Classic site

Breach registry

Breaches

Every breach below is cross-examined against four independent databases. All 1,717 records, and the places they disagree.

Accounts attested across the registry

HIBP28,427,287,783
DEHASHED31,929,374,775
LEAKCHECK13,615,738,527
VIGILANTE7,683,108,384

3,502,086,992 accounts DEHASHED reports beyond HIBP

Narrow the registry

1,717 of 1,717 records
Last Update: a few seconds ago· 00:00:00
Rows per page
12
1–12 of 1717

1,717 of 1,717 records · Page 1 of 144

Chess2026 logo

Chess.com (2026)

chess.com

4,653,212accounts
VerifiedNo Passwords Leaked
Breached2026-08-03a month ago

Attestation

HIBP4,653,212
DEHASHED4,653,212
LEAKCHECKnot attested
VIGILANTE84,397

Exposed data

  • Email addresses
  • Geographic locations
  • Names
  • Usernames

In August 2026, millions of records allegedly sourced from Chess.com were posted online. The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the email addresses had already appeared in previous data breaches, further supporting the scraping theory. Read more about scrapes and data breaches.

McKesson logo

mckesson.com

6,404,340accounts
VerifiedSensitiveNo Passwords Leaked
Breached2026-08-2124 days ago

Attestation

HIBP6,404,340
DEHASHED6,404,340
LEAKCHECKnot attested
VIGILANTEnot attested

Exposed data

  • Dates of birth
  • Email addresses
  • Employers
  • Genders
  • Names
  • Personal health data
  • Phone numbers
  • Physical addresses

In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's disclosure notice, the company advised it had identified unauthorised access to "certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units", but had "reasonable assurance of no ongoing unauthorized activity".

ManchesterAirportsGroup logo

Manchester Airports Group

magairports.com

16,752,418accounts
VerifiedNo Passwords Leaked
Breached2026-08-2718 days ago

Attestation

HIBP8,849,657
DEHASHED8,849,657
LEAKCHECK16,752,418
VIGILANTEnot attested

Exposed data

  • Browser user agent details
  • Email addresses
  • Geographic locations
  • IP addresses
  • Names
  • Phone numbers
  • Purchases
  • Vehicle registration plates

In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services. The incident was later claimed by the FulcrumSec hacking group, who subsequently published email addresses and phone numbers relating to 8.8M customers of Manchester, Stansted and East Midlands airports. The data contained personal information relating to airport services, including vehicle registrations and parking history, Fast Track purchases and lounge bookings. In their disclosure notice, MAG advised that "at no point has passenger safety or aviation security been compromised".

Questel logo
1,958,522accounts
VerifiedNo Passwords Leaked
Breached2026-08-01a month ago

Attestation

HIBP1,226,209
DEHASHED1,226,209
LEAKCHECK1,958,522
VIGILANTEnot attested

Exposed data

  • Email addresses
  • Employers
  • Job titles
  • Names
  • Phone numbers
  • Physical addresses
  • Support tickets

In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.

Carhartt logo

carhartt.com

13,746,526accounts
VerifiedNo Passwords Leaked
Breached2026-08-13a month ago

Attestation

HIBP12,933,413
DEHASHED12,933,413
LEAKCHECK13,746,526
VIGILANTEnot attested

Exposed data

  • Email addresses
  • Names
  • Phone numbers
  • Physical addresses

In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained millions of synthetic records that did not relate to real individuals and were excluded from the breach.

NIUS logo
6,090accounts
VerifiedSensitiveNo Passwords Leaked
Breached2025-07-13a year ago

Attestation

HIBP6,090
DEHASHED6,090
LEAKCHECKnot attested
VIGILANTEnot attested

Exposed data

  • Bank account numbers
  • Email addresses
  • Names
  • Partial credit card data
  • Physical addresses
  • Purchases

In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly. The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type and expiry).

GolfCanada logo

Golf Canada

golfcanada.ca

568,972accounts
VerifiedNo Passwords Leaked
Breached2026-05-144 months ago

Attestation

HIBP568,972
DEHASHED568,972
LEAKCHECKnot attested
VIGILANTEnot attested

Exposed data

  • Dates of birth
  • Email addresses
  • Genders
  • Geographic locations
  • Names
  • Usernames

In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). Golf Canada didn't respond to multiple attempts to make contact, and it remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability.

OzHairAndBeauty logo

Oz Hair and Beauty

ozhairandbeauty.com

1,988,331accounts
VerifiedNo Passwords Leaked
Breached2026-08-15a month ago

Attestation

HIBP1,988,331
DEHASHED1,988,331
LEAKCHECKnot attested
VIGILANTEnot attested

Exposed data

  • Email addresses
  • Geographic locations
  • Names
  • Phone numbers
  • Purchases

In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations (suburb and postcode) and purchases.

Fanlore logo
144,520accounts
Verified
Breached2026-08-06a month ago

Attestation

HIBP144,520
DEHASHED144,520
LEAKCHECKnot attested
VIGILANTEnot attested

Exposed data

  • Email addresses
  • Names
  • Passwords
  • Usernames

In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.

RingCentral logo

ringcentral.com

1,830,212accounts
VerifiedNo Passwords Leaked
Breached2026-07-272 months ago

Attestation

HIBP1,596,490
DEHASHED1,596,490
LEAKCHECK1,830,212
VIGILANTEnot attested

Exposed data

  • Email addresses
  • Names
  • Phone numbers
  • Physical addresses

In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addresses and phone numbers. In their disclosure notice, RingCentral advised that the incident affected "a limited portion of RingCentral customers" and that it was communicating directly with those affected.

Alcon logo
408,158accounts
VerifiedNo Passwords Leaked
Breached2026-08-01a month ago

Attestation

HIBP218,395
DEHASHED218,395
LEAKCHECK408,158
VIGILANTEnot attested

Exposed data

  • Email addresses
  • Names
  • Phone numbers
  • Physical addresses

In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and physical address.

BrinksHome logo

Brinks Home

brinkshome.com

1,247,662accounts
VerifiedNo Passwords Leaked
Breached2026-07-132 months ago

Attestation

HIBP732,162
DEHASHED732,162
LEAKCHECK1,247,662
VIGILANTEnot attested

Exposed data

  • Dates of birth
  • Email addresses
  • Names
  • Partial credit card data
  • Phone numbers
  • Physical addresses
  • Purchases

In July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks staff such as name, phone numbers and physical addresses. The data also included purchases from Brinks along with partial credit card data (last 4 digits, card type and expiry). In Brinks' disclosure notice, they acknowledged the incident and risk of disclosure, and advised that they would notify impacted parties "consistent with applicable law".

Rows per page
12
1–12 of 1717

Advertising choice

Google Analytics stays active. Allow Google Ads and Reddit Ads to measure purchases and personalize advertising? Your choice won’t affect search or purchases. You can change it in Settings.

Privacy policy