mmmm mmmm mmm mmm mmmmmmmm mm mm mmmmmmmm m#""""# ##""""# ##m m## """##""" ## ## ##"""""" ##m ##" ##mm## ## ## ## ## "####m ## "##" ## ######## ####### "## ##m ## ## ## ## ## #mmmmm#" ##mmmm# ## ## ## ## ##mmmmmm https://discord.gg/FwpbJSySF / have fun >.< """"" """" "" "" "" "" """""""" +-------------------------------------------------+ | THE COUNCIL | +-------------------------------------------------+ | 🇨🇷🇪🇩🇮🇹 🇹🇴 : 🇨🇷🇦🇻🇪 <> 🇧4🇺 <> 🇰🇦🇳🇷🇦 <> 🇼🇮🇳🇪 | +-------------------------------------------------+ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@-+@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%++++. -%@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@*++++++-.-++%%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@*+++-++++-++++++@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@+--.-- -++ +-+%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@..-+. .-+++--+*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@*++- ++-++-++**%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@*+++ -+ ..+-+++*****%%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%++++++**++ .++*++** .@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*+++++%%%+ +***++* *@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@+++++*%%++-. .++*+%%@**++ *%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*+++*@%+++++**+++++%@%**+ +@%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%++++%@@**%***%%%@%*@@*++- ++%@%@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*++++@@@%%%@@*%@@@%*%%**++.+++*@%@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%%++++%%%@+*@@@%%@@@%+*%*%*%**%+*%%@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%*++*+*%@%+**@@@@@@@*+-%%%%%**%***%@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@+++*%**@@*+***%**%%*%+-+%@@@**@%*%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@+**+%++@@@*+%****%**%**+++%@@**%@*%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@***%++*@@@@*%@*%%*%%*@*%+*--+%**%%*@*@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@*@%*%+*@@@@%*@@%%@%%%%@****+++-**%*%@%@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%@%***@@@@@%*@@%%@%*%@@%*@++**+*+*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@%%@++%@@@@@*%@@%@%@@@@@%*%**%*+***@@@@@@@@*+-%@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@- ***%@%+@@@@@%@@@@@@%@%*@+%*@@%@@@* -*%@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@* +*****@@@@@%@@@@@@%@%+*%%@@%*-.-+%@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ .+*%+*@@@@@%@@@@@@@@@**+. .+%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@*- +@@%+%@@@@@%@@@@@@@@@*-+%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@%*-. .+%@@@@@@@*+%@@@@@%@@@@@@@@@**@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@- .+%@@@@@@@@@@@++%@@@@@%@@@@@@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@.. +@@@@@@@@@@@@@@+*@@@@@@@@@@@@@@@@%+@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@ .@@@@@@@@@@%+*%@@@@@@@@@@@@@@@%+%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@**%%%@@@@@@@@@@@@@@@**@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@ %@@@@@@@@@@*%@%%@@@@@@@@@@@@@@@*+@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@+ %@@@@@@@@@%*@@%%@@@@@@@@@@@@@@@%+@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@% %@@@@@@@@@%*@@%@@@@@@@@@@@@%@@@@*%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@% %@@@@@@@@@**@@%@@@@@@@@@@@@%@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@. %@@@@@@@@@+%@@*@@@@@@@@@@@@%@@@@@+@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@% -@@@@@@@@%+%@@*@@@@@@@@@@@@*%@@@@*%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@. @@@@@@@@**@@%*@@@@@@@@@@@@*%@@@@**@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@ *@@@@@@@+*@@%*@@@@@@@@@@@@*%@@@@%*@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@%+%@@**@@@@@@@@@@@@%*@@@@@*%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@% -@@@@@*+@@@**@@@@@@@@@@@@%+@@@@@*%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@* *@@@@++@@@+*@@@@@@@@@@@@%+@@@@@**@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@% %@@%+*@@@+*@@@@@@@@@@@@%+@@@@@%+@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@+-%@@@-*@@@@@@@@@@@@%-%@@@@@**@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@- %+-****-*@@@@@@@@@@@@%+*@@@@%+-@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@% *@@@@*-+%@@@@@@@@@@@%-+%%%%%%%@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@% *@@@%++************+-+@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@% .%@@@@@@% @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ +-------------------------------------------------+ | REASON | +-------------------------------------------------+ | Abdullah Mohammed is a former owner of two dox | | groups claiming harm and dox on little kids on | | Roblox and Discord. Leaking info on his Discord | | server thinking he would be safe :) | +-------------------------------------------------+ +-------------------------------------------------+ | SUMMARY | +-------------------------------------------------+ +-------------------------------------------------+ | Legal Name | Feross Aboukhadijeh | | Phone | +1 916-220-6364 | | Emails | team@konfirmasi.com | | | awahbi289@gmail.com | | | smadav@gmail.com | | | emn178@gmail.com | | | bodabe7@gmail.com | +-------------------------------------------------+ | Online Accounts (via bodabe7@gmail.com) | +-------------------------------------------------+ | Facebook | Registered | | Google | Registered | | LinkedIn | Registered | | Microsoft | Registered | | Pinterest | Registered | | Spotify | Registered | | Twitter | Registered | | Discord | Registered | | Adobe | Registered | | Netflix | Registered | | Zoho | Registered | | Duolingo | Full name and photo available | | Firefox | Registered | | Replit | Registered | +-------------------------------------------------+ | Address | 3404 Archetto Dr | | City | El Dorado Hills | | State | CA | | ZIP | 95762 | | Type | Private Street | | USPS Valid | Confirmed | | Home Value | $800,000 - $1,000,000+ | | Home Details | 4 bed 3.5 bath built 2005 | +-------------------------------------------------+ | Business Name | 3agalty Bike Shop | | Website | 3agalty.com | | Location | Nasr City Cairo Egypt | | Specialties | Mountain Bike Road Cycling | | Services | In-store Pickup Same-day | | Payments | Cards Checks Cash | | Hours | Mon-Sat 12PM-10PM Sun | | Reputation | 4.6 stars on 99 reviews | +-------------------------------------------------+ | Social Media | Twitter Registered | | | WhatsApp Registered | +-------------------------------------------------+ shop : https://imgur.com/a/00K42eN house : https://imgur.com/a/BkNHSuz ===================================================================================================================== FULL BREACH & IP REPORT ===================================================================================================================== +---------------------------------------------+ | EMAIL: team@konfirmasi.com | +---------------------------------------------+ | Breach Name | Speedio | | Breach Date | December 2024 | | What Happened | Data taken from Speedio posted for sale. Unsecured Elasticsearch instance. | | Compromised Data| Company names, Email addresses, Phone numbers, Physical addresses | +---------------------------------------------+ | Breach Name | Pertamina | | Breach Date | November 2022 | | What Happened | Breach of MyPertamina service. 44M records exposed. | | Compromised Data| DOB, Emails, Genders, Names, Phone, Addresses, Purchases | +---------------------------------------------+ | Breach Name | Bukalapak | | Breach Date | March 2019 | | What Happened | Backup breach from Oct 2017. 13M unique emails. | | Compromised Data| Emails, IPs, Names, Passwords, Usernames | +---------------------------------------------+ +---------------------------------------------+ | EMAIL: awahbi289@gmail.com | +---------------------------------------------+ | Breach Name | Data Troll | | Breach Date | June 2025 | | What Happened | 2.7B rows of stealer logs posted. Only small portion new. | | Compromised Data| Emails, Passwords | | Domain | dashboard.uptimerobot.com | | Password | AQKrYuU6X4GVKJJ | +---------------------------------------------+ | Domain | scriptblox.com | | Password | QScXf2GA2cQawTz | +---------------------------------------------+ | Breach Name | Synthient | | Breach Date | 2025 | | What Happened | Aggregated billions of records. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | ALIEN TXTBASE | | Breach Date | February 2025 | | What Happened | 23B rows of stealer logs. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ +---------------------------------------------+ | EMAIL: smadav@gmail.com | +---------------------------------------------+ | Breach Name | Synthient | | Breach Date | 2025 | | What Happened | Aggregated billions of records from credential lists. | | Compromised Data| Emails, Passwords | | Password | backspace | +---------------------------------------------+ | Password | BESAR9&kecil1! | +---------------------------------------------+ | Password | backface | +---------------------------------------------+ | Password Hash | 30f33cb6890e3fbade1b7695c54823f1 | | Salt | a039e6 | +---------------------------------------------+ | Password Hash | 79ebf93c54bc2574b9c8f2eba92df34f6a229c766fefd4109d5e1c66f78c76e75ffa7f67a9796b85e3b4030575746b55 | | Salt | 6F56 | +---------------------------------------------+ | Password Hash | bd8e2e10bc92f3754f8b8137643ffc3eb59f8a90 | +---------------------------------------------+ | Breach Name | ALIEN TXTBASE | | Breach Date | February 2025 | | What Happened | 23B rows from Telegram. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | Speedio | | Breach Date | December 2024 | | What Happened | Posted for sale. 62M records. | | Compromised Data| Company names, Emails, Phones, Addresses | +---------------------------------------------+ | Breach Name | Internet Archive | | Breach Date | September 2024 | | What Happened | 31M records exposed. | | Compromised Data| Emails, Passwords, Usernames | +---------------------------------------------+ | Breach Name | French Citizens | | Breach Date | September 2024 | | What Happened | 90M rows exposed. | | Compromised Data| Device info, Emails, IPs, Names, CC data, Phones, Addresses | +---------------------------------------------+ | Breach Name | Naz.API | | Breach Date | September 2023 | | What Happened | 100GB of stealer logs. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | Cit0day | | Breach Date | November 2020 | | What Happened | 23,000 breached sites. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | Gravatar | | Breach Date | October 2020 | | What Happened | 167M names/usernames/MD5. | | Compromised Data| Emails, Names, Usernames | +---------------------------------------------+ | Breach Name | Tokopedia | | Breach Date | April 2020 | | What Happened | 15M rows posted. Later 76M added. | | Compromised Data| DOB, Emails, Genders, Names, Passwords | +---------------------------------------------+ | Breach Name | Covve | | Breach Date | February 2020 | | What Happened | 1.2B records exposed. | | Compromised Data| Emails, Job titles, Names, Phones, Addresses, Profiles | +---------------------------------------------+ | Breach Name | GameSprite | | Breach Date | December 2019 | | What Happened | 6M emails exposed. | | Compromised Data| Emails, IPs, Passwords, Usernames | +---------------------------------------------+ | Breach Name | People Data Labs | | Breach Date | October 2019 | | What Happened | 1.2B records exposed. | | Compromised Data| Emails, Employers, Locations, Titles, Names, Phones, Profiles | +---------------------------------------------+ | Breach Name | Verifications.io | | Breach Date | February 2019 | | What Happened | 763M emails exposed. | | Compromised Data| DOB, Emails, Employers, Genders, Locations, IPs, Titles, Names, Phones, Addresses | +---------------------------------------------+ | Breach Name | Collection #1 | | Breach Date | January 2019 | | What Happened | 2.7B records. | | Compromised Data| Emails, Passwords | | Password | BESAR9&kecil1! | +---------------------------------------------+ | Password | backspace | +---------------------------------------------+ | Password | backface | +---------------------------------------------+ | Breach Name | 2844 Breaches | | Breach Date | February 2018 | | What Happened | 3000 breaches found. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | Bukalapak | | Breach Date | March 2019 | | What Happened | 13M emails exposed. | | Compromised Data| Emails, IPs, Names, Passwords, Usernames | +---------------------------------------------+ | Breach Name | Onliner Spambot | | Breach Date | August 2017 | | What Happened | 711M emails exposed. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | SwordFantasy | | Breach Date | January 2019 | | What Happened | 2.7M emails exposed. | | Compromised Data| Emails, IPs, Passwords, Usernames | +---------------------------------------------+ | Breach Name | Exploit.In | | Breach Date | Late 2016 | | What Happened | 593M emails exposed. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | QuinStreet | | Breach Date | 2015 | | What Happened | 28 sites compromised. | | Compromised Data| DOB, Emails, IPs, Passwords, Usernames, Activity | +---------------------------------------------+ | Breach Name | 000webhost | | Breach Date | 2015 | | What Happened | 15M records exposed. | | Compromised Data| Emails, IPs, Names, Passwords | | Password | BESAR9&kecil1! | +---------------------------------------------+ | Breach Name | Adobe | | Breach Date | October 2013 | | What Happened | 153M accounts breached. | | Compromised Data| Emails, Hints, Passwords, Usernames | +---------------------------------------------+ | Breach Name | Tumblr | | Breach Date | 2013 | | What Happened | 65M accounts exposed. | | Compromised Data| Emails, Passwords | | Password Hash | bd8e2e10bc92f3754f8b8137643ffc3eb59f8a90 | +---------------------------------------------+ | Breach Name | Disqus | | Breach Date | October 2017 | | What Happened | 17.5M records exposed. | | Compromised Data| Emails, Passwords, Usernames | +---------------------------------------------+ | Breach Name | LinkedIn | | Breach Date | May 2016 | | What Happened | 164M emails exposed. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | Elance | | Breach Date | 2009 | | What Happened | 1.3M accounts exposed. | | Compromised Data| Emails, Employers, Locations, Passwords, Phones, Usernames | +---------------------------------------------+ +---------------------------------------------+ | EMAIL: emn178@gmail.com | +---------------------------------------------+ | Breach Name | Data Troll | | Breach Date | June 2025 | | What Happened | 2.7B rows posted. | | Compromised Data| Emails, Passwords | | Password | 2kof0eva | +---------------------------------------------+ | Password | emnemn | +---------------------------------------------+ | Password | peter1101 | +---------------------------------------------+ | Password Hash | 461bbbc3a13b289ea27e0116f4147d9e4c294a8e | | IP Address | 221.169.119.109 | +---------------------------------------------+ | Password Hash | $2y$10$ZU3hzpfGUeDIrX4GNVmQqeahTDkDfXt.aoRx5PVeaVVo.yjr5Qt56 | | IP Address | 195.142.179.164 | +---------------------------------------------+ | Password Hash | $2a$08$.EScQ9MFc2BtYDHSU/FG.ub5OkJJQgFoLGaOuI2SVfiNC7Wvvifii | +---------------------------------------------+ | Breach Name | ALIEN TXTBASE | | Breach Date | February 2025 | | What Happened | 23B rows from Telegram. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | SOCRadar | | Breach Date | August 2024 | | What Happened | 332M emails exposed. | | Compromised Data| Emails | +---------------------------------------------+ | Breach Name | Telegram Channels | | Breach Date | May 2024 | | What Happened | 2B rows from channels. | | Compromised Data| Emails, Passwords, Usernames | +---------------------------------------------+ | Breach Name | Trello | | Breach Date | January 2024 | | What Happened | 15M emails exposed. | | Compromised Data| Emails, Names, Usernames | +---------------------------------------------+ | Breach Name | Naz.API | | Breach Date | September 2023 | | What Happened | 100GB of data exposed. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | Manipulated Caiman | | Breach Date | July 2023 | | What Happened | Phishing on Mexican users.| | Compromised Data| Emails | +---------------------------------------------+ | Breach Name | CoinMarketCap | | Breach Date | October 2021 | | What Happened | 3.1M emails exposed. | | Compromised Data| Emails | +---------------------------------------------+ | Breach Name | Twitter Scrape | | Breach Date | 2023 | | What Happened | 200M records scraped. | | Compromised Data| Emails, Names, Profiles, Usernames | +---------------------------------------------+ | Breach Name | Cit0day | | Breach Date | November 2020 | | What Happened | 23,000 sites breached. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | Wattpad | | Breach Date | June 2020 | | What Happened | 270M records exposed. | | Compromised Data| Bios, DOB, Emails, Genders, Locations, IPs, Names, Passwords, Profiles, URLs, Usernames | +---------------------------------------------+ | Breach Name | Collection #1 | | Breach Date | January 2019 | | What Happened | 2.7B records. | | Compromised Data| Emails, Passwords | | Password | 2kof0eva | +---------------------------------------------+ | Password | emnemn | +---------------------------------------------+ | Password | peter1101 | +---------------------------------------------+ | Breach Name | Armor Games | | Breach Date | January 2019 | | What Happened | 10.6M emails exposed. | | Compromised Data| Bios, DOB, Emails, Genders, Locations, IPs, Passwords, Usernames | +---------------------------------------------+ | Breach Name | kayo.moe | | Breach Date | September 2018 | | What Happened | 42M emails exposed. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | Apollo | | Breach Date | July 2018 | | What Happened | Database exposed. | | Compromised Data| Emails, Employers, Locations, Titles, Names, Phones, Profiles | +---------------------------------------------+ | Breach Name | Onliner Spambot | | Breach Date | August 2017 | | What Happened | 711M emails exposed. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | Dailymotion | | Breach Date | October 2016 | | What Happened | 85M accounts exposed. | | Compromised Data| Emails, Passwords, Usernames | +---------------------------------------------+ | Breach Name | Exploit.In | | Breach Date | Late 2016 | | What Happened | 593M emails exposed. | | Compromised Data| Emails, Passwords | | Password | peter1101 | +---------------------------------------------+ | Password | emnemn | +---------------------------------------------+ | Breach Name | 000webhost | | Breach Date | 2015 | | What Happened | 15M records exposed. | | Compromised Data| Emails, IPs, Names, Passwords | | Password | 2kof0eva | | IP Address | 210.242.250.151 | +---------------------------------------------+ | Breach Name | BTC-E | | Breach Date | October 2014 | | What Happened | 568K accounts exposed. | | Compromised Data| Balances, Emails, IPs, Passwords, Usernames, Activity | +---------------------------------------------+ | Breach Name | Coupon Mom | | Breach Date | 2014 | | What Happened | 11M emails exposed. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | Yam.com | | Breach Date | June 2013 | | What Happened | 13M emails exposed. | | Compromised Data| DOB, Emails, Names, Passwords, Phones, Addresses, Usernames | +---------------------------------------------+ | Breach Name | Dropbox | | Breach Date | 2012 | | What Happened | 68M emails exposed. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ +---------------------------------------------+ | EMAIL: feross@feross.org | +---------------------------------------------+ | Breach Name | Data Troll | | Breach Date | June 2025 | | What Happened | 2.7B rows posted. | | Compromised Data| Emails, Passwords | | Password Hash | d08c6798da660f528502866f1c0a2ea24ed007fe | +---------------------------------------------+ | Password Hash | bdf92db84bc7410f3ede8027589eb35b37d16d1c | | Salt | S34E5yM2yblo4IhHZ4Y | +---------------------------------------------+ | Password | feross | +---------------------------------------------+ | Breach Name | Synthient | | Breach Date | 2025 | | What Happened | Aggregated billions. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | ALIEN TXTBASE | | Breach Date | February 2025 | | What Happened | 23B rows from Telegram. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | The Post Millennial | | Breach Date | May 2024 | | What Happened | Defacement and data dump. | | Compromised Data| Emails, Genders, IPs, Names, Passwords, Phones, Addresses, Usernames | +---------------------------------------------+ | Breach Name | Aditya Birla | | Breach Date | December 2021 | | What Happened | 5.4M emails exposed. | | Compromised Data| Emails, Genders, Income, Titles, Marital, Names, Passwords, Phones, Addresses, Purchases, Religions, Salutations | +---------------------------------------------+ | Breach Name | Epik | | Breach Date | September 2021 | | What Happened | Massive breach. | | Compromised Data| Emails, Names, Phones, Addresses, Purchases | +---------------------------------------------+ | Breach Name | LinkedIn (Scraped) | | Breach Date | 2021 | | What Happened | 400M records scraped. | | Compromised Data| Education, Emails, Genders, Locations, Titles, Names, Profiles | +---------------------------------------------+ | Breach Name | Lead Hunter | | Breach Date | March 2020 | | What Happened | 69M emails exposed. | | Compromised Data| Emails, Genders, IPs, Names, Phones, Addresses | +---------------------------------------------+ | Breach Name | Covve | | Breach Date | February 2020 | | What Happened | 1.2B records exposed. | | Compromised Data| Emails, Titles, Names, Phones, Addresses, Profiles | +---------------------------------------------+ | Breach Name | People Data Labs | | Breach Date | October 2019 | | What Happened | 1.2B records exposed. | | Compromised Data| Emails, Employers, Locations, Titles, Names, Phones, Profiles | +---------------------------------------------+ | Breach Name | Verifications.io | | Breach Date | February 2019 | | What Happened | 763M emails exposed. | | Compromised Data| DOB, Emails, Employers, Genders, Locations, IPs, Titles, Names, Phones, Addresses | +---------------------------------------------+ | Breach Name | Apollo | | Breach Date | July 2018 | | What Happened | Database exposed. | | Compromised Data| Emails, Employers, Locations, Titles, Names, Phones, Profiles | +---------------------------------------------+ | Breach Name | Ticketfly | | Breach Date | May 2018 | | What Happened | 26M emails exposed. | | Compromised Data| Emails, Names, Phones, Addresses | +---------------------------------------------+ | Breach Name | AerServ | | Breach Date | April 2018 | | What Happened | Breach of ad platform. | | Compromised Data| Emails, Employers, Titles, Names, Passwords, Phones, Addresses | +---------------------------------------------+ | Breach Name | Onliner Spambot | | Breach Date | August 2017 | | What Happened | 711M emails exposed. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | B2B USA Businesses | | Breach Date | Mid 2017 | | What Happened | 105M emails exposed. | | Compromised Data| Emails, Employers, Titles, Names, Phones, Addresses | +---------------------------------------------+ | Breach Name | GeekedIn | | Breach Date | August 2016 | | What Happened | 8M records exposed. | | Compromised Data| Emails, Locations, Names, Skills, Usernames, Experience | +---------------------------------------------+ | Breach Name | Whitepages | | Breach Date | Mid 2016 | | What Happened | Breach and resale. | | Compromised Data| Emails, Names, Passwords | +---------------------------------------------+ | Breach Name | Special K Data Feed | | Breach Date | Mid 2015 | | What Happened | 31M identities exposed. | | Compromised Data| DOB, Emails, Genders, IPs, Names, Addresses | +---------------------------------------------+ | Breach Name | BTC-E | | Breach Date | October 2014 | | What Happened | 568K accounts exposed. | | Compromised Data| Balances, Emails, IPs, Passwords, Usernames, Activity | +---------------------------------------------+ | Breach Name | Kickstarter | | Breach Date | February 2014 | | What Happened | 5.2M emails exposed. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ | Breach Name | Tumblr | | Breach Date | 2013 | | What Happened | 65M accounts exposed. | | Compromised Data| Emails, Passwords | +---------------------------------------------+ +---------------------------------------------+ | IP ADDRESSES | +---------------------------------------------+ | IP Address | Location | +---------------------------------------------+ | 125.161.107.240 | Indonesia - Telkom | | 14.58.47.135 | UK - Broadband DC | | 114.59.0.88 | No query | | 210.242.250.151 | Taiwan - Chunghwa Telecom | | 221.169.119.109 | Taiwan - Digital United | | 195.142.179.164 | Turkey - SOL-BNG | | 98.248.36.96 | USA | +---------------------------------------------+ ===================================================== +---------------------------------------------+ | FULL LINE OF BREACHES |TOTAL 59 ACROSS EMAILS| +---------------------------------------------+ ===================================================== team@konfirmasi.com : What Happened In December 2024, data alleged to have been taken from the Brazilian lead generation platform Speedio was posted for sale to a popular hacking forum. The data was allegedly obtained from an unsecured Elasticsearch instance and contained over 62M records of largely public business information including company names, phone numbers and physical addresses, along with 27M unique email addresses, predominantly from public services such as Gmail and Outlook. Speedio did not respond to multiple attempts to disclose the incident, and the origin of the data could not be independently verified. Compromised Data : Company names Email addresses Phone numbers Physical addresses What Happened In November 2022, the Indonesian oil and gas company Pertamina suffered a data breach of their MyPertamina service. The incident exposed 44M records with 6M unique email addresses along with names, dates of birth, genders, physical addresses and purchases. Compromised Data : Dates of birth Email addresses Genders Names Phone numbers Physical addresses Purchases What Happened In March 2019, the Indonesian e-commerce website Bukalapak discovered a data breach of the organisation's backups dating back to October 2017. The incident exposed approximately 13 million unique email addresses alongside IP addresses, names and passwords stored as bcrypt and salted SHA-512 hashes. Compromised Data : Email addresses IP addresses Names Passwords Usernames awahbi289@gmail.com : In June 2025, headlines erupted over a "16 billion password" breach. In reality, the dataset was a compilation of publicly accessible stealer logs, mostly repurposed from older leaks, with only a small portion of genuinely new material. HIBP received 2.7B rows containing 109M unique email addresses, which was subsequently added to the service under the name "Data Troll". The websites the stealer logs were captured against are searchable via the HIBP dashboard. Compromised Data : Email addresses Passwords During 2025, Synthient aggregated billions of records of "threat data" from various internet sources. The data contained 183M unique email addresses alongside the websites they were entered into and the passwords used. After normalising and deduplicating the data, 183 million unique email addresses remained, each linked to the website where the credentials were captured, and the password used. This dataset is now searchable in HIBP by email address, password, domain, and the site on which the credentials were entered. Compromised Data : Email addresses Passwords During 2025, the threat-intelligence firm Synthient aggregated 2 billion unique email addresses disclosed in credential-stuffing lists found across multiple malicious internet sources. Comprised of email addresses and passwords from previous data breaches, these lists are used by attackers to compromise other, unrelated accounts of victims who have reused their passwords. The data also included 1.3 billion unique passwords, which are now searchable in Pwned Passwords. Working to turn breached data into awareness, Synthient partnered with HIBP to help victims of cybercrime understand their exposure. Compromised Data : Email addresses Passwords LIEN TXTBASE Stealer Logs Data Breach StealerLogs Breach What Happened In February 2025, 23 billion rows of stealer logs were obtained from a Telegram channel known as ALIEN TXTBASE. The data contained 284M unique email addresses alongside the websites they were entered into and the passwords used. This data is now searchable in HIBP by both email domain and the domain of the target website. Compromised Data : Email addresses Passwords Intelligence Data Domain: dashboard.uptimerobot.com Email: awahbi289@gmail.com Password: AQKrYuU6X4GVKJJ Domain: dashboard.uptimerobot.com/sign-up Email: awahbi289@gmail.com Password: AQKrYuU6X4GVKJJ Domain: dashboard.uptimerobot.com/sign-up Email: awahbi289@gmail.com Password: AQKrYuU6X4GVKJJ Domain: scriptblox.com Email: awahbi289@gmail.com Password: QScXf2GA2cQawTz Domain: scriptblox.com Email: awahbi289@gmail.com Password: QScXf2GA2cQawTz Domain: scriptblox.com Email: awahbi289@gmail.com Password: QScXf2GA2cQawTz Domain: scriptblox.com/signup Email: awahbi289@gmail.com Password: QScXf2GA2cQawTz smadav@gmail.com : During 2025, the threat-intelligence firm Synthient aggregated 2 billion unique email addresses disclosed in credential-stuffing lists found across multiple malicious internet sources. Comprised of email addresses and passwords from previous data breaches, these lists are used by attackers to compromise other, unrelated accounts of victims who have reused their passwords. The data also included 1.3 billion unique passwords, which are now searchable in Pwned Passwords. Working to turn breached data into awareness, Synthient partnered with HIBP to help victims of cybercrime understand their exposure. Compromised Data : Email addresses Passwords In February 2025, 23 billion rows of stealer logs were obtained from a Telegram channel known as ALIEN TXTBASE. The data contained 284M unique email addresses alongside the websites they were entered into and the passwords used. This data is now searchable in HIBP by both email domain and the domain of the target website. Compromised Data: Email addresses Passwords What Happened In December 2024, data alleged to have been taken from the Brazilian lead generation platform Speedio was posted for sale to a popular hacking forum. The data was allegedly obtained from an unsecured Elasticsearch instance and contained over 62M records of largely public business information including company names, phone numbers and physical addresses, along with 27M unique email addresses, predominantly from public services such as Gmail and Outlook. Speedio did not respond to multiple attempts to disclose the incident, and the origin of the data could not be independently verified. Compromised Data: Company names Email addresses Phone numbers Physical addresses What Happened In September 2024, the digital library of internet sites Internet Archive suffered a data breach that exposed 31M records. The breach exposed user records including email addresses, screen names and