Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Have I Been Pwned

@haveibeenpwned@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Check if you have an email address or password that has been compromised in a data breach. Created and maintained by @troyhunt@infosec.exchange

19019 Followers
1 Following
50 Posts
Joined January 06, 2023
Website:
https://haveibeenpwned.com
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 2mo ago
New breach: SplitVPN had 865k unique email addresses breached last week. Data also included IP address, country and partial payment card data. 37% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/SplitVPN
Have I Been Pwned: SplitVPN Data Breach
Have I Been Pwned

Have I Been Pwned: SplitVPN Data Breach

In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).

19
4
23
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 2mo ago

New breach: Houston City College was the target of a ShinyHunters extortion attempt last month. Over 800k unique email addresses were later published with name, physical address, phone number and more. 30% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/HoustonCityCollege

Have I Been Pwned: Houston City College Data Breach
Have I Been Pwned

Have I Been Pwned: Houston City College Data Breach

In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and other personal information relating to both current students and alumni.

15
0
11
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 6mo ago

New breach: My Lovely AI, a NSFW AI girlfriend platform, suffered a breach earlier this week that exposed over 100k unique email addresses. The data also included AI prompts and links to the resulting images. 23% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/MyLovelyAI

Have I Been Pwned: My Lovely AI Data Breach
Have I Been Pwned

Have I Been Pwned: My Lovely AI Data Breach

In April 2026, the NSFW AI girlfriend platform My Lovely AI suffered a data breach that exposed over 100k users. The data included user-created prompts and links to the resulting AI-generated images, along with a small number of Discord and X usernames.

77
35
92
1
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 2mo ago
New breach: Data from Suno's November 2025 breach surfaced publicly last week. The corpus contained over 55M unique email addresses plus tens of thousands of Stripe payment records. 24% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Suno
Have I Been Pwned: Suno Data Breach
Have I Been Pwned

Have I Been Pwned: Suno Data Breach

In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year. The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a small portion of the corpus, the breach also included tens of thousands of Stripe records relating to purchases, containing names, physical addresses, purchase amounts and partial credit card data including the card type

16
4
24
1
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 5mo ago
New breach: Udemy had 1.4M email addresses leaked yesterday following an extortion attempt by ShinyHunters. Data included name, address, phone, employer info and instructor payout method. 56% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Udemy
Have I Been Pwned: Udemy Data Breach
Have I Been Pwned

Have I Been Pwned: Udemy Data Breach

In April 2026, online training company Udemy was the victim of a “pay or leak” extortion attempt perpetrated by the ShinyHunters group. The data was subsequently leaked publicly and contained 1.4M unique email addresses belonging to customers and instructors. The data also included names, physical addresses, phone numbers, employer information and instructor payout methods including PayPal, cheque and bank transfer.

48
2
98
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 3mo ago
New breach: Glendale Community College was the target of a ShinyHunters extortion attempt last month. Nearly 800k unique email addresses were later published with name, physical address, phone number and more. 28% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/GlendaleCommunityCollege
Have I Been Pwned: Glendale Community College Data Breach
Have I Been Pwned

Have I Been Pwned: Glendale Community College Data Breach

In June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, addresses, phone numbers, Social Security numbers and other information relating to student enrolments. In its disclosure notice, the college advised that "the potentially impacted information may vary for each individual an

16
0
5
1
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 2mo ago
Replying to
Updated breach: Another 131k email addresses provided by Europol were added to the 4th wave of Operation Endgame today. 36% of the new corpus was already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/OperationEndgame4
Have I Been Pwned: Operation Endgame 4.0 Data Breach
Have I Been Pwned

Have I Been Pwned: Operation Endgame 4.0 Data Breach

On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation, a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust, the operation remediated almost 15,000 compromised websites and disrupted more than 100 servers and domains used to distribute malware. Authorities initially provided HIBP with 154k impacted email addresses

11
0
13
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 3mo ago
New breach: JCPenney was targeted by a ShinyHunters extortion campaign that allegedly obtained then leaked data including 368k email addresses, names, SSNs and other HR records on current and former staff. 31% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/JCPenney
Have I Been Pwned: JCPenney Data Breach
Have I Been Pwned

Have I Been Pwned: JCPenney Data Breach

In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed records indicated they primarily related to internal HR systems and impacted current and former employees. The data included 368k corporate and personal email addresses, names, dates of birth, Social Security numbers,

