VerifiedNo Passwords Leaked
Breached2019-08-017 years ago
Attestation
HIBP17,838,396
DEHASHED17,838,396
LEAKCHECKnot attested
VIGILANTEnot attested
Exposed data
- Email addresses
- Employers
- Geographic locations
- Job titles
- Phone numbers
In 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The incident exposed tens of millions of records of largely corporate contact data containing 17.8M unique email addresses, along with phone numbers, employers, job titles and geographic locations including state, city and postcode.
VerifiedNo Passwords Leaked
Breached2024-08-252 years ago
Attestation
HIBP3,155,792
DEHASHED3,155,792
LEAKCHECK6,229,110
VIGILANTEnot attested
Exposed data
- Dates of birth
- Email addresses
- Genders
- Geographic locations
- Names
- Phone numbers
In October 2024, news of a data breach exposing Burger King Russia customers broke following an August attack on the Mindbox marketing automation platform. The breach exposed 3.2M unique email addresses along with names, genders, dates of birth, phone numbers and approximate geolocations, with the data spanning 2018 to August 2024. Burger King Russia acknowledged the incident and advised it did not include payment or passport details.
VerifiedNo Passwords Leaked
Breached2026-08-032 months ago
Attestation
HIBP4,653,212
DEHASHED4,653,212
LEAKCHECK9,309,884
VIGILANTE84,397
Exposed data
- Email addresses
- Geographic locations
- Names
- Usernames
VerifiedSensitiveNo Passwords Leaked
Breached2026-08-21a month ago
Attestation
HIBP6,404,340
DEHASHED6,404,340
LEAKCHECK10,335,678
VIGILANTEnot attested
Exposed data
- Dates of birth
- Email addresses
- Employers
- Genders
- Names
- Personal health data
- Phone numbers
- Physical addresses
In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's disclosure notice, the company advised it had identified unauthorised access to "certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units", but had "reasonable assurance of no ongoing unauthorized activity".
VerifiedNo Passwords Leaked
Breached2026-08-27a month ago
Attestation
HIBP8,849,657
DEHASHED8,849,657
LEAKCHECK16,752,418
VIGILANTEnot attested
Exposed data
- Browser user agent details
- Email addresses
- Geographic locations
- IP addresses
- Names
- Phone numbers
- Purchases
- Vehicle registration plates
VerifiedNo Passwords Leaked
Breached2026-08-012 months ago
Attestation
HIBP1,226,209
DEHASHED1,226,209
LEAKCHECK1,958,522
VIGILANTEnot attested
Exposed data
- Email addresses
- Employers
- Job titles
- Names
- Phone numbers
- Physical addresses
- Support tickets
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.
VerifiedNo Passwords Leaked
Breached2026-08-132 months ago
Attestation
HIBP12,933,413
DEHASHED12,933,413
LEAKCHECK13,746,526
VIGILANTEnot attested
Exposed data
- Email addresses
- Names
- Phone numbers
- Physical addresses
VerifiedSensitiveNo Passwords Leaked
Breached2025-07-13a year ago
Attestation
HIBP6,090
DEHASHED6,090
LEAKCHECKnot attested
VIGILANTEnot attested
Exposed data
- Bank account numbers
- Email addresses
- Names
- Partial credit card data
- Physical addresses
- Purchases
VerifiedNo Passwords Leaked
Breached2026-05-145 months ago
Attestation
HIBP568,972
DEHASHED568,972
LEAKCHECKnot attested
VIGILANTEnot attested
Exposed data
- Dates of birth
- Email addresses
- Genders
- Geographic locations
- Names
- Usernames
In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). Golf Canada didn't respond to multiple attempts to make contact, and it remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability.
VerifiedNo Passwords Leaked
Breached2026-08-152 months ago
Attestation
HIBP1,988,331
DEHASHED1,988,331
LEAKCHECK4,005,802
VIGILANTEnot attested
Exposed data
- Email addresses
- Geographic locations
- Names
- Phone numbers
- Purchases
Verified
Breached2026-08-062 months ago
Attestation
HIBP144,520
DEHASHED144,520
LEAKCHECKnot attested
VIGILANTEnot attested
Exposed data
- Email addresses
- Names
- Passwords
- Usernames
In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.
VerifiedNo Passwords Leaked
Breached2026-07-272 months ago
Attestation
HIBP1,596,490
DEHASHED1,596,490
LEAKCHECK1,830,212
VIGILANTEnot attested
Exposed data
- Email addresses
- Names
- Phone numbers
- Physical addresses