    from the Covve contacts app, the exposed data included extensive personal
                                    information and interactions between Covve users and their contacts. The data was
                                    provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Job titles, Names, Phone numbers,
                                    Physical addresses, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="GPS Underground logo" /></div>
                            <div>
                                <p><span>GPS Underground</span>: In early 2017, <a>GPS Underground was amongst a
                                        collection of compromised vBulletin websites that were found being sold
                                        online</a>. The breach dated back to mid-2016 and included 670k records with
                                    usernames, email and IP addresses, dates of birth and salted MD5 password hashes.
                                </p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Gravatar logo" /></div>
                            <div>
                                <p><span>Gravatar</span>: In October 2020, <a>a security researcher published a
                                        technique for scraping large volumes of data from Gravatar, the service for
                                        providing globally unique avatars </a>. 167 million names, usernames and MD5
                                    hashes of email addresses used to reference users' avatars were subsequently scraped
                                    and distributed within the hacking community. 114 million of the MD5 hashes were
                                    cracked and distributed alongside the source hash, thus disclosing the original
                                    email address and accompanying data. Following the impacted email addresses being
                                    searchable in HIBP, <a>Gravatar release an FAQ detailing the incident</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="GTAGaming logo" /></div>
                            <div>
                                <p><span>GTAGaming</span>: In August 2016, the Grand Theft Auto forum <a>GTAGaming was
                                        hacked and nearly 200k user accounts were leaked</a>. The vBulletin based forum
                                    included usernames, email addresses and password hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Passwords, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="HauteLook logo" /></div>
                            <div>
                                <p><span>HauteLook</span>: In mid-2018, the fashion shopping site <a>HauteLook was among
                                        a raft of sites that were breached and their data then sold in early-2019</a>.
                                    The data included over 28 million unique email addresses alongside names, genders,
                                    dates of birth and passwords stored as bcrypt hashes. The data was provided to HIBP
                                    by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders,
                                    Geographic locations, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Havenly logo" /></div>
                            <div>
                                <p><span>Havenly</span>: In June 2020, the interior design website <a>Havenly suffered a
                                        data breach</a> which impacted almost 1.4 million members of the service. The
                                    exposed data included email addresses, names, phone numbers, geographic locations
                                    and passwords stored as SHA-1 hashes, all of which was subsequently shared
                                    extensively throughout online hacking communities. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Names,
                                    Passwords, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Heroes of Gaia logo" /></div>
                            <div>
                                <p><span>Heroes of Gaia</span>: In early 2013, the online fantasy multiplayer game
                                    <a>Heroes of Gaia</a> suffered a data breach. The newest records in the data set
                                    indicate a breach date of 4 January 2013 and include usernames, IP and email
                                    addresses but no passwords.</p>
                                <p><strong>Compromised data:</strong> Browser user agent details, Email addresses, IP
                                    addresses, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Heroes of Newerth logo" /></div>
                            <div>
                                <p><span>Heroes of Newerth</span>: In December 2012, the multiplayer online battle arena
                                    game known as <a>Heroes of Newerth</a> <a> was hacked</a> and over 8 million
                                    accounts extracted from the system. The compromised data included usernames, email
                                    addresses and passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="HiAPK logo" /></div>
                            <div>
                                <p><span>HiAPK<span> (<a>unverified</a>)</span></span>: In approximately 2014, it's
                                    alleged that the Chinese Android store known as <a>HIAPK</a> suffered a data breach
                                    that impacted 13.8 million unique subscribers. Whilst there is evidence that the
                                    data is legitimate, due to the difficulty of emphatically verifying the Chinese
                                    breach it has been flagged as "unverified". The data in the breach contains
                                    usernames, email addresses and salted MD5 password hashes and was provided to HIBP
                                    by white hat security researcher and data analyst Adam Davies. <a>Read more about
                                        Chinese data breaches in Have I Been Pwned.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="HLTV logo" /></div>
                            <div>
                                <p><span>HLTV</span>: In June 2016, the "home of competitive Counter Strike" website
                                    <a>HLTV was hacked</a> and 611k accounts were exposed. The attack led to the
                                    exposure of names, usernames, email addresses and bcrypt hashes of passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Usernames,
                                    Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Home Chef logo" /></div>
                            <div>
                                <p><span>Home Chef</span>: In early 2020, the food delivery service <a>Home Chef
                                        suffered a data breach</a> which was subsequently sold online. The breach
                                    exposed the personal information of almost 9 million customers including names, IP
                                    addresses, post codes, the last 4 digits of credit card numbers and passwords stored
                                    as bcrypt hashes. The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, IP
                                    addresses, Names, Partial credit card data, Passwords, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Houzz logo" /></div>
                            <div>
                                <p><span>Houzz</span>: In mid-2018, the housing design website <a>Houzz suffered a data
                                        breach</a>. The company learned of the incident later that year then disclosed
                                    it to impacted members in February 2019. Almost 49 million unique email addresses
                                    were in the breach alongside names, IP addresses, geographic locations and either
                                    salted hashes of passwords or links to social media profiles used to authenticate to
                                    the service. The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, IP
                                    addresses, Names, Passwords, Social media profiles, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Hurb logo" /></div>
                            <div>
                                <p><span>Hurb</span>: In approximately March 2019, the online Brazilian travel agency
                                    <a>Hurb (formerly Hotel Urbano) suffered a data breach</a>. The data subsequently
                                    appeared online for download the following year and included over 20 million
                                    customer records with email and IP addresses, names, dates of birth, phone numbers
                                    and passwords stored as unsalted MD5 hashes. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Names, Passwords, Phone numbers, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="IDC Games logo" /></div>
                            <div>
                                <p><span>IDC Games</span>: In March 2021, <a>4 million records sourced from IDC Games
                                        were shared on a public hacking forum</a>. The data included usernames, email
                                    addresses and passwords stored as salted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="i-Dressup logo" /></div>
                            <div>
                                <p><span>i-Dressup</span>: In June 2016, the teen social site known as <a>i-Dressup was
                                        hacked</a> and over 2 million user accounts were exposed. At the time the hack
                                    was reported, the i-Dressup operators were not contactable and the underlying SQL
                                    injection flaw remained open, allegedly exposing a total of 5.5 million accounts.