22
2
17
1
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 2mo ago

New sensitive breach: Exact Sciences was targeted by a ShinyHunters extortion campaign last month. The group later published 10.9M email addresses and other personal data, including health information. 75% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/ExactSciences

Have I Been Pwned: Exact Sciences Data Breach
Have I Been Pwned

Have I Been Pwned: Exact Sciences Data Breach

In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign. The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10.9M unique email addresses belonging to customers, patients and healthcare providers, along with names, addresses, phone numbers and health records. Abbott subsequently published a public notice advising that "some of the

8
0
11
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 2mo ago

New breach: Inter-Con Security was targeted by ShinyHunters in a pay or leak extortion campaign in June. 276k unique email addresses were subsequently published, along with names, physical addresses and more. 44% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/InterConSecurity

Have I Been Pwned: Inter-Con Security Data Breach
Have I Been Pwned

Have I Been Pwned: Inter-Con Security Data Breach

In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign. The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompassed a combination of contacts, internal users and leads.

7
0
5
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 3mo ago
New breach: Sysco was the target of a ShinyHunters extortion campaign earlier this month. Subsequently published data contained 2.7M unique email addresses plus largely corporate contact information. 44% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Sysco
Have I Been Pwned: Sysco Data Breach
Have I Been Pwned

Have I Been Pwned: Sysco Data Breach

In June 2026, the food distribution company Sysco was targeted by a ShinyHunters "pay or leak" extortion campaign. Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact information including names, phone numbers, physical addresses, internal job titles, and customer feedback.

16
4
9
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 2mo ago
New breach: Earlier this month, Fluke was targeted in a ShinyHunters extortion campaign. The group published more than 800k email addresses along with largely corporate contact information and support cases. 51% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Fluke
Have I Been Pwned: Fluke Data Breach
Have I Been Pwned

Have I Been Pwned: Fluke Data Breach

In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present.

11
0
17
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 3mo ago

New breach: Moody Bible Institute was targeted by a ShinyHunters extortion campaign last month with 2.3M email addresses later published. Data also included name, address, phone and other personal info. 76% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/MoodyBibleInstitute

Have I Been Pwned: Moody Bible Institute Data Breach
Have I Been Pwned

Have I Been Pwned: Moody Bible Institute Data Breach

In June 2026, Moody Bible Institute was targeted by a ShinyHunters "pay or leak" extortion campaign. Over 2.3M unique email addresses and other personal data were later published publicly, including names, physical addresses, phone numbers, dates of birth and other information relating to donors, supporters, students and alumni. In their disclosure notice, Moody advised that they had "engaged both internal and external cybersecurity experts to thoroughly investigate the matter".

13
0
8
1
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 2mo ago
New breach: Last month, some Goose Creek customers received emails claiming a vulnerability and breach. Data later sent to HIBP contained 6.6M email addresses, names, phone numbers and physical addresses. 84% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/GooseCreek
Have I Been Pwned: Goose Creek Data Breach
Have I Been Pwned

Have I Been Pwned: Goose Creek Data Breach

In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers, claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contained 6.6M unique email addresses along with names, phone numbers, physical addresses, order IDs and total spent. The data appears to have been obtained from the company's Shopify instance. Goose Creek is aware of the report

10
2
13
1
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 3mo ago

New breach: Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign. This week, the group published 140k email addresses, names, phone numbers and other personal data. 85% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/RalphLauren

Have I Been Pwned: Ralph Lauren Data Breach
Have I Been Pwned

Have I Been Pwned: Ralph Lauren Data Breach

In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresses along with names, phone numbers, genders and age groups.

16
0
8
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 4mo ago

New breach: The Windows93 parody site suffered a breach of its Myspace93 sub-site in 2021. The breach exposed 46k email and IP addresses, usernames and plain text passwords. 70% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Windows93

Have I Been Pwned: Windows93 / Myspace93 Data Breach
Have I Been Pwned

Have I Been Pwned: Windows93 / Myspace93 Data Breach

In January 2021, the parody site Windows93 suffered a data breach of the Myspace93 sub-site after a beta application was exploited to download server files. The compromised data was later leaked in June and included 46k Myspace93 accounts containing email and IP addresses, usernames and passwords stored in plain text.

