Security Intelligence

Security Intelligence

Known Data Breaches

Hundreds of confirmed breaches. Billions of compromised accounts. Browse the full directory to see how widespread the threat really is, and why proactive
security matters.

Why Browse the Data Breach Directory?

Data breaches are not isolated incidents — they are cumulative. A single person’s credentials can appear in dozens of separate breaches over the years, each one adding more personal details to an attacker’s profile. This directory lets you explore the full scope of confirmed breaches: which companies were hit, how many accounts were exposed, and what types of data were compromised, from email addresses and passwords to financial records and government IDs.

Browsing the catalog puts the scale of the problem into perspective and helps you make informed decisions about which services you trust with your data. If a company you use appears here, that is a direct signal to change your credentials, review your account activity, and consider whether that service deserves continued access to your personal information.

Latest Breach

SplitVPN

splitvpn.io

Breach date: Jul 20, 2026 865,336 accounts affected
In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).
Device information Email addresses Geographic locations IP addresses Partial credit card data
1,022 Known Breaches
17.8B Compromised Accounts
165 Data Types Exposed
Showing 1–24 of 1,022 breaches
splitvpn.io
Jul 20, 2026 865,336 accounts
In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).
Device information Email addresses Geographic locations IP addresses Partial credit card data
Jun 15, 2026 831,642 accounts
In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and other personal information relating to both current students and alumni.
Academic records Citizenship statuses Dates of birth Email addresses Genders Names Phone numbers Physical addresses
suno.com
Nov 24, 2025 55,282,226 accounts
In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year. The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a small portion of the corpus, the breach also included tens of thousands of Stripe records relating to purchases, containing names, physical addresses, purchase amounts and partial credit card data including the card type, expiry date and last 4 digits. The company advised that "Suno does not have access to customers' full credit card numbers in Stripe".
Email addresses Names Partial credit card data Phone numbers Physical addresses Purchases
paidwork.com
Mar 28, 2026 23,272,765 accounts
In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale. Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The breach also included a broad range of other data relating to the operation of the platform including user profile data, banking information, payout history for workers and passwords stored as bcrypt hashes.
Bank account numbers Dates of birth Device information Education levels Email addresses Financial transactions Genders IP addresses Names Passwords Personal interests Phone numbers Physical addresses Profile photos
fluke.com
Jun 30, 2026 821,100 accounts
In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present.
Email addresses Employers Job titles Names Physical addresses Support tickets
goosecreek.com
Jun 8, 2026 6,574,121 accounts
In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers, claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contained 6.6M unique email addresses along with names, phone numbers, physical addresses, order IDs and total spent. The data appears to have been obtained from the company's Shopify instance. Goose Creek is aware of the reports but was unable to provide Have I Been Pwned with any further information at the time of publication.
Email addresses Names Phone numbers Physical addresses Purchases
Jun 14, 2026 793,925 accounts
In June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, addresses, phone numbers, Social Security numbers and other information relating to student enrolments. In its disclosure notice, the college advised that "the potentially impacted information may vary for each individual and may include all or just one of the above-listed types of information".
Academic records Dates of birth Email addresses Genders Government issued IDs Names Phone numbers Physical addresses
Jun 14, 2026 2,303,416 accounts
In June 2026, Moody Bible Institute was targeted by a ShinyHunters "pay or leak" extortion campaign. Over 2.3M unique email addresses and other personal data were later published publicly, including names, physical addresses, phone numbers, dates of birth and other information relating to donors, supporters, students and alumni. In their disclosure notice, Moody advised that they had "engaged both internal and external cybersecurity experts to thoroughly investigate the matter".
Dates of birth Email addresses Genders Marital statuses Names Phone numbers Physical addresses
sysco.com
Jun 14, 2026 2,691,852 accounts
In June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign. Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact information including names, phone numbers, physical addresses, internal job titles, and customer feedback.
Customer feedback Email addresses Employers Job titles Names Phone numbers Physical addresses Usernames
americantower.com
Jun 11, 2026 216,601 accounts
In June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly taken from the company containing more than 200k unique email addresses belonging to employees, contractors, customers, and leads. Exposed data also included names, addresses, and phone numbers.
Email addresses Job titles Names Phone numbers Physical addresses
Jun 4, 2026 9,796,738 accounts
In June 2026, the sports and entertainment company Madison Square Garden Sports was the target of a ShinyHunters "pay or leak" extortion campaign. The group later published the alleged data, which included almost 10M unique email addresses spanning staff and customers, along with extensive personal, employment and customer relationship information.
Customer service records Email addresses Names Phone numbers Physical addresses
jcpenny.com
Jun 11, 2026 368,418 accounts
In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed records indicated they primarily related to internal HR systems and impacted current and former employees. The data included 368k corporate and personal email addresses, names, dates of birth, Social Security numbers, phone numbers and home addresses.
