<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel xmlns:atom="http://www.w3.org/2005/Atom">
    <title>Have I Been Pwned latest breaches</title>
    <link>https://haveibeenpwned.com/</link>
    <description>The latest publicly leaked data breaches to hit Have I Been Pwned</description>
    <atom:link href="https://haveibeenpwned.com/feed/breaches/" rel="self" type="application/rss+xml" />
    <item>
      <guid isPermaLink="false">7-Eleven</guid>
      <link>https://haveibeenpwned.com/Breach/7-Eleven</link>
      <title>7-Eleven - 185,256 breached accounts</title>
      <description>In April 2026, &lt;a href="https://www.bleepingcomputer.com/news/security/7-eleven-confirms-data-breach-claimed-by-the-shinyhunters-gang/" target="_blank" rel="noopener"&gt;7-Eleven was the victim of a "pay or leak" extortion campaign by ShinyHunters&lt;/a&gt;, with the data later published that month. The incident exposed 185k unique email addresses, along with names, physical addresses, dates of birth and phone numbers. A small number of records also contained additional exposed data fields. The company later advised the breach was limited to "certain 7-Eleven systems used to store franchisee documents", a statement consistent with the exposed data.</description>
      <pubDate>Sun, 24 May 2026 05:15:22 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">Dragonica</guid>
      <link>https://haveibeenpwned.com/Breach/Dragonica</link>
      <title>Dragonica Lunaris - 126,293 breached accounts</title>
      <description>In December 2025, &lt;a href="https://playdragonica.eu/" target="_blank" rel="noopener"&gt;the European Dragonica private server Dragonica Lunaris&lt;/a&gt; suffered a data breach. The incident exposed 126k email addresses, usernames, dates of birth and bcrypt password hashes. The service operator confirmed the breach and advised it has since been fixed.</description>
      <pubDate>Thu, 21 May 2026 04:41:32 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">Windows93</guid>
      <link>https://haveibeenpwned.com/Breach/Windows93</link>
      <title>Windows93 / Myspace93 - 46,105 breached accounts</title>
      <description>In January 2021, the parody site &lt;a href="https://web.archive.org/web/20210704163048/https://www.windows93.net/dearCommunity.txt" target="_blank" rel="noopener"&gt;Windows93 suffered a data breach of the Myspace93 sub-site&lt;/a&gt; after a beta application was exploited to download server files. The compromised data was later leaked in June and included 46k Myspace93 accounts containing email and IP addresses, usernames and passwords stored in plain text.</description>
      <pubDate>Thu, 21 May 2026 03:45:15 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">CTT</guid>
      <link>https://haveibeenpwned.com/Breach/CTT</link>
      <title>CTT - 468,124 breached accounts</title>
      <description>In April 2026, &lt;a href="https://x.com/DarkWebInformer/status/2048772869312622609" target="_blank" rel="noopener"&gt;data allegedly obtained from CTT, Portugal's national postal service, was posted to a public hacking forum&lt;/a&gt;. The data included 468k unique email addresses along with names, phone numbers and parcel tracking numbers which can be used to retrieve the tracking history of the parcel.</description>
      <pubDate>Tue, 19 May 2026 00:28:54 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">ADDI</guid>
      <link>https://haveibeenpwned.com/Breach/ADDI</link>
      <title>Addi - 34,532,941 breached accounts</title>
      <description>In March 2026, the Colombian fintech company &lt;a href="https://www.elcolombiano.com/negocios/addi-ciberataque-hackeo-datos-filtracion-datos-usuarios-BB35164432" target="_blank" rel="noopener"&gt;Addi identified unauthorised activity on its platform&lt;/a&gt; and advised customers that "it is possible that your personal information may have been compromised". The "pay or leak" extortion group &lt;a href="https://x.com/H4ckmanac/status/2051609021690319278" target="_blank" rel="noopener"&gt;ShinyHunters subsequently claimed responsibility&lt;/a&gt; and published a large trove of personal data allegedly obtained from Addi. The data included 34M unique email addresses from credit scoring requests, credit bureau records, customer identity records and email validation logs. It also contained government issued IDs (Cédula de Ciudadanía), estimated income, socioeconomic levels, purchases and other credit-related data points.</description>
      <pubDate>Mon, 18 May 2026 20:55:51 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">Abrigo</guid>
      <link>https://haveibeenpwned.com/Breach/Abrigo</link>
      <title>Abrigo - 711,099 breached accounts</title>
