Security incidents

Incidents at named organisations, each linked to the source that reported it: material incident filings companies made to the SEC, breaches verified by Have I Been Pwned, and claims posted by ransomware groups.

142
Confirmed incidents
112
Unconfirmed claims
254
Last 30 days
136
Organisations tracked
2,705,731,734
Records disclosed
ConfirmedData breach2026-02-06

Substack: a data breach

In October 2025, the publishing platform Substack suffered a data breach that was subsequently circulated more widely in February 2026. The breach exposed 663k account holder records containing email addresses along with publicly visible profile information from Substack accounts, such as publication names and bios. A subset of records also included phone numbers.

663,121 recordsSubstackHave I Been Pwned
ConfirmedData breach2026-08-01

SplitVPN: a data breach

In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach . The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).

865,336 recordsSplitVPNHave I Been Pwned
ConfirmedData breach2026-01-27

SoundCloud: a data breach

In December 2025, SoundCloud announced it had discovered unauthorised activity on its platform . The incident allowed an attacker to map publicly available SoundCloud profile data to email addresses for approximately 20% of its users. The impacted data included 30M unique email addresses, names, usernames, avatars, follower and following counts and, in some cases, the user’s country. The attackers later attempted to extort SoundCloud before publicly releasing the data the following month.

29,815,722 recordsSoundCloudHave I Been Pwned
ConfirmedData breach2026-03-26

Sound Radix: a data breach

In March 2026, the audio production tools company Sound Radix disclosed a data breach that they subsequently self-submitted to HIBP . The incident impacted 293k unique email addresses and names. Sound Radix advised that it is possible that additional data including hashed passwords may have been exposed, and that no financial or credit card information was impacted.

292,993 recordsSound RadixHave I Been Pwned
ConfirmedData breach2026-04-04

SongTrivia2: a data breach

In April 2026, the music trivia platform SongTrivia2 suffered a data breach that was subsequently published to a public hacking forum . The data contained a total of 291k unique email addresses sourced from either Google OAuth logins or accounts created on the site, the latter also containing bcrypt password hashes. The data also included names, usernames and avatars.

291,739 recordsSongTrivia2Have I Been Pwned
ConfirmedData breach2026-03-26

Scuf Gaming: a data breach

In June 2015, custom gaming controller maker Scuf Gaming suffered a data breach . The incident exposed 129k unique email addresses along with usernames, display names, IP addresses and password hashes.

128,683 recordsScuf GamingHave I Been Pwned
ConfirmedData breach2026-03-23

RuneScape Boards: a data breach

In around 2011, the now defunct RuneScape Boards forum (also known as RSBoards) suffered a data breach that was later redistributed as part of a larger corpus of data . The vBulletin-based service exposed 223k unique email addresses along with usernames, IP addresses and salted MD5 password hashes.

222,762 recordsRuneScape BoardsHave I Been Pwned
ConfirmedData breach2026-08-13

RingCentral: a data breach

In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addresses and phone numbers. In their disclosure notice , RingCentral advised that the incident affected "a limited portion of RingCentral customers" and that it was communicating directly with those affected.

1,596,490 recordsRingCentralHave I Been Pwned
ConfirmedData breach2026-05-04

Reborn Gaming: a data breach

In April 2026, the gaming community Reborn Gaming suffered a data breach due to a vulnerability in cPanel and WebHost Manager (WHM) . The breach exposed 126 unique email addresses along with IP addresses and Steam IDs. Reborn Gaming self-submitted the data to Have I Been Pwned.

126 recordsReborn GamingHave I Been Pwned
ConfirmedData breach2026-06-18

Ralph Lauren: a data breach

In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresses along with names, phone numbers, genders and age groups.

139,903 recordsRalph LaurenHave I Been Pwned
ConfirmedData breach2026-01-19

Raaga: a data breach

In December 2025, data allegedly breached from the Indian streaming music service "Raaga" was posted for sale to a popular hacking forum . The data contained 10M unique email addresses along with names, genders, ages (in some cases, full date of birth), postcodes and passwords stored as unsalted MD5 hashes.

10,225,145 recordsRaagaHave I Been Pwned
ConfirmedData breach2026-03-02

Quitbro: a data breach

In February 2026, the porn addiction app Quitbro allegedly suffered a data breach that exposed 23k unique email addresses. The data also included users’ years of birth, responses to questions within the app and their last recorded relapse time. The app’s maker, Plantake, did not respond to multiple attempts to contact them about the incident.

22,874 recordsQuitbroHave I Been Pwned
ConfirmedData breach2026-09-01

Questel: a data breach

In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.

1,226,209 recordsQuestelHave I Been Pwned
ConfirmedData breach2026-03-03

Provecho: a data breach

In early 2026, data purportedly sourced from the recipe and meal planning service Provecho was alleged to have been obtained in a breach. The exposed data included 713k unique email address along with username and the creator account holders followed. Provecho has been notified and is aware of the claims surrounding the incident.

