Data Breach Reports

Track the latest data breaches from Have I Been Pwned. Stay informed and protect your information.

45
Breaches
22
Critical
17
High
222.9M
Accounts Exposed
Browse by: Critical · High · Medium

Critical Breaches

McGraw Hill

Apr 16, 2026

Critical
13,500,136 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses

In April 2026, education company McGraw Hill confirmed a data breach following an extortion attempt . Attributed to a Salesforce misconfiguration, the company stated the incident exposed "a limited set of data from a webpage hosted by Salesforce on its platform". More than 100GB of data was later pu...

Read Report

SongTrivia2

Apr 4, 2026

Critical
291,739 accounts exposed
Email Addresses Passwords Usernames Names

In April 2026, the music trivia platform SongTrivia2 suffered a data breach that was subsequently published to a public hacking forum . The data contained a total of 291k unique email addresses sourced from either Google OAuth logins or accounts created on the site, the latter also containing bcrypt...

Read Report

SUCCESS

Apr 1, 2026

Critical
253,510 accounts exposed
Email Addresses Passwords Names Phone Numbers +2 more

In March 2026, the personal development and achievement media brand SUCCESS suffered a data breach . The incident exposed 250k unique email addresses along with names, IP addresses, phone numbers and, for a limited number of staff members, bcrypt password hashes. The data also included orders contai...

Read Report

BreachForums Version 5

Mar 27, 2026

Critical
339,778 accounts exposed
Email Addresses Passwords Usernames Names

In March 2026, a breach of one of the many iterations of the BreachForums hacking forum known as "Version 5" was publicly disclosed . The incident exposed 340k unique email addresses along with usernames and argon2 password hashes.

Read Report

Scuf Gaming

Mar 26, 2026

Critical
128,683 accounts exposed
Email Addresses Passwords Usernames Names +1 more

In June 2015, custom gaming controller maker Scuf Gaming suffered a data breach . The incident exposed 129k unique email addresses along with usernames, display names, IP addresses and password hashes.

Read Report

Sound Radix

Mar 26, 2026

Critical
292,993 accounts exposed
Email Addresses Passwords Names Credit Cards

In March 2026, the audio production tools company Sound Radix disclosed a data breach that they subsequently self-submitted to HIBP . The incident impacted 293k unique email addresses and names. Sound Radix advised that it is possible that additional data including hashed passwords may have been exp...

Read Report

RuneScape Boards

Mar 23, 2026

Critical
222,762 accounts exposed
Email Addresses Passwords Usernames Names +1 more

In around 2011, the now defunct RuneScape Boards forum (also known as RSBoards) suffered a data breach that was later redistributed as part of a larger corpus of data . The vBulletin-based service exposed 223k unique email addresses along with usernames, IP addresses and salted MD5 password hashes.

Read Report

Aura

Mar 18, 2026

Critical
903,080 accounts exposed
Email Addresses Passwords Names Phone Numbers +2 more

In March 2026, the online safety service Aura disclosed a data breach that exposed 900k unique email addresses . The data was primarily associated with a marketing tool from a previously acquired company, with fewer than 20k active Aura customers affected. Exposed data included names, phone numbers,...

Read Report

Baydöner

Mar 15, 2026

Critical
1,266,822 accounts exposed
Email Addresses Passwords Names Phone Numbers

In March 2026, the Turkish restaurant chain Baydöner suffered a data breach which was subsequently published to a public hacking forum . The incident exposed over 1.2M unique email addresses along with names, phone numbers, cities of residence and plaintext passwords. A small number of records also ...

Read Report

Canadian Tire

Feb 25, 2026

Critical
38,306,562 accounts exposed
Email Addresses Passwords Names Phone Numbers +3 more

In October 2025, retailer Canadian Tire was the victim of a data breach that exposed almost 42M records. The data contained 38M unique email addresses along with names, phone numbers and physical addresses. Passwords were stored as PBKDF2 hashes and for a subset of records, dates of birth and partia...

Read Report

CarGurus

Feb 21, 2026

Critical
12,461,887 accounts exposed
Email Addresses Names Phone Numbers Ip Addresses

In February 2026, the automotive marketplace CarGurus was the target of a data breach attributed to the threat actor ShinyHunters . Following an attempted extortion, the data was published publicly and contained more than 12M email addresses across multiple files including user account ID mappings, ...

Read Report

Canada Goose

Feb 17, 2026

Critical
581,877 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses +2 more

In February 2026, a data breach allegedly containing data relating to Canada Goose customers was published publicly . The data contained 920k records with 582k unique email addresses and included names, phone numbers, IP addresses, physical addresses and partial credit card data, specifically card t...

