Have I Been Pwned (HIBP) Bridge

Pi-hole - 29,926 breached accounts

In July 2025, a vulnerability in the GiveWP WordPress plugin exposed the names and email addresses of approximately 30k donors to the Pi-hole network-wide ad blocking project. Pi-hole subsequently self-submitted the list of impacted donors to HIBP.

Breach date: 30 July 2025
Date added to HIBP: 31 July 2025
Compromised accounts: 29,926
Compromised data: Email addresses, Names

Creams Cafe - 159,652 breached accounts

In May 2025, 160k records of customer data was allegedly obtained from Creams Cafe, "the UK's favourite dessert parlour". The data included email and physical addresses, names and phone numbers. Creams Cafe did not respond to repeated attempts to disclose the incident, however multiple impacted HIBP subscribers confirmed the legitimacy and accuracy of the data.

Breach date: 1 May 2025
Date added to HIBP: 23 July 2025
Compromised accounts: 159,652
Compromised data: Email addresses, Names, Phone numbers, Physical addresses

MaReads - 74,453 breached accounts

In June 2025, MaReads, the website for readers and writers of Thai-language fiction and comics suffered a data breach that exposed 74k records. The breach included usernames, email addresses, phone numbers and dates of birth. MaReads is aware of the breach.

Breach date: 22 June 2025
Date added to HIBP: 15 July 2025
Compromised accounts: 74,453
Compromised data: Dates of birth, Email addresses, Phone numbers, Usernames

Omnicuris - 215,298 breached accounts

In June 2025, the Indian CME platform Omnicuris suffered a data breach that exposed approximately 200k records of healthcare professionals. The data included names, email addresses, phone numbers, geographic locations and other data attributes relating to professional expertise and training progress. Omnicuris is aware of the incident.

Breach date: 8 June 2025
Date added to HIBP: 13 July 2025
Compromised accounts: 215,298
Compromised data: Email addresses, Geographic locations, Names, Phone numbers

Catwatchful - 61,641 breached accounts

In June 2025, spyware maker Catwatchful suffered a data breach that exposed over 60k customer records. The breach was due to a SQL injection vulnerability that enabled email addresses and plain text passwords to be extracted from the system.

Sensitive breach, not publicly searchable.

Breach date: 9 June 2025
Date added to HIBP: 3 July 2025
Compromised accounts: 61,641
Compromised data: Email addresses, Passwords

Robinsons Malls - 195,597 breached accounts

In June 2024, the Philippines' largest shopping-mall operators Robinsons Malls suffered a data breach stemming from their mobile app. The incident exposed 195k unique email addresses along with names, phone numbers, dates of birth, genders and the user's city and province.

Breach date: 1 June 2024
Date added to HIBP: 25 June 2025
Compromised accounts: 195,597
Compromised data: Dates of birth, Email addresses, Genders, Geographic locations, Names, Phone numbers

Have Fun Teaching - 27,126 breached accounts

In August 2021, the teaching resources website Have Fun Teaching suffered a data breach that leaked 80k WooCommerce transactions which were later posted to a popular hacking forum. The data contained 27k unique email addresses along with physical and IP addresses, names, payment methods and the item purchased. Have Fun Teaching is aware of the incident.

Breach date: 15 August 2021
Date added to HIBP: 25 June 2025
Compromised accounts: 27,126
Compromised data: Browser user agent details, Email addresses, IP addresses, Names, Payment methods, Physical addresses, Purchases

Ualabee - 472,296 breached accounts

In May 2025, the South American mobility services platform Ualabee had hundreds of thousands of records scraped from an interface on their platform. The data included 472k unique email addresses along with names, profile photos, dates of birth and phone numbers.

Breach date: 6 May 2025
Date added to HIBP: 13 June 2025
Compromised accounts: 472,296
Compromised data: Dates of birth, Email addresses, Names, Phone numbers, Profile photos

WiredBucks - 918,529 breached accounts

In May 2022, the now defunct social media influencer platform WiredBucks suffered a data breach that was later redistributed as part of a larger corpus of data. The incident exposed over 900k email and IP addresses alongside names, usernames, earnings via the platform, physical addresses and passwords stored as plain text.

Breach date: 25 May 2022
Date added to HIBP: 10 June 2025
Compromised accounts: 918,529
Compromised data: Earnings, Email addresses, IP addresses, Names, Passwords, Physical addresses, Usernames

Disk Union - 690,667 breached accounts

In June 2022, the Japanese record chain store Disk Union suffered a data breach. The incident exposed 690k unique email addresses along with names, post codes, phone numbers and plain text passwords.

Breach date: 24 June 2022
Date added to HIBP: 7 June 2025
Compromised accounts: 690,667
Compromised data: Email addresses, Geographic locations, Names, Passwords, Phone numbers, Usernames

ColoCrossing - 7,183 breached accounts

In May 2025, hosting provider ColoCrossing identified a data breach that impacted customers of their ColoCloud virtual server product. ColoCrossing advised the incident was isolated to their cloud/VPS platform and stemmed from a single sign-on vulnerability. 7k email addresses were exposed in the incident along with names and MD5-Crypt password hashes.