                                    The breach included email addresses and passwords stored in plain text.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="IIMJobs logo" /></div>
                            <div>
                                <p><span>IIMJobs</span>: In December 2018, the Indian job portal <a>IIMJobs suffered a
                                        data breach that exposed 4.1 million unique email addresses</a>. The data also
                                    included names, phone numbers, geographic locations, dates of birth, job titles, job
                                    applications and cover letters plus passwords stored as unsalted MD5 hashes. The
                                    data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Geographic
                                    locations, IP addresses, Job applications, Job titles, Names, Passwords, Phone
                                    numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="iMesh logo" /></div>
                            <div>
                                <p><span>iMesh</span>: In September 2013, the media and file sharing client known as
                                    <a>iMesh was hacked and approximately 50M accounts were exposed</a>. The data was
                                    later put up for sale on a dark market website in mid-2016 and included email and IP
                                    addresses, usernames and salted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="IndiaMART logo" /></div>
                            <div>
                                <p><span>IndiaMART</span>: In August 2021, <a>38 million records from Indian e-commerce
                                        company IndiaMART were found being traded on a popular hacking forum</a>. Dated
                                    several months earlier, the data included over 20 million unique email addresses
                                    alongside names, phone numbers and physical addresses. It's unclear whether
                                    IndiaMART intentionally exposed the data attributes as part of the intended design
                                    of the platform or whether the data was obtained by exploiting a vulnerability in
                                    the service.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Phone numbers, Physical
                                    addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Instant Checkmate logo" /></div>
                            <div>
                                <p><span>Instant Checkmate</span>: In 2019, the public records search service <a>Instant
                                        Checkmate suffered a data breach that later came to light in early 2023</a>. The
                                    data included almost 12M unique customer email addresses, names, phone numbers and
                                    passwords stored as scrypt hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Phone numbers
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="InterPals logo" /></div>
                            <div>
                                <p><span>InterPals</span>: In late 2015, the online penpal site InterPals had their
                                    website hacked and 3.4 million accounts exposed. The compromised data included email
                                    addresses, geographical locations, birthdates and salted hashes of passwords.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Geographic
                                    locations, Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="iPmart logo" /></div>
                            <div>
                                <p><span>iPmart</span>: During 2015, the <a>iPmart forum</a> (now known as Mobi NUKE)
                                    was hacked and over 2 million forum members' details were exposed. The vBulletin
                                    forum included IP addresses, birth dates and passwords stored as salted hashes using
                                    a weak implementation enabling many to be rapidly cracked. A further 368k accounts
                                    were added to "Have I Been Pwned" in March 2016 bringing the total to over 2.4M.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ixigo logo" /></div>
                            <div>
                                <p><span>ixigo</span>: In January 2019, the travel and hotel booking site <a>ixigo
                                        suffered a data breach</a>. The data appeared for sale on a dark web marketplace
                                    the following month and included over 17M unique email addresses alongside names,
                                    genders, phone numbers, connections to Facebook profiles and passwords stored as MD5
                                    hashes. The data was provided to HIBP by a source who requested it to be attributed
                                    to "BenjaminBlue@exploit.im".</p>
                                <p><strong>Compromised data:</strong> Auth tokens, Device information, Email addresses,
                                    Genders, Names, Passwords, Phone numbers, Salutations, Social media profiles,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="JD logo" /></div>
                            <div>
                                <p><span>JD</span>: In 2013 (exact date unknown), the Chinese e-commerce service <a>JD
                                        suffered a data breach</a> that exposed 13GB of data containing 77 million
                                    unique email addresses. The data also included usernames, phone numbers and
                                    passwords stored as SHA-1 hashes. The data was provided to HIBP by a source who
                                    requested it be attributed to "white_peacock@riseup.net".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Phone numbers,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Jefit logo" /></div>
                            <div>
                                <p><span>Jefit</span>: In August 2020, the workout tracking app <a>Jefit suffered a data
                                        breach</a>. The data was subsequently sold within the hacking community and
                                    included over 9 million email and IP addresses, usernames and passwords stored as
                                    either vBulletin or argon2 hashes. Several million cracked passwords later appeared
                                    in broad circulation.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Jobandtalent logo" /></div>
                            <div>
                                <p><span>Jobandtalent</span>: In approximately February 2018, <a>the employment website
                                        Jobandtalent suffered a data breach which then appeared for sale alongside other
                                        breaches a year later</a>. The incident impacted 11 million subscribers and
                                    exposed their names, email and IP addresses and passwords stored as salted SHA-1
                                    hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Passwords
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="JukinMedia logo" /></div>
                            <div>
                                <p><span>JukinMedia</span>: In October 2021, the "global leader in user-generated
                                    entertainment" <a>Jukin Media suffered a data breach</a>. The breach exposed 13GB of
                                    code, configuration and data consisting of 314k unique email addresses along with
                                    names, phone numbers, IP addresses and bcrypt password hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Employers, IP addresses, Names,
                                    Occupations, Passwords, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Kayo.moe Credential Stuffing List logo" /></div>
                            <div>
                                <p><span>Kayo.moe Credential Stuffing List<span> (<a>unverified</a>)</span></span>: In
                                    September 2018, a collection of almost 42 million email address and plain text
                                    password pairs was uploaded to the anonymous file sharing service <a>kayo.moe</a>.
                                    The operator of the service contacted HIBP to report the data which, upon further
                                    investigation, turned out to be a large credential stuffing list. For more
                                    information, read about <a>The 42M Record kayo.moe Credential Stuffing Data</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Kickstarter logo" /></div>
                            <div>
                                <p><span>Kickstarter</span>: In February 2014, the crowdfunding platform <a>Kickstarter
                                        announced they'd suffered a data breach</a>. The breach contained almost 5.2
                                    million unique email addresses, usernames and salted SHA1 hashes of passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Knuddels logo" /></div>
                            <div>
                                <p><span>Knuddels</span>: In September 2018, the German social media website <a>Knuddels
                                        suffered a data breach</a>. The incident exposed 808k unique email addresses
                                    alongside usernames, real names, the city of the person and their password in plain
                                    text. Knuddels was <a>subsequently fined €20k for the breach</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Names,
                                    Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Last.fm logo" /></div>
                            <div>
                                <p><span>Last.fm</span>: In March 2012, the music website <a>Last.fm was hacked</a> and
                                    43 million user accounts were exposed. Whilst <a>Last.fm knew of an incident back in
                                        2012</a>, the scale of the hack was not known until the data was released
                                    publicly in September 2016. The breach included 37 million unique email addresses,
                                    usernames and passwords stored as unsalted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames, Website
                                    activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Lazada RedMart logo" /></div>
                            <div>
                                <p><span>Lazada RedMart</span>: In October 2020, <a>news broke of Lazada RedMart data
                                        breach</a> containing records as recent as July 2020 and being sold via an
                                    online marketplace. In all, the data contained 1.1 million customer email addresses
                                    alongside names, phone numbers, physical addresses, partial credit card numbers and
                                    passwords stored as SHA-1 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Partial credit card data,
                                    Passwords, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Lead Hunter logo" /></div>
                            <div>
                                <p><span>Lead Hunter</span>: In March 2020, <a>a massive trove of personal information
                                        referred to as "Lead Hunter"</a> was provided to HIBP after being found left
                                    exposed on a publicly facing Elasticsearch server. The data contained 69 million
                                    unique email addresses across 110 million rows of data accompanied by additional
                                    personal information including names, phone numbers, genders and physical addresses.
