Breach Intelligence

2,693

Total breached databases

Search breaches

In April 2021, a large data set of over 500 million Facebook users was made freely available for download. Encompassing approximately 20% of Facebook's subscribers, the data was allegedly obtained by exploiting a vulnerability Facebook advises they rectified in August 2019. The primary value of the data is the association of phone numbers to identities; whilst each record included phone, only 2.5 million contained an email address. Most records contained names and genders with many also including dates of birth, location, relationship status and employer.
  • Date: Aug 2019
  • Domain: facebook.com
  • Category: Social Media & Communication
  • Records Announced: 509,458,528
  • Numer of lines: 494,061,315
  • Records Imported: 494,004,907
  • Size: 76.57 GB
  • Data: Birthdates, Company Information, Email Addresses, Genders, Geographic Locations, Names, Phone Numbers, Relationship Statuses
  • Passwords: No
  • Imported:
  • Sources:
In March 2020 the Chinese site Sina Weibo had faced a data breach exposing over 500 million Weibo user records on darkweb.
  • Date: Mar 2020
  • Domain: weibo.com
  • Country: China
  • Category: Social Media & Communication
  • Records Announced: 503,925,370
  • Numer of lines: 503,925,370
  • Records Imported: 503,925,368
  • Size: 11.26 GB
  • Data: Government IDs, Phone Numbers
  • Passwords: No
  • Imported:
  • Source: zdnet.com
In November 2022, a significant data leak involving WhatsApp was reported. Approximately 487 million WhatsApp user records were offered for sale on an underground forum. This data included mobile phone numbers from 84 countries. It is speculated that the data might have been obtained through scraping, which violates WhatsApp's terms of service. However, the exact method used by the seller was not disclosed.
  • Date: Nov 2022
  • Domain: whatsapp.com
  • Category: Social Media & Communication
  • Records Announced: 500,000,000
  • Numer of lines: 366,337,738
  • Records Imported: 366,337,631
  • Size: 4.63 GB
  • Data: Phone Numbers
  • Passwords: No
  • Imported:
  • Source: cybernews.com
In approximately August 2021, hundreds of gigabytes of data produced by Bureau van Dijk (BVD) was obtained and later published to a popular hacking forum. BVD claims to "capture and treat private company information for better decision making and increased efficiency", and the corpus of data released contained hundreds of millions of lines about corporations and individuals, including personal information such as names and dates of birth. The data also included 28M unique email addresses along with physical addresses (presumedly corporate locations), phone numbers and job titles.
  • Date: Aug 19, 2021
  • Domain: bvdinfo.com
  • Country: Netherlands
  • Category: Data Brokers
  • Records Announced: 484,305,582
  • Numer of lines: 484,305,582
  • Records Imported: 701,192,728
  • Size: 426.82 GB
  • Data: Birthdates, Email Addresses, Job Information, Names, Phone Numbers, Physical Locations
  • Passwords: No
  • Imported:
  • Source: haveibeenpwned.com
This collection is part of a larger series of data dumps, including Collections #1 through #5, which compiled email addresses and passwords from thousands of sources, from previously known data breaches and some new alleged breaches. Collection #1 alone contained about 2.7 billion records, including 1.2 billion unique email and password combinations, 773 million unique email addresses, and 21 million unique plaintext passwords. Additional collections, named Collections #2 through #5, along with "AP MYR&ZABUGOR #2" and "ANTIPUBLIC #1," were also discovered, significantly adding to the scope of compromised data​.
  • Date: 2016
  • Category: Compilations & Combo lists
  • Numer of lines: 479,310,893
  • Records Imported: 477,890,374
  • Size: 14.11 GB
  • Data: Email Addresses, Passwords
  • Passwords: Plaintext
  • Imported:
  • Source: recordedfuture.com