Breach Intelligence

2,843

Total breached databases

In September 2021, the domain registrar and web host Epik suffered a significant data breach, allegedly in retaliation for hosting alt-right websites. The breach exposed a huge volume of data not just of Epik customers, but also scraped WHOIS records belonging to individuals and organisations who were not Epik customers. The data included over 15 million unique email addresses (including anonymised versions for domain privacy), names, phone numbers, physical addresses, purchases and passwords stored in various formats.
  • Data: Email Addresses Names Order Information Phone Numbers Physical Locations
  • Imported:
  • Records Imported: 88,043
  • Number of lines: 704,291,909
  • Size: 177.01 GB
  • Passwords: No
In mid-2012, the real-time strategy game War Inc. suffered a data breach. The attack resulted in the exposure of over 1 million accounts including usernames, email addresses and salted MD5 hashes of passwords.
  • Data: Email Addresses Passwords Site Activity Usernames
  • Imported:
  • Records Imported: 761,863
  • Number of lines: 762,022
  • Size: 22.73 MB
  • Passwords: vBulletin
  • Cracked: 118%
In December 2020, the travel platform Minube.com, known for its features related to travel planning and recommendations, suffered a data breach. The exposed information reportedly consisted of approximately 1,068,978 lines of data. Among the compromised data were email addresses and passwords.
  • Date: Dec 30, 2020
  • Domain: minube.com
  • Country: Spain
  • Category: Travel
  • Records Announced: 1,067,608
  • Source: hashmob.net
  • Data: Email Addresses Passwords
  • Imported:
  • Records Imported: 2,134,369
  • Number of lines: 2,136,586
  • Size: 56.59 MB
  • Passwords: MD5
  • Cracked: 116%
In January 2023, a database backup from Reebonz.co.kr, a luxury goods marketplace, was leaked. The breach exposed approximately 1.2 million records and occurred due to an AWS S3 bucket being accessed via an exposed environment file on a web application called Miniprofiler, which had been indexed by Google and contained AWS keys. Among the compromised data were email addresses and passwords.
  • Date: Jan 2023
  • Domain: rebonz.co.kr
  • Threat Actor: donjuji
  • Country: South Korea
  • Category: E-commerce & Retail
  • Records Announced: 1,183,324
  • Source: hashmob.net
  • Data: Email Addresses Passwords
  • Imported:
  • Records Imported: 1,183,324
  • Number of lines: 1,183,325
  • Size: 70.71 MB
  • Passwords: MySQL
  • Cracked: 58%
In August 2016, the mobile app to "compare anything" known as Wishbone suffered a data breach. The data contained 9.4 million records with 2.2 million unique email addresses and was allegedly a subset of the complete data set. The exposed data included genders, birthdates, email addresses and phone numbers for an audience predominantly composed of teenagers and young adults.
  • Data: Birthdates Email Addresses Genders Names Phone Numbers Security Credentials Usernames
  • Imported:
  • Records Imported: 7,656,195
  • Number of lines: 7,656,356
  • Size: 254.7 MB
  • Passwords: MD5
  • Cracked: 83%