22
0
16
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 3mo ago

New stealer log corpus: A collection of hundreds of millions of stealer log records containing 56M unique email addresses has been added. The data also contained 124M unique passwords added to Pwned Passwords. 86% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/June2026StealerLogs

Have I Been Pwned: June 2026 Stealer Logs Data Breach
Have I Been Pwned

Have I Been Pwned: June 2026 Stealer Logs Data Breach

In June 2026, a collection of accumulated stealer logs from various sources was added to HIBP. The corpus comprised 56M unique email addresses across hundreds of millions of stealer log records. The data also contained 124M unique passwords, which have been added to Pwned Passwords and are now searchable. Individuals can view any records captured against their email address in the stealer logs section of their dashboard. Organisations can see logs affecting their domain via the stealer logs API.

15
0
11
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 5mo ago

New breach: McGraw Hill suffered a breach last week attributed to a Salesforce misconfiguration. Data leaked today included 13.5M email addresses. Some records included name, phone and physical address. 47% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/McGrawHill

Have I Been Pwned: McGraw Hill Data Breach
Have I Been Pwned

Have I Been Pwned: McGraw Hill Data Breach

In April 2026, education company McGraw Hill confirmed a data breach following an extortion attempt. Attributed to a Salesforce misconfiguration, the company stated the incident exposed "a limited set of data from a webpage hosted by Salesforce on its platform". More than 100GB of data was later publicly distributed, containing 13.5M unique email addresses across multiple files, with additional fields such as name, physical address and phone number appearing inconsistently across some records.

29
0
27
1
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 2mo ago
New breach: Paidwork allegedly suffered a breach in March that was offered for sale before being published this month. Data included profile data, banking info, payout history and bcrypt password hashes. 35% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Paidwork
Have I Been Pwned: Paidwork Data Breach
Have I Been Pwned

Have I Been Pwned: Paidwork Data Breach

In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale. Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The breach also included a broad range of other data relating to the operation of the platform including user profile data, banking information, payout history for workers and passwords stored as bcrypt hashes.

7
0
5
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 4mo ago

New breach: 7-Eleven was targeted by the ShinyHunters extortion group last month, with 185k email addresses related to franchisees impacted. Data also included name, physical address, phone number and DoB. 53% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/7-Eleven

Have I Been Pwned: 7-Eleven Data Breach
Have I Been Pwned

Have I Been Pwned: 7-Eleven Data Breach

In April 2026, 7-Eleven was the victim of a "pay or leak" extortion campaign by ShinyHunters, with the data later published that month. The incident exposed 185k unique email addresses, along with names, physical addresses, dates of birth and phone numbers. A small number of records also contained additional exposed data fields. The company later advised the breach was limited to "certain 7-Eleven systems used to store franchisee documents", a statement consistent with the exposed data.

17
4
23
1
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 3mo ago
Replying to
Updated breach: A further 4M email addresses and 9M passwords from the StealC malware operation targeted by the 4th wave of Operation Endgame have been added to HIBP. 64% of the combined corpus was already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/OperationEndgame4
Have I Been Pwned: Operation Endgame 4.0 Data Breach
Have I Been Pwned

Have I Been Pwned: Operation Endgame 4.0 Data Breach

On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation, a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust, the operation remediated almost 15,000 compromised websites and disrupted more than 100 servers and domains used to distribute malware. Authorities initially provided HIBP with 154k impacted email addresses

10
2
7
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 5mo ago

New breach: Vimeo was named in a ShinyHunters extortion campaign following a compromise of the Anodot analytics service. The incident exposed hundreds of gigabytes of data, including 119k unique email addresses. 56% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Vimeo

Have I Been Pwned: Vimeo Data Breach
Have I Been Pwned

Have I Been Pwned: Vimeo Data Breach

In April 2026, the ShinyHunters extortion group listed Vimeo on their extortion portal as part of their "pay or leak" campaign. They subsequently published hundreds of gigabytes of data, predominantly consisting of video titles, technical data and metadata. The data also included 119k unique email addresses, sometimes accompanied by names. Vimeo attributed the exposure to a breach of Anodot, a third-party analytics vendor, and advised the incident does not include "Vimeo video content, valid use

16
0
23
1
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 4mo ago

New breach: Ameriprise was the victim of a ShinyHunters extortion campaign in March. The published data contained 500k email addresses along with names, phone numbers, physical addresses and employer info. 65% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Ameriprise

