GO TO DOXBIN.COM FOR THE FULL PASTE:
mmmm mmmm mmm mmm mmmmmmmm mm mm mmmmmmmm
m#""""# ##""""# ##m m## """##""" ## ## ##""""""
##m ##" ##mm## ## ## ## ##
"####m ## "##" ## ######## #######
"## ##m ## ## ## ## ##
#mmmmm#" ##mmmm# ## ## ## ## ##mmmmmm https://discord.gg/FwpbJSySF / have fun >.<
""""" """" "" "" "" "" """"""""
+-------------------------------------------------+
| THE COUNCIL |
+-------------------------------------------------+
| 🇨🇷🇪🇩🇮🇹 🇹🇴 : 🇨🇷🇦🇻🇪 <> 🇧4🇺 <> 🇰🇦🇳🇷🇦 <> 🇼🇮🇳🇪 |
+-------------------------------------------------+
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@-+@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%++++. -%@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@*++++++-.-++%%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@*+++-++++-++++++@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@+--.-- -++ +-+%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@..-+. .-+++--+*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@*++- ++-++-++**%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@*+++ -+ ..+-+++*****%%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%++++++**++ .++*++** .@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*+++++%%%+ +***++* *@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@+++++*%%++-. .++*+%%@**++ *%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*+++*@%+++++**+++++%@%**+ +@%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%++++%@@**%***%%%@%*@@*++- ++%@%@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*++++@@@%%%@@*%@@@%*%%**++.+++*@%@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%%++++%%%@+*@@@%%@@@%+*%*%*%**%+*%%@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*++*+*%@%+**@@@@@@@*+-%%%%%**%***%@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@+++*%**@@*+***%**%%*%+-+%@@@**@%*%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@+**+%++@@@*+%****%**%**+++%@@**%@*%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@***%++*@@@@*%@*%%*%%*@*%+*--+%**%%*@*@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@*@%*%+*@@@@%*@@%%@%%%%@****+++-**%*%@%@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%@%***@@@@@%*@@%%@%*%@@%*@++**+*+*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%%@++%@@@@@*%@@%@%@@@@@%*%**%*+***@@@@@@@@*+-%@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@- ***%@%+@@@@@%@@@@@@%@%*@+%*@@%@@@* -*%@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@* +*****@@@@@%@@@@@@%@%+*%%@@%*-.-+%@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ .+*%+*@@@@@%@@@@@@@@@**+. .+%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@*- +@@%+%@@@@@%@@@@@@@@@*-+%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@%*-. .+%@@@@@@@*+%@@@@@%@@@@@@@@@**@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@- .+%@@@@@@@@@@@++%@@@@@%@@@@@@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@.. +@@@@@@@@@@@@@@+*@@@@@@@@@@@@@@@@%+@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@ .@@@@@@@@@@%+*%@@@@@@@@@@@@@@@%+%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@**%%%@@@@@@@@@@@@@@@**@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@ %@@@@@@@@@@*%@%%@@@@@@@@@@@@@@@*+@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@+ %@@@@@@@@@%*@@%%@@@@@@@@@@@@@@@%+@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@% %@@@@@@@@@%*@@%@@@@@@@@@@@@%@@@@*%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@% %@@@@@@@@@**@@%@@@@@@@@@@@@%@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@. %@@@@@@@@@+%@@*@@@@@@@@@@@@%@@@@@+@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@% -@@@@@@@@%+%@@*@@@@@@@@@@@@*%@@@@*%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@. @@@@@@@@**@@%*@@@@@@@@@@@@*%@@@@**@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@ *@@@@@@@+*@@%*@@@@@@@@@@@@*%@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@%+%@@**@@@@@@@@@@@@%*@@@@@*%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@% -@@@@@*+@@@**@@@@@@@@@@@@%+@@@@@*%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@* *@@@@++@@@+*@@@@@@@@@@@@%+@@@@@**@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@% %@@%+*@@@+*@@@@@@@@@@@@%+@@@@@%+@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@+-%@@@-*@@@@@@@@@@@@%-%@@@@@**@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@- %+-****-*@@@@@@@@@@@@%+*@@@@%+-@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@% *@@@@*-+%@@@@@@@@@@@%-+%%%%%%%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@% *@@@%++************+-+@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@% .%@@@@@@% @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
+-------------------------------------------------+
| REASON |
+-------------------------------------------------+
| Abdullah Mohammed is a former owner of two dox |
| groups claiming harm and dox on little kids on |
| Roblox and Discord. Leaking info on his Discord |
| server thinking he would be safe :) |
+-------------------------------------------------+
+-------------------------------------------------+
| SUMMARY |
+-------------------------------------------------+
+-------------------------------------------------+
| Legal Name | Feross Aboukhadijeh |
| Phone | +1 916-220-6364 |
| Emails | team@konfirmasi.com |
| | awahbi289@gmail.com |
| | smadav@gmail.com |
| | emn178@gmail.com |
| | bodabe7@gmail.com |
+-------------------------------------------------+
| Online Accounts (via bodabe7@gmail.com) |
+-------------------------------------------------+
| Facebook | Registered |
| Google | Registered |
| LinkedIn | Registered |
| Microsoft | Registered |
| Pinterest | Registered |
| Spotify | Registered |
| Twitter | Registered |
| Discord | Registered |
| Adobe | Registered |
| Netflix | Registered |
| Zoho | Registered |
| Duolingo | Full name and photo available |
| Firefox | Registered |
| Replit | Registered |
+-------------------------------------------------+
| Address | 3404 Archetto Dr |
| City | El Dorado Hills |
| State | CA |
| ZIP | 95762 |
| Type | Private Street |
| USPS Valid | Confirmed |
| Home Value | $800,000 - $1,000,000+ |
| Home Details | 4 bed 3.5 bath built 2005 |
+-------------------------------------------------+
| Business Name | 3agalty Bike Shop |
| Website | 3agalty.com |
| Location | Nasr City Cairo Egypt |
| Specialties | Mountain Bike Road Cycling |
| Services | In-store Pickup Same-day |
| Payments | Cards Checks Cash |
| Hours | Mon-Sat 12PM-10PM Sun |
| Reputation | 4.6 stars on 99 reviews |
+-------------------------------------------------+
| Social Media | Twitter Registered |
| | WhatsApp Registered |
+-------------------------------------------------+
shop : https://imgur.com/a/00K42eN
house : https://imgur.com/a/BkNHSuz
=====================================================================================================================
FULL BREACH & IP REPORT
=====================================================================================================================
+---------------------------------------------+
| EMAIL: team@konfirmasi.com |
+---------------------------------------------+
| Breach Name | Speedio |
| Breach Date | December 2024 |
| What Happened | Data taken from Speedio posted for sale. Unsecured Elasticsearch instance. |
| Compromised Data| Company names, Email addresses, Phone numbers, Physical addresses |
+---------------------------------------------+
| Breach Name | Pertamina |
| Breach Date | November 2022 |
| What Happened | Breach of MyPertamina service. 44M records exposed. |
| Compromised Data| DOB, Emails, Genders, Names, Phone, Addresses, Purchases |
+---------------------------------------------+
| Breach Name | Bukalapak |
| Breach Date | March 2019 |
| What Happened | Backup breach from Oct 2017. 13M unique emails. |
| Compromised Data| Emails, IPs, Names, Passwords, Usernames |
+---------------------------------------------+
+---------------------------------------------+
| EMAIL: awahbi289@gmail.com |
+---------------------------------------------+
| Breach Name | Data Troll |
| Breach Date | June 2025 |
| What Happened | 2.7B rows of stealer logs posted. Only small portion new. |
| Compromised Data| Emails, Passwords |
| Domain | dashboard.uptimerobot.com |
| Password | AQKrYuU6X4GVKJJ |
+---------------------------------------------+
| Domain | scriptblox.com |
| Password | QScXf2GA2cQawTz |
+---------------------------------------------+
| Breach Name | Synthient |
| Breach Date | 2025 |
| What Happened | Aggregated billions of records. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | ALIEN TXTBASE |
| Breach Date | February 2025 |
| What Happened | 23B rows of stealer logs. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
+---------------------------------------------+
| EMAIL: smadav@gmail.com |
+---------------------------------------------+
| Breach Name | Synthient |
| Breach Date | 2025 |
| What Happened | Aggregated billions of records from credential lists. |
| Compromised Data| Emails, Passwords |
| Password | backspace |
+---------------------------------------------+
| Password | BESAR9&kecil1! |
+---------------------------------------------+
| Password | backface |
+---------------------------------------------+
| Password Hash | 30f33cb6890e3fbade1b7695c54823f1 |
| Salt | a039e6 |
+---------------------------------------------+
| Password Hash | 79ebf93c54bc2574b9c8f2eba92df34f6a229c766fefd4109d5e1c66f78c76e75ffa7f67a9796b85e3b4030575746b55 |
| Salt | 6F56 |
+---------------------------------------------+
| Password Hash | bd8e2e10bc92f3754f8b8137643ffc3eb59f8a90 |
+---------------------------------------------+
| Breach Name | ALIEN TXTBASE |
| Breach Date | February 2025 |
| What Happened | 23B rows from Telegram. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | Speedio |
| Breach Date | December 2024 |
| What Happened | Posted for sale. 62M records. |
| Compromised Data| Company names, Emails, Phones, Addresses |
+---------------------------------------------+
| Breach Name | Internet Archive |
| Breach Date | September 2024 |
| What Happened | 31M records exposed. |
| Compromised Data| Emails, Passwords, Usernames |
+---------------------------------------------+
| Breach Name | French Citizens |
| Breach Date | September 2024 |
| What Happened | 90M rows exposed. |
| Compromised Data| Device info, Emails, IPs, Names, CC data, Phones, Addresses |
+---------------------------------------------+
| Breach Name | Naz.API |
| Breach Date | September 2023 |
| What Happened | 100GB of stealer logs. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | Cit0day |
| Breach Date | November 2020 |
| What Happened | 23,000 breached sites. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | Gravatar |
| Breach Date | October 2020 |
| What Happened | 167M names/usernames/MD5. |
| Compromised Data| Emails, Names, Usernames |
+---------------------------------------------+
| Breach Name | Tokopedia |
| Breach Date | April 2020 |
| What Happened | 15M rows posted. Later 76M added. |
| Compromised Data| DOB, Emails, Genders, Names, Passwords |
+---------------------------------------------+
| Breach Name | Covve |