      <description>In April 2026, the fintech software company &lt;a href="https://x.com/DailyDarkWeb/status/2046928648393937001" target="_blank" rel="noopener"&gt;Abrigo was targeted in a "pay or leak" extortion attempt by the ShinyHunters group&lt;/a&gt;. Shortly after, data allegedly taken from the company's Salesforce instance was published publicly and contained over 700k unique email addresses belonging to both Abrigo staff and external contacts. Whilst separate from &lt;a href="https://abrigo.link/duediligence/Abrigo+Response+to+Drift.pdf" target="_blank" rel="noopener"&gt;Abrigo's Salesforce compromise via the Drift application connector the previous year&lt;/a&gt;, the data fields described in that incident are consistent with the ShinyHunters data, namely that it was "business contact information" including "institution name, employee name, email addresses, and phone numbers".</description>
      <pubDate>Thu, 14 May 2026 03:37:50 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">CanadaLife</guid>
      <link>https://haveibeenpwned.com/Breach/CanadaLife</link>
      <title>Canada Life - 237,810 breached accounts</title>
      <description>In April 2026, &lt;a href="https://www.scworld.com/brief/multiple-other-companies-purportedly-breached-by-shinyhunters-over-9m-record-leak-warned" target="_blank" rel="noopener"&gt;Canada Life was the victim of a "pay or leak" extortion campaign by the ShinyHunters group&lt;/a&gt;. The group subsequently published the data which contained over 200k unique email addresses along with names, phone numbers, physical addresses and, in some cases, customer support tickets. In &lt;a href="https://www.canadalife.com/about-us/news-highlights/news/canada-life-recently-identified-a-cyber-incident.html" target="_blank" rel="noopener"&gt;their disclosure notice&lt;/a&gt;, Canada Life advised that "it is a small proportion of our customers who may have been impacted". In the wake of the incident, &lt;a href="https://www.canadalife.com/fraud-prevention/suspicious-communications.html" target="_blank" rel="noopener"&gt;Canada Life also published an alert cautioning customers to be wary of phishing attacks&lt;/a&gt;, a pattern often seen after the public release of breached data.</description>
      <pubDate>Wed, 13 May 2026 06:51:17 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">CushmanWakefield</guid>
      <link>https://haveibeenpwned.com/Breach/CushmanWakefield</link>
      <title>Cushman &amp; Wakefield - 310,431 breached accounts</title>
      <description>In May 2026, the real estate services firm &lt;a href="https://www.theregister.com/security/2026/05/05/cushman-wakefield-confirms-vishing-cyberattack/5228718" target="_blank" rel="noopener"&gt;Cushman &amp; Wakefield was the target of a "pay or leak" extortion campaign by the ShinyHunters group&lt;/a&gt;. Following the threat, the group publicly published data they alleged had been obtained from the firm, consisting mostly of C&amp;W email addresses along with tens of thousands of external email addresses and corporate contact records. The exposed data was primarily business information, including names, job titles, company addresses and phone numbers.</description>
      <pubDate>Tue, 12 May 2026 06:58:16 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">Zara</guid>
      <link>https://haveibeenpwned.com/Breach/Zara</link>
      <title>Zara - 197,376 breached accounts</title>
      <description>In April 2026, the fashion brand &lt;a href="https://hackread.com/shinyhunters-leak-udemy-zara-7-eleven-data-breach/" target="_blank" rel="noopener"&gt;Zara was among a number of organisations targeted by the ShinyHunters extortion group&lt;/a&gt; as part of their "pay or leak" campaign. The group claimed the breach was related to a compromise of the Anodot analytics platform and subsequently published a terabyte of data allegedly including 95M support ticket records. The data contained 197k unique email addresses alongside product SKUs, order IDs and the market the support ticket originated in. Zara's parent company &lt;a href="https://ww.fashionnetwork.com/news/Inditex-flags-contractor-data-leak-says-client-records-safe,1824228.html" target="_blank" rel="noopener"&gt;Inditex advised that the incident didn't affect passwords or payment information&lt;/a&gt;.</description>
      <pubDate>Fri, 08 May 2026 07:14:22 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">Woflow</guid>
      <link>https://haveibeenpwned.com/Breach/Woflow</link>
      <title>Woflow - 447,593 breached accounts</title>
      <description>In March 2026, the AI-driven merchant data platform &lt;a href="https://cybernews.com/security/shinyhunters-claims-woflow-data-breach/" target="_blank" rel="noopener"&gt;Woflow was named as a victim by the ShinyHunters data extortion group&lt;/a&gt;. The group subsequently published tens of thousands of files allegedly obtained from the company, comprising more than 2TB of data. The trove included hundreds of thousands of email addresses, names, phone numbers and physical addresses, with the data indicating it related to Woflow customers and, in turn, the customers of merchants using their platform.</description>
