Security incidents

Incidents at named organisations, each linked to the source that reported it: material incident filings companies made to the SEC, breaches verified by Have I Been Pwned, and claims posted by ransomware groups.

142
Confirmed incidents
112
Unconfirmed claims
254
Last 30 days
136
Organisations tracked
2,705,731,734
Records disclosed

This view includes organisations named on ransomware leak sites. Those are the groups’ claims, not confirmed breaches — the organisations have not confirmed them and no filing or verified record supports them.

ConfirmedData breach2026-04-26

Udemy: a data breach

In April 2026, online training company Udemy was the victim of a “pay or leak” extortion attempt perpetrated by the ShinyHunters group. The data was subsequently leaked publicly and contained 1.4M unique email addresses belonging to customers and instructors. The data also included names, physical addresses, phone numbers, employer information and instructor payout methods including PayPal, cheque and bank transfer.

1,401,259 recordsUdemyHave I Been Pwned
ConfirmedData breach2026-02-10

Toy Battles: a data breach

In February 2026, the online gaming community Toy Battles suffered a data breach. The incident exposed 1k unique email addresses alongside usernames, IP addresses and chat logs. Following the breach, Toy Battles self-submitted the data to Have I Been Pwned.

1,017 recordsToy BattlesHave I Been Pwned
ConfirmedData breach2025-12-18

The Botting Network: a data breach

In August 2012, the forum for making money with botting "The Botting Network" suffered a data breach that exposed 96k user records . The now defunct vBulletin forum leaked 96k email addresses, usernames, dates of birth and salted MD5 password hashes.

96,320 recordsThe Botting NetworkHave I Been Pwned
ConfirmedData breach2026-06-28

Sysco: a data breach

In June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign . Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact information including names, phone numbers, physical addresses, internal job titles, and customer feedback.

2,691,852 recordsSyscoHave I Been Pwned
ConfirmedData breach2025-10-21

Synthient Stealer Log Threat Data: credentials harvested by infostealer malware

During 2025, Synthient aggregated billions of records of "threat data" from various internet sources . The data contained 183M unique email addresses alongside the websites they were entered into and the passwords used. After normalising and deduplicating the data, 183 million unique email addresses remained, each linked to the website where the credentials were captured, and the password used. This dataset is now searchable in HIBP by email address, password, domain, and the site on which the credentials were entered.

182,962,095 recordsHave I Been Pwned
ConfirmedData breach2025-11-06

Synthient Credential Stuffing Threat Data: a data breach

During 2025, the threat-intelligence firm Synthient aggregated 2 billion unique email addresses disclosed in credential-stuffing lists found across multiple malicious internet sources . Comprised of email addresses and passwords from previous data breaches, these lists are used by attackers to compromise other, unrelated accounts of victims who have reused their passwords. The data also included 1.3 billion unique passwords, which are now searchable in Pwned Passwords. Working to turn breached data into awareness, Synthient partnered with HIBP to help victims of cybercrime understand their exposure.

1,957,476,021 recordsHave I Been Pwned
ConfirmedData breach2026-07-20

Suno: a data breach

In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year . The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a small portion of the corpus, the breach also included tens of thousands of Stripe records relating to purchases, containing names, physical addresses, purchase amounts and partial credit card data including the card type, expiry date and last 4 digits. The company advised that "Suno does not have access to customers' full credit card numbers in Stripe".

55,282,226 recordsSunoHave I Been Pwned
ConfirmedData breach2026-04-01

SUCCESS: a data breach

In March 2026, the personal development and achievement media brand SUCCESS suffered a data breach . The incident exposed 250k unique email addresses along with names, IP addresses, phone numbers and, for a limited number of staff members, bcrypt password hashes. The data also included orders containing physical addresses and the payment method used. In SUCCESS' disclosure notice , they advised their system had also been abused to send offensive newsletters with quotes falsely attributed to contributors.

253,510 recordsSUCCESSHave I Been Pwned
ConfirmedData breach2026-02-06

Substack: a data breach

In October 2025, the publishing platform Substack suffered a data breach that was subsequently circulated more widely in February 2026. The breach exposed 663k account holder records containing email addresses along with publicly visible profile information from Substack accounts, such as publication names and bios. A subset of records also included phone numbers.

663,121 recordsSubstackHave I Been Pwned
ConfirmedData breach2026-08-01

SplitVPN: a data breach

In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach . The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).

865,336 recordsSplitVPNHave I Been Pwned
ConfirmedData breach2026-01-27

SoundCloud: a data breach

In December 2025, SoundCloud announced it had discovered unauthorised activity on its platform . The incident allowed an attacker to map publicly available SoundCloud profile data to email addresses for approximately 20% of its users. The impacted data included 30M unique email addresses, names, usernames, avatars, follower and following counts and, in some cases, the user’s country. The attackers later attempted to extort SoundCloud before publicly releasing the data the following month.

29,815,722 recordsSoundCloudHave I Been Pwned
ConfirmedData breach2026-03-26

Sound Radix: a data breach

In March 2026, the audio production tools company Sound Radix disclosed a data breach that they subsequently self-submitted to HIBP . The incident impacted 293k unique email addresses and names. Sound Radix advised that it is possible that additional data including hashed passwords may have been exposed, and that no financial or credit card information was impacted.