| Breach Date | February 2020 |
| What Happened | 1.2B records exposed. |
| Compromised Data| Emails, Job titles, Names, Phones, Addresses, Profiles |
+---------------------------------------------+
| Breach Name | GameSprite |
| Breach Date | December 2019 |
| What Happened | 6M emails exposed. |
| Compromised Data| Emails, IPs, Passwords, Usernames |
+---------------------------------------------+
| Breach Name | People Data Labs |
| Breach Date | October 2019 |
| What Happened | 1.2B records exposed. |
| Compromised Data| Emails, Employers, Locations, Titles, Names, Phones, Profiles |
+---------------------------------------------+
| Breach Name | Verifications.io |
| Breach Date | February 2019 |
| What Happened | 763M emails exposed. |
| Compromised Data| DOB, Emails, Employers, Genders, Locations, IPs, Titles, Names, Phones, Addresses |
+---------------------------------------------+
| Breach Name | Collection #1 |
| Breach Date | January 2019 |
| What Happened | 2.7B records. |
| Compromised Data| Emails, Passwords |
| Password | BESAR9&kecil1! |
+---------------------------------------------+
| Password | backspace |
+---------------------------------------------+
| Password | backface |
+---------------------------------------------+
| Breach Name | 2844 Breaches |
| Breach Date | February 2018 |
| What Happened | 3000 breaches found. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | Bukalapak |
| Breach Date | March 2019 |
| What Happened | 13M emails exposed. |
| Compromised Data| Emails, IPs, Names, Passwords, Usernames |
+---------------------------------------------+
| Breach Name | Onliner Spambot |
| Breach Date | August 2017 |
| What Happened | 711M emails exposed. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | SwordFantasy |
| Breach Date | January 2019 |
| What Happened | 2.7M emails exposed. |
| Compromised Data| Emails, IPs, Passwords, Usernames |
+---------------------------------------------+
| Breach Name | Exploit.In |
| Breach Date | Late 2016 |
| What Happened | 593M emails exposed. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | QuinStreet |
| Breach Date | 2015 |
| What Happened | 28 sites compromised. |
| Compromised Data| DOB, Emails, IPs, Passwords, Usernames, Activity |
+---------------------------------------------+
| Breach Name | 000webhost |
| Breach Date | 2015 |
| What Happened | 15M records exposed. |
| Compromised Data| Emails, IPs, Names, Passwords |
| Password | BESAR9&kecil1! |
+---------------------------------------------+
| Breach Name | Adobe |
| Breach Date | October 2013 |
| What Happened | 153M accounts breached. |
| Compromised Data| Emails, Hints, Passwords, Usernames |
+---------------------------------------------+
| Breach Name | Tumblr |
| Breach Date | 2013 |
| What Happened | 65M accounts exposed. |
| Compromised Data| Emails, Passwords |
| Password Hash | bd8e2e10bc92f3754f8b8137643ffc3eb59f8a90 |
+---------------------------------------------+
| Breach Name | Disqus |
| Breach Date | October 2017 |
| What Happened | 17.5M records exposed. |
| Compromised Data| Emails, Passwords, Usernames |
+---------------------------------------------+
| Breach Name | LinkedIn |
| Breach Date | May 2016 |
| What Happened | 164M emails exposed. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | Elance |
| Breach Date | 2009 |
| What Happened | 1.3M accounts exposed. |
| Compromised Data| Emails, Employers, Locations, Passwords, Phones, Usernames |
+---------------------------------------------+
+---------------------------------------------+
| EMAIL: emn178@gmail.com |
+---------------------------------------------+
| Breach Name | Data Troll |
| Breach Date | June 2025 |
| What Happened | 2.7B rows posted. |
| Compromised Data| Emails, Passwords |
| Password | 2kof0eva |
+---------------------------------------------+
| Password | emnemn |
+---------------------------------------------+
| Password | peter1101 |
+---------------------------------------------+
| Password Hash | 461bbbc3a13b289ea27e0116f4147d9e4c294a8e |
| IP Address | 221.169.119.109 |
+---------------------------------------------+
| Password Hash | $2y$10$ZU3hzpfGUeDIrX4GNVmQqeahTDkDfXt.aoRx5PVeaVVo.yjr5Qt56 |
| IP Address | 195.142.179.164 |
+---------------------------------------------+
| Password Hash | $2a$08$.EScQ9MFc2BtYDHSU/FG.ub5OkJJQgFoLGaOuI2SVfiNC7Wvvifii |
+---------------------------------------------+
| Breach Name | ALIEN TXTBASE |
| Breach Date | February 2025 |
| What Happened | 23B rows from Telegram. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | SOCRadar |
| Breach Date | August 2024 |
| What Happened | 332M emails exposed. |
| Compromised Data| Emails |
+---------------------------------------------+
| Breach Name | Telegram Channels |
| Breach Date | May 2024 |
| What Happened | 2B rows from channels. |
| Compromised Data| Emails, Passwords, Usernames |
+---------------------------------------------+
| Breach Name | Trello |
| Breach Date | January 2024 |
| What Happened | 15M emails exposed. |
| Compromised Data| Emails, Names, Usernames |
+---------------------------------------------+
| Breach Name | Naz.API |
| Breach Date | September 2023 |
| What Happened | 100GB of data exposed. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | Manipulated Caiman |
| Breach Date | July 2023 |
| What Happened | Phishing on Mexican users.|
| Compromised Data| Emails |
+---------------------------------------------+
| Breach Name | CoinMarketCap |
| Breach Date | October 2021 |
| What Happened | 3.1M emails exposed. |
| Compromised Data| Emails |
+---------------------------------------------+
| Breach Name | Twitter Scrape |
| Breach Date | 2023 |
| What Happened | 200M records scraped. |
| Compromised Data| Emails, Names, Profiles, Usernames |
+---------------------------------------------+
| Breach Name | Cit0day |
| Breach Date | November 2020 |
| What Happened | 23,000 sites breached. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | Wattpad |
| Breach Date | June 2020 |
| What Happened | 270M records exposed. |
| Compromised Data| Bios, DOB, Emails, Genders, Locations, IPs, Names, Passwords, Profiles, URLs, Usernames |
+---------------------------------------------+
| Breach Name | Collection #1 |
| Breach Date | January 2019 |
| What Happened | 2.7B records. |
| Compromised Data| Emails, Passwords |
| Password | 2kof0eva |
+---------------------------------------------+
| Password | emnemn |
+---------------------------------------------+
| Password | peter1101 |
+---------------------------------------------+
| Breach Name | Armor Games |
| Breach Date | January 2019 |
| What Happened | 10.6M emails exposed. |
| Compromised Data| Bios, DOB, Emails, Genders, Locations, IPs, Passwords, Usernames |
+---------------------------------------------+
| Breach Name | kayo.moe |
| Breach Date | September 2018 |
| What Happened | 42M emails exposed. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | Apollo |
| Breach Date | July 2018 |
| What Happened | Database exposed. |
| Compromised Data| Emails, Employers, Locations, Titles, Names, Phones, Profiles |
+---------------------------------------------+
| Breach Name | Onliner Spambot |
| Breach Date | August 2017 |
| What Happened | 711M emails exposed. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | Dailymotion |
| Breach Date | October 2016 |
| What Happened | 85M accounts exposed. |
| Compromised Data| Emails, Passwords, Usernames |
+---------------------------------------------+
| Breach Name | Exploit.In |
| Breach Date | Late 2016 |
| What Happened | 593M emails exposed. |
| Compromised Data| Emails, Passwords |
| Password | peter1101 |
+---------------------------------------------+
| Password | emnemn |
+---------------------------------------------+
| Breach Name | 000webhost |
| Breach Date | 2015 |
| What Happened | 15M records exposed. |
| Compromised Data| Emails, IPs, Names, Passwords |
| Password | 2kof0eva |
| IP Address | 210.242.250.151 |
+---------------------------------------------+
| Breach Name | BTC-E |
| Breach Date | October 2014 |
| What Happened | 568K accounts exposed. |
| Compromised Data| Balances, Emails, IPs, Passwords, Usernames, Activity |
+---------------------------------------------+
| Breach Name | Coupon Mom |
| Breach Date | 2014 |
| What Happened | 11M emails exposed. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | Yam.com |
| Breach Date | June 2013 |
| What Happened | 13M emails exposed. |
| Compromised Data| DOB, Emails, Names, Passwords, Phones, Addresses, Usernames |
+---------------------------------------------+
| Breach Name | Dropbox |
| Breach Date | 2012 |
| What Happened | 68M emails exposed. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
+---------------------------------------------+
| EMAIL: feross@feross.org |
+---------------------------------------------+
| Breach Name | Data Troll |
| Breach Date | June 2025 |
| What Happened | 2.7B rows posted. |
| Compromised Data| Emails, Passwords |
| Password Hash | d08c6798da660f528502866f1c0a2ea24ed007fe |
+---------------------------------------------+
| Password Hash | bdf92db84bc7410f3ede8027589eb35b37d16d1c |
| Salt | S34E5yM2yblo4IhHZ4Y |
+---------------------------------------------+
| Password | feross |
+---------------------------------------------+
| Breach Name | Synthient |
| Breach Date | 2025 |
| What Happened | Aggregated billions. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | ALIEN TXTBASE |
| Breach Date | February 2025 |
| What Happened | 23B rows from Telegram. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | The Post Millennial |
| Breach Date | May 2024 |
| What Happened | Defacement and data dump. |
| Compromised Data| Emails, Genders, IPs, Names, Passwords, Phones, Addresses, Usernames |
+---------------------------------------------+
| Breach Name | Aditya Birla |
| Breach Date | December 2021 |
| What Happened | 5.4M emails exposed. |
| Compromised Data| Emails, Genders, Income, Titles, Marital, Names, Passwords, Phones, Addresses, Purchases, Religions, Salutations |
+---------------------------------------------+
| Breach Name | Epik |
| Breach Date | September 2021 |
| What Happened | Massive breach. |
| Compromised Data| Emails, Names, Phones, Addresses, Purchases |
+---------------------------------------------+
| Breach Name | LinkedIn (Scraped) |
| Breach Date | 2021 |
| What Happened | 400M records scraped. |
| Compromised Data| Education, Emails, Genders, Locations, Titles, Names, Profiles |
+---------------------------------------------+
| Breach Name | Lead Hunter |
| Breach Date | March 2020 |
| What Happened | 69M emails exposed. |
| Compromised Data| Emails, Genders, IPs, Names, Phones, Addresses |
+---------------------------------------------+
| Breach Name | Covve |
| Breach Date | February 2020 |
| What Happened | 1.2B records exposed. |
| Compromised Data| Emails, Titles, Names, Phones, Addresses, Profiles |
+---------------------------------------------+
| Breach Name | People Data Labs |
| Breach Date | October 2019 |
| What Happened | 1.2B records exposed. |