Have I Been Pwned: Ameriprise Data Breach
Have I Been Pwned

Have I Been Pwned: Ameriprise Data Breach

In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group claimed possession of more than 200GB of compressed data exfiltrated from Ameriprise's Salesforce environment and internal SharePoint infrastructure, and subsequently published the data after negotiations allegedly failed. The published data contained 500k unique email addresses as well as names, phone numbers, physical addresses and employer inform

12
0
6
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 4mo ago

New breach: Edmunds was listed by ShinyHunters as allegedly breached in Jan, with the data later published online. It contained 178k unique email addresses, usernames, IP addresses, phone numbers and passwords. 91% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Edmunds

Have I Been Pwned: Edmunds Data Breach
Have I Been Pwned

Have I Been Pwned: Edmunds Data Breach

In January 2026, the automotive research and car-shopping platform Edmunds was listed by the ShinyHunters hacking group as having been breached. Data purportedly obtained in the incident was later published publicly and included 178k unique email addresses, usernames, passwords, IP addresses, phone numbers and vehicle-related records.

11
0
3
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 4mo ago

New breach: The Atlas Menu GTA V and CS2 cheat service had 64k accounts breached yesterday. Data includes email and IP addresses, usernames, passwords stored as bcrypt hashes and support tickets. 49% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/AtlasMenu

Have I Been Pwned: Atlas Menu Data Breach
Have I Been Pwned

Have I Been Pwned: Atlas Menu Data Breach

In May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and published the service's database to a public GitHub repository. The incident exposed 64k unique email addresses along with usernames, IP addresses, support tickets and passwords stored as bcrypt hashes.

11
0
6
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 5mo ago

New breach: Amtrak was claimed as a victim of ShinyHunters earlier this month with over 2M email addresses then published this week. Data also included names, physical addresses and support tickets. 80% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Amtrak

Have I Been Pwned: Amtrak Data Breach
Have I Been Pwned

Have I Been Pwned: Amtrak Data Breach

In April 2026, the hacking group ShinyHunters claimed they had breached Amtrak. The group typically compromises organisations' Salesforce instances before demanding a ransom and later, if not paid, dumping the data publicly. They subsequently published the alleged data which contained over 2M unique email addresses along with names, physical addresses and customer support records.

18
1
22
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 3mo ago

New breach: CFGI was targeted in a ShinyHunters extortion campaign in March. They subsequently published 243k unique email addresses along with names and largely corporate contact information. 53% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/CFGI

Have I Been Pwned: CFGI Data Breach
Have I Been Pwned

Have I Been Pwned: CFGI Data Breach

In March 2026, the financial consulting and advisory firm CFGI was the target of a ShinyHunters "pay-or-leak" extortion campaign. The group subsequently publicised data allegedly obtained from CFGI comprising corporate contact information, including 243k unique email addresses, names, phone numbers and physical addresses.

8
0
3
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 3mo ago

New breach: Madison Square Garden Sports was the target of a ShinyHunters extortion campaign earlier this month. Almost 10M email addresses and extensive staff and customer relationship data was later published. 80% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/MadisonSquareGardenSports

Have I Been Pwned: Madison Square Garden Sports Data Breach
Have I Been Pwned

Have I Been Pwned: Madison Square Garden Sports Data Breach

In June 2026, the sports and entertainment company Madison Square Garden Sports was the target of a ShinyHunters "pay or leak" extortion campaign. The group later published the alleged data, which included almost 10M unique email addresses spanning staff and customers, along with extensive personal, employment and customer relationship information.

7
0
7
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 6mo ago
New breach: Hallmark was allegedly breached in March with attackers accessing Salesforce and publishing data this week. It exposed 1.7M unique email addresses with name, phone, physical address & support tickets. 82% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Hallmark
Have I Been Pwned: Hallmark Data Breach
Have I Been Pwned

Have I Been Pwned: Hallmark Data Breach

In March 2026, Hallmark suffered an alleged breach and subsequent extortion after attackers gained access to data stored within Salesforce. The data was later published after the extortion deadline passed, exposing 1.7M unique email addresses across both Hallmark and the Hallmark+ streaming service, along with names, phone numbers, physical addresses and support tickets.

17
3
40
1
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 4mo ago

New breach: Mytheresa was targeted by ShinyHunters in an extortion campaign last month. The leaked data contained 84k email addresses along with name, address, phone, purchase and partial card data. 97% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Mytheresa

Have I Been Pwned: Mytheresa Data Breach
Have I Been Pwned

Have I Been Pwned: Mytheresa Data Breach

In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters "pay or leak" extortion group. After the ransom deadline passed, the group publicly released the data which contained 84k unique email addresses. The exposed data also included names, phone numbers, physical addresses, purchases and partial credit card data including card type, last 4 digits and expiry date.