Breach date: 24 May 2025
Date added to HIBP: 3 June 2025
Compromised accounts: 7,183
Compromised data: Email addresses, Names, Passwords

Free - 13,926,173 breached accounts

In October 2024, French ISP "Free" suffered a data breach which was subsequently posted for sale and later, leaked publicly. The data included 14M unique email addresses along with names, physical addresses, phone numbers, genders, dates of birth and for many records, IBAN bank account numbers. Free advised that the numbers were "not enough to make a direct debit from a bank".

Breach date: 17 October 2024
Date added to HIBP: 27 May 2025
Compromised accounts: 13,926,173
Compromised data: Bank account numbers, Dates of birth, Genders, Names, Phone numbers, Physical addresses

Operation Endgame 2.0 - 15,436,844 breached accounts

In May 2025, a coalition of law enforcement agencies took down the criminal infrastructure behind the malware used to launch ransomware attacks in a new phase of "Operation Endgame". This followed the first Operation Endgame exercise a year earlier, with the latest action resulting in 15.3M victim email addresses being provided to HIBP by law enforcement. A further 43.8M victim passwords were also provided for HIBP's Pwned Passwords service.

Malware breach.

Breach date: 23 May 2025
Date added to HIBP: 23 May 2025
Compromised accounts: 15,436,844
Compromised data: Email addresses, Passwords

Fédération Francaise de Rugby - 281,977 breached accounts

In June 2023, the Fédération Francaise de Rugby (French Rugby Federation) suffered a data breach and attempted ransom. The breach exposed 282k unique email addresses along with names, dates of birth and phone numbers. The Federation subsequently published a disclosure notice and stated that the attack primarily affected email servers.

Breach date: 6 July 2023
Date added to HIBP: 22 May 2025
Compromised accounts: 281,977
Compromised data: Dates of birth, Email addresses, Names, Phone numbers

OnRPG - 1,047,640 breached accounts

In July 2016, the now defunct free online games list website OnRPG suffered a data breach that was later redistributed as part of a larger corpus of data. The incident exposed just over 1M email and IP addresses alongside usernames and passwords stored as salted MD5 hashes.

Breach date: 1 July 2016
Date added to HIBP: 8 May 2025
Compromised accounts: 1,047,640
Compromised data: Email addresses, IP addresses, Passwords, Usernames

TehetségKapu - 54,357 breached accounts

In March 2025, almost 55k records were breached from the Hungarian education office website TehetségKapu. The data was subsequently published to a popular hacking forum and included email addresses, names and usernames.

Breach date: 26 March 2025
Date added to HIBP: 1 May 2025
Compromised accounts: 54,357
Compromised data: Email addresses, Names, Usernames

Samsung Germany Customer Tickets - 216,333 breached accounts

In March 2025, data from Samsung Germany was compromised in a data breach of their logistics provider, Spectos. Allegedly due to credentials being obtained by malware running on a Spectos employee's machine, the breach included 216k unique email addresses along with names, physical addresses, items purchased from Samsung Germany and related support tickets and shipping tracking numbers.

Breach date: 30 March 2025
Date added to HIBP: 13 April 2025
Compromised accounts: 216,333
Compromised data: Email addresses, Names, Physical addresses, Purchases, Salutations, Shipment tracking numbers, Support tickets

Qraved - 984,519 breached accounts

In July 2021, the Indonesian restaurant website Qraved suffered a data breach that was later redistributed as part of a larger corpus of data. The breach exposed almost 1M unique email addresses along with names, phone numbers, dates of birth and passwords stored as MD5 hashes.

Breach date: 9 July 2021
Date added to HIBP: 9 April 2025
Compromised accounts: 984,519
Compromised data: Dates of birth, Email addresses, Names, Passwords, Phone numbers

Boulanger - 2,077,078 breached accounts

In September 2024, French electronics retailer Boulanger suffered a data breach that exposed over 27M rows of data. The data included 2M unique email addresses along with names, physical addresses, phone numbers and latitude and longitude. The data was later publicly published to a popular hacking forum.

Breach date: 6 September 2024
Date added to HIBP: 8 April 2025
Compromised accounts: 2,077,078
Compromised data: Email addresses, Geographic locations, Names, Phone numbers, Physical addresses

German Doner Kebab - 162,373 breached accounts

In March 2025, data allegedly sourced from German Doner Kebab was published on a popular hacking forum. The data included 162k unique email addresses alongside names, phone numbers and physical addresses. German Doner Kebab subsequently sent a disclosure notice to impacted individuals.

Breach date: 27 March 2025
Date added to HIBP: 30 March 2025
Compromised accounts: 162,373
Compromised data: Email addresses, Names, Phone numbers, Physical addresses