bcrypt password hashes. Compromised Data: Email addresses Passwords Usernames What Happened In September 2024, over 90M rows of data on French Citizens was found left exposed in a publicly facing database. Compiled from various data breaches, the corpus contained 28M unique email addresses with the various source breaches each exposing different fields including name, physical and IP address, phone number and partial credit card data including payment type and last 4 digits. Compromised Data: Device information Email addresses IP addresses Names Partial credit card data Phone numbers Physical addresses What Happened In September 2023, over 100GB of stealer logs and credential stuffing lists titled "Naz.API" was posted to a popular hacking forum. The incident contained a combination of email address and plain text password pairs alongside the service they were entered into, and standalone credential pairs obtained from unnamed sources. In total, the corpus of data included 71M unique email addresses and 100M unique passwords. Compromised Data: Email addresses Passwords Cit0day In November 2020, a collection of more than 23,000 allegedly breached websites known as Cit0day were made available for download on several hacking forums. The data consisted of 226M unique email address alongside password pairs, often represented as both password hashes and the cracked, plain text versions. Independent verification of the data established it contains many legitimate, previously undisclosed breaches. The data was provided to HIBP by dehashed.com. Compromised data: Email addresses Passwords In October 2020, a security researcher published a technique for scraping large volumes of data from Gravatar, the service for providing globally unique avatars . 167 million names, usernames and MD5 hashes of email addresses used to reference users' avatars were subsequently scraped and distributed within the hacking community. 114 million of the MD5 hashes were cracked and distributed alongside the source hash, thus disclosing the original email address and accompanying data. Following the impacted email addresses being searchable in HIBP, Gravatar release an FAQ detailing the incident. Compromised data: Email addresses Names Usernames In April 2020, Indonesia's largest online store Tokopedia suffered a data breach. The incident resulted in 15M rows of data being posted to a popular hacking forum. An additional 76M rows were later provided to HIBP in July 2020. In total, the data included over 71M unique email addresses alongside names, genders, birth dates and passwords stored as SHA2-384 hashes. Compromised data: Dates of birth Email addresses Genders Names Passwords In February 2020, a massive trove of personal information referred to as "db8151dd" was provided to HIBP after being found left exposed on a publicly facing Elasticsearch server. Later identified as originating from the Covve contacts app, the exposed data included extensive personal information and interactions between Covve users and their contacts. The data was provided to HIBP by dehashed.com. Compromised data: Email addresses Job titles Names Phone numbers Physical addresses Social media profiles In December 2019, the now defunct gaming platform GameSprite suffered a data breach that exposed over 6M unique email addresses. The impacted data also included usernames, IP addresses and salted MD5 password hashes. Compromised data: Email addresses IP addresses Passwords Usernames Data Enrichment Exposure From PDL Customer In October 2019, security researchers Vinny Troia and Bob Diachenko identified an unprotected Elasticsearch server holding 1.2 billion records of personal data. The exposed data included an index indicating it was sourced from data enrichment company People Data Labs (PDL) and contained 622 million unique email addresses. The server was not owned by PDL and it's believed a customer failed to properly secure the database. Exposed information included email addresses, phone numbers, social media profiles and job history data. Compromised data: Email addresses Employers Geographic locations Job titles Names Phone numbers Social media profiles Verifications.io In February 2019, the email address validation service verifications.io suffered a data breach. Discovered by Bob Diachenko and Vinny Troia, the breach was due to the data being stored in a MongoDB instance left publicly facing without a password and resulted in 763 million unique email addresses being exposed. Many records within the data also included additional personal attributes such as names, phone numbers, IP addresses, dates of birth and genders. No passwords were included in the data. The Verifications.io website went offline during the disclosure process, although an archived copy remains viewable. Compromised data: Dates of birth Email addresses Employers Genders Geographic locations IP addresses Job titles Names Phone numbers Physical addresses In January 2019, a large collection of credential stuffing lists (combinations of email addresses and passwords used to hijack accounts on other services) was discovered being distributed on a popular hacking forum. The data contained almost 2.7 billion records including 773 million unique email addresses alongside passwords those addresses had used on other breached services. Full details on the incident and how to search the breached passwords are provided in the blog post The 773 Million Record "Collection #1" Data Breach. Compromised data: Email addresses Passwords 2,844 Separate Data Breaches In February 2018, a massive collection of almost 3,000 alleged data breaches was found online. Whilst some of the data had previously been seen in Have I Been Pwned, 2,844 of the files consisting of more than 80 million unique email addresses had not previously been seen. Each file contained both an email address and plain text password and were consequently loaded as a single "unverified" data breach. Compromised data: Email addresses Passwords In March 2019, the Indonesian e-commerce website Bukalapak discovered a data breach of the organisation's backups dating back to October 2017. The incident exposed approximately 13 million unique email addresses alongside IP addresses, names and passwords stored as bcrypt and salted SHA-512 hashes. Compromised data: Email addresses IP addresses Names Passwords Usernames In August 2017, a spambot by the name of Onliner Spambot was identified by security researcher Benkow moʞuƎq. The malicious software contained a server-based component located on an IP address in the Netherlands which exposed a large number of files containing personal information. In total, there were 711 million unique email addresses, many of which were also accompanied by corresponding passwords. A full write-up on what data was found is in the blog post titled Inside the Massive 711 Million Record Onliner Spambot Dump. Compromised data: Email addresses Passwords In January 2019, the now defunct MMO and RPG game SwordFantasy suffered a data breach that exposed 2.7M unique email addresses. Other impacted data included username, IP address and salted MD5 password hashes. Compromised data: Email addresses IP addresses Passwords Usernames In late 2016, a huge list of email address and password pairs appeared in a "combo list" referred to as "Exploit.In". The list contained 593 million unique email addresses, many with multiple different passwords hacked from various online systems. The list was broadly circulated and used for "credential stuffing", that is attackers employ it in an attempt to identify other online systems where the account owner had reused their password. For detailed background on this incident, read Password reuse, credential stuffing and another billion records in Have I Been Pwned. Compromised data: Email addresses Passwords In approximately late 2015, the maker of "performance marketing products" QuinStreet had a number of their online assets compromised. The attack impacted 28 separate sites, predominantly technology forums such as flashkit.com, codeguru.com and webdeveloper.com (view a full list of sites). QuinStreet advised that impacted users have been notified and passwords reset. The data contained details on over 4.9 million people and included email addresses, dates of birth and salted MD5 hashes. Compromised data: Dates of birth Email addresses IP addresses Passwords Usernames Website activity In approximately March 2015, the free web hosting provider 000webhost suffered a major data breach that exposed almost 15 million customer records. The data was sold and traded before 000webhost was alerted in October. The breach included names, email addresses and plain text passwords. Compromised data: Email addresses IP addresses Names Passwords ott 2013 Adobe Logo Adobe In October 2013, 153 million Adobe accounts were breached with each containing an internal ID, username, email, encrypted password and a password hint in plain text. The password cryptography was poorly done and many were quickly resolved back to plain text. The unencrypted hints also disclosed much about the passwords adding further to the risk that hundreds of millions of Adobe customers already faced. Compromised data: Email addresses Password hints Passwords Usernames tumblr In early 2013, tumblr suffered a data breach which resulted in the exposure of over 65 million accounts. The data was later put up for sale on a dark market website and included email addresses and passwords stored as salted SHA1 hashes. Compromised data: Email addresses Passwords Disqus In October 2017, the blog commenting service Disqus announced they'd suffered a data breach. The breach dated back to July 2012 but wasn't identified until years later when the data finally surfaced. The breach contained over 17.5 million unique email addresses and usernames. Users who created logins on Disqus had salted SHA1 hashes of passwords whilst users who logged in via social providers only had references to those accounts. Compromised data: Email addresses Passwords Usernames LinkedIn In May 2016, LinkedIn had 164 million email addresses and passwords exposed. Originally hacked in 2012, the data remained out of sight until being offered for sale on a dark market site 4 years later. The passwords in the breach were stored as SHA1 hashes without salt, the vast majority of which were quickly cracked in the days following the release of the data. Compromised data: Email addresses Passwords gen 2009 Elance Logo Elance Sometime in 2009, staffing platform Elance suffered a data breach that impacted 