Read Report

Association Nationale des Premiers Secours

Feb 10, 2026

Critical
5,600 accounts exposed
Email Addresses Passwords Names Dates Of Birth

In January 2026, a data breach impacting the French non-profit Association Nationale des Premiers Secours (ANPS) was posted to a hacking forum . The breach exposed 5.6k unique email addresses along with names, dates of birth and places of birth. ANPS self-submitted the data to HIBP and advised the i...

Read Report

Betterment

Feb 5, 2026

Critical
1,435,174 accounts exposed
Email Addresses Passwords Names Phone Numbers +3 more

In January 2026, the automated investment platform Betterment confirmed it had suffered a data breach attributed to a social engineering attack . As part of the incident, Betterment customers received fraudulent crypto-related messages promising high returns if funds were sent to an attacker-control...

Read Report

SoundCloud

Jan 27, 2026

Critical
29,815,722 accounts exposed
Email Addresses Usernames Names

In December 2025, SoundCloud announced it had discovered unauthorised activity on its platform . The incident allowed an attacker to map publicly available SoundCloud profile data to email addresses for approximately 20% of its users. The impacted data included 30M unique email addresses, names, use...

Read Report

Under Armour

Jan 21, 2026

Critical
72,742,892 accounts exposed
Email Addresses Names Dates Of Birth Genders +1 more

In November 2025, the Everest ransomware group claimed Under Armour as a victim and attempted to extort a ransom , alleging they had obtained access to 343GB of data. In January 2026, customer data from the incident was published publicly on a popular hacking forum , including 72M email addresses. M...

Read Report

Raaga

Jan 19, 2026

Critical
10,225,145 accounts exposed
Email Addresses Passwords Names Genders

In December 2025, data allegedly breached from the Indian streaming music service 'Raaga' was posted for sale to a popular hacking forum . The data contained 10M unique email addresses along with names, genders, ages (in some cases, full date of birth), postcodes and passwords stored as unsalted MD5...

Read Report

Instagram

Jan 11, 2026

Critical
6,215,150 accounts exposed
Email Addresses Passwords Usernames Names +1 more

In January 2026, data allegedly scraped via an Instagram API was posted to a popular hacking forum . The dataset contained 17M rows of public Instagram information, including usernames, display names, account IDs, and in some cases, geolocation data. Of these records, 6.2M included an associated ema...

Read Report

BreachForums (2025)

Jan 10, 2026

Critical
672,247 accounts exposed
Email Addresses Passwords Usernames Names

In October 2025, a reincarnation of the hacking forum BreachForums, which had previously been shut down multiple times, was taken offline by a coalition of law enforcement agencies . In the months leading up to the takedown, the site itself suffered a data breach that exposed a total of 672k unique ...

Read Report

WhiteDate

Jan 6, 2026

Critical
20,363 accounts exposed
Email Addresses Passwords Usernames Names +1 more

In December 2025, the dating website 'for a Europid vision' WhiteDate suffered a data breach that was subsequently leaked online , initially exposing 6.1k unique email addresses. The leaked data included extensive personal information such as physical appearance, income, education and IQ. A more com...

Read Report

The Botting Network

Dec 18, 2025

Critical
96,320 accounts exposed
Email Addresses Passwords Usernames Names +1 more

In August 2012, the forum for making money with botting 'The Botting Network' suffered a data breach that exposed 96k user records . The now defunct vBulletin forum leaked 96k email addresses, usernames, dates of birth and salted MD5 password hashes.

Read Report

Web Hosting Talk

Dec 17, 2025

Critical
515,149 accounts exposed
Email Addresses Passwords Usernames Names +1 more

In July 2016, the Web Hosting Talk forum suffered a data breach that was subsequently listed for sale . The breach of the vBulletin based forum exposed 515k user records including usernames, email addresses, IP addresses and salted MD5 password hashes.

Read Report

High Severity Breaches

Amtrak

Apr 17, 2026

High
2,147,679 accounts exposed
Email Addresses Names Physical Addresses

In April 2026, the hacking group ShinyHunters claimed they had breached Amtrak . The group typically compromises organisations' Salesforce instances before demanding a ransom and later, if not paid, dumping the data publicly. They subsequently published the alleged data which contained over 2M uniqu...

Read Report

Hallmark

Apr 12, 2026

High
1,736,520 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses

In March 2026, Hallmark suffered an alleged breach and subsequent extortion after attackers gained access to data stored within Salesforce. The data was later published after the extortion deadline passed, exposing 1.7M unique email addresses across both Hallmark and the Hallmark+ streaming service,...

Read Report

Crunchyroll

Apr 4, 2026

High
1,195,684 accounts exposed
Email Addresses Names Ip Addresses Geographic Locations

In March 2026, the anime streaming service Crunchyroll suffered a data breach alleged to have impacted 6.8M users . The exposed data is reported to have originated from the company's Zendesk support system where "name, login name, email address, IP address, general geographic location and the conten...

