Have I Been Pwned
Check if you have an email address or password that has been compromised in a data breach. Created and maintained by @troyhunt@infosec.exchange
New breach: Houston City College was the target of a ShinyHunters extortion attempt last month. Over 800k unique email addresses were later published with name, physical address, phone number and more. 30% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/HoustonCityCollege
New breach: My Lovely AI, a NSFW AI girlfriend platform, suffered a breach earlier this week that exposed over 100k unique email addresses. The data also included AI prompts and links to the resulting images. 23% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/MyLovelyAI
New sensitive breach: Exact Sciences was targeted by a ShinyHunters extortion campaign last month. The group later published 10.9M email addresses and other personal data, including health information. 75% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/ExactSciences
New breach: Inter-Con Security was targeted by ShinyHunters in a pay or leak extortion campaign in June. 276k unique email addresses were subsequently published, along with names, physical addresses and more. 44% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/InterConSecurity
New breach: Moody Bible Institute was targeted by a ShinyHunters extortion campaign last month with 2.3M email addresses later published. Data also included name, address, phone and other personal info. 76% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/MoodyBibleInstitute
New breach: Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign. This week, the group published 140k email addresses, names, phone numbers and other personal data. 85% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/RalphLauren
New breach: The Windows93 parody site suffered a breach of its Myspace93 sub-site in 2021. The breach exposed 46k email and IP addresses, usernames and plain text passwords. 70% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Windows93
New stealer log corpus: A collection of hundreds of millions of stealer log records containing 56M unique email addresses has been added. The data also contained 124M unique passwords added to Pwned Passwords. 86% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/June2026StealerLogs
New breach: McGraw Hill suffered a breach last week attributed to a Salesforce misconfiguration. Data leaked today included 13.5M email addresses. Some records included name, phone and physical address. 47% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/McGrawHill
New breach: 7-Eleven was targeted by the ShinyHunters extortion group last month, with 185k email addresses related to franchisees impacted. Data also included name, physical address, phone number and DoB. 53% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/7-Eleven
New breach: Vimeo was named in a ShinyHunters extortion campaign following a compromise of the Anodot analytics service. The incident exposed hundreds of gigabytes of data, including 119k unique email addresses. 56% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Vimeo
New breach: Ameriprise was the victim of a ShinyHunters extortion campaign in March. The published data contained 500k email addresses along with names, phone numbers, physical addresses and employer info. 65% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Ameriprise
New breach: Edmunds was listed by ShinyHunters as allegedly breached in Jan, with the data later published online. It contained 178k unique email addresses, usernames, IP addresses, phone numbers and passwords. 91% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Edmunds
New breach: The Atlas Menu GTA V and CS2 cheat service had 64k accounts breached yesterday. Data includes email and IP addresses, usernames, passwords stored as bcrypt hashes and support tickets. 49% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/AtlasMenu
New breach: Amtrak was claimed as a victim of ShinyHunters earlier this month with over 2M email addresses then published this week. Data also included names, physical addresses and support tickets. 80% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Amtrak
New breach: CFGI was targeted in a ShinyHunters extortion campaign in March. They subsequently published 243k unique email addresses along with names and largely corporate contact information. 53% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/CFGI
New breach: Madison Square Garden Sports was the target of a ShinyHunters extortion campaign earlier this month. Almost 10M email addresses and extensive staff and customer relationship data was later published. 80% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/MadisonSquareGardenSports
New breach: Mytheresa was targeted by ShinyHunters in an extortion campaign last month. The leaked data contained 84k email addresses along with name, address, phone, purchase and partial card data. 97% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Mytheresa
New breach: American Tower was the target of a ShinyHunters extortion campaign earlier this month. Leaked data included 217k unique email addresses along with names, phone numbers, and addresses. 62% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/AmericanTower
New breach: Woflow was named as a ShinyHunters victim in March, after which hundreds of thousands of email addresses, names, phone numbers and physical addresses were publicly dumped. 75% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Woflow
New breach: LegionProxy had 10k email addresses breached last month. Data also included bcrypt password hashes, names and purchases. 31% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/LegionProxy
New breach: ShinyHunters claimed Pitney Bowes as an extortion victim last week before later dumping 8.2M email addresses publicly. Data also included name, physical address, phone number and employee job title. 53% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/PitneyBowes
New breach: Abrigo was targeted by ShinyHunters last month, who subsequently published over 700k unique email addresses allegedly taken from their Salesforce instance. Data also included business contact info. 57% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Abrigo
New breach: Canada Life was named as a ShinyHunters victim last month, after which data containing more than 200k email addresses was published. The incident also impacted name, phone number and physical address. 47% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/CanadaLife
New breach: Cushman & Wakefield was named as a ShinyHunters victim last week, after which mostly corporate contact records were published. Impacted data included email address, job title and company address. 21% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/CushmanWakefield
New breach: Zara was named as a ShinyHunters victim last month, after which data containing 197k unique email addresses was published. Impacted data included customer support records, product SKUs and order IDs. 60% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Zara
New self-submitted breach: Reborn Gaming had 126 unique email addresses breached last week due to a cPanel/WHM vulnerability. Data also included IP address and Steam ID. 68% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/RebornGaming
New breach: The Dragonica Lunaris private server suffered a breach in December which exposed 126k email addresses, usernames, dates of birth and bcrypt password hashes. 69% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Dragonica
New breach: Charter Communications was named in a ShinyHunters "pay or leak" extortion campaign last week after which 4.9M unique email addresses along with name, phone number and physical address were published. 68% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Charter
New breach: ShinyHunters claimed terabytes of data were exfiltrated from ZenBusiness then released publicly after an extortion attempt. Data included 5M unique email addresses, many with names and phone numbers. 53% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/ZenBusiness
New breach: Aman was the target of a ShinyHunters "pay or leak" extortion that resulted in over 200k email addresses being published this week. Data also included name, address, phone, nationality and VIP status. 74% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Aman
New breach: Data allegedly taken from CTT, Portugal's postal service, appeared on a hacking forum last month. It contained 468k unique email addresses, along with name, phone number and parcel tracking number. 55% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/CTT
New breach: Marcus & Millichap was named in a ShinyHunters "pay or leak" extortion campaign last month. Impacted data included 1.8M unique email addresses, name, phone number and employment-related info. 70% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/MarcusMillichap
New breach: Addi was named as a ShinyHunters victim earlier this month and data containing 34M email addresses allegedly obtained from the platform were published. Credit-related data points were also included. 29% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Addi
New breach: Cruise operator Carnival was targeted in a ShinyHunters “pay or leak” attack last week. 8.7M records with 7.5M email addresses and loyalty program data were published yesterday. 85% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Carnival
New breach: Kemper was targeted by ShinyHunters last month in an extortion campaign resulting in 269k email addresses being published. Data also included names, phone numbers, addresses and partial card data. 53% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Kemper