10
0
6
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 3mo ago

New breach: American Tower was the target of a ShinyHunters extortion campaign earlier this month. Leaked data included 217k unique email addresses along with names, phone numbers, and addresses. 62% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/AmericanTower

Have I Been Pwned: American Tower Data Breach
Have I Been Pwned

Have I Been Pwned: American Tower Data Breach

In June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly taken from the company containing more than 200k unique email addresses belonging to employees, contractors, customers, and leads. Exposed data also included names, addresses, and phone numbers.

6
0
3
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 5mo ago

New breach: Woflow was named as a ShinyHunters victim in March, after which hundreds of thousands of email addresses, names, phone numbers and physical addresses were publicly dumped. 75% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Woflow

Have I Been Pwned: Woflow Data Breach
Have I Been Pwned

Have I Been Pwned: Woflow Data Breach

In March 2026, the AI-driven merchant data platform Woflow was named as a victim by the ShinyHunters data extortion group. The group subsequently published tens of thousands of files allegedly obtained from the company, comprising more than 2TB of data. The trove included hundreds of thousands of email addresses, names, phone numbers and physical addresses, with the data indicating it related to Woflow customers and, in turn, the customers of merchants using their platform.

12
0
6
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 5mo ago

New breach: LegionProxy had 10k email addresses breached last month. Data also included bcrypt password hashes, names and purchases. 31% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/LegionProxy

Have I Been Pwned: LegionProxy Data Breach
Have I Been Pwned

Have I Been Pwned: LegionProxy Data Breach

In April 2026, the commercial residential and ISP proxy network LegionProxy suffered a data breach. The incident exposed 10k email addresses, bcrypt password hashes, names and purchases.

12
0
5
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 5mo ago

New breach: ShinyHunters claimed Pitney Bowes as an extortion victim last week before later dumping 8.2M email addresses publicly. Data also included name, physical address, phone number and employee job title. 53% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/PitneyBowes

Have I Been Pwned: Pitney Bowes Data Breach
Have I Been Pwned

Have I Been Pwned: Pitney Bowes Data Breach

In April 2026, the hacking collective ShinyHunters claimed to have obtained data from Pitney Bowes as part of a broader extortion campaign that also named several other organisations. After negotiations allegedly failed, the group publicly released the data which included 8.2M unique email addresses, along with names, phone numbers and physical addresses. A subset of the data also included Pitney Bowes employee records with job titles.

13
1
9
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 5mo ago
New breach: ADT suffered a "pay or leak" extortion that resulted in 5.5M unique email addresses being published today. Data also included name, address, phone and a small number of DoBs and partial SSNs. 71% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/ADT
Have I Been Pwned: ADT Data Breach
Have I Been Pwned

Have I Been Pwned: ADT Data Breach

In April 2026, home security firm ADT confirmed a data breach by ShinyHunters, which listed the company on its website as part of a "pay or leak" extortion attempt. The breach impacted 5.5M unique email addresses along with names, phone numbers and physical addresses. ADT also advised that "in a small percentage of cases, dates of birth and the last four digits of Social Security numbers or Tax IDs were included" and that it had contacted all affected people.

13
0
21
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 4mo ago

New breach: Abrigo was targeted by ShinyHunters last month, who subsequently published over 700k unique email addresses allegedly taken from their Salesforce instance. Data also included business contact info. 57% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Abrigo

Have I Been Pwned: Abrigo Data Breach
Have I Been Pwned

Have I Been Pwned: Abrigo Data Breach

In April 2026, the fintech software company Abrigo was targeted in a "pay or leak" extortion attempt by the ShinyHunters group. Shortly after, data allegedly taken from the company's Salesforce instance was published publicly and contained over 700k unique email addresses belonging to both Abrigo staff and external contacts. Whilst separate from Abrigo's Salesforce compromise via the Drift application connector the previous year, the data fields described in that incident are consistent with the

10
0
7
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 4mo ago

New breach: Canada Life was named as a ShinyHunters victim last month, after which data containing more than 200k email addresses was published. The incident also impacted name, phone number and physical address. 47% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/CanadaLife