712,904 recordsProvechoHave I Been Pwned
ConfirmedData breach2025-10-16

Prosper: a data breach

In September 2025, Prosper announced that it had detected unauthorised access to their systems, which resulted in the exposure of customer and applicant information . The data breach impacted 17.6M unique email addresses, along with other customer information, including US Social Security numbers. Prosper advised that they did not find any evidence of unauthorised access to customer accounts and funds, and that their customer-facing operations were uninterrupted. Further information about the incident is contained in Prosper's FAQs .

17,605,276 recordsProsperHave I Been Pwned
ConfirmedData breach2026-04-27

Pitney Bowes: a data breach

In April 2026, the hacking collective ShinyHunters claimed to have obtained data from Pitney Bowes as part of a broader extortion campaign that also named several other organisations. After negotiations allegedly failed, the group publicly released the data which included 8.2M unique email addresses, along with names, phone numbers and physical addresses. A subset of the data also included Pitney Bowes employee records with job titles.

8,243,989 recordsPitney BowesHave I Been Pwned
ConfirmedData breach2026-01-18

Pass'Sport: a data breach

In December 2025, data from France's Pass'Sport program was posted to a popular hacking forum . Initially misattributed to CAF (the French family allowance fund), the data contained 6.5M unique email addresses affecting 3.5M households. The data also included names, phone numbers, genders and physical addresses. The Ministry of Sports subsequently released a statement acknowledging the incident .

6,366,133 recordsPass'SportHave I Been Pwned
ConfirmedData breach2026-01-31

Panera Bread: a data breach

In January 2026, Panera Bread suffered a data breach that exposed 14M records . After an attempted extortion failed, the attackers published the data publicly, which included 5.1M unique email addresses along with associated account information such as names, phone numbers and physical addresses. Panera Bread subsequently confirmed that "the data involved is contact information" and that authorities were notified.

5,112,502 recordsPanera BreadHave I Been Pwned
ConfirmedData breach2026-07-19

Paidwork: a data breach

In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale . Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The breach also included a broad range of other data relating to the operation of the platform including user profile data, banking information, payout history for workers and passwords stored as bcrypt hashes.

23,272,765 recordsPaidworkHave I Been Pwned
ConfirmedData breach2026-08-19

Oz Hair and Beauty: a data breach

In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack . The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations (suburb and postcode) and purchases.

1,988,331 recordsOz Hair and BeautyHave I Been Pwned
ConfirmedData breach2026-06-18

Operation Endgame 4.0: data obtained by malware

On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation , a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust, the operation remediated almost 15,000 compromised websites and disrupted more than 100 servers and domains used to distribute malware. Authorities initially provided HIBP with 154k impacted email addresses and more than half a million previously unseen passwords. The following week, a further 4M email addresses and 9M passwords relating to the StealC malware operation also targeted by Operation Endgame were provided, followed by another 131k email addresses the following month, bringing the total to more than 4.3M unique email addresses.

4,348,526 recordsHave I Been Pwned
ConfirmedData breach2025-11-13

Operation Endgame 3.0: data obtained by malware

Between 10 and 13 November 2025, the latest phase of Operation Endgame was coordinated from Europol's headquarters in The Hague . The actions targeted one of the biggest infostealer Rhadamanthys, the Remote Access Trojan VenomRAT, and the botnet Elysium, all of which played a key role in international cybercrime. Authorities took down these three large cybercrime enablers and provided 2 million impacted email addresses and 7.4 million passwords to HIBP.

2,046,030 recordsHave I Been Pwned
ConfirmedData breach2026-02-26

Odido: a data breach

In February 2026, Dutch telco Odido was the victim of a data breach and subsequent extortion attempt . Shortly after, a total of 6M unique email addresses were published across four separate data releases over consecutive days. The exposed data includes names, physical addresses, phone numbers, bank account numbers, dates of birth, customer service notes and passport, driver’s licence and European national ID numbers. Odido has published a disclosure notice including an FAQ to support affected customers.

6,077,025 recordsOdidoHave I Been Pwned
ConfirmedData breach2026-08-23

NIUS: a data breach

In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly . The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type and expiry).

6,090 recordsNIUSHave I Been Pwned
ConfirmedData breach2025-10-27

MyVidster (2025): a data breach

In October 2025, the data of almost 4M MyVidster users was posted to a public hacking forum . Separate to the 2015 breach, this incident exposed usernames, email addresses and in a small number of cases, profile photos.

3,864,364 recordsMyVidster (2025)Have I Been Pwned
Page 2 of 6 · 142 incidentsPreviousNext

Filings come from SEC EDGAR and are filtered to 8-K submissions that declare Item 1.05, not merely mention it. Breach records come from Have I Been Pwned. Ransomware claims come from RansomLook, used under CC BY 4.0; we store metadata only and never leak links.