Jul 20, 2026
865,336 accounts
Device information
Email addresses
Geographic locations
IP addresses
Partial credit card data
Jun 15, 2026
831,642 accounts
Academic records
Citizenship statuses
Dates of birth
Email addresses
Genders
Names
Phone numbers
Physical addresses
Nov 24, 2025
55,282,226 accounts
In November 2025,
AI music generation tool Suno suffered a data breach that later came to light in July the following year. The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a small portion of the corpus, the breach also included tens of thousands of Stripe records relating to purchases, containing names, physical addresses, purchase amounts and partial credit card data including the card type, expiry date and last 4 digits. The company advised that "Suno does not have access to customers' full credit card numbers in Stripe".
Email addresses
Names
Partial credit card data
Phone numbers
Physical addresses
Purchases
Mar 28, 2026
23,272,765 accounts
Bank account numbers
Dates of birth
Device information
Education levels
Email addresses
Financial transactions
Genders
IP addresses
Names
Passwords
Personal interests
Phone numbers
Physical addresses
Profile photos
Jun 30, 2026
821,100 accounts
In July 2026, electronic test and measurement equipment company
Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present.
Email addresses
Employers
Job titles
Names
Physical addresses
Support tickets
Jun 8, 2026
6,574,121 accounts
Email addresses
Names
Phone numbers
Physical addresses
Purchases
Jun 14, 2026
793,925 accounts
Academic records
Dates of birth
Email addresses
Genders
Government issued IDs
Names
Phone numbers
Physical addresses
Jun 14, 2026
2,303,416 accounts
Dates of birth
Email addresses
Genders
Marital statuses
Names
Phone numbers
Physical addresses
Jun 14, 2026
2,691,852 accounts
In June 2026, the food distribution company
Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign. Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact information including names, phone numbers, physical addresses, internal job titles, and customer feedback.
Customer feedback
Email addresses
Employers
Job titles
Names
Phone numbers
Physical addresses
Usernames
Jun 11, 2026
216,601 accounts
Email addresses
Job titles
Names
Phone numbers
Physical addresses
Jun 4, 2026
9,796,738 accounts
Customer service records
Email addresses
Names
Phone numbers
Physical addresses
Jun 11, 2026
368,418 accounts
Dates of birth
Email addresses
Government issued IDs
Job titles
Names
Phone numbers
Physical addresses
Usernames
Jun 10, 2026
139,903 accounts
Age groups
Email addresses
Genders
Names
Phone numbers
Jun 17, 2026
4,348,526 accounts
On 18 June 2026, the latest phase of
Operation Endgame targeted the SocGholish malware operation, a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust, the operation remediated almost 15,000 compromised websites and disrupted more than 100 servers and domains used to distribute malware. Authorities initially provided HIBP with 154k impacted email addresses and more than half a million previously unseen passwords. The following week, a further 4M email addresses and 9M passwords relating to
the StealC malware operation also targeted by Operation Endgame were provided, followed by another 131k email addresses the following month, bringing the total to more than 4.3M unique email addresses.
Email addresses
Passwords
Mar 5, 2026
248,235 accounts
Email addresses
Employers
Job titles
Names
Phone numbers
Physical addresses
Jun 14, 2026
56,278,397 accounts
In June 2026, a collection of accumulated stealer logs from various sources was added to HIBP. The corpus comprised 56M unique email addresses across hundreds of millions of stealer log records. The data also contained 124M unique passwords, which have been added to
Pwned Passwords and are now searchable. Individuals can view any records captured against their email address in
the stealer logs section of their dashboard. Organisations can see logs affecting their domain via
the stealer logs API.
Email addresses
Passwords
Mar 18, 2026
305,216 accounts
Email addresses
Employers
Names
Phone numbers
Physical addresses
Mar 17, 2026
137,123 accounts
Email addresses
Employers
Job titles
Names
Phone numbers
Physical addresses
Support tickets
Usernames
Jun 8, 2026
454,635 accounts
In June 2026,
the University of Nottingham was the target of a cyber attack, later linked to a ShinyHunters "pay or leak" extortion campaign. Tens of gigabytes of data were subsequently published online and included 455k unique email addresses along with extensive personal information including names, addresses, phone numbers, ethnicities, disabilities, passport numbers and information relating to academic enrolments and fee payments.
In a post about the incident, the university advised that the breach affected both "current students, and alumni".
Academic records
Citizenship statuses
Dates of birth
Disabilities
Email addresses
Ethnicities
Genders
IP addresses
Names
Passport numbers
Phone numbers
Physical addresses
Purchases
Salutations
Usernames
May 22, 2026
102,935 accounts
In May 2026, the HVAC/R wholesale distributor
Baker Distributing Company was added to the ShinyHunters data extortion group's "pay or leak" site. In early June, the group publicly published data they claimed had been obtained from Baker's SharePoint and Salesforce infrastructure including 103k unique email addresses along with names, physical addresses, phone numbers and tickets relating to the company's HVAC contractor customer base. The exposed data was largely corporate contact and support information with limited sensitivity.
Email addresses
Names
Phone numbers
Physical addresses
Support tickets
May 28, 2026
396,313 accounts
In May 2026, the corporate travel management company
BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other exposed data included names, addresses, phone numbers, job titles and employer names, spanning a variety of different data sets including leads, internal staff and support tickets.
Email addresses
Employers
Job titles
Names
Phone numbers
Physical addresses
Support tickets
May 22, 2026
2,553,599 accounts
Dates of birth
Email addresses
Genders
Government issued IDs
Health insurance information
Names
Phone numbers
Physical addresses
Jan 23, 2026
177,860 accounts
Device information
Email addresses
IP addresses
Passwords
Phone numbers
Usernames
May 29, 2026
63,926 accounts
In May 2026, the GTA V and CS2 cheat service
Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and published the service's database to a public GitHub repository. The incident exposed 64k unique email addresses along with usernames, IP addresses, support tickets and passwords stored as bcrypt hashes.
Email addresses
IP addresses
Passwords
Support tickets
Usernames