      <pubDate>Thu, 07 May 2026 06:48:33 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">LegionProxy</guid>
      <link>https://haveibeenpwned.com/Breach/LegionProxy</link>
      <title>LegionProxy - 10,144 breached accounts</title>
      <description>In April 2026, the commercial residential and ISP proxy network &lt;a href="https://discord.com/channels/1236697205138788462/1239163077983735828/1500601065731653763" target="_blank" rel="noopener"&gt;LegionProxy suffered a data breach&lt;/a&gt;. The incident exposed 10k email addresses, bcrypt password hashes, names and purchases.</description>
      <pubDate>Wed, 06 May 2026 10:11:25 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">Vimeo</guid>
      <link>https://haveibeenpwned.com/Breach/Vimeo</link>
      <title>Vimeo - 119,167 breached accounts</title>
      <description>In April 2026, the ShinyHunters extortion group &lt;a href="https://www.bleepingcomputer.com/news/security/video-service-vimeo-confirms-anodot-breach-exposed-user-data/" target="_blank" rel="noopener"&gt;listed Vimeo on their extortion portal as part of their "pay or leak" campaign&lt;/a&gt;. They subsequently published hundreds of gigabytes of data, predominantly consisting of video titles, technical data and metadata. The data also included 119k unique email addresses, sometimes accompanied by names. &lt;a href="https://vimeo.com/blog/post/anodot-third-party-security-incident" target="_blank" rel="noopener"&gt;Vimeo attributed the exposure&lt;/a&gt; to a breach of Anodot, a third-party analytics vendor, and advised the incident &lt;em&gt;does not&lt;/em&gt; include "Vimeo video content, valid user login credentials, or payment card information".</description>
      <pubDate>Tue, 05 May 2026 02:08:50 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">RebornGaming</guid>
      <link>https://haveibeenpwned.com/Breach/RebornGaming</link>
      <title>Reborn Gaming - 126 breached accounts</title>
      <description>In April 2026, the gaming community &lt;a href="https://reborngaming.net/threads/6120/" target="_blank" rel="noopener"&gt;Reborn Gaming suffered a data breach due to a vulnerability in cPanel and WebHost Manager (WHM)&lt;/a&gt;. The breach exposed 126 unique email addresses along with IP addresses and Steam IDs. Reborn Gaming self-submitted the data to Have I Been Pwned.</description>
      <pubDate>Mon, 04 May 2026 03:43:06 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">MarcusMillichap</guid>
      <link>https://haveibeenpwned.com/Breach/MarcusMillichap</link>
      <title>Marcus &amp; Millichap - 1,837,078 breached accounts</title>
      <description>In April 2026, the commercial real estate brokerage firm &lt;a href="https://www.scworld.com/brief/multiple-other-companies-purportedly-breached-by-shinyhunters-over-9m-record-leak-warned" target="_blank" rel="noopener"&gt;Marcus &amp; Millichap was named as one of multiple alleged victims of the ShinyHunters hacking and extortion group&lt;/a&gt;. Data alleged to have been obtained from the company was subsequently released publicly and included 1.8M unique email addresses, along with names, phone numbers and employment-related information including employer, job title and physical company address. In &lt;a href="https://www.marcusmillichap.com/news-events/press/2026/04/marcus-millichap-releases-information-regarding-cybersecurity-incident" target="_blank" rel="noopener"&gt;their disclosure notice&lt;/a&gt;, Marcus &amp; Millichap advised that data which may have been accessed appeared limited to "company forms, templates, marketing materials, and general contact information".</description>
      <pubDate>Sun, 03 May 2026 22:53:12 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">ZenBusiness</guid>
      <link>https://haveibeenpwned.com/Breach/ZenBusiness</link>
      <title>ZenBusiness - 5,118,184 breached accounts</title>
      <description>In March 2026, &lt;a href="https://cybernews.com/security/zenbusiness-shinyhunters-data-breach-mark-cuban/" target="_blank" rel="noopener"&gt;the hacker and extortion group "ShinyHunters" claimed to have obtained a substantial corpus of data from ZenBusiness&lt;/a&gt;, a business formation and compliance platform. The group claimed the data had been exfiltrated from platforms including Snowflake, Mixpanel and Salesforce, and threatened to publish it if a ransom was not paid. The following month, after claiming payment had not been made, ShinyHunters publicly released the data. The collection amounted to many terabytes across thousands of files that appeared to originate from multiple systems and business functions, including leads, support records and other CRM-related data. The data contained approximately 5M unique email addresses, often accompanied by name and phone number depending on the source file.</description>
