Incident tracker

Recent cyber attacks and data breaches

This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.

DisclosedCompanyWhat happenedTypeRecordsSource
2025-11-23ADDAADDA: a data breach

In March 2025, data allegedly breached from the ADDA housing societies service was posted to a public hacking forum . The data contained over 1.8M unique email addresses along with names, phone numbers and MD5 password hashes.

Data breach
1,829,314Have I Been Pwned
2025-11-20International Kiteboarding OrganizationInternational Kiteboarding Organization: a data breach

In November 2025, the International Kiteboarding Organization suffered a data breach that exposed 340k user records . The data was subsequently listed for sale on a hacking forum and included email addresses, names, usernames and in many cases, the user's city and country.

Data breach
340,349Have I Been Pwned
2025-11-20Beckett CollectiblesBeckett Collectibles: a data breach

In November 2025, Beckett Collectibles experienced a data breach accompanied by website content defacement . The stolen data was later advertised for sale on a prominent hacking forum, with portions subsequently released publicly. The publicly circulating data initially included more than 500k email addresses reportedly belonging to North American customers, before a larger corpus of over 1M addresses was published the following month. The impacted data included names, usernames, phone numbers and physical addresses.

Data breach
1,041,238Have I Been Pwned
2025-11-20EurofiberEurofiber: a data breach

In November 2025, Eurofiber France disclosed a data breach of its ticket management platform . Data containing 10k unique email addresses and a smaller number of names and phone numbers was subsequently leaked. A threat actor claiming responsibility for the breach alleges to have additional, more sensitive data including screenshots, VPN configuration files, credentials, source code, certificates, archives, and SQL backup files.

Data breach
10,003Have I Been Pwned
2025-11-20VultrVultr: a data breach

In March 2023, the "AI-first global cloud platform" Vultr disclosed a security incident at a third-party vendor . Dating back to the previous year, the incident was attributed to the ActiveCampaign email marketing service provider and resulted in the exposure of 188k unique email addresses. A small number of records also included name, IP address and country of origin. No Vultr systems or additional customer data were impacted. Vultr subsequently self-submitted the impacted data to HIBP.

Data breach
187,872Have I Been Pwned
2025-11-13Operation Endgame 3.0Operation Endgame 3.0: data obtained by malware

Between 10 and 13 November 2025, the latest phase of Operation Endgame was coordinated from Europol's headquarters in The Hague . The actions targeted one of the biggest infostealer Rhadamanthys, the Remote Access Trojan VenomRAT, and the botnet Elysium, all of which played a key role in international cybercrime. Authorities took down these three large cybercrime enablers and provided 2 million impacted email addresses and 7.4 million passwords to HIBP.

Data breach
2,046,030Have I Been Pwned
2025-11-08TISZA VilágTISZA Világ: a data breach

In late October 2025, data breached from the Hungarian political party TISZA was published online before being extensively redistributed . Stemming from a compromise of the TISZA Világ service earlier in the month, the breach exposed 200k records of personal data including email addresses along with names, phone numbers and physical addresses.

Data breach
198,520Have I Been Pwned
2025-11-06Synthient Credential Stuffing Threat DataSynthient Credential Stuffing Threat Data: a data breach

During 2025, the threat-intelligence firm Synthient aggregated 2 billion unique email addresses disclosed in credential-stuffing lists found across multiple malicious internet sources . Comprised of email addresses and passwords from previous data breaches, these lists are used by attackers to compromise other, unrelated accounts of victims who have reused their passwords. The data also included 1.3 billion unique passwords, which are now searchable in Pwned Passwords. Working to turn breached data into awareness, Synthient partnered with HIBP to help victims of cybercrime understand their exposure.

Data breach
1,957,476,021Have I Been Pwned
2025-10-27MyVidster (2025)MyVidster (2025): a data breach

In October 2025, the data of almost 4M MyVidster users was posted to a public hacking forum . Separate to the 2015 breach, this incident exposed usernames, email addresses and in a small number of cases, profile photos.

Data breach
3,864,364Have I Been Pwned
2025-10-21Synthient Stealer Log Threat DataSynthient Stealer Log Threat Data: credentials harvested by infostealer malware

During 2025, Synthient aggregated billions of records of "threat data" from various internet sources . The data contained 183M unique email addresses alongside the websites they were entered into and the passwords used. After normalising and deduplicating the data, 183 million unique email addresses remained, each linked to the website where the credentials were captured, and the password used. This dataset is now searchable in HIBP by email address, password, domain, and the site on which the credentials were entered.

Data breach
182,962,095Have I Been Pwned

About this tracker

435
Incidents
287
Ransomware gang claims
722
Last 30 days
389
Companies tracked
2,742,501,669
Records disclosed