                                    At the time of publishing, the breach could not be attributed to those responsible
                                    for obtaining and exposing it. The data was provided to HIBP by <a>dehashed.com</a>.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, IP addresses, Names,
                                    Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Leaked Reality logo" /></div>
                            <div>
                                <p><span>Leaked Reality</span>: In January 2022, <a>the now defunct uncensored video
                                        website Leaked Reality</a> suffered a data breach that exposed 115k unique email
                                    addresses. The data also included usernames, IP addresses and passwords stored as
                                    either MD5 or phpass hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Ledger logo" /></div>
                            <div>
                                <p><span>Ledger</span>: In June 2020, the hardware crypto wallet manufacturer <a>Ledger
                                        suffered a data breach that exposed over 1 million email addresses</a>. The data
                                    was initially sold before being dumped publicly in December 2020 and included names,
                                    physical addresses and phone numbers. The data was provided to HIBP by <a>Alon Gal,
                                        CTO of cybercrime intelligence firm Hudson Rock</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Phone numbers, Physical
                                    addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Leet logo" /></div>
                            <div>
                                <p><span>Leet</span>: In August 2016, the service for creating and running Pocket
                                    Minecraft edition servers known as <a>Leet was reported as having suffered a data
                                        breach that impacted 6 million subscribers</a>. The incident reported by
                                    Softpedia had allegedly taken place earlier in the year, although the data set sent
                                    to HIBP was dated as recently as early September but contained only 2 million
                                    subscribers. The data included usernames, email and IP addresses and SHA512 hashes.
                                    A further 3 million accounts were obtained and added to HIBP several days after the
                                    initial data was loaded bringing the total to over 5 million.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Lifeboat logo" /></div>
                            <div>
                                <p><span>Lifeboat</span>: In January 2016, the Minecraft community known as Lifeboat
                                    <a>was hacked and more than 7 million accounts leaked</a>. Lifeboat knew of the
                                    incident for three months before the breach was made public but elected not to
                                    advise customers. The leaked data included usernames, email addresses and passwords
                                    stored as straight MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="LinkedIn logo" /></div>
                            <div>
                                <p><span>LinkedIn</span>: In May 2016, <a>LinkedIn had 164 million email addresses and
                                        passwords exposed</a>. Originally hacked in 2012, the data remained out of sight
                                    until being offered for sale on a dark market site 4 years later. The passwords in
                                    the breach were stored as SHA1 hashes without salt, the vast majority of which were
                                    quickly cracked in the days following the release of the data.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="LinkedIn Scraped Data logo" /></div>
                            <div>
                                <p><span>LinkedIn Scraped Data</span>: During the first half of 2021, <a>LinkedIn was
                                        targeted by attackers who scraped data from hundreds of millions of public
                                        profiles and later sold them online</a>. Whilst the scraping did not constitute
                                    a data breach nor did it access any personal data not intended to be publicly
                                    accessible, the data was still monetised and later broadly circulated in hacking
                                    circles. The scraped data contains approximately 400M records with 125M unique email
                                    addresses, as well as names, geographic locations, genders and job titles. LinkedIn
                                    specifically addresses the incident in their post on <a>An update on report of
                                        scraped data</a>.</p>
                                <p><strong>Compromised data:</strong> Education levels, Email addresses, Genders,
                                    Geographic locations, Job titles, Names, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Little Monsters logo" /></div>
                            <div>
                                <p><span>Little Monsters</span>: In approximately January 2017, <a>the Lady Gaga fan
                                        site known as "Little Monsters" suffered a data breach that impacted 1 million
                                        accounts</a>. The data contained usernames, email addresses, dates of birth and
                                    bcrypt hashes of passwords.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="LiveAuctioneers logo" /></div>
                            <div>
                                <p><span>LiveAuctioneers</span>: In June 2020, the online antiques marketplace
                                    <a>LiveAuctioneers suffered a data breach</a> which was subsequently sold online
                                    then extensively redistributed in the hacking community. The data contained 3.4
                                    million records including names, email and IP addresses, physical addresses, phones
                                    numbers and passwords stored as unsalted MD5 hashes. The data was provided to HIBP
                                    by <a>breachbase.pw</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Passwords,
                                    Phone numbers, Physical addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="LiveJournal logo" /></div>
                            <div>
                                <p><span>LiveJournal</span>: In mid-2019, <a>news broke of an alleged LiveJournal data
                                        breach</a>. This followed <a>multiple reports of credential abuse against
                                        Dreamwidth beginning in 2018</a>, a fork of LiveJournal with a significant
                                    crossover in user base. The breach allegedly dates back to 2017 and contains 26M
                                    unique usernames and email addresses (both of which have been confirmed to exist on
                                    LiveJournal) alongside plain text passwords. An archive of the data was subsequently
                                    shared on a popular hacking forum in May 2020 and redistributed broadly. The data
                                    was provided to HIBP by a source who requested it be attributed to
                                    "nano@databases.pw".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Luxottica logo" /></div>
                            <div>
                                <p><span>Luxottica</span>: In March 2021, the world's largest eyewear company
                                    <a>Luxoticca suffered a data breach via one of their partners that exposed the
                                        personal information of more than 70M people</a>. The data was subsequently sold
                                    via a popular hacking forum in late 2022 and included email and physical addresses,
                                    names, genders, dates of birth and phone numbers. In a statement from Luxottica,
                                    they advised they were aware of the incident and are currently "considering other
                                    notification obligations".</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, Names,
                                    Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="MangaDex logo" /></div>
                            <div>
                                <p><span>MangaDex</span>: In March 2021, the manga fan site <a>MangaDex suffered a data
                                        breach</a> that resulted in the exposure of almost 3 million subscribers. The
                                    data included email and IP addresses, usernames and passwords stored as bcrypt
                                    hashes. The data was subsequently circulated within hacking groups.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Mangatoon logo" /></div>
                            <div>
                                <p><span>Mangatoon</span>: In May 2022, the Hong Kong based Manga service
                                    <a>Mangatoon</a> suffered a data breach that exposed 23M subscriber records. The
                                    breach exposed names, email addresses, genders, social media account identities,
                                    auth tokens from social logins and passwords stored as salted MD5 hashes. Mangatoon
                                    did not respond to multiple attempts to make contact regarding the breach.</p>
                                <p><strong>Compromised data:</strong> Auth tokens, Avatars, Email addresses, Genders,
                                    Names, Passwords, Social media profiles, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Mathway logo" /></div>
                            <div>
                                <p><span>Mathway</span>: In January 2020, the math solving website <a>Mathway suffered a
                                        data breach that exposed over 25M records</a>. The data was subsequently sold on
                                    a dark web marketplace and included names, Google and Facebook IDs, email addresses
                                    and salted password hashes.</p>
                                <p><strong>Compromised data:</strong> Device information, Email addresses, Names,
                                    Passwords, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Minehut logo" /></div>
                            <div>
                                <p><span>Minehut</span>: In May 2019, the Minecraft server website <a>Minehut</a>