      <pubDate>Sat, 02 May 2026 05:53:38 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">Aman</guid>
      <link>https://haveibeenpwned.com/Breach/Aman</link>
      <title>Aman - 215,563 breached accounts</title>
      <description>In April 2026, the ultra-luxury hotel brand &lt;a href="https://www.scworld.com/brief/multiple-other-companies-purportedly-breached-by-shinyhunters-over-9m-record-leak-warned" target="_blank" rel="noopener"&gt;Aman was named by ShinyHunters as the target of a "pay or leak" extortion campaign&lt;/a&gt;, with the data allegedly obtained from their Salesforce CRM. The data was subsequently leaked publicly and contained over 200k unique email addresses. Whilst not present on all records, the data also included genders, physical addresses, phone numbers, nationalities, dates of birth, spouse names and VIP status codes.</description>
      <pubDate>Fri, 01 May 2026 03:34:30 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">PitneyBowes</guid>
      <link>https://haveibeenpwned.com/Breach/PitneyBowes</link>
      <title>Pitney Bowes - 8,243,989 breached accounts</title>
      <description>In April 2026, the hacking collective &lt;a href="https://breachnews.com/breaches/shinyhunters-lists-new-victims-including-zara-7-eleven-and-pitney-bowes-in-alleged-data-release/" target="_blank" rel="noopener"&gt;ShinyHunters claimed to have obtained data from Pitney Bowes&lt;/a&gt; as part of a broader extortion campaign that also named several other organisations. After negotiations allegedly failed, the group publicly released the data which included 8.2M unique email addresses, along with names, phone numbers and physical addresses. A subset of the data also included Pitney Bowes employee records with job titles.</description>
      <pubDate>Mon, 27 Apr 2026 22:52:07 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">ADT</guid>
      <link>https://haveibeenpwned.com/Breach/ADT</link>
      <title>ADT - 5,488,888 breached accounts</title>
      <description>In April 2026, home security firm &lt;a href="https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/" target="_blank" rel="noopener"&gt;ADT confirmed a data breach by ShinyHunters&lt;/a&gt;, which listed the company on its website as part of a "pay or leak" extortion attempt. The breach impacted 5.5M unique email addresses along with names, phone numbers and physical addresses. ADT also advised that "in a small percentage of cases, dates of birth and the last four digits of Social Security numbers or Tax IDs were included" and that it had contacted all affected people.</description>
      <pubDate>Mon, 27 Apr 2026 07:36:42 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">Udemy</guid>
      <link>https://haveibeenpwned.com/Breach/Udemy</link>
      <title>Udemy - 1,401,259 breached accounts</title>
      <description>In April 2026, online training company &lt;a href="https://cybernews.com/security/shinyhunters-claim-udemy-data-theft/" target="_blank" rel="noopener"&gt;Udemy was the victim of a “pay or leak” extortion attempt&lt;/a&gt; perpetrated by the ShinyHunters group. The data was subsequently leaked publicly and contained 1.4M unique email addresses belonging to customers and instructors. The data also included names, physical addresses, phone numbers, employer information and instructor payout methods including PayPal, cheque and bank transfer.</description>
      <pubDate>Sun, 26 Apr 2026 23:01:50 Z</pubDate>
    </item>
    <item>
      <guid isPermaLink="false">Carnival</guid>
      <link>https://haveibeenpwned.com/Breach/Carnival</link>
      <title>Carnival - 7,531,359 breached accounts</title>
      <description>In April 2026, the notorious hacking collective &lt;a href="https://cyberinsider.com/carnival-corporation-probes-data-breach-after-claims-of-8-7m-records-theft/" target="_blank" rel="noopener"&gt;ShinyHunters claimed they had obtained a substantial volume of data belonging to the Carnival cruise operator&lt;/a&gt; and attempted to extort the organisation to prevent the data from being leaked. The following week, the group published the data publicly, which contained 8.7M records with 7.5M unique email addresses. The data contained fields indicating it related to the Mariner Society loyalty program run by Holland America, a cruise line brand under Carnival, and included names, dates of birth, genders and data relating to status within the loyalty program. Carnival acknowledged a phishing incident involving a single user account and advised they were working to better understand the scope of the unauthorised activity.</description>
      <pubDate>Fri, 24 Apr 2026 01:58:19 Z</pubDate>
    </item>
  </channel>
</rss>