Read Report

KomikoAI

Mar 2, 2026

High
1,060,191 accounts exposed
Email Addresses Names

In February, the AI-powered comic generation platform KomikoAI suffered a data breach . The incident exposed 1M unique email addresses along with names, user posts and the AI prompts used to generate content. The exposed data enables the mapping of individual AI prompts to specific email addresses.

Read Report

Odido

Feb 26, 2026

High
688,102 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses +1 more

In February 2026, Dutch telco Odido was the victim of a data breach and subsequent extortion attempt . Following the incident, 1M records containing 317k unique email addresses were published, with the attackers threatening to leak additional data in the following days. That threat was subsequently ...

Read Report

CarMax

Feb 20, 2026

High
431,371 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses

In January 2026, data allegedly sourced from US automotive retailer CarMax was published online following a failed extortion attempt . The data included 431k unique email addresses along with names, phone numbers and physical addresses.

Read Report

Figure

Feb 18, 2026

High
967,178 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses +1 more

In February 2026, data obtained from the fintech lending platform Figure was publicly posted online . The exposed data, dating back to January 2026, contained over 900k unique email addresses along with names, phone numbers, physical addresses and dates of birth. Figure confirmed the incident and at...

Read Report

APOIA.se

Feb 16, 2026

High
450,764 accounts exposed
Email Addresses Names Physical Addresses

In December 2025, a database of the Brazilian crowdfunding platform APOIA.se was posted to an online forum . In January 2026, the company confirmed it had suffered a data breach. The incident exposed 451k unique email addresses along with names and physical addresses.

Read Report

University of Pennsylvania

Feb 16, 2026

High
623,750 accounts exposed
Email Addresses Names Physical Addresses Genders

In October 2025, the University of Pennsylvania was the victim of a data breach followed by a ransom demand , largely affecting its donor database. After the incident, the attackers sent inflammatory emails to some victims. The data was later published online in February 2026 and included 624k uniqu...

Read Report

Toy Battles

Feb 10, 2026

High
1,017 accounts exposed
Email Addresses Usernames Names Ip Addresses

In February 2026, the online gaming community Toy Battles suffered a data breach. The incident exposed 1k unique email addresses alongside usernames, IP addresses and chat logs. Following the breach, Toy Battles self-submitted the data to Have I Been Pwned.

Read Report

Substack

Feb 6, 2026

High
663,121 accounts exposed
Email Addresses Names Phone Numbers

In October 2025, the publishing platform Substack suffered a data breach that was subsequently circulated more widely in February 2026. The breach exposed 663k account holder records containing email addresses along with publicly visible profile information from Substack accounts, such as publicatio...

Read Report

Panera Bread

Jan 31, 2026

High
5,112,502 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses

In January 2026, Panera Bread suffered a data breach that exposed 14M records . After an attempted extortion failed, the attackers published the data publicly, which included 5.1M unique email addresses along with associated account information such as names, phone numbers and physical addresses. Pa...

Read Report

Pass'Sport

Jan 18, 2026

High
6,366,133 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses +1 more

In December 2025, data from France's Pass'Sport program was posted to a popular hacking forum . Initially misattributed to CAF (the French family allowance fund), the data contained 6.5M unique email addresses affecting 3.5M households. The data also included names, phone numbers, genders and physic...

Read Report

WIRED

Dec 27, 2025

High
2,364,431 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses +2 more

In December 2025, 2.3M records of WIRED magazine users allegedly obtained from parent company Condé Nast were published online . The most recent data dated back to the previous September and exposed email addresses and display names, as well as, for a small number of users, their name, phone number,...

Read Report

Utair

Dec 26, 2025

High
401,400 accounts exposed
Email Addresses Names Physical Addresses Dates Of Birth

In August 2020, news broke of a data breach of Russian airline Utair that dated back to the previous year . The breach contained over 400k unique email addresses along with extensive personal information including names, physical addresses, dates of birth, passport numbers and loyalty program detail...

Read Report

Медицинская лаборатория Гемотест (Gemotest)

Dec 24, 2025

High
6,341,495 accounts exposed
Email Addresses Names Physical Addresses Dates Of Birth

In April 2022, Russian pharmaceutical company Gemotest suffered a data breach that exposed 31 million patients . The data contained 6.3 million unique email addresses along with names, physical addresses, dates of birth, passport and insurance numbers. Gemotest was later fined for the breach.

Read Report

AUTOSUR

Dec 18, 2025

High
487,226 accounts exposed
Email Addresses Names Phone Numbers Physical Addresses

In March 2025, the French vehicle inspection company AUTOSUR suffered a data breach exposing over 10M customer records, though only 487k unique email addresses were present. The compromised data included names, phone numbers, physical addresses, and vehicle details such as make and model, VIN, and r...

Read Report

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.