| Compromised Data| Emails, Employers, Locations, Titles, Names, Phones, Profiles |
+---------------------------------------------+
| Breach Name | Verifications.io |
| Breach Date | February 2019 |
| What Happened | 763M emails exposed. |
| Compromised Data| DOB, Emails, Employers, Genders, Locations, IPs, Titles, Names, Phones, Addresses |
+---------------------------------------------+
| Breach Name | Apollo |
| Breach Date | July 2018 |
| What Happened | Database exposed. |
| Compromised Data| Emails, Employers, Locations, Titles, Names, Phones, Profiles |
+---------------------------------------------+
| Breach Name | Ticketfly |
| Breach Date | May 2018 |
| What Happened | 26M emails exposed. |
| Compromised Data| Emails, Names, Phones, Addresses |
+---------------------------------------------+
| Breach Name | AerServ |
| Breach Date | April 2018 |
| What Happened | Breach of ad platform. |
| Compromised Data| Emails, Employers, Titles, Names, Passwords, Phones, Addresses |
+---------------------------------------------+
| Breach Name | Onliner Spambot |
| Breach Date | August 2017 |
| What Happened | 711M emails exposed. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | B2B USA Businesses |
| Breach Date | Mid 2017 |
| What Happened | 105M emails exposed. |
| Compromised Data| Emails, Employers, Titles, Names, Phones, Addresses |
+---------------------------------------------+
| Breach Name | GeekedIn |
| Breach Date | August 2016 |
| What Happened | 8M records exposed. |
| Compromised Data| Emails, Locations, Names, Skills, Usernames, Experience |
+---------------------------------------------+
| Breach Name | Whitepages |
| Breach Date | Mid 2016 |
| What Happened | Breach and resale. |
| Compromised Data| Emails, Names, Passwords |
+---------------------------------------------+
| Breach Name | Special K Data Feed |
| Breach Date | Mid 2015 |
| What Happened | 31M identities exposed. |
| Compromised Data| DOB, Emails, Genders, IPs, Names, Addresses |
+---------------------------------------------+
| Breach Name | BTC-E |
| Breach Date | October 2014 |
| What Happened | 568K accounts exposed. |
| Compromised Data| Balances, Emails, IPs, Passwords, Usernames, Activity |
+---------------------------------------------+
| Breach Name | Kickstarter |
| Breach Date | February 2014 |
| What Happened | 5.2M emails exposed. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
| Breach Name | Tumblr |
| Breach Date | 2013 |
| What Happened | 65M accounts exposed. |
| Compromised Data| Emails, Passwords |
+---------------------------------------------+
+---------------------------------------------+
| IP ADDRESSES |
+---------------------------------------------+
| IP Address | Location |
+---------------------------------------------+
| 125.161.107.240 | Indonesia - Telkom |
| 14.58.47.135 | UK - Broadband DC |
| 114.59.0.88 | No query |
| 210.242.250.151 | Taiwan - Chunghwa Telecom |
| 221.169.119.109 | Taiwan - Digital United |
| 195.142.179.164 | Turkey - SOL-BNG |
| 98.248.36.96 | USA |
+---------------------------------------------+
=====================================================
+---------------------------------------------+
| FULL LINE OF BREACHES |TOTAL 59 ACROSS EMAILS|
+---------------------------------------------+
=====================================================
team@konfirmasi.com :
What Happened
In December 2024, data alleged to have been taken from the Brazilian lead generation platform Speedio was posted for sale to a popular hacking forum. The data was allegedly obtained from an unsecured Elasticsearch instance and contained over 62M records of largely public business information including company names, phone numbers and physical addresses, along with 27M unique email addresses, predominantly from public services such as Gmail and Outlook. Speedio did not respond to multiple attempts to disclose the incident, and the origin of the data could not be independently verified.
Compromised Data :
Company names
Email addresses
Phone numbers
Physical addresses
What Happened
In November 2022, the Indonesian oil and gas company Pertamina suffered a data breach of their MyPertamina service. The incident exposed 44M records with 6M unique email addresses along with names, dates of birth, genders, physical addresses and purchases.
Compromised Data :
Dates of birth
Email addresses
Genders
Names
Phone numbers
Physical addresses
Purchases
What Happened
In March 2019, the Indonesian e-commerce website Bukalapak discovered a data breach of the organisation's backups dating back to October 2017. The incident exposed approximately 13 million unique email addresses alongside IP addresses, names and passwords stored as bcrypt and salted SHA-512 hashes.
Compromised Data :
Email addresses
IP addresses
Names
Passwords
Usernames
awahbi289@gmail.com :
In June 2025, headlines erupted over a "16 billion password" breach. In reality, the dataset was a compilation of publicly accessible stealer logs, mostly repurposed from older leaks, with only a small portion of genuinely new material. HIBP received 2.7B rows containing 109M unique email addresses, which was subsequently added to the service under the name "Data Troll". The websites the stealer logs were captured against are searchable via the HIBP dashboard.
Compromised Data :
Email addresses
Passwords
During 2025, Synthient aggregated billions of records of "threat data" from various internet sources. The data contained 183M unique email addresses alongside the websites they were entered into and the passwords used. After normalising and deduplicating the data, 183 million unique email addresses remained, each linked to the website where the credentials were captured, and the password used. This dataset is now searchable in HIBP by email address, password, domain, and the site on which the credentials were entered.
Compromised Data :
Email addresses
Passwords
During 2025, the threat-intelligence firm Synthient aggregated 2 billion unique email addresses disclosed in credential-stuffing lists found across multiple malicious internet sources. Comprised of email addresses and passwords from previous data breaches, these lists are used by attackers to compromise other, unrelated accounts of victims who have reused their passwords. The data also included 1.3 billion unique passwords, which are now searchable in Pwned Passwords. Working to turn breached data into awareness, Synthient partnered with HIBP to help victims of cybercrime understand their exposure.
Compromised Data :
Email addresses
Passwords
LIEN TXTBASE Stealer Logs Data Breach
StealerLogs Breach
What Happened
In February 2025, 23 billion rows of stealer logs were obtained from a Telegram channel known as ALIEN TXTBASE. The data contained 284M unique email addresses alongside the websites they were entered into and the passwords used. This data is now searchable in HIBP by both email domain and the domain of the target website.
Compromised Data :
Email addresses
Passwords
Intelligence Data
Domain:
dashboard.uptimerobot.com
Email:
awahbi289@gmail.com
Password:
AQKrYuU6X4GVKJJ
Domain:
dashboard.uptimerobot.com/sign-up
Email:
awahbi289@gmail.com
Password:
AQKrYuU6X4GVKJJ
Domain:
dashboard.uptimerobot.com/sign-up
Email:
awahbi289@gmail.com
Password:
AQKrYuU6X4GVKJJ
Domain:
scriptblox.com
Email:
awahbi289@gmail.com
Password:
QScXf2GA2cQawTz
Domain:
scriptblox.com
Email:
awahbi289@gmail.com
Password:
QScXf2GA2cQawTz
Domain:
scriptblox.com
Email:
awahbi289@gmail.com
Password:
QScXf2GA2cQawTz
Domain:
scriptblox.com/signup
Email:
awahbi289@gmail.com
Password:
QScXf2GA2cQawTz
smadav@gmail.com :
During 2025, the threat-intelligence firm Synthient aggregated 2 billion unique email addresses disclosed in credential-stuffing lists found across multiple malicious internet sources. Comprised of email addresses and passwords from previous data breaches, these lists are used by attackers to compromise other, unrelated accounts of victims who have reused their passwords. The data also included 1.3 billion unique passwords, which are now searchable in Pwned Passwords. Working to turn breached data into awareness, Synthient partnered with HIBP to help victims of cybercrime understand their exposure.
Compromised Data :
Email addresses
Passwords
In February 2025, 23 billion rows of stealer logs were obtained from a Telegram channel known as ALIEN TXTBASE. The data contained 284M unique email addresses alongside the websites they were entered into and the passwords used. This data is now searchable in HIBP by both email domain and the domain of the target website.
Compromised Data:
Email addresses
Passwords
What Happened
In December 2024, data alleged to have been taken from the Brazilian lead generation platform Speedio was posted for sale to a popular hacking forum. The data was allegedly obtained from an unsecured Elasticsearch instance and contained over 62M records of largely public business information including company names, phone numbers and physical addresses, along with 27M unique email addresses, predominantly from public services such as Gmail and Outlook. Speedio did not respond to multiple attempts to disclose the incident, and the origin of the data could not be independently verified.
Compromised Data:
Company names
Email addresses
Phone numbers
Physical addresses
What Happened
In September 2024, the digital library of internet sites Internet Archive suffered a data breach that exposed 31M records. The breach exposed user records including email addresses, screen names and bcrypt password hashes.
Compromised Data:
Email addresses
Passwords
Usernames
What Happened
In September 2024, over 90M rows of data on French Citizens was found left exposed in a publicly facing database. Compiled from various data breaches, the corpus contained 28M unique email addresses with the various source breaches each exposing different fields including name, physical and IP address, phone number and partial credit card data including payment type and last 4 digits.
Compromised Data:
Device information
Email addresses
IP addresses
Names
Partial credit card data
Phone numbers
Physical addresses
What Happened
In September 2023, over 100GB of stealer logs and credential stuffing lists titled "Naz.API" was posted to a popular hacking forum. The incident contained a combination of email address and plain text password pairs alongside the service they were entered into, and standalone credential pairs obtained from unnamed sources. In total, the corpus of data included 71M unique email addresses and 100M unique passwords.
Compromised Data:
Email addresses
Passwords
Cit0day
In November 2020, a collection of more than 23,000 allegedly breached websites known as Cit0day were made available for download on several hacking forums. The data consisted of 226M unique email address alongside password pairs, often represented as both password hashes and the cracked, plain text versions. Independent verification of the data established it contains many legitimate, previously undisclosed breaches. The data was provided to HIBP by dehashed.com.