1.3 million accounts. Appearing online 8 years later, the data contained usernames, email addresses, phone numbers and SHA1 hashes of passwords, amongst other personal data. Compromised data: Email addresses Employers Geographic locations Passwords Phone numbers Usernames Intelligence Data Email: smadav@gmail.com Domain: gmail.com Username: smadav312 Email: smadav@gmail.com Lastip: 125.161.107.240 Password Hash: 30f33cb6890e3fbade1b7695c54823f1 Salt: a039e6 Domain: gmail.com Uid: 1185937 Created: 1471956298 Email: smadav@gmail.com Password Hash: 79ebf93c54bc2574b9c8f2eba92df34f6a229c766fefd4109d5e1c66f78c76e75ffa7f67a9796b85e3b4030575746b55 Salt: 6F56 Name: Smadav Domain: gmail.com Email: smadav@gmail.com Password Hash: bd8e2e10bc92f3754f8b8137643ffc3eb59f8a90 Domain: gmail.com Email: smadav@gmail.com Password: backspace Domain: gmail.com ntelligence Data Label: VERIFICATIONS IO 789M MARKETING 022019 Date: 02/20/19 Email: smadav@gmail.com Domain: gmail.com Label: GAMESPRITE ME 7M GAMING 122019 Date: 12/20/19 Username: smadav312 Email: smadav@gmail.com Lastip: 125.161.107.240 Password Hash: 30f33cb6890e3fbade1b7695c54823f1 Salt: a039e6 Domain: gmail.com Uid: 1185937 Created: 1471956298 Label: TOKOPEDIA COM 71M SHOPPING 042020 Date: 04/20/20 Email: smadav@gmail.com Password Hash: 79ebf93c54bc2574b9c8f2eba92df34f6a229c766fefd4109d5e1c66f78c76e75ffa7f67a9796b85e3b4030575746b55 Salt: 6F56 Name: Smadav Domain: gmail.com Label: TUMBLR COM 73M SOCIAL 2013 Date: 2013 Email: smadav@gmail.com Password Hash: bd8e2e10bc92f3754f8b8137643ffc3eb59f8a90 Domain: gmail.com Label: PEMIBLANC COM 134M COMBOLIST 2018 Date: 2018 Email: smadav@gmail.com Password: backspace Domain: gmail.com Intelligence Data Source: Collection #1 Categories: combolist Breach Date: 2019-01-01T00:00:00Z Email: smadav@gmail.com Password: BESAR9&kecil1! Domain: gmail.com Source: Collection #1 Categories: combolist Breach Date: 2019-01-01T00:00:00Z Email: smadav@gmail.com Password: fairesahand Domain: gmail.com Source: swordfantasy.com Categories: gaming Uid: 1185937 Username: smadav312 Password: 30f33cb6890e3fbade1b7695c54823f1 Email: smadav@gmail.com Salt: a039e6 IP Address: 125.161.107.240 Domain: gmail.com Source: Collection #1 Categories: combolist Breach Date: 2019-01-01T00:00:00Z Email: smadav@gmail.com Password: backspace Domain: gmail.com Source: Collection #1 Categories: combolist Breach Date: 2019-01-01T00:00:00Z Email: smadav@gmail.com Password: backface Domain: gmail.com Intelligence Data Origin: tumblr.com Email: smadav@gmail.com Password: bd8e2e10bc92f3754f8b8137643ffc3eb59f8a90 Origin: 000webhost Name: Zainuddin Nafarin Email: smadav@gmail.com IP Address: 114.59.0.88 Password: BESAR9&kecil1! Origin: adobe.com Email: smadav@gmail.com Password: 1234567890 Origin: collection_1 Password: BESAR9&kecil1! Email: smadav@gmail.com Origin: comb1 Email: smadav@gmail.com Password: BESAR9&kecil1! Intelligence Data Name: 000webhost.com Date: 2015-02 Email: smadav@gmail.com Password: BESAR9&kecil1! IP Address: 114.59.0.88 Name: antipublic Email: smadav@gmail.com Password: backspace Name: antipublic Email: smadav@gmail.com Password: BESAR9&kecil1! Name: cit0day Date: 2020-10 Email: smadav@gmail.com Password: backface Name: collection-1 Email: smadav@gmail.com Password: BESAR9&kecil1! 125.161.107.240 Map 🇮🇩 Ujung Menteng, Jakarta, Indonesia PT. TELKOM INDONESIA ASAS7713 VPN/Proxy: No DC: No Mobile: No 14.58.47.135 Map 🇬🇧 London, England, United Kingdom Broadband Customer Of IndosatM2 ASAS16509 VPN/Proxy: No DC: Yes Mobile: No 114.59.0.88 no query founded Intelligence Data Source: 3.9M (TWITTER - NETFLIX - FACEBOOK) Email: smadav@gmail.com emn178@gmail.com In June 2025, headlines erupted over a "16 billion password" breach. In reality, the dataset was a compilation of publicly accessible stealer logs, mostly repurposed from older leaks, with only a small portion of genuinely new material. HIBP received 2.7B rows containing 109M unique email addresses, which was subsequently added to the service under the name "Data Troll". The websites the stealer logs were captured against are searchable via the HIBP dashboard. Compromised data: Email addresses Passwords During 2025, the threat-intelligence firm Synthient aggregated 2 billion unique email addresses disclosed in credential-stuffing lists found across multiple malicious internet sources. Comprised of email addresses and passwords from previous data breaches, these lists are used by attackers to compromise other, unrelated accounts of victims who have reused their passwords. The data also included 1.3 billion unique passwords, which are now searchable in Pwned Passwords. Working to turn breached data into awareness, Synthient partnered with HIBP to help victims of cybercrime understand their exposure. Compromised data: Email addresses Passwords ALIEN TXTBASE Stealer Logs In February 2025, 23 billion rows of stealer logs were obtained from a Telegram channel known as ALIEN TXTBASE. The data contained 284M unique email addresses alongside the websites they were entered into and the passwords used. This data is now searchable in HIBP by both email domain and the domain of the target website. Compromised data: Email addresses Passwords In August 2024, over 332M rows of email addresses were posted to a popular hacking forum. The post alleged the addresses were scraped from cybersecurity firm SOCRadar, however an investigation on their behalf concluded that "the actor merely utilised functionalities inherent in the platform's standard offerings, designed to gather information from publicly available sources". There is no suggestion the incident compromised SOCRadar's security or posed any risk to their customers. In total, the data set contained 282M unique addresses of valid email address format. Compromised data: Email addresses In May 2024, 2B rows of data with 361M unique email addresses were collated from malicious Telegram channels. The data contained 122GB across 1.7k files with email addresses, usernames, passwords and in many cases, the website they were entered into. The data appears to have been sourced from a combination of existing combolists and info stealer malware. Compromised data: Email addresses Passwords Usernames In January 2024, data was scraped from Trello and posted for sale on a popular hacking forum. Containing over 15M email addresses, names and usernames, the data was obtained by enumerating a publicly accessible resource using email addresses from previous breach corpuses. Trello advised that no unauthorised access had occurred. Compromised data: Email addresses Names Usernames In September 2023, over 100GB of stealer logs and credential stuffing lists titled "Naz.API" was posted to a popular hacking forum. The incident contained a combination of email address and plain text password pairs alongside the service they were entered into, and standalone credential pairs obtained from unnamed sources. In total, the corpus of data included 71M unique email addresses and 100M unique passwords. Compromised data: Email addresses Passwords In July 2023, Perception Point reported on a phishing operation dubbed "Manipulated Caiman". Targeting primarily the citizens of Mexico, the campaign attempted to gain access to victims' bank accounts via spear phishing attacks using malicious attachments. Researchers obtained almost 40M email addresses targeted in the campaign and provided the data to HIBP to alert potential victims. Compromised data: Email addresses During October 2021, 3.1 million email addresses with accounts on the cryptocurrency market capitalisation website CoinMarketCap were discovered being traded on hacking forums. Whilst the email addresses were found to correlate with CoinMarketCap accounts, it's unclear precisely how they were obtained. CoinMarketCap has provided the following statement on the data: "CoinMarketCap has become aware that batches of data have shown up online purporting to be a list of user accounts. While the data lists we have seen are only email addresses (no passwords), we have found a correlation with our subscriber base. We have not found any evidence of a data leak from our own servers — we are actively investigating this issue and will update our subscribers as soon as we have any new information." Compromised data: Email addresses In early 2023, over 200M records scraped from Twitter appeared on a popular hacking forum. The data was obtained sometime in 2021 by abusing an API that enabled email addresses to be resolved to Twitter profiles. The subsequent results were then composed into a corpus of data containing email addresses alongside public Twitter profile information including names, usernames and follower counts. Compromised data: Email addresses Names Social media profiles Usernames In November 2020, a collection of more than 23,000 allegedly breached websites known as Cit0day were made available for download on several hacking forums. The data consisted of 226M unique email address alongside password pairs, often represented as both password hashes and the cracked, plain text versions. Independent verification of the data established it contains many legitimate, previously undisclosed breaches. The data was provided to HIBP by dehashed.com. Compromised data: Email addresses Passwords In June 2020, the user-generated stories website Wattpad suffered a huge data breach that exposed almost 270 million records. The data was initially sold then published on a public hacking forum where it was broadly shared. The incident exposed extensive personal information including names and usernames, email and IP addresses, genders, birth dates and passwords stored as bcrypt hashes. Compromised data: Bios Dates of birth Email addresses Genders Geographic locations IP addresses Names Passwords Social media profiles User website URLs Usernames In January 2019, a large collection of credential stuffing lists (combinations of email addresses and passwords used to hijack accounts on other services) was discovered being distributed on a popular hacking forum. The data contained almost 2.7 billion records including 773 million unique email addresses alongside passwords those addresses had used on other breached services. Full details on the incident and how to search the breached passwords are provided in the blog post The 773 Million Record "Collection #1" Data Breach. Compromised data: Email addresses Passwords In January 2019, the game portal website Armor Games suffered a data breach. A total of 10.6 million email addresses were impacted by the breach which also exposed