Have I Been Pwned: Canada Life Data Breach
Have I Been Pwned

Have I Been Pwned: Canada Life Data Breach

In April 2026, Canada Life was the victim of a "pay or leak" extortion campaign by the ShinyHunters group. The group subsequently published the data which contained over 200k unique email addresses along with names, phone numbers, physical addresses and, in some cases, customer support tickets. In their disclosure notice, Canada Life advised that "it is a small proportion of our customers who may have been impacted". In the wake of the incident, Canada Life also published an alert cautioning cus

10
1
17
1
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 5mo ago

New breach: Cushman & Wakefield was named as a ShinyHunters victim last week, after which mostly corporate contact records were published. Impacted data included email address, job title and company address. 21% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/CushmanWakefield

Have I Been Pwned: Cushman & Wakefield Data Breach
Have I Been Pwned

Have I Been Pwned: Cushman & Wakefield Data Breach

In May 2026, the real estate services firm Cushman & Wakefield was the target of a "pay or leak" extortion campaign by the ShinyHunters group. Following the threat, the group publicly published data they alleged had been obtained from the firm, consisting mostly of C&W email addresses along with tens of thousands of external email addresses and corporate contact records. The exposed data was primarily business information, including names, job titles, company addresses and phone numbers.

10
0
5
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 5mo ago

New breach: Zara was named as a ShinyHunters victim last month, after which data containing 197k unique email addresses was published. Impacted data included customer support records, product SKUs and order IDs. 60% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Zara

Have I Been Pwned: Zara Data Breach
Have I Been Pwned

Have I Been Pwned: Zara Data Breach

In April 2026, the fashion brand Zara was among a number of organisations targeted by the ShinyHunters extortion group as part of their "pay or leak" campaign. The group claimed the breach was related to a compromise of the Anodot analytics platform and subsequently published a terabyte of data allegedly including 95M support ticket records. The data contained 197k unique email addresses alongside product SKUs, order IDs and the market the support ticket originated in. Zara's parent company Indi

10
0
15
2
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 5mo ago

New self-submitted breach: Reborn Gaming had 126 unique email addresses breached last week due to a cPanel/WHM vulnerability. Data also included IP address and Steam ID. 68% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/RebornGaming

Have I Been Pwned: Reborn Gaming Data Breach
Have I Been Pwned

Have I Been Pwned: Reborn Gaming Data Breach

In April 2026, the gaming community Reborn Gaming suffered a data breach due to a vulnerability in cPanel and WebHost Manager (WHM). The breach exposed 126 unique email addresses along with IP addresses and Steam IDs. Reborn Gaming self-submitted the data to Have I Been Pwned.

10
0
6
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 4mo ago

New breach: The Dragonica Lunaris private server suffered a breach in December which exposed 126k email addresses, usernames, dates of birth and bcrypt password hashes. 69% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Dragonica

Have I Been Pwned: Dragonica Lunaris Data Breach
Have I Been Pwned

Have I Been Pwned: Dragonica Lunaris Data Breach

In December 2025, the European Dragonica private server Dragonica Lunaris suffered a data breach. The incident exposed 126k email addresses, usernames, dates of birth and bcrypt password hashes. The service operator confirmed the breach and advised it has since been fixed.

8
0
4
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 4mo ago

New breach: Charter Communications was named in a ShinyHunters "pay or leak" extortion campaign last week after which 4.9M unique email addresses along with name, phone number and physical address were published. 68% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Charter

Have I Been Pwned: Charter Data Breach
Have I Been Pwned

Have I Been Pwned: Charter Data Breach

In May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group later published the data, which exposed 4.9M unique email addresses along with names, phone numbers and physical addresses. A subset of approximately 85k records originating from an internal employee directory also included job titles. Charter confirmed the incident, but

7
0
13
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 5mo ago

New breach: ShinyHunters claimed terabytes of data were exfiltrated from ZenBusiness then released publicly after an extortion attempt. Data included 5M unique email addresses, many with names and phone numbers. 53% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/ZenBusiness

Have I Been Pwned: ZenBusiness Data Breach
Have I Been Pwned

Have I Been Pwned: ZenBusiness Data Breach

In March 2026, the hacker and extortion group "ShinyHunters" claimed to have obtained a substantial corpus of data from ZenBusiness, a business formation and compliance platform. The group claimed the data had been exfiltrated from platforms including Snowflake, Mixpanel and Salesforce, and threatened to publish it if a ransom was not paid. The following month, after claiming payment had not been made, ShinyHunters publicly released the data. The collection amounted to many terabytes across thou