292,993 recordsSound RadixHave I Been Pwned
ConfirmedData breach2026-04-04

SongTrivia2: a data breach

In April 2026, the music trivia platform SongTrivia2 suffered a data breach that was subsequently published to a public hacking forum . The data contained a total of 291k unique email addresses sourced from either Google OAuth logins or accounts created on the site, the latter also containing bcrypt password hashes. The data also included names, usernames and avatars.

291,739 recordsSongTrivia2Have I Been Pwned
ConfirmedData breach2026-03-26

Scuf Gaming: a data breach

In June 2015, custom gaming controller maker Scuf Gaming suffered a data breach . The incident exposed 129k unique email addresses along with usernames, display names, IP addresses and password hashes.

128,683 recordsScuf GamingHave I Been Pwned
ConfirmedData breach2026-03-23

RuneScape Boards: a data breach

In around 2011, the now defunct RuneScape Boards forum (also known as RSBoards) suffered a data breach that was later redistributed as part of a larger corpus of data . The vBulletin-based service exposed 223k unique email addresses along with usernames, IP addresses and salted MD5 password hashes.

222,762 recordsRuneScape BoardsHave I Been Pwned
ConfirmedData breach2026-08-13

RingCentral: a data breach

In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addresses and phone numbers. In their disclosure notice , RingCentral advised that the incident affected "a limited portion of RingCentral customers" and that it was communicating directly with those affected.

1,596,490 recordsRingCentralHave I Been Pwned
ConfirmedData breach2026-05-04

Reborn Gaming: a data breach

In April 2026, the gaming community Reborn Gaming suffered a data breach due to a vulnerability in cPanel and WebHost Manager (WHM) . The breach exposed 126 unique email addresses along with IP addresses and Steam IDs. Reborn Gaming self-submitted the data to Have I Been Pwned.

126 recordsReborn GamingHave I Been Pwned
ConfirmedData breach2026-06-18

Ralph Lauren: a data breach

In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresses along with names, phone numbers, genders and age groups.

139,903 recordsRalph LaurenHave I Been Pwned
ConfirmedData breach2026-01-19

Raaga: a data breach

In December 2025, data allegedly breached from the Indian streaming music service "Raaga" was posted for sale to a popular hacking forum . The data contained 10M unique email addresses along with names, genders, ages (in some cases, full date of birth), postcodes and passwords stored as unsalted MD5 hashes.

10,225,145 recordsRaagaHave I Been Pwned
ConfirmedData breach2026-03-02

Quitbro: a data breach

In February 2026, the porn addiction app Quitbro allegedly suffered a data breach that exposed 23k unique email addresses. The data also included users’ years of birth, responses to questions within the app and their last recorded relapse time. The app’s maker, Plantake, did not respond to multiple attempts to contact them about the incident.

22,874 recordsQuitbroHave I Been Pwned
ConfirmedData breach2026-09-01

Questel: a data breach

In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.

1,226,209 recordsQuestelHave I Been Pwned
ConfirmedData breach2026-03-03

Provecho: a data breach

In early 2026, data purportedly sourced from the recipe and meal planning service Provecho was alleged to have been obtained in a breach. The exposed data included 713k unique email address along with username and the creator account holders followed. Provecho has been notified and is aware of the claims surrounding the incident.

712,904 recordsProvechoHave I Been Pwned
ConfirmedData breach2025-10-16

Prosper: a data breach

In September 2025, Prosper announced that it had detected unauthorised access to their systems, which resulted in the exposure of customer and applicant information . The data breach impacted 17.6M unique email addresses, along with other customer information, including US Social Security numbers. Prosper advised that they did not find any evidence of unauthorised access to customer accounts and funds, and that their customer-facing operations were uninterrupted. Further information about the incident is contained in Prosper's FAQs .

17,605,276 recordsProsperHave I Been Pwned
ConfirmedData breach2026-04-27

Pitney Bowes: a data breach

In April 2026, the hacking collective ShinyHunters claimed to have obtained data from Pitney Bowes as part of a broader extortion campaign that also named several other organisations. After negotiations allegedly failed, the group publicly released the data which included 8.2M unique email addresses, along with names, phone numbers and physical addresses. A subset of the data also included Pitney Bowes employee records with job titles.

8,243,989 recordsPitney BowesHave I Been Pwned
ConfirmedData breach2026-01-31

Panera Bread: a data breach

In January 2026, Panera Bread suffered a data breach that exposed 14M records . After an attempted extortion failed, the attackers published the data publicly, which included 5.1M unique email addresses along with associated account information such as names, phone numbers and physical addresses. Panera Bread subsequently confirmed that "the data involved is contact information" and that authorities were notified.

5,112,502 recordsPanera BreadHave I Been Pwned
Page 4 of 10 · 227 incidentsPreviousNext

Filings come from SEC EDGAR and are filtered to 8-K submissions that declare Item 1.05, not merely mention it. Breach records come from Have I Been Pwned. Ransomware claims come from RansomLook, used under CC BY 4.0; we store metadata only and never leak links.