usernames, IP addresses, birthdays of administrator accounts and passwords stored as salted SHA-1 hashes. Compromised data: Bios Dates of birth Email addresses Genders Geographic locations IP addresses Passwords Usernames In September 2018, a collection of almost 42 million email address and plain text password pairs was uploaded to the anonymous file sharing service kayo.moe. The operator of the service contacted HIBP to report the data which, upon further investigation, turned out to be a large credential stuffing list. For more information, read about The 42M Record kayo.moe Credential Stuffing Data. Compromised data: Email addresses Passwords In July 2018, the sales engagement startup Apollo left a database containing billions of data points publicly exposed without a password. The data was discovered by security researcher Vinny Troia who subsequently sent a subset of the data containing 126 million unique email addresses to Have I Been Pwned. The data left exposed by Apollo was used in their "revenue acceleration platform" and included personal information such as names and email addresses as well as professional information including places of employment, the roles people hold and where they're located. Apollo stressed that the exposed data did not include sensitive information such as passwords, social security numbers or financial data. The Apollo website has a contact form for those looking to get in touch with the organisation. Compromised data: Email addresses Employers Geographic locations Job titles Names Phone numbers Salutations Social media profiles In August 2017, a spambot by the name of Onliner Spambot was identified by security researcher Benkow moʞuƎq. The malicious software contained a server-based component located on an IP address in the Netherlands which exposed a large number of files containing personal information. In total, there were 711 million unique email addresses, many of which were also accompanied by corresponding passwords. A full write-up on what data was found is in the blog post titled Inside the Massive 711 Million Record Onliner Spambot Dump. Compromised data: Email addresses Passwords In October 2016, the video sharing platform Dailymotion suffered a data breach. The attack led to the exposure of more than 85 million user accounts and included email addresses, usernames and bcrypt hashes of passwords. Compromised data: Email addresses Passwords Usernames In late 2016, a huge list of email address and password pairs appeared in a "combo list" referred to as "Exploit.In". The list contained 593 million unique email addresses, many with multiple different passwords hacked from various online systems. The list was broadly circulated and used for "credential stuffing", that is attackers employ it in an attempt to identify other online systems where the account owner had reused their password. For detailed background on this incident, read Password reuse, credential stuffing and another billion records in Have I Been Pwned. Compromised data: Email addresses Passwords In approximately March 2015, the free web hosting provider 000webhost suffered a major data breach that exposed almost 15 million customer records. The data was sold and traded before 000webhost was alerted in October. The breach included names, email addresses and plain text passwords. Compromised data: Email addresses IP addresses Names Passwords In October 2014, the Bitcoin exchange BTC-E was hacked and 568k accounts were exposed. The data included email and IP addresses, wallet balances and hashed passwords. Compromised data: Account balances Email addresses IP addresses Passwords Usernames Website activity In 2014, a file allegedly containing data hacked from Coupon Mom was created and included 11 million email addresses and plain text passwords. On further investigation, the file was also found to contain data indicating it had been sourced from Armor Games. Subsequent verification with HIBP subscribers confirmed the passwords had previously been used and many subscribers had used either Coupon Mom or Armor Games in the past. On disclosure to both organisations, each found that the data did not represent their entire customer base and possibly includes records from other sources with common subscribers. The breach has subsequently been flagged as "unverified" as the source cannot be emphatically proven. In July 2020, the data was also found to contain BeerAdvocate accounts sourced from a previously unknown breach. Compromised data: Email addresses Passwords In June 2013, the Taiwanese website Yam.com suffered a data breach which was shared to a popular hacking forum in 2021. The data included 13 million unique email addresses alongside names, usernames, phone numbers, physical addresses, dates of birth and unsalted MD5 password hashes. Compromised data: Dates of birth Email addresses Names Passwords Phone numbers Physical addresses Usernames l In mid-2012, Dropbox suffered a data breach which exposed the stored credentials of tens of millions of their customers. In August 2016, they forced password resets for customers they believed may be at risk. A large volume of data totalling over 68 million records was subsequently traded online and included email addresses and salted hashes of passwords (half of them SHA1, half of them bcrypt). Compromised data: Email addresses Passwords Local Database Email: emn178@gmail.com Username: emn178 Password: 2kof0eva IP Address: 210.242.250.151 Domain: gmail.com Email: emn178@gmail.com Username: emn178 Password: 2kof0eva IP Address: 210.242.250.151 Domain: gmail.com Intelligence Data Username: emn178 Email: emn178@gmail.com Name: Emn178 Domain: gmail.com Id: 51b9ac0a00791e2f3f0031aa Website: https://trello.com/emn178 Username: emn178 Email: emn178@gmail.com Name: Emn178 Domain: gmail.com Id: 51b9ac0a00791e2f3f0031aa Website: https://trello.com/emn178 Email: emn178@gmail.com Password: emnemn Domain: gmail.com Email: emn178@gmail.com Domain: gmail.com Email: emn178@gmail.com Name: Yi-Cyuan Chen Domain: gmail.com Phone Number: +10933388614 Country: Taiwan Company: None_5828 Username: emn178 Email: emn178@gmail.com Lastip: 221.169.119.109 Password Hash: 461bbbc3a13b289ea27e0116f4147d9e4c294a8e Domain: gmail.com Id: 2610123 Uid: 9fae830eaac7eca3fa23e14c1e9b4cad Created: 1321109163 Updated: 1321109163 Birthdate: 0000-00-00 Username: g7fy7rxt6t7f Email: emn178@gmail.com Lastip: 195.142.179.164 Password Hash: $2y$10$ZU3hzpfGUeDIrX4GNVmQqeahTDkDfXt.aoRx5PVeaVVo.yjr5Qt56 Domain: gmail.com Created: 2016-07-28 11:18:26 Updated: 2016-07-28 11:18:26 Birthdate: 0000-00-00 Country: TR Email: emn178@gmail.com Password Hash: $2a$08$.EScQ9MFc2BtYDHSU/FG.ub5OkJJQgFoLGaOuI2SVfiNC7Wvvifii Domain: gmail.com Email: emn178@gmail.com Password: 2kof0eva Domain: gmail.com Email: emn178@gmail.com Password: peter1101 Domain: gmail.com Username: emn178 Email: emn178@gmail.com Lastip: 122.146.59.233 Password Hash: 4096$12$4$mYeYZvi&a%h6bqFr$cfbfa4e9d71dd0361ac4625bbd432315388c30655ff81cc1d6c17bc791c344e7 Domain: gmail.com Uid: 86258 Created: 1366758826 Language: en Email: emn178@gmail.com Password: emnemn Domain: gmail.com Username: emn178 Email: emn178@gmail.com Lastip: 210.242.250.151 Password: 2kof0eva Domain: gmail.com Email: emn178@gmail.com Password: 2kof0eva Domain: gmail.com Email: emn178@gmail.com Password: peter1101 Domain: gmail.com Username: dm_521e9608f298c Email: emn178@gmail.com Domain: gmail.com Intelligence Data Source: coinmarketcap.com Categories: cryptocurrency, finance Email: emn178@gmail.com Domain: gmail.com Source: twitter.com Categories: social Email: emn178@gmail.com Name: Yi-Cyuan Username: emn178 Created: Thu Nov 05 23:54:42 +0000 2015 Domain: gmail.com Source: Collection #1 Categories: combolist Breach Date: 2019-01-01T00:00:00Z Email: emn178@gmail.com Password: b5ee607f867744fde859bbddc6d0918d Domain: gmail.com Source: Exploit.in Categories: combolist Breach Date: 2016-10-01T00:00:00Z Email: emn178@gmail.com Password: emnemn Domain: gmail.com Source: trello.com Categories: social Email: emn178@gmail.com Website: https://trello.com/emn178 Username: emn178 Name: Emn178 Domain: gmail.com Source: dropbox.com Categories: media Email: emn178@gmail.com Password: $2a$08$.EScQ9MFc2BtYDHSU/FG.ub5OkJJQgFoLGaOuI2SVfiNC7Wvvifii Domain: gmail.com Source: armorgames.com Categories: gaming Id: 2610123 Uid: 9fae830eaac7eca3fa23e14c1e9b4cad Username: emn178 Email: emn178@gmail.com Password: 461bbbc3a13b289ea27e0116f4147d9e4c294a8e Avatar: 422 Date of Birth: 0000-00-00 Created On: 1321109163 Updated On: 1321109163 Chat: 1 Active: 1 Comment Notify: Y Comments: Y Merit Notify: Y Role: user IP Address: 221.169.119.109 Domain: gmail.com Source: trello.com Categories: social Email: emn178@gmail.com Website: https://trello.com/emn178 Username: emn178 Name: Emn178 Domain: gmail.com Source: 000webhost.com Categories: hosting Name: emn178 Email: emn178@gmail.com IP Address: 210.242.250.151 Password: 2kof0eva Domain: gmail.com Source: Exploit.in Categories: combolist Breach Date: 2016-10-01T00:00:00Z Email: emn178@gmail.com Password: peter1101 Domain: gmail.com Source: combos.vip Categories: combos Email: emn178@gmail.com Pass Plain: emnemn Domain: gmail.com Source: Wattpad Categories: social, media, art Id: 110684272 Username: g7fy7rxt6t7f Password: $2y$10$ZU3hzpfGUeDIrX4GNVmQqeahTDkDfXt.aoRx5PVeaVVo.yjr5Qt56 Email: emn178@gmail.com Createdate: 2016-07-28 09:18:26 Modifydate: 2016-07-28 09:18:26 IP Address: 195.142.179.164 Logindate: 2016-07-28 16:18:26 Country: TR Language: 23 Dateofbirth: 0000-00-00 Domain: gmail.com Source: Collection #1 Categories: combolist Breach Date: 2019-01-01T00:00:00Z Email: emn178@gmail.com Password: 2kof0eva Domain: gmail.com Source: Collection #1 Categories: combolist Breach Date: 2019-01-01T00:00:00Z Email: emn178@gmail.com Password: emn178 Domain: gmail.com Source: dailymotion.com Categories: media Username: dm_521e9608f298c Email: emn178@gmail.com Domain: gmail.com Source: Collection #1 Categories: combolist Breach Date: 2019-01-01T00:00:00Z Email: emn178@gmail.com Password: peter1101 Domain: gmail.com Source: Collection #1 Categories: combolist Breach Date: 2019-01-01T00:00:00Z Email: emn178@gmail.com Password: emnemn Domain: gmail.com Intelligence Data Origin: 000webhost Name: emn178 Email: emn178@gmail.com IP Address: 210.242.250.151 Password: 2kof0eva Origin: twitter_scrape Name: Yi-Cyuan Username: emn178 Email: emn178@gmail.com Origin: collection_1 Email: emn178@gmail.com Password: 2kof0eva Origin: collection_1 Email: emn178@gmail.com Password: emn178 Origin: collection_2 Email: emn178@gmail.com Password: 2kof0eva Origin: collection_2 Email: emn178@gmail.com Password: peter1101 Origin: collection_1 Password: emnemn Email: emn178@gmail.com Origin: collection_1 Email: emn178@gmail.com Password: peter1101 Origin: collection_1 Password: peter1101 Email: emn178@gmail.com Origin: comb2 Password: 2kof0eva Email: emn178@gmail.com Origin: comb2 Password: emn178 Email: emn178@gmail.com Origin: comb2 Password: emnemn Email: emn178@gmail.com Origin: comb2 Password: peter1101 Email: emn178@gmail.com Origin: collection_1 Email: emn178@gmail.com Password: peter1101 Origin: collection_1 Email: emn178@gmail.com Password: 2kof0eva Origin: collection_1 Email: emn178@gmail.com Password: peter1101 Origin: collection_1 Email: emn178@gmail.com Password: 2kof0eva Origin: collection_1 Email: emn178@gmail.com Password: peter1101 Origin: collection_1 Email: emn178@gmail.com Password: 2kof0eva Origin: collection_1 Email: emn178@gmail.com Password: peter1101 Origin: collection_1 Email: emn178@gmail.com Password: 2kof0eva Origin: collection_1 Email: emn178@gmail.com Password: 2kof0eva Origin: collection_1 Email: emn178@gmail.com Password: 2kof0eva Origin: collection_1 Email: emn178@gmail.com Password: peter1101 Origin: collection_1 Email: emn178@gmail.com Password: peter1101 Origin: collection_1 Email: emn178@gmail.com Password: 2kof0eva Origin: collection_1 Email: emn178@gmail.com Password: 2kof0eva Origin: collection_1 Email: emn178@gmail.com Password: peter1101 Origin: collection_1 Email: emn178@gmail.com Password: peter1101 Origin: collection_1 Email: emn178@gmail.com Password: 2kof0eva Origin: collection_1 Email: emn178@gmail.com Password: 2kof0eva Origin: collection_1 Email: emn178@gmail.com Password: peter1101 Origin: collection_1 Email: emn178@gmail.com Password: peter1101 Origin: collection_1 Email: emn178@gmail.com Password: 2kof0eva Origin: collection_1 Email: emn178@gmail.com Password: 2kof0eva Origin: collection_1 Password: 2kof0eva Email: emn178@gmail.com Origin: collection_1 Email: emn178@gmail.com Password: 4096$12$4$mYeYZvi&a%h6bqFr$cfbfa4e9d71dd0361ac4625bbd432315388c30655ff81cc1d6c17bc791c344e7 Origin: collection_1 Email: emn178@gmail.com Password: b5ee607f867744fde859bbddc6d0918d Origin: collection_1 Email: emn178@gmail.com Password: emnemn Origin: collection_1 Password: peter1101 Email: emn178@gmail.com Origin: collection_1 Password: peter1101 Email: emn178@gmail.com Origin: collection_1 Password: 2kof0eva Email: emn178@gmail.com Origin: collection_1 Password: peter1101 Email: emn178@gmail.com Origin: collection_1 Password: peter1101 Email: emn178@gmail.com Origin: collection_1 Password: 2kof0eva Email: emn178@gmail.com Origin: collection_1 Password: 2kof0eva Email: emn178@gmail.com Origin: comb3 Email: emn178@gmail.com Password: 2kof0eva Origin: comb3 Email: emn178@gmail.com Password: emn178 Origin: comb3 Email: emn178@gmail.com Password: emnemn Origin: comb3 Email: emn178@gmail.com Password: peter1101 Intelligence Data Name: 000webhost.com Date: 2015-02 Email: emn178@gmail.com Password: 2kof0eva IP Address: 210.242.250.151 Name: antipublic Email: emn178@gmail.com Password: 2kof0eva Name: antipublic Email: emn178@gmail.com Password: peter1101 Name: antipublic Email: emn178@gmail.com Password: emnemn Name: armorgames.com Date: 2018-12 Email: emn178@gmail.com Password: emnemn Name: cex.io Email: emn178@gmail.com Password: emn178 Name: cit0day Date: 2020-10 Email: emn178@gmail.com Password: b5ee607f867744fde859bbddc6d0918d Name: cit0day Date: 2020-10 Email: emn178@gmail.com Password: emnemn Name: collection-1 Email: emn178@gmail.com Password: emn178 Name: collection-1 Email: emn178@gmail.com Password: 2kof0eva Name: collection-1 Email: emn178@gmail.com Password: peter1101 Name: collection-1 Email: emn178@gmail.com Password: emnemn Name: collection-2 Email: emn178@gmail.com Password: emn178 Name: collection-2 Email: emn178@gmail.com Password: peter1101 Name: collection-2 Email: emn178@gmail.com Password: emnemn Name: collection-2 Email: emn178@gmail.com Password: 2kof0eva Name: collection-4 Email: emn178@gmail.com Password: peter1101 Name: collection-4 Email: emn178@gmail.com Password: 2kof0eva Name: collection-5 Email: emn178@gmail.com Password: 2kof0eva Name: collection-5 Email: emn178@gmail.com Password: peter1101 Name: comp Email: emn178@gmail.com Password: 2kof0eva Name: comp Email: emn178@gmail.com Password: peter1101 Name: couponmom.com Date: 2013-12 Email: emn178@gmail.com Password: emnemn Name: dailymotion.com Date: 2016-09 Email: emn178@gmail.com Username: dm_521e9608f298c Name: dropbox.com Date: 2012-06 Email: emn178@gmail.com Password: 2kof0eva Name: dropbox.com Date: 2012-06 Email: emn178@gmail.com Password: peter1101 Name: exploit.in Email: emn178@gmail.com Password: peter1101 Name: exploit.in Email: emn178@gmail.com Password: emnemn Name: intelx-pastes Email: emn178@gmail.com Password: emn178 Name: intelx-pastes Email: emn178@gmail.com Password: emn178 Name: manpower.com Email: emn178@gmail.com Password: emnem Name: nazapi Date: 2023-08 Email: emn178@gmail.com Password: peter1101 Name: nazapi Date: 2023-08 Email: emn178@gmail.com Password: 2kof0eva Name: twitter-scrape Date: 2022-01 Email: emn178@gmail.com Username: emn178 Full Name: Yi-Cyuan Created: Thu Nov 05 23:54:42 +0000 2015 Followers: 2 Name: twitter-scrape Date: 2022-01 Email: emn178@gmail.com Username: emn178 Full Name: Yi-Cyuan Created: Thu Nov 05 23:54:42 +0000 2015 Followers: 1 Email: emn178@gmail.com Password: 2k0f03va! Email: emn178@gmail.com Password: peter1101 Name: wattpad.com Date: 2020-04 Email: emn178@gmail.com Username: g7fy7rxt6t7f IP Address: 195.142.179.164 🇺🇸 +10933388614 United States SeekNow • Snusbase 210.242.250.151 Map 🇹🇼 Huwei, Yunlin, Taiwan Chunghwa Telecom Co. Ltd. ASAS3462 VPN/Proxy: No DC: No Mobile: No 221.169.119.109 Map 🇹🇼 Neihu District, Taiwan, Taiwan Digital United Inc. ASAS4780 VPN/Proxy: No DC: No Mobile: No 195.142.179.164 Map Istanbul, Istanbul, Türkiye SOL-BNG ASAS34984 VPN/Proxy: No DC: No Mobile: No feross@feross.org In June 2025, headlines erupted over a "16 billion password" breach. In reality, the dataset was a compilation of publicly accessible stealer logs, mostly repurposed from older leaks, with only a small portion of genuinely new material. HIBP received 2.7B rows containing 109M unique email addresses, which was subsequently added to the service under the name "Data Troll". The websites the stealer logs were captured against are searchable via the HIBP dashboard. Compromised data: Email addresses Passwords SynthientCredentialStuffingThreatData Logo Synthient Credential Stuffing Threat Data During 2025, the threat-intelligence firm Synthient aggregated 2 billion unique email addresses disclosed in credential-stuffing lists found across multiple malicious internet sources. Comprised of email addresses and passwords from previous data breaches, these lists are used by attackers to compromise other, unrelated accounts of victims who have reused their passwords. The data also included 1.3 billion unique passwords, which are now searchable in Pwned Passwords. Working to turn breached data into awareness, Synthient partnered with HIBP to help victims of cybercrime understand their exposure. Compromised data: Email addresses Passwords AlienStealerLogs Logo ALIEN TXTBASE Stealer Logs In February 2025, 23 billion rows of stealer logs were obtained from a Telegram channel known as ALIEN TXTBASE. The data contained 284M unique email addresses alongside the websites they were entered into and the passwords used. This data is now searchable in HIBP by both email domain and the domain of the target website. Compromised data: Email addresses Passwords ThePostMillennial Logo The Post Millennial In May 2024, the conservative news website The Post Millennial suffered a data breach. The breach resulted in the defacement of the website and links posted to 3 different corpuses of data including hundreds of writers and editors (IP, physical address and email exposed), tens of thousands of subscribers to the site (name, email, username, phone and plain text password exposed), and tens of millions of email addresses from thousands of mailing lists alleged to have been used by The Post Millennial (this has not been independently verified). The mailing lists appear to be sourced from various campaigns not necessarily run by The Post Millennial and contain a variety of different personal attributes including name, phone and physical address (depending on the campaign). The data was subsequently posted to a popular hacking forum and extensively torrented. Compromised data: Email addresses Genders IP addresses Names Passwords Phone numbers Physical addresses Usernames Aditya Birla Fashion and Retail In December 2021, Indian retailer Aditya Birla Fashion and Retail Ltd was breached and ransomed. The ransom demand was allegedly rejected and data containing 5.4M unique email addresses was subsequently dumped publicly on a popular hacking forum the next month. The data contained extensive personal customer information including names, phone numbers, physical addresses, DoBs, order histories and passwords stored as MD5 hashes. Employee data was also dumped publicly and included salary grades, marital statuses and religions. Compromised data: Email addresses Genders Income levels Job titles Marital statuses Names Passwords Phone numbers Physical addresses Purchases Religions Salutations In September 2021, the domain registrar and web host Epik suffered a significant data breach, allegedly in retaliation for hosting alt-right websites. The breach exposed a huge volume of data not just of Epik customers, but also scraped WHOIS records belonging to individuals and organisations who were not Epik customers. The data included over 15 million unique email addresses (including anonymised versions for domain privacy), names, phone numbers, physical addresses, purchases and passwords stored in various formats. Compromised data: Email addresses Names Phone numbers Physical addresses Purchases During the first half of 2021, LinkedIn was targeted by attackers who scraped data from hundreds of millions of public profiles and later sold them online. Whilst the scraping did not constitute a data breach nor did it access any personal data not intended to be publicly accessible, the data was still monetised and later broadly circulated in hacking circles. The scraped data contains approximately 400M records with 125M unique email addresses, as well as names, geographic locations, genders and job titles. LinkedIn