9
0
13
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 5mo ago

New breach: Aman was the target of a ShinyHunters "pay or leak" extortion that resulted in over 200k email addresses being published this week. Data also included name, address, phone, nationality and VIP status. 74% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Aman

Have I Been Pwned: Aman Data Breach
Have I Been Pwned

Have I Been Pwned: Aman Data Breach

In April 2026, the ultra-luxury hotel brand Aman was named by ShinyHunters as the target of a "pay or leak" extortion campaign, with the data allegedly obtained from their Salesforce CRM. The data was subsequently leaked publicly and contained over 200k unique email addresses. Whilst not present on all records, the data also included genders, physical addresses, phone numbers, nationalities, dates of birth, spouse names and VIP status codes.

9
0
4
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 4mo ago

New breach: Data allegedly taken from CTT, Portugal's postal service, appeared on a hacking forum last month. It contained 468k unique email addresses, along with name, phone number and parcel tracking number. 55% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/CTT

Have I Been Pwned: CTT Data Breach
Have I Been Pwned

Have I Been Pwned: CTT Data Breach

In April 2026, data allegedly obtained from CTT, Portugal's national postal service, was posted to a public hacking forum. The data included 468k unique email addresses along with names, phone numbers and parcel tracking numbers which can be used to retrieve the tracking history of the parcel.

7
0
4
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 5mo ago

New breach: Marcus & Millichap was named in a ShinyHunters "pay or leak" extortion campaign last month. Impacted data included 1.8M unique email addresses, name, phone number and employment-related info. 70% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/MarcusMillichap

Have I Been Pwned: Marcus & Millichap Data Breach
Have I Been Pwned

Have I Been Pwned: Marcus & Millichap Data Breach

In April 2026, the commercial real estate brokerage firm Marcus & Millichap was named as one of multiple alleged victims of the ShinyHunters hacking and extortion group. Data alleged to have been obtained from the company was subsequently released publicly and included 1.8M unique email addresses, along with names, phone numbers and employment-related information including employer, job title and physical company address. In their disclosure notice, Marcus & Millichap advised that data which may

8
0
5
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 4mo ago

New breach: Addi was named as a ShinyHunters victim earlier this month and data containing 34M email addresses allegedly obtained from the platform were published. Credit-related data points were also included. 29% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Addi

Have I Been Pwned: Addi Data Breach
Have I Been Pwned

Have I Been Pwned: Addi Data Breach

In March 2026, the Colombian fintech company Addi identified unauthorised activity on its platform and advised customers that "it is possible that your personal information may have been compromised". The "pay or leak" extortion group ShinyHunters subsequently claimed responsibility and published a large trove of personal data allegedly obtained from Addi. The data included 34M unique email addresses from credit scoring requests, credit bureau records, customer identity records and email validat

6
0
2
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 5mo ago

New breach: Cruise operator Carnival was targeted in a ShinyHunters “pay or leak” attack last week. 8.7M records with 7.5M email addresses and loyalty program data were published yesterday. 85% were already in @haveibeenpwned@infosec.exchange. Read more: https://haveibeenpwned.com/Breach/Carnival

Have I Been Pwned: Carnival Data Breach
Have I Been Pwned

Have I Been Pwned: Carnival Data Breach

In April 2026, the notorious hacking collective ShinyHunters claimed they had obtained a substantial volume of data belonging to the Carnival cruise operator and attempted to extort the organisation to prevent the data from being leaked. The following week, the group published the data publicly, which contained 8.7M records with 7.5M unique email addresses. The data contained fields indicating it related to the Mariner Society loyalty program run by Holland America, a cruise line brand under Car

7
0
11
0
Open post
Have I Been Pwned @haveibeenpwned@infosec.exchange
· 4mo ago

New breach: Kemper was targeted by ShinyHunters last month in an extortion campaign resulting in 269k email addresses being published. Data also included names, phone numbers, addresses and partial card data. 53% were already in @haveibeenpwned@infosec.exchange. More: https://haveibeenpwned.com/Breach/Kemper

Have I Been Pwned: Kemper Data Breach
Have I Been Pwned

Have I Been Pwned: Kemper Data Breach

In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign. The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part of a broader campaign targeting hundreds of organisations using the same method. The group later published tens of gigabytes of data they claimed included internal directory data, Salesforce records and Stripe payment logs. Among the 269k unique

4
0
4
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 06:32:12 UTC