Have I Been Pwned latest breaches The latest publicly leaked data breaches to hit Have I Been Pwned
- Spyic – 875,999 breached accountson February 20, 2025 at 11:12 pm
In February 2025, the spyware service Spyic suffered a data breach along with sibling spyware service, Cocospy. The Spyic breach alone exposed almost 876k customer email addresses which were provided to HIBP, and reportedly also enabled unauthorised access to captured messages, photos, call logs, and more. The data was provided to HIBP by a source who requested it be attributed to “zathienaephi@proton.me”.
- Cocospy – 1,798,059 breached accountson February 20, 2025 at 10:36 pm
In February 2025, the spyware service Cocospy suffered a data breach along with sibling spyware service, Spyic. The Cocospy breach alone exposed almost 1.8M customer email addresses which were provided to HIBP, and reportedly also enabled unauthorised access to captured messages, photos, call logs, and more. The data was provided to HIBP by a source who requested it be attributed to “zathienaephi@proton.me”.
- Storenvy – 11,052,071 breached accountson February 16, 2025 at 8:31 am
In mid-2019, the e-commerce website Storenvy suffered a data breach that exposed millions of customer records. A portion of the breached records were subsequently posted to a hacking forum with cracked password hashes, whilst the entire corpus of 23M rows was put up for sale. The data contained 11M unique email addresses alongside usernames, IP addresses, the user’s city, gender date of birth and original salted SHA-1 password hash.
- Doxbin (TOoDA) – 136,461 breached accountson February 13, 2025 at 7:18 am
In February 2025, the “doxing” website Doxbin was compromised by a group calling themselves “TOoDA” and the data dumped publicly. Included in the breach were 336k unique email addresses alongside usernames. The data was provided to HIBP by a source who requested it be attributed to “emo.rip”.
- Zacks (2024) – 11,994,223 breached accountson February 12, 2025 at 11:19 pm
In June 2024, the investment research company Zacks was allegedly breached, and data was later published to a popular hacking forum. This comes after a separate Zacks data breach confirmed by the organisation in 2023 with the subsequent breach disclosing millions of additional records representing a superset of data from the first incident. The 2024 breach included 12M unique email addresses along with IP and physical addresses, names, usernames, phone numbers and unsalted SHA-256 password hashes. Zacks did not respond to multiple attempts to contact them about the incident.
- LandAirSea – 337,373 breached accountson February 11, 2025 at 2:35 am
In January 2025, the GPS tracking service LandAirSea suffered a data breach that exposed 337k unique customer email addresses alongside names, usernames and password hashes. The breach also exposed partial credit card data (card type, last 4 digits and expiration), and GPS device identifiers and locations. LandAirSea is aware of the breach and has remediated the underlying vulnerability. The data was provided to HIBP by a source who requested it be attributed to “zathienaephi@proton.me”.
- Adopt Me Trading Values – 86,136 breached accountson February 10, 2025 at 2:58 am
In July 2022, the Adopt Me Trading Values website for assessing the value of pet trades within the “Adopt Me!” Roblox game suffered a data breach that was later redistributed as part of a larger corpus of data. The breach exposed 86k unique email addresses along with usernames (and Roblox usernames), IP addresses and bcrypt password hashes. The data was provided to HIBP by a source who requested it be attributed to “Leidhall”.
- Youthmanual – 937,912 breached accountson February 9, 2025 at 6:28 am
In January 2019, the Indonesian college and career platform Youthmanual suffered a data breach that exposed 1.1M records of data. The breached included 938k unique email addresses along with extensive personal information including names, genders, dates and places of birth, phone numbers, physical addresses and salted SHA-1 password hashes.
- Thermomix Recipe World Forum – 3,123,439 breached accountson February 6, 2025 at 8:20 pm
In January 2025, the Rezeptwelt (German for “recipe world”) forum for Thermomix owners suffered a data breach. The incident exposed 3.1M registered users’ details including names, email and physical addresses, phone numbers, dates of birth and bios (usually cooking related). The data was provided to HIBP by a source who requested it be attributed to “ayame@xmpp.jp”.
