Security incidents

Incidents at named organisations, each linked to the source that reported it: material incident filings companies made to the SEC, breaches verified by Have I Been Pwned, and claims posted by ransomware groups.

142
Confirmed incidents
112
Unconfirmed claims
254
Last 30 days
136
Organisations tracked
2,705,731,734
Records disclosed
ConfirmedData breach2026-03-02

Lovora: a data breach

In February 2026, the couples and relationship app Lovora allegedly suffered a data breach that exposed 496k unique email addresses. The data also included users’ display names and profile photos, along with other personal information collected through use of the app. The app’s maker, Plantake, did not respond to multiple attempts to contact them about the incident.

495,556 recordsHave I Been Pwned
ConfirmedData breach2026-05-06

LegionProxy: a data breach

In April 2026, the commercial residential and ISP proxy network LegionProxy suffered a data breach . The incident exposed 10k email addresses, bcrypt password hashes, names and purchases.

10,144 recordsLegionProxyHave I Been Pwned
ConfirmedData breach2025-10-03

Latest Pilot Jobs: a data breach

In August 2022, the Latest Pilot Jobs website suffered a data breach that later appeared on a popular hacking forum before being redistributed as part of a larger corpus of data . The data included 119k unique email addresses along with names, usernames and unsalted MD5 password hashes.

118,864 recordsLatest Pilot JobsHave I Been Pwned
ConfirmedData breach2026-03-02

KomikoAI: a data breach

In February, the AI-powered comic generation platform KomikoAI suffered a data breach . The incident exposed 1M unique email addresses along with names, user posts and the AI prompts used to generate content. The exposed data enables the mapping of individual AI prompts to specific email addresses.

1,060,191 recordsKomikoAIHave I Been Pwned
ConfirmedData breach2025-12-06

KinoKong: a data breach

In March 2021, the Russian online streaming service KinoKong suffered a data breach that was later redistributed as part of a larger corpus of data . The breach exposed over 800k unique email addresses along with names, usernames, IP addresses and MD5 password hashes.

817,808 recordsKinoKongHave I Been Pwned
ConfirmedData breach2026-05-28

Kemper: a data breach

In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign . The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part of a broader campaign targeting hundreds of organisations using the same method. The group later published tens of gigabytes of data they claimed included internal directory data, Salesforce records and Stripe payment logs. Among the 269k unique email addresses were names, phone numbers, physical addresses and partial payment card data including the last 4 digits, expiry dates and card brands. Kemper confirmed the incident and stated they had engaged third-party cybersecurity experts and notified law enforcement.

269,299 recordsKemperHave I Been Pwned
ConfirmedData breach2026-06-15

June 2026 Stealer Logs: credentials harvested by infostealer malware

In June 2026, a collection of accumulated stealer logs from various sources was added to HIBP. The corpus comprised 56M unique email addresses across hundreds of millions of stealer log records. The data also contained 124M unique passwords, which have been added to Pwned Passwords and are now searchable. Individuals can view any records captured against their email address in the stealer logs section of their dashboard . Organisations can see logs affecting their domain via the stealer logs API .

56,278,397 recordsHave I Been Pwned
ConfirmedData breach2026-06-20

JCPenney: a data breach

In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed records indicated they primarily related to internal HR systems and impacted current and former employees. The data included 368k corporate and personal email addresses, names, dates of birth, Social Security numbers, phone numbers and home addresses.

368,418 recordsJCPenneyHave I Been Pwned
ConfirmedData breach2026-08-05

Inter-Con Security: a data breach

In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign . The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompassed a combination of contacts, internal users and leads.

276,114 recordsInter-Con SecurityHave I Been Pwned
ConfirmedData breach2026-01-11

Instagram: a data breach

In January 2026, data allegedly scraped via an Instagram API was posted to a popular hacking forum . The dataset contained 17M rows of public Instagram information, including usernames, display names, account IDs, and in some cases, geolocation data. Of these records, 6.2M included an associated email address, and some also contained a phone number. The scraped data appears to be unrelated to password reset requests initiated on the platform , despite coinciding in timeframe. There is no evidence that passwords or other sensitive data were compromised.

6,215,150 recordsInstagramHave I Been Pwned
ConfirmedData breach2026-06-15

Infinite Campus: a data breach

In March 2026, the student information system Infinite Campus was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they alleged was taken from Infinite Campus, containing 137k unique email addresses along with names, phone numbers, physical addresses and support tickets. Infinite Campus subsequently sent notifications , advising that the exposed data largely consisted of "names and contact information for school staff" and that "the majority is directory information commonly found on school websites".

137,123 recordsInfinite CampusHave I Been Pwned
ConfirmedData breach2026-07-28

Houston City College: a data breach

In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and other personal information relating to both current students and alumni.