                                    suffered a data breach. The company advised a database backup had been obtained
                                    after which they subsequently notified all impacted users. 397k email addresses from
                                    the incident were provided to HIBP. A data set with both email addresses and bcrypt
                                    password hashes was also later provided to HIBP.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Minted logo" /></div>
                            <div>
                                <p><span>Minted</span>: In May 2020, the online marketplace for independent artists
                                    <a>Minted suffered a data breach</a> that exposed 4.4M unique customer records
                                    subsequently sold on a dark web marketplace. Exposed data also included names,
                                    physical addresses, phone numbers and passwords stored as bcrypt hashes. The data
                                    was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Phone numbers,
                                    Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Modern Business Solutions logo" /></div>
                            <div>
                                <p><span>Modern Business Solutions</span>: In October 2016, a large Mongo DB file
                                    containing tens of millions of accounts <a>was shared publicly on Twitter</a> (the
                                    file has since been removed). The database contained over 58M unique email addresses
                                    along with IP addresses, names, home addresses, genders, job titles, dates of birth
                                    and phone numbers. The data was subsequently <a>attributed to "Modern Business
                                        Solutions"</a>, a company that provides data storage and database hosting
                                    solutions. They've yet to acknowledge the incident or explain how they came to be in
                                    possession of the data.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, IP
                                    addresses, Job titles, Names, Phone numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="MPGH logo" /></div>
                            <div>
                                <p><span>MPGH</span>: In October 2015, the multiplayer game hacking website <a>MPGH was
                                        hacked</a> and 3.1 million user accounts disclosed. The vBulletin forum breach
                                    contained usernames, email addresses, IP addresses and salted hashes of passwords.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="MyFitnessPal logo" /></div>
                            <div>
                                <p><span>MyFitnessPal</span>: In February 2018, the diet and exercise service
                                    <a>MyFitnessPal suffered a data breach</a>. The incident exposed 144 million unique
                                    email addresses alongside usernames, IP addresses and passwords stored as SHA-1 and
                                    bcrypt hashes (the former for earlier accounts, the latter for newer accounts). In
                                    2019, <a>the data appeared listed for sale on a dark web marketplace</a> (along with
                                    several other large breaches) and subsequently began circulating more broadly. The
                                    data was provided to HIBP by a source who requested it to be attributed to
                                    "BenjaminBlue@exploit.im".</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="MyHeritage logo" /></div>
                            <div>
                                <p><span>MyHeritage</span>: In October 2017, the genealogy website <a>MyHeritage
                                        suffered a data breach</a>. The incident was reported 7 months later after a
                                    security researcher discovered the data and contacted MyHeritage. In total, more
                                    than 92M customer records were exposed and included email addresses and salted SHA-1
                                    password hashes. In 2019, <a>the data appeared listed for sale on a dark web
                                        marketplace</a> (along with several other large breaches) and subsequently began
                                    circulating more broadly. The data was provided to HIBP by a source who requested it
                                    be attributed to "BenjaminBlue@exploit.im".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="myRepoSpace logo" /></div>
                            <div>
                                <p><span>myRepoSpace</span>: In July 2015, the Cydia repository known as
                                    <a>myRepoSpace</a> was hacked and <a>user data leaked publicly</a>. Cydia is
                                    designed to facilitate the installation of apps on jailbroken iOS devices. The
                                    repository service was allegedly hacked by <a>@its_not_herpes</a> and
                                    <a>0x8badfl00d</a> in retaliation for the service refusing to remove pirated tweaks.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="MySpace logo" /></div>
                            <div>
                                <p><span>MySpace</span>: In approximately 2008, <a>MySpace suffered a data breach that
                                        exposed almost 360 million accounts</a>. In May 2016 the data was offered up for
                                    sale on the "Real Deal" dark market website and included email addresses, usernames
                                    and SHA1 hashes of the first 10 characters of the password converted to lowercase
                                    and stored without a salt. The exact breach date is unknown, but <a>analysis of the
                                        data suggests it was 8 years before being made public</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="NemoWeb logo" /></div>
                            <div>
                                <p><span>NemoWeb</span>: In September 2016, almost 21GB of data from the French website
                                    used for "standardised and decentralized means of exchange for publishing newsgroup
                                    articles" <a>NemoWeb</a> was leaked from what appears to have been an unprotected
                                    Mongo DB. The data consisted of a large volume of emails sent to the service and
                                    included almost 3.5M unique addresses, albeit many of them auto-generated. Multiple
                                    attempts were made to contact the operators of NemoWeb but no response was received.
                                </p>
                                <p><strong>Compromised data:</strong> Email addresses, Names</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Neopets logo" /></div>
                            <div>
                                <p><span>Neopets</span>: In May 2016, <a>a set of breached data originating from the
                                        virtual pet website "Neopets" was found being traded online</a>. Allegedly
                                    hacked "several years earlier", the data contains sensitive personal information
                                    including birthdates, genders and names as well as almost 27 million unique email
                                    addresses. Passwords were stored in plain text and IP addresses were also present in
                                    the breach.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders,
                                    Geographic locations, IP addresses, Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="NetEase logo" /></div>
                            <div>
                                <p><span>NetEase<span> (<a>unverified</a>)</span></span>: In October 2015, the Chinese
                                    site known as <a>NetEase</a> (located at <a>163.com</a>) was <a>reported as having
                                        suffered a data breach that impacted hundreds of millions of subscribers</a>.
                                    Whilst there is evidence that the data itself is legitimate (multiple HIBP
                                    subscribers confirmed a password they use is in the data), due to the difficulty of
                                    emphatically verifying the Chinese breach it has been flagged as "unverified". The
                                    data in the breach contains email addresses and plain text passwords. <a>Read more
                                        about Chinese data breaches in Have I Been Pwned.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Netlog logo" /></div>
                            <div>
                                <p><span>Netlog</span>: In July 2018, the Belgian social networking site <a>Netlog
                                        identified a data breach of their systems dating back to November 2012
                                        (PDF)</a>. Although the service was discontinued in 2015, the data breach still
                                    impacted 49 million subscribers for whom email addresses and plain text passwords
                                    were exposed. The data was provided to HIBP by a source who requested it be
                                    attributed to "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="NextGenUpdate logo" /></div>
                            <div>
                                <p><span>NextGenUpdate</span>: Early in 2014, the video game website
                                    <a>NextGenUpdate</a> reportedly <a>suffered a data breach</a> that disclosed almost
                                    1.2 million accounts. Amongst the data breach was usernames, email addresses, IP
                                    addresses and salted and hashed passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Nihonomaru logo" /></div>
                            <div>
                                <p><span>Nihonomaru</span>: In late 2015, the anime community known as Nihonomaru had
                                    their vBulletin forum hacked and 1.7 million accounts exposed. The compromised data
                                    included email and IP addresses, usernames and salted hashes of passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Nitro logo" /></div>
                            <div>
                                <p><span>Nitro</span>: In September 2020, <a>the Nitro PDF service suffered a massive
                                        data breach which exposed over 70 million unique email addresses</a>. The breach
                                    also exposed names, bcrypt password hashes and the titles of converted documents.