- Hakko Corporation – 9,665 breached accountson February 6, 2025 at 1:58 am
In March 2019, the Japanese solder-related business Hakko Corporation suffered a data breach. The incident exposed almost 10k customer records including email and physical addresses, phone numbers, names, usernames, genders, dates of birth and plain text passwords.
- PoinCampus – 89,116 breached accountson February 4, 2025 at 12:29 am
In November 2024, the South Korean education platform PoinCampus suffered a data breach which was later published to a popular hacking forum. The data included 89k unique email addresses, names and a small number of phone numbers and dates of birth. The data was provided to HIBP by a source who requested it be attributed to “Threat Actor 888”.
- 1win – 96,166,543 breached accountson February 3, 2025 at 5:37 pm
In November 2024, the online betting platform 1win suffered a data breach that exposed 96M users. The exposed data included email and IP addresses, phone numbers, dates of birth, country and SHA-256 password hashes. The data was provided to HIBP by a source who requested it be attributed to “Leidhall”.
- DragonNest – 511,290 breached accountson February 3, 2025 at 4:29 am
In August 2013, the massively multiplayer online role-playing game (MMORGP) DragonNest suffered a data breach that was later redistributed as part of a larger corpus of data. The breach exposed over 500k unique email addresses along with usernames, IP addresses and plain text passwords. The service later suffered a massive data loss.
- 9Lives – 109,515 breached accountson February 2, 2025 at 2:04 am
In October 2014, the (now defunct) Belgian gaming news forum 9Lives suffered a data breach that was later redistributed as part of a larger corpus of data. The breach exposed 109k unique email addresses along with usernames and salted MD5 password hashes. The data was provided to HIBP by a source who requested it be attributed to “Leidhall”.
- Speedio (unverified) – 27,501,041 breached accountson January 30, 2025 at 7:14 am
In December 2024, data alleged to have been taken from the Brazilian lead generation platform Speedio was posted for sale to a popular hacking forum. The data was allegedly obtained from an unsecured Elasticsearch instance and contained over 62M records of largely public business information including company names, phone numbers and physical addresses, along with 27M unique email addresses, predominantly from public services such as Gmail and Outlook. Speedio did not respond to multiple attempts to disclose the incident, and the origin of the data could not be independently verified. The data was provided to HIBP by a source who requested it be attributed to “ayame@xmpp.jp”.
- HeatGames – 647,896 breached accountson January 28, 2025 at 7:40 am
In June 2021, the (now defunct) gaming website HeatGames suffered a data breach that was later redistributed as part of a larger corpus of data. The breach exposed almost 650k unique email addresses along with IP addresses, country and salted MD5 password hashes.
- Doxbin Scrape – 435,784 breached accountson January 28, 2025 at 2:09 am
In January 2025, 435k email addresses were scraped from the “doxing” service Doxbin. Posts to the service are usually intended to disclose the personal information of non-consensually third parties. The data was provided to HIBP by a source who requested it be attributed to “oathnet.ru”.
- Frame & Optic – 15,678 breached accountson January 22, 2025 at 8:46 am
In January 2025, the eyewear seller Frame & Optic suffered a data breach. The incident exposed almost 16k unique email addresses along with names, phone numbers and geolocation data including country, state and postcode. The data was provided to HIBP by a source who requested it be attributed to “oathnet.ru”.
- Welhof – 107,292 breached accountson January 22, 2025 at 8:28 am
In late 2023, the Dutch appliance store Welhof suffered a data breach. The incident exposed over 100k unique email addresses along with names, physical addresses and the value of purchases made. The data was provided to HIBP by a source who requested it be attributed to “oathnet.ru”.
- Otelier – 436,855 breached accountson January 18, 2025 at 6:47 am
In July 2024, a threat actor gained access to the hotel management platform Otelier and retrieved customer data from well-known hotel brands including Marriott, Hilton, and Hyatt. The data included 437k customer email addresses (a further 868k generated email addresses from the booking.com and Expedia platforms were not loaded into HIBP), names, physical addresses, phone numbers, booking information related to travel plans, purchases recorded by the platform and in a small number of cases, partial credit card data. The data was provided to HIBP by a source who requested it be attributed to “ayame@xmpp.jp”.