Incident tracker

Recent cyber attacks and data breaches

This view includes companies named on ransomware leak sites. Those are the gangs’ claims, not verified breaches.

DisclosedCompanyWhat happenedTypeRecordsSource
2025-11-08TISZA VilágTISZA Világ: a data breach

In late October 2025, data breached from the Hungarian political party TISZA was published online before being extensively redistributed . Stemming from a compromise of the TISZA Világ service earlier in the month, the breach exposed 200k records of personal data including email addresses along with names, phone numbers and physical addresses.

Data breach
198,520Have I Been Pwned
2025-11-06Synthient Credential Stuffing Threat DataSynthient Credential Stuffing Threat Data: a data breach

During 2025, the threat-intelligence firm Synthient aggregated 2 billion unique email addresses disclosed in credential-stuffing lists found across multiple malicious internet sources . Comprised of email addresses and passwords from previous data breaches, these lists are used by attackers to compromise other, unrelated accounts of victims who have reused their passwords. The data also included 1.3 billion unique passwords, which are now searchable in Pwned Passwords. Working to turn breached data into awareness, Synthient partnered with HIBP to help victims of cybercrime understand their exposure.

Data breach
1,957,476,021Have I Been Pwned
2025-10-27MyVidster (2025)MyVidster (2025): a data breach

In October 2025, the data of almost 4M MyVidster users was posted to a public hacking forum . Separate to the 2015 breach, this incident exposed usernames, email addresses and in a small number of cases, profile photos.

Data breach
3,864,364Have I Been Pwned
2025-10-21Synthient Stealer Log Threat DataSynthient Stealer Log Threat Data: credentials harvested by infostealer malware

During 2025, Synthient aggregated billions of records of "threat data" from various internet sources . The data contained 183M unique email addresses alongside the websites they were entered into and the passwords used. After normalising and deduplicating the data, 183 million unique email addresses remained, each linked to the website where the credentials were captured, and the password used. This dataset is now searchable in HIBP by email address, password, domain, and the site on which the credentials were entered.

Data breach
182,962,095Have I Been Pwned
2025-10-16ProsperProsper: a data breach

In September 2025, Prosper announced that it had detected unauthorised access to their systems, which resulted in the exposure of customer and applicant information . The data breach impacted 17.6M unique email addresses, along with other customer information, including US Social Security numbers. Prosper advised that they did not find any evidence of unauthorised access to customer accounts and funds, and that their customer-facing operations were uninterrupted. Further information about the incident is contained in Prosper's FAQs .

Data breach
17,605,276Have I Been Pwned
2025-10-15Hello CakeHello Cake: a data breach

In July 2025, the sexual healthcare product maker Hello Cake suffered a data breach . The data was subsequently posted on a public hacking forum and included 23k unique email addresses along with names, phone numbers, physical addresses, dates of birth and purchases.

Data breach
22,907Have I Been Pwned
2025-10-11Vietnam AirlinesVietnam Airlines: a data breach

In October 2025, data stolen from the Salesforce instances of multiple companies by a hacking group calling itself "Scattered LAPSUS$ Hunters" was publicly released . Among the affected organisations was Vietnam Airlines, which had 7.3M unique customer email addresses exposed following a breach of its Salesforce environment in June of that year. The compromised data also included names, phone numbers, dates of birth, and loyalty program membership numbers.

Data breach
7,316,915Have I Been Pwned
2025-10-07AdpostAdpost: a data breach

In February 2025, data obtained from an earlier Adpost breach surfaced. The dataset contained 3.3M records including email addresses, usernames, and display names. Adpost later published a disclosure notice and advised they'd forced a credential refresh, among other actions.

Data breach
3,339,512Have I Been Pwned
2025-10-04Artists&ClientsArtists&Clients: a data breach

In August 2025, the "marketplace that connects artists to prospective clients" Artists&Clients, suffered a data breach and subsequent ransom demand of US$50k . The data was subsequently leaked publicly and included 95k unique email addresses alongside usernames, IP addresses and bcrypt password hashes.

Data breach
95,351Have I Been Pwned
2025-10-03HomeRefillHomeRefill: a data breach

In April 2020, now defunct Brazilian e-commerce platform HomeRefill suffered a data breach that was later redistributed as part of a larger corpus of data . The data included 187k unique email addresses along with names, phone numbers, dates of birth and salted password hashes.

Data breach
187,457Have I Been Pwned

About this tracker

442
Incidents
314
Ransomware gang claims
756
Last 30 days
414
Companies tracked
2,742,606,708
Records disclosed