                                    The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Nulled.cr logo" /></div>
                            <div>
                                <p><span>Nulled.cr</span>: In May 2016, the cracking community forum known as
                                    <a>Nulled.cr</a> was hacked and 599k user accounts were leaked publicly. The
                                    compromised data included email and IP addresses, weak salted MD5 password hashes
                                    and hundreds of thousands of private messages between members.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, IP addresses,
                                    Passwords, Private messages, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="OGUsers (2019 breach) logo" /></div>
                            <div>
                                <p><span>OGUsers (2019 breach)</span>: In May 2019, the account hijacking and SIM
                                    swapping forum <a>OGusers suffered a data breach</a>. The breach exposed a database
                                    backup from December 2018 which was published on a rival hacking forum. There were
                                    161k unique email addresses spread across 113k forum users and other tables in the
                                    database. The exposed data also included usernames, IP addresses, private messages
                                    and passwords stored as salted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords, Private
                                    messages, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="OGUsers (2020 breach) logo" /></div>
                            <div>
                                <p><span>OGUsers (2020 breach)</span>: In April 2020, the account hijacking and SIM
                                    swapping forum <a>OGUsers suffered their second data breach in less than a year</a>.
                                    As with the previous breach, the exposed data included email and IP addresses,
                                    usernames, private messages and passwords stored as salted MD5 hashes. A total of
                                    263k email addresses across user accounts and other tables were posted to a rival
                                    hacking forum.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords, Private
                                    messages, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="OGUsers (2021 breach) logo" /></div>
                            <div>
                                <p><span>OGUsers (2021 breach)</span>: In April 2021, the account hijacking and SIM
                                    swapping forum <a>OGusers suffered a data breach</a>, the fourth since December
                                    2018. The breach was subsequently sold on a rival hacking forum and contained
                                    usernames, email and IP addresses and passwords stored as either salted MD5 or
                                    argon2 hashes. A total of 348k unique email addresses appeared in the breach.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="OGUsers (2022 breach) logo" /></div>
                            <div>
                                <p><span>OGUsers (2022 breach)</span>: In July 2022, the account hijacking and SIM
                                    swapping forum OGusers suffered a data breach, the fifth since December 2018. The
                                    breach contained usernames, email and IP addresses and passwords stored as argon2
                                    hashes. A total of 529k unique email addresses appeared in the breach.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Onliner Spambot logo" /></div>
                            <div>
                                <p><span>Onliner Spambot<span> (<a>spam list</a>)</span></span>: In August 2017, a
                                    spambot by the name of <a>Onliner Spambot was identified by security researcher
                                        Benkow moʞuƎq</a>. The malicious software contained a server-based component
                                    located on an IP address in the Netherlands which exposed a large number of files
                                    containing personal information. In total, there were 711 million unique email
                                    addresses, many of which were also accompanied by corresponding passwords. A full
                                    write-up on what data was found is in the blog post titled <a>Inside the Massive 711
                                        Million Record Onliner Spambot Dump</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Onverse logo" /></div>
                            <div>
                                <p><span>Onverse</span>: In January 2016, the online virtual world known as
                                    <a>Onverse</a> was hacked and 800k accounts were exposed. Along with email and IP
                                    addresses, the site also exposed salted MD5 password hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Open CS:GO logo" /></div>
                            <div>
                                <p><span>Open CS:GO</span>: In December 2017, the website for purchasing Counter-Strike
                                    skins known as <a>Open CS:GO</a> (Counter-Strike: Global Offensive) suffered a data
                                    breach (address since redirects to dropgun.com). The 10GB file contained an
                                    extensive amount of personal information including email and IP addresses, phone
                                    numbers, physical addresses and purchase histories. <a>Numerous attempts were made
                                        to contact Open CS:GO about the incident</a>, however no responses were
                                    received.</p>
                                <p><strong>Compromised data:</strong> Avatars, Email addresses, IP addresses, Phone
                                    numbers, Physical addresses, Purchases, Social media profiles, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="OwnedCore logo" /></div>
                            <div>
                                <p><span>OwnedCore</span>: In approximately August 2013, the World of Warcraft exploits
                                    forum known as <a>OwnedCore</a> was hacked and more than 880k accounts were exposed.
                                    The vBulletin forum included IP addresses and passwords stored as salted hashes
                                    using a weak implementation enabling many to be rapidly cracked.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Oxfam logo" /></div>
                            <div>
                                <p><span>Oxfam</span>: In January 2021, <a>Oxfam Australia was the victim of a data
                                        breach</a> which exposed 1.8M unique email addresses of supporters of the
                                    charity. The data was put up for sale on a popular hacking forum and also included
                                    names, phone numbers, addresses, genders and dates of birth. A small number of
                                    people also had partial credit card data exposed (the first 6 and last 3 digits of
                                    the card, plus card type and expiry) and in some cases the bank name, account number
                                    and BSB were also exposed. The data was subsequently made freely available on the
                                    hacking forum later the following month.</p>
                                <p><strong>Compromised data:</strong> Bank account numbers, Dates of birth, Email
                                    addresses, Genders, Names, Partial credit card data, Payment histories, Phone
                                    numbers, Physical addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Paddy Power logo" /></div>
                            <div>
                                <p><span>Paddy Power</span>: In October 2010, the Irish bookmaker <a>Paddy Power
                                        suffered a data breach</a> that exposed 750,000 customer records with nearly
                                    600,000 unique email addresses. The breach was not disclosed until July 2014 and
                                    contained extensive personal information including names, addresses, phone numbers
                                    and plain text security questions and answers.</p>
                                <p><strong>Compromised data:</strong> Account balances, Dates of birth, Email addresses,
                                    IP addresses, Names, Phone numbers, Physical addresses, Security questions and
                                    answers, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Paragon Cheats logo" /></div>
                            <div>
                                <p><span>Paragon Cheats</span>: In May 2021, the Grand Theft Auto Online cheats website
                                    <a>Paragon Cheats suffered a data breach that lead to the shutdown of the
                                        service</a>. The breach exposed 188k customer records including usernames, email
                                    and IP addresses. The data was provided to HIBP by a source who requested it be
                                    attributed to "VRAirhead and xFueY".</p>
                                <p><strong>Compromised data:</strong> Browser user agent details, Email addresses, IP
                                    addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ParkMobile logo" /></div>
                            <div>
                                <p><span>ParkMobile</span>: In March 2021, the mobile parking app service <a>ParkMobile
                                        suffered a data breach which exposed 21 million customers' personal data</a>.