831,642 recordsHouston City CollegeHave I Been Pwned
ConfirmedData breach2025-10-15

Hello Cake: a data breach

In July 2025, the sexual healthcare product maker Hello Cake suffered a data breach . The data was subsequently posted on a public hacking forum and included 23k unique email addresses along with names, phone numbers, physical addresses, dates of birth and purchases.

22,907 recordsHello CakeHave I Been Pwned
ConfirmedData breach2026-04-12

Hallmark: a data breach

In March 2026, Hallmark suffered an alleged breach and subsequent extortion after attackers gained access to data stored within Salesforce. The data was later published after the extortion deadline passed, exposing 1.7M unique email addresses across both Hallmark and the Hallmark+ streaming service, along with names, phone numbers, physical addresses and support tickets.

1,736,520 recordsHallmarkHave I Been Pwned
ConfirmedData breach2026-07-15

Goose Creek: a data breach

In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers , claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contained 6.6M unique email addresses along with names, phone numbers, physical addresses, order IDs and total spent. The data appears to have been obtained from the company's Shopify instance. Goose Creek is aware of the reports but was unable to provide Have I Been Pwned with any further information at the time of publication.

6,574,121 recordsGoose CreekHave I Been Pwned
ConfirmedData breach2026-07-11

Glendale Community College: a data breach

In June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, addresses, phone numbers, Social Security numbers and other information relating to student enrolments. In its disclosure notice , the college advised that "the potentially impacted information may vary for each individual and may include all or just one of the above-listed types of information".

793,925 recordsGlendale Community CollegeHave I Been Pwned
ConfirmedData breach2025-09-18

FreeOnes: a data breach

In February 2017, the forum for the adult website FreeOnes suffered a data breach that was later redistributed as part of a larger corpus of data . The data included 960k unique email addresses alongside usernames, IP addresses and salted MD5 password hashes.

960,213 recordsFreeOnesHave I Been Pwned
ConfirmedData breach2026-07-15

Fluke: a data breach

In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present.

821,100 recordsFlukeHave I Been Pwned
ConfirmedData breach2026-02-18

Figure: a data breach

In February 2026, data obtained from the fintech lending platform Figure was publicly posted online . The exposed data, dating back to January 2026, contained over 900k unique email addresses along with names, phone numbers, physical addresses and dates of birth. Figure confirmed the incident and attributed it to a social engineering attack in which an employee was tricked into providing access.

967,178 recordsFigureHave I Been Pwned
ConfirmedData breach2026-08-19

Fanlore: a data breach

In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates . The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.

144,520 recordsFanloreHave I Been Pwned
ConfirmedData breach2026-08-07

Exact Sciences: a data breach

In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign . The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10.9M unique email addresses belonging to customers, patients and healthcare providers, along with names, addresses, phone numbers and health records. Abbott subsequently published a public notice advising that "some of the impacted files contain personal information and/or personal health information" and that more specific information would follow once their review of the incident was complete. For context, Exact Sciences is the maker of the Cologuard at-home colorectal cancer screening test.

10,869,543 recordsExact SciencesHave I Been Pwned
ConfirmedData breach2025-11-20

Eurofiber: a data breach

In November 2025, Eurofiber France disclosed a data breach of its ticket management platform . Data containing 10k unique email addresses and a smaller number of names and phone numbers was subsequently leaked. A threat actor claiming responsibility for the breach alleges to have additional, more sensitive data including screenshots, VPN configuration files, credentials, source code, certificates, archives, and SQL backup files.

10,003 recordsEurofiberHave I Been Pwned
ConfirmedData breach2026-06-01

Edmunds: a data breach

In January 2026, the automotive research and car-shopping platform Edmunds was listed by the ShinyHunters hacking group as having been breached . Data purportedly obtained in the incident was later published publicly and included 178k unique email addresses, usernames, passwords, IP addresses, phone numbers and vehicle-related records.

177,860 recordsEdmundsHave I Been Pwned
ConfirmedData breach2026-05-21

Dragonica Lunaris: a data breach

In December 2025, the European Dragonica private server Dragonica Lunaris suffered a data breach. The incident exposed 126k email addresses, usernames, dates of birth and bcrypt password hashes. The service operator confirmed the breach and advised it has since been fixed.

126,293 recordsDragonica LunarisHave I Been Pwned
Page 3 of 5 · 115 incidentsPreviousNext

Filings come from SEC EDGAR and are filtered to 8-K submissions that declare Item 1.05, not merely mention it. Breach records come from Have I Been Pwned. Ransomware claims come from RansomLook, used under CC BY 4.0; we store metadata only and never leak links.