Compromised data:
Email addresses
Passwords
In October 2020, a security researcher published a technique for scraping large volumes of data from Gravatar, the service for providing globally unique avatars . 167 million names, usernames and MD5 hashes of email addresses used to reference users' avatars were subsequently scraped and distributed within the hacking community. 114 million of the MD5 hashes were cracked and distributed alongside the source hash, thus disclosing the original email address and accompanying data. Following the impacted email addresses being searchable in HIBP, Gravatar release an FAQ detailing the incident.
Compromised data:
Email addresses
Names
Usernames
In April 2020, Indonesia's largest online store Tokopedia suffered a data breach. The incident resulted in 15M rows of data being posted to a popular hacking forum. An additional 76M rows were later provided to HIBP in July 2020. In total, the data included over 71M unique email addresses alongside names, genders, birth dates and passwords stored as SHA2-384 hashes.
Compromised data:
Dates of birth
Email addresses
Genders
Names
Passwords
In February 2020, a massive trove of personal information referred to as "db8151dd" was provided to HIBP after being found left exposed on a publicly facing Elasticsearch server. Later identified as originating from the Covve contacts app, the exposed data included extensive personal information and interactions between Covve users and their contacts. The data was provided to HIBP by dehashed.com.
Compromised data:
Email addresses
Job titles
Names
Phone numbers
Physical addresses
Social media profiles
In December 2019, the now defunct gaming platform GameSprite suffered a data breach that exposed over 6M unique email addresses. The impacted data also included usernames, IP addresses and salted MD5 password hashes.
Compromised data:
Email addresses
IP addresses
Passwords
Usernames
Data Enrichment Exposure From PDL Customer
In October 2019, security researchers Vinny Troia and Bob Diachenko identified an unprotected Elasticsearch server holding 1.2 billion records of personal data. The exposed data included an index indicating it was sourced from data enrichment company People Data Labs (PDL) and contained 622 million unique email addresses. The server was not owned by PDL and it's believed a customer failed to properly secure the database. Exposed information included email addresses, phone numbers, social media profiles and job history data.
Compromised data:
Email addresses
Employers
Geographic locations
Job titles
Names
Phone numbers
Social media profiles
Verifications.io
In February 2019, the email address validation service verifications.io suffered a data breach. Discovered by Bob Diachenko and Vinny Troia, the breach was due to the data being stored in a MongoDB instance left publicly facing without a password and resulted in 763 million unique email addresses being exposed. Many records within the data also included additional personal attributes such as names, phone numbers, IP addresses, dates of birth and genders. No passwords were included in the data. The Verifications.io website went offline during the disclosure process, although an archived copy remains viewable.
Compromised data:
Dates of birth
Email addresses
Employers
Genders
Geographic locations
IP addresses
Job titles
Names
Phone numbers
Physical addresses
In January 2019, a large collection of credential stuffing lists (combinations of email addresses and passwords used to hijack accounts on other services) was discovered being distributed on a popular hacking forum. The data contained almost 2.7 billion records including 773 million unique email addresses alongside passwords those addresses had used on other breached services. Full details on the incident and how to search the breached passwords are provided in the blog post The 773 Million Record "Collection #1" Data Breach.
Compromised data:
Email addresses
Passwords
2,844 Separate Data Breaches
In February 2018, a massive collection of almost 3,000 alleged data breaches was found online. Whilst some of the data had previously been seen in Have I Been Pwned, 2,844 of the files consisting of more than 80 million unique email addresses had not previously been seen. Each file contained both an email address and plain text password and were consequently loaded as a single "unverified" data breach.
Compromised data:
Email addresses
Passwords
In March 2019, the Indonesian e-commerce website Bukalapak discovered a data breach of the organisation's backups dating back to October 2017. The incident exposed approximately 13 million unique email addresses alongside IP addresses, names and passwords stored as bcrypt and salted SHA-512 hashes.
Compromised data:
Email addresses
IP addresses
Names
Passwords
Usernames
In August 2017, a spambot by the name of Onliner Spambot was identified by security researcher Benkow moÊžuÆŽq. The malicious software contained a server-based component located on an IP address in the Netherlands which exposed a large number of files containing personal information. In total, there were 711 million unique email addresses, many of which were also accompanied by corresponding passwords. A full write-up on what data was found is in the blog post titled Inside the Massive 711 Million Record Onliner Spambot Dump.
Compromised data:
Email addresses
Passwords
In January 2019, the now defunct MMO and RPG game SwordFantasy suffered a data breach that exposed 2.7M unique email addresses. Other impacted data included username, IP address and salted MD5 password hashes.
Compromised data:
Email addresses
IP addresses
Passwords
Usernames
In late 2016, a huge list of email address and password pairs appeared in a "combo list" referred to as "Exploit.In". The list contained 593 million unique email addresses, many with multiple different passwords hacked from various online systems. The list was broadly circulated and used for "credential stuffing", that is attackers employ it in an attempt to identify other online systems where the account owner had reused their password. For detailed background on this incident, read Password reuse, credential stuffing and another billion records in Have I Been Pwned.
Compromised data:
Email addresses
Passwords
In approximately late 2015, the maker of "performance marketing products" QuinStreet had a number of their online assets compromised. The attack impacted 28 separate sites, predominantly technology forums such as flashkit.com, codeguru.com and webdeveloper.com (view a full list of sites). QuinStreet advised that impacted users have been notified and passwords reset. The data contained details on over 4.9 million people and included email addresses, dates of birth and salted MD5 hashes.
Compromised data:
Dates of birth
Email addresses
IP addresses
Passwords
Usernames
Website activity
In approximately March 2015, the free web hosting provider 000webhost suffered a major data breach that exposed almost 15 million customer records. The data was sold and traded before 000webhost was alerted in October. The breach included names, email addresses and plain text passwords.
Compromised data:
Email addresses
IP addresses
Names
Passwords
ott
2013
Adobe Logo
Adobe
In October 2013, 153 million Adobe accounts were breached with each containing an internal ID, username, email, encrypted password and a password hint in plain text. The password cryptography was poorly done and many were quickly resolved back to plain text. The unencrypted hints also disclosed much about the passwords adding further to the risk that hundreds of millions of Adobe customers already faced.
Compromised data:
Email addresses
Password hints
Passwords
Usernames
tumblr
In early 2013, tumblr suffered a data breach which resulted in the exposure of over 65 million accounts. The data was later put up for sale on a dark market website and included email addresses and passwords stored as salted SHA1 hashes.
Compromised data:
Email addresses
Passwords
Disqus
In October 2017, the blog commenting service Disqus announced they'd suffered a data breach. The breach dated back to July 2012 but wasn't identified until years later when the data finally surfaced. The breach contained over 17.5 million unique email addresses and usernames. Users who created logins on Disqus had salted SHA1 hashes of passwords whilst users who logged in via social providers only had references to those accounts.
Compromised data:
Email addresses
Passwords
Usernames
LinkedIn
In May 2016, LinkedIn had 164 million email addresses and passwords exposed. Originally hacked in 2012, the data remained out of sight until being offered for sale on a dark market site 4 years later. The passwords in the breach were stored as SHA1 hashes without salt, the vast majority of which were quickly cracked in the days following the release of the data.
Compromised data:
Email addresses
Passwords
gen
2009
Elance Logo
Elance
Sometime in 2009, staffing platform Elance suffered a data breach that impacted 1.3 million accounts. Appearing online 8 years later, the data contained usernames, email addresses, phone numbers and SHA1 hashes of passwords, amongst other personal data.
Compromised data:
Email addresses
Employers
Geographic locations
Passwords
Phone numbers
Usernames
Intelligence Data
Email:
smadav@gmail.com
Domain:
gmail.com
Username:
smadav312
Email:
smadav@gmail.com
Lastip:
125.161.107.240
Password Hash:
30f33cb6890e3fbade1b7695c54823f1
Salt:
a039e6
Domain:
gmail.com
Uid:
1185937
Created:
1471956298
Email:
smadav@gmail.com
Password Hash:
79ebf93c54bc2574b9c8f2eba92df34f6a229c766fefd4109d5e1c66f78c76e75ffa7f67a9796b85e3b4030575746b55
Salt:
6F56
Name:
Smadav
Domain:
gmail.com
Email:
smadav@gmail.com
Password Hash:
bd8e2e10bc92f3754f8b8137643ffc3eb59f8a90
Domain:
gmail.com
Email:
smadav@gmail.com
Password:
backspace
Domain:
gmail.com
ntelligence Data
Label:
VERIFICATIONS IO 789M MARKETING 022019
Date:
02/20/19
Email:
smadav@gmail.com
Domain:
gmail.com
Label:
GAMESPRITE ME 7M GAMING 122019
Date:
12/20/19
Username:
smadav312
Email:
smadav@gmail.com
Lastip:
125.161.107.240
Password Hash:
30f33cb6890e3fbade1b7695c54823f1
Salt:
a039e6
Domain:
gmail.com
Uid:
1185937
Created:
1471956298
Label:
TOKOPEDIA COM 71M SHOPPING 042020
Date:
04/20/20
Email:
smadav@gmail.com
Password Hash:
79ebf93c54bc2574b9c8f2eba92df34f6a229c766fefd4109d5e1c66f78c76e75ffa7f67a9796b85e3b4030575746b55
Salt:
6F56
Name:
Smadav
Domain:
gmail.com
Label:
TUMBLR COM 73M SOCIAL 2013
Date:
2013
Email:
smadav@gmail.com
Password Hash:
bd8e2e10bc92f3754f8b8137643ffc3eb59f8a90
Domain:
gmail.com
Label:
PEMIBLANC COM 134M COMBOLIST 2018
Date:
2018
Email:
smadav@gmail.com
Password:
backspace
Domain:
gmail.com
Intelligence Data
Source:
Collection #1
Categories:
combolist
Breach Date:
2019-01-01T00:00:00Z
Email:
smadav@gmail.com
Password:
BESAR9&kecil1!