                                    The impacted data included email addresses, names, phone numbers, vehicle licence
                                    plates and passwords stored as bcrypt hashes. The following month, the data appeared
                                    on a public hacking forum where it was extensively redistributed.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Licence plates, Names, Passwords,
                                    Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="PayHere logo" /></div>
                            <div>
                                <p><span>PayHere</span>: In late March 2022, the Sri Lankan payment gateway <a>PayHere
                                        suffered a data breach that exposed more than 65GB of payment records</a>
                                    including over 1.5M unique email addresses. The data also included IP and physical
                                    addresses, names, phone numbers, purchase histories and partially obfuscated credit
                                    card data (card type, first 6 and last 4 digits plus expiry date). A month later,
                                    PayHere published a blog on the incident titled <a>Ensuring Integrity on PayHere
                                        Cybersecurity Incident</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Partial
                                    credit card data, Phone numbers, Physical addresses, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Peatix logo" /></div>
                            <div>
                                <p><span>Peatix</span>: In January 2019, the event organising platform <a>Peatix
                                        suffered a data breach</a>. The incident exposed 4.2M email addresses, names and
                                    salted password hashes. The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Pemiblanc logo" /></div>
                            <div>
                                <p><span>Pemiblanc<span> (<a>unverified</a>)</span></span>: In April 2018, a credential
                                    stuffing list containing 111 million email addresses and passwords known as
                                    <a>Pemiblanc</a> was discovered on a French server. The list contained email
                                    addresses and passwords collated from different data breaches and used to mount
                                    account takeover attacks against other services. <a>Read more about the
                                        incident.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="PetFlow logo" /></div>
                            <div>
                                <p><span>PetFlow</span>: In December 2017, the pet care delivery service <a>PetFlow
                                        suffered a data breach which consequently appeared for sale on a dark web
                                        marketplace</a>. Almost 1M accounts were impacted and exposed email addresses
                                    and passwords stored as unsalted MD5 hashes. The data was provided to HIBP by a
                                    source who requested it be attributed to "nano@databases.pw".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Pixlr logo" /></div>
                            <div>
                                <p><span>Pixlr</span>: In October 2020, the online photo editing application <a>Pixlr
                                        suffered a data breach</a> exposing 1.9 million subscribers. Impacted data
                                    included names, email addresses, social media profiles, the country signed up from
                                    and passwords stored as SHA-512 hashes. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Geographic locations, Names,
                                    Passwords, Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="piZap logo" /></div>
                            <div>
                                <p><span>piZap</span>: In approximately December 2017, the online photo editing site
                                    <a>piZap suffered a data breach</a>. The data was later placed up for sale on a dark
                                    web marketplace along with a collection of other data breaches in February 2019. A
                                    total of 42 million unique email addresses were included in the breach alongside
                                    names, genders and links to Facebook profiles when the social media platform was
                                    used to authenticate to piZap. When accounts were created directly on piZap without
                                    using Facebook for authentication, passwords stored as SHA-1 hashes were also
                                    exposed. The data was provided to HIBP by a source who requested it be attributed to
                                    "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Geographic locations,
                                    Names, Passwords, Social media profiles, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Planet Ice logo" /></div>
                            <div>
                                <p><span>Planet Ice</span>: In January 2023, the UK-based ice skating rink booking
                                    service <a>Planet Ice suffered a data breach</a>. The incident exposed the personal
                                    data of 240k people including email and physical addresses, phone numbers, genders,
                                    dates of birth and passwords stored as MD5 hashes. The data also included the names,
                                    genders and dates of birth of children having parties.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, IP
                                    addresses, Names, Passwords, Phone numbers, Physical addresses, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Pluto TV logo" /></div>
                            <div>
                                <p><span>Pluto TV</span>: In October 2018, the internet television service <a>Pluto TV
                                        suffered a data breach</a> which was then shared extensively in hacking
                                    communities. Pluto TV "decided not to proactively inform users of the breach" which
                                    contained 3.2M unique email and IP addresses, names, usernames, genders, dates of
                                    birth and passwords stored as bcrypt hashes. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Device information, Email
                                    addresses, Genders, IP addresses, Names, Passwords, Social media profiles, Usernames
                                </p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Pokébip logo" /></div>
                            <div>
                                <p><span>Pokébip</span>: In July 2015, the French Pokémon site <a>Pokébip suffered a
                                        data breach</a> which exposed 657k subscriber identities. The data included
                                    email and IP addresses, usernames and passwords stored as unsalted MD5 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords, Time
                                    zones, Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Pokémon Creed logo" /></div>
                            <div>
                                <p><span>Pokémon Creed</span>: In August 2014, the Pokémon RPG website <a>Pokémon
                                        Creed</a> was hacked after a dispute with rival site, <a>Pokémon Dusk</a>. In a
                                    <a>post on Facebook</a>, "Cruz Dusk" announced the hack then pasted the dumped MySQL
                                    database on <a>pkmndusk.in</a>. The breached data included over 116k usernames,
                                    email addresses and plain text passwords.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, IP addresses, Passwords,
                                    Usernames, Website activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Poshmark logo" /></div>
                            <div>
                                <p><span>Poshmark</span>: In mid-2018, social commerce marketplace <a>Poshmark suffered
                                        a data breach</a> that exposed 36M user accounts. The compromised data included
                                    email addresses, names, usernames, genders, locations and passwords stored as bcrypt
                                    hashes. The data was provided to HIBP by a source who requested it be attributed to
                                    "JimScott.Sec@protonmail.com".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Geographic locations,
                                    Names, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Powerbot logo" /></div>
                            <div>
                                <p><span>Powerbot</span>: In approximately September 2014, the RuneScape bot website
                                    <a>Powerbot</a> suffered a data breach resulting in the exposure of over half a
                                    million unique user records. The data contained email and IP addresses, usernames
                                    and salted MD5 hashes of passwords. The site was previously reported as compromised
                                    on the <a>Vigilante.pw</a> breached database directory.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="ProctorU logo" /></div>
                            <div>
                                <p><span>ProctorU</span>: In June 2020, the online exam service <a>ProctorU suffered a
                                        data breach</a> which was subsequently shared extensively across online hacking
                                    communities. The breach contained 444k user records including names, email and
                                    physical addresses, phones numbers and passwords stored as bcrypt hashes. The data
                                    was provided to HIBP by <a>breachbase.pw</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords, Phone numbers,
                                    Physical addresses, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Promo logo" /></div>
                            <div>
                                <p><span>Promo</span>: In July 2020, the self-proclaimed "World's #1 Marketing Video
                                    Maker" <a>Promo suffered a data breach</a> which was then shared extensively on a
                                    hacking forum. The incident exposed 22 million records containing almost 15 million
                                    unique email addresses alongside IP addresses, genders, names and salted SHA-256
                                    password hashes. The data was provided to HIBP by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, IP addresses, Names,
                                    Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Promofarma logo" /></div>
                            <div>
                                <p><span>Promofarma</span>: In August 2019, <a>a data breach from the Spanish online
                                        pharmacy Promofarma appeared for sale on a dark web marketplace</a>. The breach
                                    exposed over 2.7M records and contained almost 1.3M unique customer email addresses.