specifically addresses the incident in their post on An update on report of scraped data. Compromised data: Education levels Email addresses Genders Geographic locations Job titles Names Social media profiles In March 2020, a massive trove of personal information referred to as "Lead Hunter" was provided to HIBP after being found left exposed on a publicly facing Elasticsearch server. The data contained 69 million unique email addresses across 110 million rows of data accompanied by additional personal information including names, phone numbers, genders and physical addresses. At the time of publishing, the breach could not be attributed to those responsible for obtaining and exposing it. The data was provided to HIBP by dehashed.com. Compromised data: Email addresses Genders IP addresses Names Phone numbers Physical addresses In February 2020, a massive trove of personal information referred to as "db8151dd" was provided to HIBP after being found left exposed on a publicly facing Elasticsearch server. Later identified as originating from the Covve contacts app, the exposed data included extensive personal information and interactions between Covve users and their contacts. The data was provided to HIBP by dehashed.com. Compromised data: Email addresses Job titles Names Phone numbers Physical addresses Social media profiles Data Enrichment Exposure From PDL Customer In October 2019, security researchers Vinny Troia and Bob Diachenko identified an unprotected Elasticsearch server holding 1.2 billion records of personal data. The exposed data included an index indicating it was sourced from data enrichment company People Data Labs (PDL) and contained 622 million unique email addresses. The server was not owned by PDL and it's believed a customer failed to properly secure the database. Exposed information included email addresses, phone numbers, social media profiles and job history data. Compromised data: Email addresses Employers Geographic locations Job titles Names Phone numbers Social media profiles In February 2019, the email address validation service verifications.io suffered a data breach. Discovered by Bob Diachenko and Vinny Troia, the breach was due to the data being stored in a MongoDB instance left publicly facing without a password and resulted in 763 million unique email addresses being exposed. Many records within the data also included additional personal attributes such as names, phone numbers, IP addresses, dates of birth and genders. No passwords were included in the data. The Verifications.io website went offline during the disclosure process, although an archived copy remains viewable. Compromised data: Dates of birth Email addresses Employers Genders Geographic locations IP addresses Job titles Names Phone numbers Physical addresses In July 2018, the sales engagement startup Apollo left a database containing billions of data points publicly exposed without a password. The data was discovered by security researcher Vinny Troia who subsequently sent a subset of the data containing 126 million unique email addresses to Have I Been Pwned. The data left exposed by Apollo was used in their "revenue acceleration platform" and included personal information such as names and email addresses as well as professional information including places of employment, the roles people hold and where they're located. Apollo stressed that the exposed data did not include sensitive information such as passwords, social security numbers or financial data. The Apollo website has a contact form for those looking to get in touch with the organisation. Compromised data: Email addresses Employers Geographic locations Job titles Names Phone numbers Salutations Social media profiles In May 2018, the website for the ticket distribution service Ticketfly was defaced by an attacker and was subsequently taken offline. The attacker allegedly requested a ransom to share details of the vulnerability with Ticketfly but did not receive a reply and subsequently posted the breached data online to a publicly accessible location. The data included over 26 million unique email addresses along with names, physical addresses and phone numbers. Whilst there were no passwords in the publicly leaked data, Ticketfly later issued an incident update and stated that "It is possible, however, that hashed values of password credentials could have been accessed". Compromised data: Email addresses Names Phone numbers Physical addresses In April 2018, the ad management platform known as AerServ suffered a data breach. Acquired by InMobi earlier in the year, the AerServ breach impacted over 66k unique email addresses and also included contact information and passwords stored as salted SHA-512 hashes. The data was publicly posted to Twitter later in 2018 after which InMobi was notified and advised they were aware of the incident. Compromised data: Email addresses Employers Job titles Names Passwords Phone numbers Physical addresses In August 2017, a spambot by the name of Onliner Spambot was identified by security researcher Benkow moʞuƎq. The malicious software contained a server-based component located on an IP address in the Netherlands which exposed a large number of files containing personal information. In total, there were 711 million unique email addresses, many of which were also accompanied by corresponding passwords. A full write-up on what data was found is in the blog post titled Inside the Massive 711 Million Record Onliner Spambot Dump. Compromised data: Email addresses Passwords In mid-2017, a spam list of over 105 million individuals in corporate America was discovered online. Referred to as "B2B USA Businesses", the list categorised email addresses by employer, providing information on individuals' job titles plus their work phone numbers and physical addresses. Read more about spam lists in HIBP. Compromised data: Email addresses Employers Job titles Names Phone numbers Physical addresses In August 2016, the technology recruitment site GeekedIn left a MongoDB database exposed and over 8M records were extracted by an unknown third party. The breached data was originally scraped from GitHub in violation of their terms of use and contained information exposed in public profiles, including over 1 million members' email addresses. Full details on the incident (including how impacted members can see their leaked data) are covered in the blog post on 8 million GitHub profiles were leaked from GeekedIn's MongoDB - here's how to see yours. Compromised data: Email addresses Geographic locations Names Professional skills Usernames Years of professional experience In mid-2016, the telephone and address directory service Whitepages was among a raft of sites that were breached and their data then sold in early-2019. The data included over 11 million unique email addresses alongside names and passwords stored as either a SHA-1 or bcrypt hash. Compromised data: Email addresses Names Passwords In mid to late 2015, a spam list known as the Special K Data Feed was discovered containing almost 31M identities. The data includes personal attributes such as names, physical and IP addresses, genders, birth dates and phone numbers. Read more about spam lists in HIBP. Compromised data: Dates of birth Email addresses Genders IP addresses Names Physical addresses In October 2014, the Bitcoin exchange BTC-E was hacked and 568k accounts were exposed. The data included email and IP addresses, wallet balances and hashed passwords. Compromised data: Account balances Email addresses IP addresses Passwords Usernames Website activity In February 2014, the crowdfunding platform Kickstarter announced they'd suffered a data breach. The breach contained almost 5.2 million unique email addresses, usernames and salted SHA1 hashes of passwords. Compromised data: Email addresses Passwords In early 2013, tumblr suffered a data breach which resulted in the exposure of over 65 million accounts. The data was later put up for sale on a dark market website and included email addresses and passwords stored as salted SHA1 hashes. Compromised data: Email addresses Passwords Intelligence Data Username: feross Email: feross@feross.org Domain: feross.org Company: @SocketDev, @WebTorrent, @Standard Email: feross@feross.org Domain: feross.org Email: FEROSS@FEROSS.ORG Name: FEROSS ABOUKHADIJEH Domain: FEROSS.ORG City: STANFORD Zip Code: 94309 Email: feross@feross.org Name: Feross Aboukhadijeh Domain: feross.org Company: Brave Software, Inc. Email: feross@feross.org Name: Feross Aboukhadijeh Domain: feross.org City: San Francisco Country: United States Company: Standard JS Website: http://www.linkedin.com/in/feross Email: feross@feross.org Password Hash: d08c6798da660f528502866f1c0a2ea24ed007fe Domain: feross.org Email: feross@feross.org Name: Feross Aboukhadijeh Domain: feross.org Phone Number: 916-220-6364 Address: 3404 Archetto Dr City: El Dorado Hills State: CA Zip Code: 95762 Username: feross Email: feross@feross.org Lastip: 98.248.36.96 Password Hash: 4096$12$4$JHQvu0QFFBP#3cnH$a8bc42cc12dea3e8cea6346d726ef173845ef8ece46ea63560535a2cd68a51b6 Domain: feross.org Uid: 305705 Created: 1386024110 Language: en Email: feross@feross.org Password Hash: bdf92db84bc7410f3ede8027589eb35b37d16d1c Salt: S34E5yM2yblo4IhHZ4Y Domain: feross.org Source: Verifications.io Categories: marketing Email: feross@feross.org Domain: feross.org Breach Date: 2019-02-01T00:00:00Z Source: Doordash.com 2021 Categories: food, unverified Uid: 26123 Email: feross@feross.org Fname: Feross Lname: Aboukhadijeh Phone Number: (916) 220-6364 CreatedAt: 2014-03-02T04:15:54Z Card Type: Visa Card Display Name: Chase Freedom Unlimited Card Last4: 4181 Card Exp Month: 02 Card Exp Year: 2021 Card Fingerprint: 7fswc2rq4j5raYnG Domain: feross.org Source: tumblr.com Categories: social Email: feross@feross.org Password Hash: d08c6798da660f528502866f1c0a2ea24ed007fe Domain: feross.org Source: Verifications.io Categories: marketing Email: FEROSS@FEROSS.ORG City: STANFORD Country: UNITED STATES Zip Code: 94309 First Name: FEROSS ABOUKHADIJEH Name: FEROSS ABOUKHADIJEH Domain: FEROSS.ORG Breach Date: 2019-02-01T00:00:00Z Source: kickstarter.com Categories: media, finance Email: feross@feross.org Password: bdf92db84bc7410f3ede8027589eb35b37d16d1c Salt: S34E5yM2yblo4IhHZ4Y Domain: feross.org ntelligence Data Origin: tumblr.com Email: feross@feross.org Password: d08c6798da660f528502866f1c0a2ea24ed007fe Origin: comb2 Password: feross Email: feross@feross.org Intelligence Data Name: collection-2 Email: feross@feross.org Password: feross