Domain:
gmail.com
Source:
Collection #1
Categories:
combolist
Breach Date:
2019-01-01T00:00:00Z
Email:
smadav@gmail.com
Password:
fairesahand
Domain:
gmail.com
Source:
swordfantasy.com
Categories:
gaming
Uid:
1185937
Username:
smadav312
Password:
30f33cb6890e3fbade1b7695c54823f1
Email:
smadav@gmail.com
Salt:
a039e6
IP Address:
125.161.107.240
Domain:
gmail.com
Source:
Collection #1
Categories:
combolist
Breach Date:
2019-01-01T00:00:00Z
Email:
smadav@gmail.com
Password:
backspace
Domain:
gmail.com
Source:
Collection #1
Categories:
combolist
Breach Date:
2019-01-01T00:00:00Z
Email:
smadav@gmail.com
Password:
backface
Domain:
gmail.com
Intelligence Data
Origin:
tumblr.com
Email:
smadav@gmail.com
Password:
bd8e2e10bc92f3754f8b8137643ffc3eb59f8a90
Origin:
000webhost
Name:
Zainuddin Nafarin
Email:
smadav@gmail.com
IP Address:
114.59.0.88
Password:
BESAR9&kecil1!
Origin:
adobe.com
Email:
smadav@gmail.com
Password:
1234567890
Origin:
collection_1
Password:
BESAR9&kecil1!
Email:
smadav@gmail.com
Origin:
comb1
Email:
smadav@gmail.com
Password:
BESAR9&kecil1!
Intelligence Data
Name:
000webhost.com
Date:
2015-02
Email:
smadav@gmail.com
Password:
BESAR9&kecil1!
IP Address:
114.59.0.88
Name:
antipublic
Email:
smadav@gmail.com
Password:
backspace
Name:
antipublic
Email:
smadav@gmail.com
Password:
BESAR9&kecil1!
Name:
cit0day
Date:
2020-10
Email:
smadav@gmail.com
Password:
backface
Name:
collection-1
Email:
smadav@gmail.com
Password:
BESAR9&kecil1!
125.161.107.240
Map
🇮🇩
Ujung Menteng, Jakarta, Indonesia
PT. TELKOM INDONESIA
ASAS7713
VPN/Proxy: No
DC: No
Mobile: No
14.58.47.135
Map
🇬🇧
London, England, United Kingdom
Broadband Customer Of IndosatM2
ASAS16509
VPN/Proxy: No
DC: Yes
Mobile: No
114.59.0.88
no query founded
Intelligence Data
Source:
3.9M (TWITTER - NETFLIX - FACEBOOK)
Email:
smadav@gmail.com
emn178@gmail.com
In June 2025, headlines erupted over a "16 billion password" breach. In reality, the dataset was a compilation of publicly accessible stealer logs, mostly repurposed from older leaks, with only a small portion of genuinely new material. HIBP received 2.7B rows containing 109M unique email addresses, which was subsequently added to the service under the name "Data Troll". The websites the stealer logs were captured against are searchable via the HIBP dashboard.
Compromised data:
Email addresses
Passwords
During 2025, the threat-intelligence firm Synthient aggregated 2 billion unique email addresses disclosed in credential-stuffing lists found across multiple malicious internet sources. Comprised of email addresses and passwords from previous data breaches, these lists are used by attackers to compromise other, unrelated accounts of victims who have reused their passwords. The data also included 1.3 billion unique passwords, which are now searchable in Pwned Passwords. Working to turn breached data into awareness, Synthient partnered with HIBP to help victims of cybercrime understand their exposure.
Compromised data:
Email addresses
Passwords
ALIEN TXTBASE Stealer Logs
In February 2025, 23 billion rows of stealer logs were obtained from a Telegram channel known as ALIEN TXTBASE. The data contained 284M unique email addresses alongside the websites they were entered into and the passwords used. This data is now searchable in HIBP by both email domain and the domain of the target website.
Compromised data:
Email addresses
Passwords
In August 2024, over 332M rows of email addresses were posted to a popular hacking forum. The post alleged the addresses were scraped from cybersecurity firm SOCRadar, however an investigation on their behalf concluded that "the actor merely utilised functionalities inherent in the platform's standard offerings, designed to gather information from publicly available sources". There is no suggestion the incident compromised SOCRadar's security or posed any risk to their customers. In total, the data set contained 282M unique addresses of valid email address format.
Compromised data:
Email addresses
In May 2024, 2B rows of data with 361M unique email addresses were collated from malicious Telegram channels. The data contained 122GB across 1.7k files with email addresses, usernames, passwords and in many cases, the website they were entered into. The data appears to have been sourced from a combination of existing combolists and info stealer malware.
Compromised data:
Email addresses
Passwords
Usernames
In January 2024, data was scraped from Trello and posted for sale on a popular hacking forum. Containing over 15M email addresses, names and usernames, the data was obtained by enumerating a publicly accessible resource using email addresses from previous breach corpuses. Trello advised that no unauthorised access had occurred.
Compromised data:
Email addresses
Names
Usernames
In September 2023, over 100GB of stealer logs and credential stuffing lists titled "Naz.API" was posted to a popular hacking forum. The incident contained a combination of email address and plain text password pairs alongside the service they were entered into, and standalone credential pairs obtained from unnamed sources. In total, the corpus of data included 71M unique email addresses and 100M unique passwords.
Compromised data:
Email addresses
Passwords
In July 2023, Perception Point reported on a phishing operation dubbed "Manipulated Caiman". Targeting primarily the citizens of Mexico, the campaign attempted to gain access to victims' bank accounts via spear phishing attacks using malicious attachments. Researchers obtained almost 40M email addresses targeted in the campaign and provided the data to HIBP to alert potential victims.
Compromised data:
Email addresses
During October 2021, 3.1 million email addresses with accounts on the cryptocurrency market capitalisation website CoinMarketCap were discovered being traded on hacking forums. Whilst the email addresses were found to correlate with CoinMarketCap accounts, it's unclear precisely how they were obtained. CoinMarketCap has provided the following statement on the data: "CoinMarketCap has become aware that batches of data have shown up online purporting to be a list of user accounts. While the data lists we have seen are only email addresses (no passwords), we have found a correlation with our subscriber base. We have not found any evidence of a data leak from our own servers — we are actively investigating this issue and will update our subscribers as soon as we have any new information."
Compromised data:
Email addresses
In early 2023, over 200M records scraped from Twitter appeared on a popular hacking forum. The data was obtained sometime in 2021 by abusing an API that enabled email addresses to be resolved to Twitter profiles. The subsequent results were then composed into a corpus of data containing email addresses alongside public Twitter profile information including names, usernames and follower counts.
Compromised data:
Email addresses
Names
Social media profiles
Usernames
In November 2020, a collection of more than 23,000 allegedly breached websites known as Cit0day were made available for download on several hacking forums. The data consisted of 226M unique email address alongside password pairs, often represented as both password hashes and the cracked, plain text versions. Independent verification of the data established it contains many legitimate, previously undisclosed breaches. The data was provided to HIBP by dehashed.com.
Compromised data:
Email addresses
Passwords
In June 2020, the user-generated stories website Wattpad suffered a huge data breach that exposed almost 270 million records. The data was initially sold then published on a public hacking forum where it was broadly shared. The incident exposed extensive personal information including names and usernames, email and IP addresses, genders, birth dates and passwords stored as bcrypt hashes.
Compromised data:
Bios
Dates of birth
Email addresses
Genders
Geographic locations
IP addresses
Names
Passwords
Social media profiles
User website URLs
Usernames
In January 2019, a large collection of credential stuffing lists (combinations of email addresses and passwords used to hijack accounts on other services) was discovered being distributed on a popular hacking forum. The data contained almost 2.7 billion records including 773 million unique email addresses alongside passwords those addresses had used on other breached services. Full details on the incident and how to search the breached passwords are provided in the blog post The 773 Million Record "Collection #1" Data Breach.
Compromised data:
Email addresses
Passwords
In January 2019, the game portal website Armor Games suffered a data breach. A total of 10.6 million email addresses were impacted by the breach which also exposed usernames, IP addresses, birthdays of administrator accounts and passwords stored as salted SHA-1 hashes.
Compromised data:
Bios
Dates of birth
Email addresses
Genders
Geographic locations
IP addresses
Passwords
Usernames
In September 2018, a collection of almost 42 million email address and plain text password pairs was uploaded to the anonymous file sharing service kayo.moe. The operator of the service contacted HIBP to report the data which, upon further investigation, turned out to be a large credential stuffing list. For more information, read about The 42M Record kayo.moe Credential Stuffing Data.
Compromised data:
Email addresses
Passwords
In July 2018, the sales engagement startup Apollo left a database containing billions of data points publicly exposed without a password. The data was discovered by security researcher Vinny Troia who subsequently sent a subset of the data containing 126 million unique email addresses to Have I Been Pwned. The data left exposed by Apollo was used in their "revenue acceleration platform" and included personal information such as names and email addresses as well as professional information including places of employment, the roles people hold and where they're located. Apollo stressed that the exposed data did not include sensitive information such as passwords, social security numbers or financial data. The Apollo website has a contact form for those looking to get in touch with the organisation.
Compromised data:
Email addresses
Employers
Geographic locations
Job titles
Names
Phone numbers
Salutations
Social media profiles
In August 2017, a spambot by the name of Onliner Spambot was identified by security researcher Benkow moÊžuÆŽq. The malicious software contained a server-based component located on an IP address in the Netherlands which exposed a large number of files containing personal information. In total, there were 711 million unique email addresses, many of which were also accompanied by corresponding passwords. A full write-up on what data was found is in the blog post titled Inside the Massive 711 Million Record Onliner Spambot Dump.
Compromised data:
Email addresses
Passwords
In October 2016, the video sharing platform Dailymotion suffered a data breach. The attack led to the exposure of more than 85 million user accounts and included email addresses, usernames and bcrypt hashes of passwords.
Compromised data:
Email addresses
Passwords
Usernames
In late 2016, a huge list of email address and password pairs appeared in a "combo list" referred to as "Exploit.In". The list contained 593 million unique email addresses, many with multiple different passwords hacked from various online systems. The list was broadly circulated and used for "credential stuffing", that is attackers employ it in an attempt to identify other online systems where the account owner had reused their password. For detailed background on this incident, read Password reuse, credential stuffing and another billion records in Have I Been Pwned.
Compromised data:
Email addresses
Passwords
In approximately March 2015, the free web hosting provider 000webhost suffered a major data breach that exposed almost 15 million customer records. The data was sold and traded before 000webhost was alerted in October. The breach included names, email addresses and plain text passwords.
Compromised data:
Email addresses
IP addresses
Names
Passwords
In October 2014, the Bitcoin exchange BTC-E was hacked and 568k accounts were exposed. The data included email and IP addresses, wallet balances and hashed passwords.