                                    The data also included customer names and was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="PropTiger logo" /></div>
                            <div>
                                <p><span>PropTiger</span>: In January 2018, the Indian property website <a>PropTiger</a>
                                    suffered a data breach which resulted in a 3.46GB database file being exposed and
                                    subsequently shared extensively on a popular hacking forum 2 years later. The
                                    exposed data contained both user records and login histories with over 2M unique
                                    customer email addresses. Exposed data also included additional personal attributes
                                    such as names, dates of birth, genders, IP addresses and passwords stored as MD5
                                    hashes. PropTiger advised they believe the usability of the data is "limited" due to
                                    how certain data attributes were generated and stored. The data was provided to HIBP
                                    by <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Device information, Email
                                    addresses, Genders, IP addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="QIP logo" /></div>
                            <div>
                                <p><span>QIP</span>: In mid-2011, the Russian instant messaging service known as <a>QIP
                                        (Quiet Internet Pager) suffered a data breach</a>. The attack resulted in the
                                    disclosure of over 26 million unique accounts including email addresses and
                                    passwords with the data eventually appearing in public years later.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames, Website
                                    activity</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="QuestionPro logo" /></div>
                            <div>
                                <p><span>QuestionPro</span>: In May 2022, <a>the survey website QuestionPro was the
                                        target of an extortion attempt relating to an alleged data breach</a>. Over
                                    100GB of data containing 22M unique email addresses (some of which appear to be
                                    generated by the platform), are alleged to have been extracted from the service
                                    along with IP addresses, browser user agents and results relating to surveys.
                                    QuestionPro would not confirm whether a breach had occurred (although they did
                                    confirm they were the target of an extortion attempt), so the data was initially
                                    flagged as "unverified". <a>Subsequent verification by impacted HIBP subscribers</a>
                                    later led to the removal of the unverified flag.</p>
                                <p><strong>Compromised data:</strong> Browser user agent details, Email addresses, IP
                                    addresses, Survey results</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Quidd logo" /></div>
                            <div>
                                <p><span>Quidd</span>: In 2019, online marketplace for trading stickers, cards, toys,
                                    and other collectibles <a>Quidd suffered a data breach</a>. The breach exposed
                                    almost 4 million users' email addresses, usernames and passwords stored as bcrypt
                                    hashes. The data was subsequently sold then redistributed extensively via hacking
                                    forums.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="R2Games logo" /></div>
                            <div>
                                <p><span>R2Games</span>: In late 2015, the gaming website <a>R2Games</a> was hacked and
                                    more than 2.1M personal records disclosed. The vBulletin forum included IP addresses
                                    and passwords stored as salted hashes using a weak implementation enabling many to
                                    be rapidly cracked. A further 11M accounts were added to "Have I Been Pwned" in
                                    March 2016 and another 9M in July 2016 bringing the total to over 22M.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Passwords,
                                    Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Raychat logo" /></div>
                            <div>
                                <p><span>Raychat</span>: In January 2021, the now defunct Iranian social media platform
                                    <a>Raychat suffered a data breach that exposed 939 thousand unique email
                                        addresses</a>. The data included names, IP addresses, browser user agent strings
                                    and passwords stored as bcrypt hashes. The data was provided to HIBP by
                                    <a>dehashed.com</a>.</p>
                                <p><strong>Compromised data:</strong> Browser user agent details, Email addresses, IP
                                    addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Rbx.Rocks logo" /></div>
                            <div>
                                <p><span>Rbx.Rocks</span>: In August 2018, the Roblox trading site <a>Rbx.Rocks</a>
                                    suffered a data breach. Almost 25k records were sent to HIBP in November and
                                    included names, email addresses and passwords stored as bcrypt hashes. In July 2019,
                                    a further 125k records emerged bringing the total size of the incident to 150k. The
                                    website has since gone offline with a message stating that "Rbx.Rocks v2.0 is
                                    currently under construction".</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Read Novel logo" /></div>
                            <div>
                                <p><span>Read Novel<span> (<a>unverified</a>)</span></span>: In May 2019, the Chinese
                                    literature website <a>Read Novel</a> allegedly suffered a data breach that exposed
                                    22M unique email addresses. Data also included usernames, genders, phone numbers and
                                    passwords stored as salted MD5 hashes. The data was provided to HIBP by a source who
                                    requested it be attributed to "white_peacock@riseup.net". <a>Read more about Chinese
                                        data breaches in Have I Been Pwned.</a></p>
                                <p><strong>Compromised data:</strong> Email addresses, Genders, Passwords, Phone
                                    numbers, Usernames</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="RedDoorz logo" /></div>
                            <div>
                                <p><span>RedDoorz</span>: In September 2020, the hotel management &amp; booking platform
                                    <a>RedDoorz suffered a data breach that exposed over 5.8M user accounts</a>. The
                                    breached data included names, email addresses, phone numbers, genders, dates of
                                    birth and passwords stored as bcrypt hashes. The data was provided to HIBP by a
                                    source who requested it be attributed to "white_peacock@riseup.net".</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders, Names,
                                    Occupations, Passwords, Phone numbers</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Reincubate logo" /></div>
                            <div>
                                <p><span>Reincubate</span>: In October 2020, the app data company <a>Reincubate suffered
                                        a data breach</a> which exposed a backup from November 2017 (the newest record
                                    in the data appeared several months earlier). The data included over 616k unique
                                    email addresses, names and passwords stored as PBKDF2 hashes.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Names, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="RentoMojo logo" /></div>
                            <div>
                                <p><span>RentoMojo</span>: In April 2023, the Indian rental service <a>RentoMojo
                                        suffered a data breach</a>. The breach exposed over 2M unique email addresses
                                    along with names, phone, passport and Aadhaar numbers, genders, dates of birth,
                                    purchases and bcrypt password hashes.</p>
                                <p><strong>Compromised data:</strong> Dates of birth, Email addresses, Genders,
                                    Government issued IDs, Names, Passport numbers, Passwords, Phone numbers, Purchases,
                                    Social media profiles</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Retina-X logo" /></div>
                            <div>
                                <p><span>Retina-X</span>: In February 2017, the mobile device monitoring software
                                    developer Retina-X was hacked and customer data downloaded before being wiped from
                                    their servers. The incident was covered in the Motherboard article titled <a>Inside
                                        the 'Stalkerware' Surveillance Market, Where Ordinary People Tap Each Other's
                                        Phones</a>. The service, used to monitor mobile devices, had 71k email addresses
                                    and MD5 hashes with no salt exposed. Retina-X <a>disclosed the incident in a blog
                                        post</a> on April 27, 2017.</p>
                                <p><strong>Compromised data:</strong> Email addresses, Passwords</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="River City Media Spam List logo" /></div>
                            <div>
                                <p><span>River City Media Spam List<span> (<a>spam list</a>)</span></span>: In January
                                    2017, <a>a massive trove of data from River City Media was found exposed online</a>.
