Have I Been Pwned latest breaches The latest publicly leaked data breaches to hit Have I Been Pwned
- Giant Tiger – 2,842,669 breached accountson April 12, 2024 at 10:31 pm
In March 2024, Canadian discount store Giant Tiger suffered a data breach that exposed 2.8M customer records. Attributed to a vendor of the retailer, the breach included physical and email addresses, names and phone numbers.
- Salvadoran Citizens – 946,989 breached accountson April 10, 2024 at 10:25 pm
In April 2024, nearly 6 million records of Salvadoran citizens were published to a popular hacking forum. The data included names, dates of birth, phone numbers, physical addresses and nearly 1M unique email addresses. Further, over 5M corresponding profile photos were also included in the breach.
- Kaspersky Club – 55,971 breached accountson April 9, 2024 at 6:22 am
In March 2024, the independent fan forum Kaspersky Club suffered a data breach. The incident exposed 56k unique email addresses alongside usernames, IP addresses and passwords stored as either MD5 or bcrypt hashes.
- boAt – 7,528,985 breached accountson April 8, 2024 at 8:33 am
In March 2024, the Indian audio and wearables brand boAt suffered a data breach that exposed 7.5M customer records. The data included physical and email address, names and phone numbers, all of which were subsequently published to a popular clear web hacking forum.
- SurveyLama – 4,426,879 breached accountson April 2, 2024 at 11:04 pm
In February 2024, the paid survey website SurveyLama suffered a data breach that exposed 4.4M customer email addresses. The incident also exposed names, physical and IP addresses, phone numbers, dates of birth and passwords stored as either salted SHA-1, bcrypt or argon2 hashes. When contacted about the incident, SurveyLama advised that they had already “notified the users by email”.
- Pandabuy – 1,348,407 breached accountson April 1, 2024 at 8:34 am
In March 2024, 1.3M unique email addresses from the online store for purchasing goods from China, Pandabuy, were posted to a popular hacking forum. The data also included IP and physical addresses, names, phone numbers and order enquiries. The breach was alleged to be attributed to “Sanggiero” and “IntelBroker”.
- Washington State Food Worker Card – 1,594,305 breached accountson March 31, 2024 at 2:34 am
In June 2023, the Tacoma-Pierce County Health Department announced a data breach of their Washington State Food Worker Card online training system. The breach was published to a popular hacking forum the year before and dated back to a 2018 database backup. Included in the data were 1.6M unique email addresses along with names, post codes, dates of birth and approximately 9.5k driver’s licence numbers.
- England Cricket – 43,299 breached accountson March 29, 2024 at 1:10 am
In March 2024, English Cricket’s icoachcricket website suffered a data breach that exposed over 40k records. The data included email addresses and passwords stored as either bcrypt hashes, salted MD5 hashes or both. The data was provided to HIBP by a source who requested it be attributed to “IntelBroker”.
- Exvagos – 2,121,789 breached accountson March 28, 2024 at 6:28 am
In July 2022, the direct download website Exvagos suffered a data breach that was later redistributed as part of a larger corpus of data. The breach exposed 2.1M unique email addresses along with IP addresses, usernames, dates of birth and MD5 password hashes.
- GSM Hosting – 2,607,440 breached accountson March 27, 2024 at 6:23 am
In August 2016, breached data from the vBulletin forum for GSM-Hosting appeared for sale alongside dozens of other hacked services. The breach impacted 2.6M users of the service and included email and IP addresses, usernames and salted MD5 password hashes.
- SwordFantasy – 2,690,657 breached accountson March 26, 2024 at 8:31 am
In January 2019, the now defunct MMO and RPG game SwordFantasy suffered a data breach that exposed 2.7M unique email addresses. Other impacted data included username, IP address and salted MD5 password hashes.
- MediaWorks – 162,710 breached accountson March 22, 2024 at 6:43 am
In March 2024, millions of rows of data from the New Zealand media company MediaWorks was publicly posted to a popular hacking forum. The incident exposed 163k unique email addresses provided by visitors who filled out online competitions and included names, physical addresses, phone numbers, dates of birth, genders and the responses to questions in the competition. Some victims of the breach subsequently received ransom demands requesting payment to have their data deleted.
- AT&T – 49,102,176 breached accountson March 19, 2024 at 6:30 am
In March 2024, tens of millions of records allegedly breached from AT&T were posted to a popular hacking forum. Dating back to August 2021, the data was originally posted for sale before later being freely released. At the time, AT&T maintained that there had not been a breach of their systems and that the data originated from elsewhere. 12 days later, AT&T acknowledged that data fields specific to them were in the breach and that it was not yet known whether the breach occurred at their end or that of a vendor. AT&T also proceeded to reset customer account passcodes, an indicator that there was sufficient belief passcodes had been compromised. The incident exposed names, email and physical addresses, dates of birth, phone numbers and US social security numbers.
- ClickASnap – 3,262,980 breached accountson March 13, 2024 at 3:47 am
In September 2022, the online photo sharing platform ClickASnap suffered a data breach. The incident exposed almost 3.3M personal records including email addresses, usernames and passwords stored as SHA-512 hashes. Further, a collection of paid subscriptions were also included and contained names, physical addresses and amounts paid.
- Flipkart – 552,094 breached accountson March 12, 2024 at 5:09 am
In September 2022, over 500k customer records from the Indian e-commerce service Flipkart appeared on a popular hacking forum. The breach exposed email addresses, latitudes and longitudes, names and phone numbers.
- Habib’s – 3,517,679 breached accountson March 10, 2024 at 3:31 am
In August 2021, the Brazilian fast food company “Habib’s” suffered a data breach that was later redistributed as part of a larger corpus of data. The breach exposed 3.5M unique email addresses along with IP addresses, names, phone numbers, dates of birth and links to social media profiles.
- APK.TW – 2,451,197 breached accountson March 9, 2024 at 12:17 am
In September 2022, the Taiwanese Android forum APK.TW suffered a data breach that was later redistributed as part of a larger corpus of data. The breach exposed 2.5M unique email addresses along with IP addresses, usernames and salted MD5 password hashes.
- Online Trade (Онлайн Трейд) – 3,805,265 breached accountson March 7, 2024 at 6:51 am
In September 2022, the Russian e-commerce website Online Trade (Онлайн Трейд) suffered a data breach that exposed 3.8M customer records. The data included email and IP addresses, names, phone numbers, dates of birth and MD5 password hashes.
- WoTLabs – 21,994 breached accountson March 7, 2024 at 3:32 am
In March 2024, WoTLabs (World of Tanks Statistics and Resources) suffered a data breach and website defacement attributed to “chromebook breachers”. The breach exposed 22k forum members’ personal data including email and IP addresses, usernames, dates of birth and time zones.
- Mr. Green Gaming – 27,123 breached accountson March 3, 2024 at 6:28 am
In March 2024, the online games community Mr. Green Gaming suffered a data breach that exposed 27k user records. Acknowledged on their Discord server, the incident exposed email and IP addresses, usernames, geographic locations and dates of birth.