Compromised data:
Account balances
Email addresses
IP addresses
Passwords
Usernames
Website activity
In 2014, a file allegedly containing data hacked from Coupon Mom was created and included 11 million email addresses and plain text passwords. On further investigation, the file was also found to contain data indicating it had been sourced from Armor Games. Subsequent verification with HIBP subscribers confirmed the passwords had previously been used and many subscribers had used either Coupon Mom or Armor Games in the past. On disclosure to both organisations, each found that the data did not represent their entire customer base and possibly includes records from other sources with common subscribers. The breach has subsequently been flagged as "unverified" as the source cannot be emphatically proven. In July 2020, the data was also found to contain BeerAdvocate accounts sourced from a previously unknown breach.
Compromised data:
Email addresses
Passwords
In June 2013, the Taiwanese website Yam.com suffered a data breach which was shared to a popular hacking forum in 2021. The data included 13 million unique email addresses alongside names, usernames, phone numbers, physical addresses, dates of birth and unsalted MD5 password hashes.
Compromised data:
Dates of birth
Email addresses
Names
Passwords
Phone numbers
Physical addresses
Usernames
l
In mid-2012, Dropbox suffered a data breach which exposed the stored credentials of tens of millions of their customers. In August 2016, they forced password resets for customers they believed may be at risk. A large volume of data totalling over 68 million records was subsequently traded online and included email addresses and salted hashes of passwords (half of them SHA1, half of them bcrypt).
Compromised data:
Email addresses
Passwords
Local Database
Email:
emn178@gmail.com
Username:
emn178
Password:
2kof0eva
IP Address:
210.242.250.151
Domain:
gmail.com
Email:
emn178@gmail.com
Username:
emn178
Password:
2kof0eva
IP Address:
210.242.250.151
Domain:
gmail.com
Intelligence Data
Username:
emn178
Email:
emn178@gmail.com
Name:
Emn178
Domain:
gmail.com
Id:
51b9ac0a00791e2f3f0031aa
Website:
https://trello.com/emn178
Username:
emn178
Email:
emn178@gmail.com
Name:
Emn178
Domain:
gmail.com
Id:
51b9ac0a00791e2f3f0031aa
Website:
https://trello.com/emn178
Email:
emn178@gmail.com
Password:
emnemn
Domain:
gmail.com
Email:
emn178@gmail.com
Domain:
gmail.com
Email:
emn178@gmail.com
Name:
Yi-Cyuan Chen
Domain:
gmail.com
Phone Number:
+10933388614
Country:
Taiwan
Company:
None_5828
Username:
emn178
Email:
emn178@gmail.com
Lastip:
221.169.119.109
Password Hash:
461bbbc3a13b289ea27e0116f4147d9e4c294a8e
Domain:
gmail.com
Id:
2610123
Uid:
9fae830eaac7eca3fa23e14c1e9b4cad
Created:
1321109163
Updated:
1321109163
Birthdate:
0000-00-00
Username:
g7fy7rxt6t7f
Email:
emn178@gmail.com
Lastip:
195.142.179.164
Password Hash:
$2y$10$ZU3hzpfGUeDIrX4GNVmQqeahTDkDfXt.aoRx5PVeaVVo.yjr5Qt56
Domain:
gmail.com
Created:
2016-07-28 11:18:26
Updated:
2016-07-28 11:18:26
Birthdate:
0000-00-00
Country:
TR
Email:
emn178@gmail.com
Password Hash:
$2a$08$.EScQ9MFc2BtYDHSU/FG.ub5OkJJQgFoLGaOuI2SVfiNC7Wvvifii
Domain:
gmail.com
Email:
emn178@gmail.com
Password:
2kof0eva
Domain:
gmail.com
Email:
emn178@gmail.com
Password:
peter1101
Domain:
gmail.com
Username:
emn178
Email:
emn178@gmail.com
Lastip:
122.146.59.233
Password Hash:
4096$12$4$mYeYZvi&a%h6bqFr$cfbfa4e9d71dd0361ac4625bbd432315388c30655ff81cc1d6c17bc791c344e7
Domain:
gmail.com
Uid:
86258
Created:
1366758826
Language:
en
Email:
emn178@gmail.com
Password:
emnemn
Domain:
gmail.com
Username:
emn178
Email:
emn178@gmail.com
Lastip:
210.242.250.151
Password:
2kof0eva
Domain:
gmail.com
Email:
emn178@gmail.com
Password:
2kof0eva
Domain:
gmail.com
Email:
emn178@gmail.com
Password:
peter1101
Domain:
gmail.com
Username:
dm_521e9608f298c
Email:
emn178@gmail.com
Domain:
gmail.com
Intelligence Data
Source:
coinmarketcap.com
Categories:
cryptocurrency, finance
Email:
emn178@gmail.com
Domain:
gmail.com
Source:
twitter.com
Categories:
social
Email:
emn178@gmail.com
Name:
Yi-Cyuan
Username:
emn178
Created:
Thu Nov 05 23:54:42 +0000 2015
Domain:
gmail.com
Source:
Collection #1
Categories:
combolist
Breach Date:
2019-01-01T00:00:00Z
Email:
emn178@gmail.com
Password:
b5ee607f867744fde859bbddc6d0918d
Domain:
gmail.com
Source:
Exploit.in
Categories:
combolist
Breach Date:
2016-10-01T00:00:00Z
Email:
emn178@gmail.com
Password:
emnemn
Domain:
gmail.com
Source:
trello.com
Categories:
social
Email:
emn178@gmail.com
Website:
https://trello.com/emn178
Username:
emn178
Name:
Emn178
Domain:
gmail.com
Source:
dropbox.com
Categories:
media
Email:
emn178@gmail.com
Password:
$2a$08$.EScQ9MFc2BtYDHSU/FG.ub5OkJJQgFoLGaOuI2SVfiNC7Wvvifii
Domain:
gmail.com
Source:
armorgames.com
Categories:
gaming
Id:
2610123
Uid:
9fae830eaac7eca3fa23e14c1e9b4cad
Username:
emn178
Email:
emn178@gmail.com
Password:
461bbbc3a13b289ea27e0116f4147d9e4c294a8e
Avatar:
422
Date of Birth:
0000-00-00
Created On:
1321109163
Updated On:
1321109163
Chat:
1
Active:
1
Comment Notify:
Y
Comments:
Y
Merit Notify:
Y
Role:
user
IP Address:
221.169.119.109
Domain:
gmail.com
Source:
trello.com
Categories:
social
Email:
emn178@gmail.com
Website:
https://trello.com/emn178
Username:
emn178
Name:
Emn178
Domain:
gmail.com
Source:
000webhost.com
Categories:
hosting
Name:
emn178
Email:
emn178@gmail.com
IP Address:
210.242.250.151
Password:
2kof0eva
Domain:
gmail.com
Source:
Exploit.in
Categories:
combolist
Breach Date:
2016-10-01T00:00:00Z
Email:
emn178@gmail.com
Password:
peter1101
Domain:
gmail.com
Source:
combos.vip
Categories:
combos
Email:
emn178@gmail.com
Pass Plain:
emnemn
Domain:
gmail.com
Source:
Wattpad
Categories:
social, media, art
Id:
110684272
Username:
g7fy7rxt6t7f
Password:
$2y$10$ZU3hzpfGUeDIrX4GNVmQqeahTDkDfXt.aoRx5PVeaVVo.yjr5Qt56
Email:
emn178@gmail.com
Createdate:
2016-07-28 09:18:26
Modifydate:
2016-07-28 09:18:26
IP Address:
195.142.179.164
Logindate:
2016-07-28 16:18:26
Country:
TR
Language:
23
Dateofbirth:
0000-00-00
Domain:
gmail.com
Source:
Collection #1
Categories:
combolist
Breach Date:
2019-01-01T00:00:00Z
Email:
emn178@gmail.com
Password:
2kof0eva
Domain:
gmail.com
Source:
Collection #1
Categories:
combolist
Breach Date:
2019-01-01T00:00:00Z
Email:
emn178@gmail.com
Password:
emn178
Domain:
gmail.com
Source:
dailymotion.com
Categories:
media
Username:
dm_521e9608f298c
Email:
emn178@gmail.com
Domain:
gmail.com
Source:
Collection #1
Categories:
combolist
Breach Date:
2019-01-01T00:00:00Z
Email:
emn178@gmail.com
Password:
peter1101
Domain:
gmail.com
Source:
Collection #1
Categories:
combolist
Breach Date:
2019-01-01T00:00:00Z
Email:
emn178@gmail.com
Password:
emnemn
Domain:
gmail.com
Intelligence Data
Origin:
000webhost
Name:
emn178
Email:
emn178@gmail.com
IP Address:
210.242.250.151
Password:
2kof0eva
Origin:
twitter_scrape
Name:
Yi-Cyuan
Username:
emn178
Email:
emn178@gmail.com
Origin:
collection_1
Email:
emn178@gmail.com
Password:
2kof0eva
Origin:
collection_1
Email:
emn178@gmail.com
Password:
emn178
Origin:
collection_2
Email:
emn178@gmail.com
Password:
2kof0eva
Origin:
collection_2
Email:
emn178@gmail.com
Password:
peter1101
Origin:
collection_1
Password:
emnemn
Email:
emn178@gmail.com
Origin:
collection_1
Email:
emn178@gmail.com
Password:
peter1101
Origin:
collection_1
Password:
peter1101
Email:
emn178@gmail.com
Origin:
comb2
Password:
2kof0eva
Email:
emn178@gmail.com
Origin:
comb2
Password:
emn178
Email:
emn178@gmail.com
Origin:
comb2
Password:
emnemn
Email:
emn178@gmail.com
Origin:
comb2
Password:
peter1101
Email:
emn178@gmail.com
Origin:
collection_1
Email:
emn178@gmail.com
Password:
peter1101
Origin:
collection_1
Email:
emn178@gmail.com
Password:
2kof0eva
Origin:
collection_1
Email:
emn178@gmail.com
Password:
peter1101
Origin:
collection_1
Email:
emn178@gmail.com
Password:
2kof0eva
Origin:
collection_1
Email:
emn178@gmail.com
Password:
peter1101
Origin:
collection_1
Email:
emn178@gmail.com
Password:
2kof0eva
Origin:
collection_1
Email:
emn178@gmail.com
Password:
peter1101
Origin:
collection_1
Email:
emn178@gmail.com
Password:
2kof0eva
Origin:
collection_1
Email:
emn178@gmail.com
Password:
2kof0eva
Origin:
collection_1
Email:
emn178@gmail.com
Password:
2kof0eva
Origin:
collection_1
Email:
emn178@gmail.com
Password:
peter1101
Origin:
collection_1
Email:
emn178@gmail.com
Password:
peter1101
Origin:
collection_1
Email:
emn178@gmail.com
Password:
2kof0eva
Origin:
collection_1
Email:
emn178@gmail.com
Password:
2kof0eva
Origin:
collection_1
Email:
emn178@gmail.com
Password:
peter1101
Origin:
collection_1
Email:
emn178@gmail.com
Password:
peter1101
Origin:
collection_1
Email:
emn178@gmail.com
Password:
2kof0eva
Origin:
collection_1
Email:
emn178@gmail.com
Password:
2kof0eva
Origin:
collection_1
Email:
emn178@gmail.com
Password:
peter1101
Origin:
collection_1
Email:
emn178@gmail.com
Password:
peter1101
Origin:
collection_1
Email:
emn178@gmail.com
Password:
2kof0eva
Origin:
collection_1
Email:
emn178@gmail.com
Password:
2kof0eva
Origin:
collection_1
Password:
2kof0eva
Email:
emn178@gmail.com
Origin:
collection_1
Email:
emn178@gmail.com
Password:
4096$12$4$mYeYZvi&a%h6bqFr$cfbfa4e9d71dd0361ac4625bbd432315388c30655ff81cc1d6c17bc791c344e7
Origin:
collection_1
Email:
emn178@gmail.com
Password:
b5ee607f867744fde859bbddc6d0918d
Origin:
collection_1
Email:
emn178@gmail.com
Password:
emnemn
Origin:
collection_1
Password:
peter1101
Email:
emn178@gmail.com
Origin:
collection_1
Password:
peter1101
Email:
emn178@gmail.com
Origin:
collection_1
Password:
2kof0eva
Email:
emn178@gmail.com
Origin:
collection_1
Password:
peter1101
Email:
emn178@gmail.com
Origin:
collection_1
Password:
peter1101
Email:
emn178@gmail.com
Origin:
collection_1
Password:
2kof0eva
Email:
emn178@gmail.com
Origin:
collection_1
Password:
2kof0eva
Email:
emn178@gmail.com
Origin:
comb3
Email:
emn178@gmail.com
Password:
2kof0eva
Origin:
comb3
Email:
emn178@gmail.com
Password:
emn178
Origin:
comb3
Email:
emn178@gmail.com
Password:
emnemn
Origin:
comb3
Email:
emn178@gmail.com
Password:
peter1101
Intelligence Data
Name:
000webhost.com
Date:
2015-02
Email:
emn178@gmail.com
Password:
2kof0eva
IP Address:
210.242.250.151
Name:
antipublic
Email:
emn178@gmail.com
Password:
2kof0eva
Name:
antipublic
Email:
emn178@gmail.com
Password:
peter1101
Name:
antipublic
Email:
emn178@gmail.com
Password:
emnemn
Name:
armorgames.com
Date:
2018-12
Email:
emn178@gmail.com
Password:
emnemn
Name:
cex.io
Email:
emn178@gmail.com
Password:
emn178
Name:
cit0day
Date:
2020-10
Email:
emn178@gmail.com
Password:
b5ee607f867744fde859bbddc6d0918d
Name:
cit0day
Date:
2020-10
Email:
emn178@gmail.com
Password:
emnemn
Name:
collection-1
Email:
emn178@gmail.com
Password:
emn178
Name:
collection-1
Email:
emn178@gmail.com
Password:
2kof0eva
Name:
collection-1
Email:
emn178@gmail.com
Password:
peter1101
Name:
collection-1
Email:
emn178@gmail.com
Password:
emnemn
Name:
collection-2
Email:
emn178@gmail.com
Password:
emn178
Name:
collection-2
Email:
emn178@gmail.com
Password:
peter1101
Name:
collection-2
Email:
emn178@gmail.com
Password:
emnemn
Name:
collection-2
Email:
emn178@gmail.com
Password:
2kof0eva
Name:
collection-4
Email:
emn178@gmail.com
Password:
peter1101
Name:
collection-4
Email:
emn178@gmail.com
Password:
2kof0eva
Name:
collection-5
Email:
emn178@gmail.com
Password:
2kof0eva
Name:
collection-5
Email:
emn178@gmail.com
Password:
peter1101
Name:
comp
Email:
emn178@gmail.com
Password:
2kof0eva
Name:
comp
Email:
emn178@gmail.com
Password:
peter1101
Name:
couponmom.com
Date:
2013-12
Email:
emn178@gmail.com
Password:
emnemn
Name:
dailymotion.com
Date:
2016-09
Email:
emn178@gmail.com
Username:
dm_521e9608f298c
Name:
dropbox.com
Date:
2012-06
Email:
emn178@gmail.com
Password:
2kof0eva
Name:
dropbox.com
Date:
2012-06
Email:
emn178@gmail.com
Password:
peter1101
Name:
exploit.in
Email:
emn178@gmail.com
Password:
peter1101
Name:
exploit.in
Email:
emn178@gmail.com
Password:
emnemn
Name:
intelx-pastes
Email:
emn178@gmail.com
Password:
emn178
Name:
intelx-pastes
Email:
emn178@gmail.com
Password:
emn178
Name:
manpower.com
Email:
emn178@gmail.com
Password:
emnem
Name:
nazapi
Date:
2023-08
Email:
emn178@gmail.com
Password:
peter1101
Name:
nazapi
Date:
2023-08
Email:
emn178@gmail.com
Password:
2kof0eva
Name:
twitter-scrape
Date:
2022-01
Email:
emn178@gmail.com
Username:
emn178
Full Name:
Yi-Cyuan
Created:
Thu Nov 05 23:54:42 +0000 2015
Followers:
2
Name:
twitter-scrape
Date:
2022-01
Email:
emn178@gmail.com
Username:
emn178
Full Name:
Yi-Cyuan
Created:
Thu Nov 05 23:54:42 +0000 2015
Followers:
1
Email:
emn178@gmail.com
Password:
2k0f03va!
Email:
emn178@gmail.com
Password:
peter1101
Name:
wattpad.com
Date:
2020-04
Email:
emn178@gmail.com
Username:
g7fy7rxt6t7f
IP Address:
195.142.179.164
🇺🇸
+10933388614
United States
SeekNow • Snusbase
210.242.250.151
Map
🇹🇼
Huwei, Yunlin, Taiwan
Chunghwa Telecom Co. Ltd.
ASAS3462
VPN/Proxy: No
DC: No
Mobile: No
221.169.119.109
Map
🇹🇼
Neihu District, Taiwan, Taiwan
Digital United Inc.
ASAS4780
VPN/Proxy: No
DC: No
Mobile: No
195.142.179.164
Map
Istanbul, Istanbul, Türkiye
SOL-BNG
ASAS34984
VPN/Proxy: No
DC: No
Mobile: No
feross@feross.org
In June 2025, headlines erupted over a "16 billion password" breach. In reality, the dataset was a compilation of publicly accessible stealer logs, mostly repurposed from older leaks, with only a small portion of genuinely new material. HIBP received 2.7B rows containing 109M unique email addresses, which was subsequently added to the service under the name "Data Troll". The websites the stealer logs were captured against are searchable via the HIBP dashboard.
Compromised data:
Email addresses
Passwords
SynthientCredentialStuffingThreatData Logo
Synthient Credential Stuffing Threat Data
During 2025, the threat-intelligence firm Synthient aggregated 2 billion unique email addresses disclosed in credential-stuffing lists found across multiple malicious internet sources. Comprised of email addresses and passwords from previous data breaches, these lists are used by attackers to compromise other, unrelated accounts of victims who have reused their passwords. The data also included 1.3 billion unique passwords, which are now searchable in Pwned Passwords. Working to turn breached data into awareness, Synthient partnered with HIBP to help victims of cybercrime understand their exposure.
Compromised data:
Email addresses
Passwords
AlienStealerLogs Logo
ALIEN TXTBASE Stealer Logs
In February 2025, 23 billion rows of stealer logs were obtained from a Telegram channel known as ALIEN TXTBASE. The data contained 284M unique email addresses alongside the websites they were entered into and the passwords used. This data is now searchable in HIBP by both email domain and the domain of the target website.
Compromised data:
Email addresses
Passwords
ThePostMillennial Logo
The Post Millennial
In May 2024, the conservative news website The Post Millennial suffered a data breach. The breach resulted in the defacement of the website and links posted to 3 different corpuses of data including hundreds of writers and editors (IP, physical address and email exposed), tens of thousands of subscribers to the site (name, email, username, phone and plain text password exposed), and tens of millions of email addresses from thousands of mailing lists alleged to have been used by The Post Millennial (this has not been independently verified). The mailing lists appear to be sourced from various campaigns not necessarily run by The Post Millennial and contain a variety of different personal attributes including name, phone and physical address (depending on the campaign). The data was subsequently posted to a popular hacking forum and extensively torrented.
Compromised data:
Email addresses
Genders
IP addresses
Names
Passwords
Phone numbers
Physical addresses
Usernames
Aditya Birla Fashion and Retail
In December 2021, Indian retailer Aditya Birla Fashion and Retail Ltd was breached and ransomed. The ransom demand was allegedly rejected and data containing 5.4M unique email addresses was subsequently dumped publicly on a popular hacking forum the next month. The data contained extensive personal customer information including names, phone numbers, physical addresses, DoBs, order histories and passwords stored as MD5 hashes. Employee data was also dumped publicly and included salary grades, marital statuses and religions.
Compromised data:
Email addresses
Genders
Income levels
Job titles
Marital statuses
Names
Passwords
Phone numbers
Physical addresses
Purchases
Religions
Salutations
In September 2021, the domain registrar and web host Epik suffered a significant data breach, allegedly in retaliation for hosting alt-right websites. The breach exposed a huge volume of data not just of Epik customers, but also scraped WHOIS records belonging to individuals and organisations who were not Epik customers. The data included over 15 million unique email addresses (including anonymised versions for domain privacy), names, phone numbers, physical addresses, purchases and passwords stored in various formats.