                                    The data was found to contain almost 1.4 billion records including email and IP
                                    addresses, names and physical addresses, all of which was used as part of an
                                    enormous spam operation. Once de-duplicated, there were 393 million unique email
                                    addresses within the exposed data.</p>
                                <p><strong>Compromised data:</strong> Email addresses, IP addresses, Names, Physical
                                    addresses</p>
                            </div>
                        </div>
                    </div>
                </div>
                <div>
                    <div>
                        <div>
                            <div><img alt="Weee logo" /></div>
                            <div>
                                <p><span>Weee</span>: In February 2023, <a>data belonging to the Asian and Hispanic food
                                        delivery service Weee appeared on a popular hacking forum</a>. Dating back to
                                    mid-2022, the data included 1.1M unique email addresses from 11M rows of orders
                                    containing names, phone numbers and delivery instructions.</p>
                                <p><strong>Compromised data:</strong> Delivery instructions, Email addresses, Names,
                                    Phone numbers, Purchases</p>
                            </div>
                        </div>
                    </div>
                </div>
            </div>
        </div>
        <div>
            <div>
                <div>
                    <h3>Pastes you were found in</h3>
                    <p>
                        A <a>paste</a> is information that has been published to a
                        publicly facing website designed to share content and is often an early indicator of a data
                        breach. Pastes are automatically imported and often removed shortly after having been
                        posted. Using the <a>1Password password manager</a>
                        helps you ensure all your passwords are strong and unique such that a breach of one service
                        doesn't put your other services at risk.
                    </p>
                </div>
            </div>
        </div>
    </div>
    <div role="dialog">
        <div>
            <div>
                <div>
                    <button type="button">×</button>
                </div>
            </div>
        </div>
    </div>
    <div>
        <div>
            <div><span>674</span></div>
            <div><span>12,576,062,746</span></div>
            <div><span>115,747</span></div>
            <div><span>228,723,401</span></div>
        </div>
        <div>
            <div>
                <h3>Largest breaches</h3>
                <div>
                    <table>
                        <tbody>
                            <tr>
                                <td><img alt="Collection #1 logo" /></td>
                                <td>772,904,991</td>
                                <td><a>Collection #1 accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Verifications.io logo" /></td>
                                <td>763,117,241</td>
                                <td><a>Verifications.io accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Onliner Spambot logo" /></td>
                                <td>711,477,622</td>
                                <td><a>Onliner Spambot accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Data Enrichment Exposure From PDL Customer logo" /></td>
                                <td>622,161,052</td>
                                <td><a>Data Enrichment Exposure From PDL Customer accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Exploit.In logo" /></td>
                                <td>593,427,119</td>
                                <td><a>Exploit.In accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Facebook logo" /></td>
                                <td>509,458,528</td>
                                <td><a>Facebook accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Anti Public Combo List logo" /></td>
                                <td>457,962,538</td>
                                <td><a>Anti Public Combo List accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="River City Media Spam List logo" /></td>
                                <td>393,430,309</td>
                                <td><a>River City Media Spam List accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="MySpace logo" /></td>
                                <td>359,420,698</td>
                                <td><a>MySpace accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Wattpad logo" /></td>
                                <td>268,765,495</td>
                                <td><a>Wattpad accounts</a></td>
                            </tr>
                        </tbody>
                    </table>
                </div>
            </div>
            <div>
                <h3>Recently added breaches</h3>
                <div>
                    <table>
                        <tbody>
                            <tr>
                                <td><img alt="Luxottica logo" /></td>
                                <td>77,093,812</td>
                                <td><a>Luxottica accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="RentoMojo logo" /></td>
                                <td>2,185,697</td>
                                <td><a>RentoMojo accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="CityJerks logo" /></td>
                                <td>177,554</td>
                                <td><a>CityJerks accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="MEO logo" /></td>
                                <td>8,227</td>
                                <td><a>MEO accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Terravision logo" /></td>
                                <td>2,075,625</td>
                                <td><a>Terravision accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="OGUsers (2022 breach) logo" /></td>
                                <td>529,020</td>
                                <td><a>OGUsers (2022 breach) accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="The Kodi Foundation logo" /></td>
                                <td>400,635</td>
                                <td><a>The Kodi Foundation accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Genesis Market logo" /></td>
                                <td>8,000,000</td>
                                <td><a>Genesis Market accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Sundry Files logo" /></td>
                                <td>274,461</td>
                                <td><a>Sundry Files accounts</a></td>
                            </tr>
                            <tr>
                                <td><img alt="Leaked Reality logo" /></td>
                                <td>114,907</td>
                                <td><a>Leaked Reality accounts</a></td>
                            </tr>
                        </tbody>
                    </table>
                </div>
            </div>
        </div>
    </div>
    <div role="dialog">
        <div>
            <div>
                <div>
                    <button type="button">×</button>
                    <h4>Notify me</h4>
                </div>
                <div>
                    <div>
                        <form role="form">
                            <p>
                                Get notified when future pwnage occurs and your account is compromised.
                            </p>
                            <div>
                                <div>
                                    <input name="NotifyEmail" placeholder="enter your email address" type="email" />
                                </div>
                            </div>
                            <div>
                                <div>
                                    <div>
                                        <div><iframe name="a-264q2ixba10l" title="reCAPTCHA" /></div><textarea
                                            name="g-recaptcha-response" />
                                    </div>
                                </div>
                            </div>
                            <div>
                                <input type="submit" value="notify me of pwnage" />
                            </div>
                        </form>
                    </div>
                    <div>
                        <p>
                            You've just been sent a verification email, all you need to do now is confirm your
                            address by clicking on the link when it hits your mailbox and you'll be automatically
                            notified of future pwnage. In case it doesn't show up, check your junk mail and if
                            you <em>still</em> can't find it, you can always repeat this process.
                        </p>
                        <p>
                            <a>add another address</a>
                        </p>
                    </div>
                </div>
            </div>
        </div>
    </div>
    <footer>
        <div>
            <p>
                <a>A troyhunt.com project</a>
            </p>
        </div>
    </footer>
    <div>
        <div><iframe name="c-264q2ixba10l" title="recaptcha challenge expires in two minutes" /></div>
    </div>
</body>

</html>