Dates of birth Email addresses Government issued IDs Job titles Names Phone numbers Physical addresses Usernames
ralphlauren.com
Jun 10, 2026 139,903 accounts
In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresses along with names, phone numbers, genders and age groups.
Age groups Email addresses Genders Names Phone numbers
Jun 17, 2026 4,348,526 accounts
On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation, a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust, the operation remediated almost 15,000 compromised websites and disrupted more than 100 servers and domains used to distribute malware. Authorities initially provided HIBP with 154k impacted email addresses and more than half a million previously unseen passwords. The following week, a further 4M email addresses and 9M passwords relating to the StealC malware operation also targeted by Operation Endgame were provided, followed by another 131k email addresses the following month, bringing the total to more than 4.3M unique email addresses.
Email addresses Passwords
cfgi.com
Mar 5, 2026 248,235 accounts
In March 2026, the financial consulting and advisory firm CFGI was the target of a ShinyHunters "pay-or-leak" extortion campaign. The group subsequently publicised data allegedly obtained from CFGI comprising corporate contact information, including 243k unique email addresses, names, phone numbers and physical addresses.
Email addresses Employers Job titles Names Phone numbers Physical addresses
Jun 14, 2026 56,278,397 accounts
In June 2026, a collection of accumulated stealer logs from various sources was added to HIBP. The corpus comprised 56M unique email addresses across hundreds of millions of stealer log records. The data also contained 124M unique passwords, which have been added to Pwned Passwords and are now searchable. Individuals can view any records captured against their email address in the stealer logs section of their dashboard. Organisations can see logs affecting their domain via the stealer logs API.
Email addresses Passwords
berkadia.com
Mar 18, 2026 305,216 accounts
In March 2026, the commercial real estate finance company Berkadia was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from Berkadia's Salesforce instance, including over 300k unique email addresses as well as names, physical addresses and phone numbers, among other data.
Email addresses Employers Names Phone numbers Physical addresses
infinitecampus.com
Mar 17, 2026 137,123 accounts
In March 2026, the student information system Infinite Campus was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from Infinite Campus, containing 137k unique email addresses along with names, phone numbers, physical addresses and support tickets. Infinite Campus subsequently sent notifications, advising that the exposed data largely consisted of "names and contact information for school staff" and that "the majority is directory information commonly found on school websites".
Email addresses Employers Job titles Names Phone numbers Physical addresses Support tickets Usernames
nottingham.ac.uk
Jun 8, 2026 454,635 accounts
In June 2026, the University of Nottingham was the target of a cyber attack, later linked to a ShinyHunters "pay or leak" extortion campaign. Tens of gigabytes of data were subsequently published online and included 455k unique email addresses along with extensive personal information including names, addresses, phone numbers, ethnicities, disabilities, passport numbers and information relating to academic enrolments and fee payments. In a post about the incident, the university advised that the breach affected both "current students, and alumni".
Academic records Citizenship statuses Dates of birth Disabilities Email addresses Ethnicities Genders IP addresses Names Passport numbers Phone numbers Physical addresses Purchases Salutations Usernames
bakerdist.com
May 22, 2026 102,935 accounts
In May 2026, the HVAC/R wholesale distributor Baker Distributing Company was added to the ShinyHunters data extortion group's "pay or leak" site. In early June, the group publicly published data they claimed had been obtained from Baker's SharePoint and Salesforce infrastructure including 103k unique email addresses along with names, physical addresses, phone numbers and tickets relating to the company's HVAC contractor customer base. The exposed data was largely corporate contact and support information with limited sensitivity.
Email addresses Names Phone numbers Physical addresses Support tickets
bcdtravel.com
May 28, 2026 396,313 accounts
In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other exposed data included names, addresses, phone numbers, job titles and employer names, spanning a variety of different data sets including leads, internal staff and support tickets.
Email addresses Employers Job titles Names Phone numbers Physical addresses Support tickets
dentaquest.com
May 22, 2026 2,553,599 accounts
In May 2026, the dental benefits administrator DentaQuest was the target of a ShinyHunters "pay or leak" extortion campaign that resulted in the group publicly publishing hundreds of gigabytes of data allegedly obtained from the company. The data included 2.6M unique email addresses along with names, addresses and phone numbers. Much of the data appeared in healthcare enrollment files (ASC X12 transaction sets) with some containing Medicaid IDs, while additional data appeared in member records and related files. DentaQuest acknowledged "a cybersecurity incident involving unauthorized access to a limited portion of our network", and advised they had contained the attack and mitigated the threat.
Dates of birth Email addresses Genders Government issued IDs Health insurance information Names Phone numbers Physical addresses
edmunds.com
Jan 23, 2026 177,860 accounts
In January 2026, the automotive research and car-shopping platform Edmunds was listed by the ShinyHunters hacking group as having been breached. Data purportedly obtained in the incident was later published publicly and included 178k unique email addresses, usernames, passwords, IP addresses, phone numbers and vehicle-related records.
Device information Email addresses IP addresses Passwords Phone numbers Usernames
atlasmenu.net
May 29, 2026 63,926 accounts
In May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and published the service's database to a public GitHub repository. The incident exposed 64k unique email addresses along with usernames, IP addresses, support tickets and passwords stored as bcrypt hashes.
Email addresses IP addresses Passwords Support tickets Usernames