Compromised data:
Email addresses
Names
Phone numbers
Physical addresses
Purchases
During the first half of 2021, LinkedIn was targeted by attackers who scraped data from hundreds of millions of public profiles and later sold them online. Whilst the scraping did not constitute a data breach nor did it access any personal data not intended to be publicly accessible, the data was still monetised and later broadly circulated in hacking circles. The scraped data contains approximately 400M records with 125M unique email addresses, as well as names, geographic locations, genders and job titles. LinkedIn specifically addresses the incident in their post on An update on report of scraped data.
Compromised data:
Education levels
Email addresses
Genders
Geographic locations
Job titles
Names
Social media profiles
In March 2020, a massive trove of personal information referred to as "Lead Hunter" was provided to HIBP after being found left exposed on a publicly facing Elasticsearch server. The data contained 69 million unique email addresses across 110 million rows of data accompanied by additional personal information including names, phone numbers, genders and physical addresses. At the time of publishing, the breach could not be attributed to those responsible for obtaining and exposing it. The data was provided to HIBP by dehashed.com.
Compromised data:
Email addresses
Genders
IP addresses
Names
Phone numbers
Physical addresses
In February 2020, a massive trove of personal information referred to as "db8151dd" was provided to HIBP after being found left exposed on a publicly facing Elasticsearch server. Later identified as originating from the Covve contacts app, the exposed data included extensive personal information and interactions between Covve users and their contacts. The data was provided to HIBP by dehashed.com.
Compromised data:
Email addresses
Job titles
Names
Phone numbers
Physical addresses
Social media profiles
Data Enrichment Exposure From PDL Customer
In October 2019, security researchers Vinny Troia and Bob Diachenko identified an unprotected Elasticsearch server holding 1.2 billion records of personal data. The exposed data included an index indicating it was sourced from data enrichment company People Data Labs (PDL) and contained 622 million unique email addresses. The server was not owned by PDL and it's believed a customer failed to properly secure the database. Exposed information included email addresses, phone numbers, social media profiles and job history data.
Compromised data:
Email addresses
Employers
Geographic locations
Job titles
Names
Phone numbers
Social media profiles
In February 2019, the email address validation service verifications.io suffered a data breach. Discovered by Bob Diachenko and Vinny Troia, the breach was due to the data being stored in a MongoDB instance left publicly facing without a password and resulted in 763 million unique email addresses being exposed. Many records within the data also included additional personal attributes such as names, phone numbers, IP addresses, dates of birth and genders. No passwords were included in the data. The Verifications.io website went offline during the disclosure process, although an archived copy remains viewable.
Compromised data:
Dates of birth
Email addresses
Employers
Genders
Geographic locations
IP addresses
Job titles
Names
Phone numbers
Physical addresses
In July 2018, the sales engagement startup Apollo left a database containing billions of data points publicly exposed without a password. The data was discovered by security researcher Vinny Troia who subsequently sent a subset of the data containing 126 million unique email addresses to Have I Been Pwned. The data left exposed by Apollo was used in their "revenue acceleration platform" and included personal information such as names and email addresses as well as professional information including places of employment, the roles people hold and where they're located. Apollo stressed that the exposed data did not include sensitive information such as passwords, social security numbers or financial data. The Apollo website has a contact form for those looking to get in touch with the organisation.
Compromised data:
Email addresses
Employers
Geographic locations
Job titles
Names
Phone numbers
Salutations
Social media profiles
In May 2018, the website for the ticket distribution service Ticketfly was defaced by an attacker and was subsequently taken offline. The attacker allegedly requested a ransom to share details of the vulnerability with Ticketfly but did not receive a reply and subsequently posted the breached data online to a publicly accessible location. The data included over 26 million unique email addresses along with names, physical addresses and phone numbers. Whilst there were no passwords in the publicly leaked data, Ticketfly later issued an incident update and stated that "It is possible, however, that hashed values of password credentials could have been accessed".
Compromised data:
Email addresses
Names
Phone numbers
Physical addresses
In April 2018, the ad management platform known as AerServ suffered a data breach. Acquired by InMobi earlier in the year, the AerServ breach impacted over 66k unique email addresses and also included contact information and passwords stored as salted SHA-512 hashes. The data was publicly posted to Twitter later in 2018 after which InMobi was notified and advised they were aware of the incident.
Compromised data:
Email addresses
Employers
Job titles
Names
Passwords
Phone numbers
Physical addresses
In August 2017, a spambot by the name of Onliner Spambot was identified by security researcher Benkow moÊžuÆŽq. The malicious software contained a server-based component located on an IP address in the Netherlands which exposed a large number of files containing personal information. In total, there were 711 million unique email addresses, many of which were also accompanied by corresponding passwords. A full write-up on what data was found is in the blog post titled Inside the Massive 711 Million Record Onliner Spambot Dump.
Compromised data:
Email addresses
Passwords
In mid-2017, a spam list of over 105 million individuals in corporate America was discovered online. Referred to as "B2B USA Businesses", the list categorised email addresses by employer, providing information on individuals' job titles plus their work phone numbers and physical addresses. Read more about spam lists in HIBP.
Compromised data:
Email addresses
Employers
Job titles
Names
Phone numbers
Physical addresses
In August 2016, the technology recruitment site GeekedIn left a MongoDB database exposed and over 8M records were extracted by an unknown third party. The breached data was originally scraped from GitHub in violation of their terms of use and contained information exposed in public profiles, including over 1 million members' email addresses. Full details on the incident (including how impacted members can see their leaked data) are covered in the blog post on 8 million GitHub profiles were leaked from GeekedIn's MongoDB - here's how to see yours.
Compromised data:
Email addresses
Geographic locations
Names
Professional skills
Usernames
Years of professional experience
In mid-2016, the telephone and address directory service Whitepages was among a raft of sites that were breached and their data then sold in early-2019. The data included over 11 million unique email addresses alongside names and passwords stored as either a SHA-1 or bcrypt hash.
Compromised data:
Email addresses
Names
Passwords
In mid to late 2015, a spam list known as the Special K Data Feed was discovered containing almost 31M identities. The data includes personal attributes such as names, physical and IP addresses, genders, birth dates and phone numbers. Read more about spam lists in HIBP.
Compromised data:
Dates of birth
Email addresses
Genders
IP addresses
Names
Physical addresses
In October 2014, the Bitcoin exchange BTC-E was hacked and 568k accounts were exposed. The data included email and IP addresses, wallet balances and hashed passwords.
Compromised data:
Account balances
Email addresses
IP addresses
Passwords
Usernames
Website activity
In February 2014, the crowdfunding platform Kickstarter announced they'd suffered a data breach. The breach contained almost 5.2 million unique email addresses, usernames and salted SHA1 hashes of passwords.
Compromised data:
Email addresses
Passwords
In early 2013, tumblr suffered a data breach which resulted in the exposure of over 65 million accounts. The data was later put up for sale on a dark market website and included email addresses and passwords stored as salted SHA1 hashes.
Compromised data:
Email addresses
Passwords
Intelligence Data
Username:
feross
Email:
feross@feross.org
Domain:
feross.org
Company:
@SocketDev,
@WebTorrent,
@Standard
Email:
feross@feross.org
Domain:
feross.org
Email:
FEROSS@FEROSS.ORG
Name:
FEROSS ABOUKHADIJEH
Domain:
FEROSS.ORG
City:
STANFORD
Zip Code:
94309
Email:
feross@feross.org
Name:
Feross Aboukhadijeh
Domain:
feross.org
Company:
Brave Software, Inc.
Email:
feross@feross.org
Name:
Feross Aboukhadijeh
Domain:
feross.org
City:
San Francisco
Country:
United States
Company:
Standard JS
Website:
http://www.linkedin.com/in/feross
Email:
feross@feross.org
Password Hash:
d08c6798da660f528502866f1c0a2ea24ed007fe
Domain:
feross.org
Email:
feross@feross.org
Name:
Feross Aboukhadijeh
Domain:
feross.org
Phone Number:
916-220-6364
Address:
3404 Archetto Dr
City:
El Dorado Hills
State:
CA
Zip Code:
95762
Username:
feross
Email:
feross@feross.org
Lastip:
98.248.36.96
Password Hash:
4096$12$4$JHQvu0QFFBP#3cnH$a8bc42cc12dea3e8cea6346d726ef173845ef8ece46ea63560535a2cd68a51b6
Domain:
feross.org
Uid:
305705
Created:
1386024110
Language:
en
Email:
feross@feross.org
Password Hash:
bdf92db84bc7410f3ede8027589eb35b37d16d1c
Salt:
S34E5yM2yblo4IhHZ4Y
Domain:
feross.org
Source:
Verifications.io
Categories:
marketing
Email:
feross@feross.org
Domain:
feross.org
Breach Date:
2019-02-01T00:00:00Z
Source:
Doordash.com
2021
Categories:
food, unverified
Uid:
26123
Email:
feross@feross.org
Fname:
Feross
Lname:
Aboukhadijeh
Phone Number:
(916) 220-6364
CreatedAt:
2014-03-02T04:15:54Z
Card Type:
Visa
Card Display Name:
Chase Freedom Unlimited
Card Last4:
4181
Card Exp Month:
02
Card Exp Year:
2021
Card Fingerprint:
7fswc2rq4j5raYnG
Domain:
feross.org
Source:
tumblr.com
Categories:
social
Email:
feross@feross.org
Password Hash:
d08c6798da660f528502866f1c0a2ea24ed007fe
Domain:
feross.org
Source:
Verifications.io
Categories:
marketing
Email:
FEROSS@FEROSS.ORG
City:
STANFORD
Country:
UNITED STATES
Zip Code:
94309
First Name:
FEROSS ABOUKHADIJEH
Name:
FEROSS ABOUKHADIJEH
Domain:
FEROSS.ORG
Breach Date:
2019-02-01T00:00:00Z
Source:
kickstarter.com
Categories:
media, finance
Email:
feross@feross.org
Password:
bdf92db84bc7410f3ede8027589eb35b37d16d1c
Salt:
S34E5yM2yblo4IhHZ4Y
Domain:
feross.org
ntelligence Data
Origin:
tumblr.com
Email:
feross@feross.org
Password:
d08c6798da660f528502866f1c0a2ea24ed007fe
Origin:
comb2
Password:
feross
Email:
feross@feross.org
Intelligence Data
Name:
collection-2
Email:
feross@feross.org
Password:
feross