Life360
March 1, 2024
•[ leak, misconfiguration, manufacturing ]
A threat actor has leaked a database containing the personal information of 442,519 Life360 customers collected by abusing a flaw in the login API.
Telefónica
March 1, 2024
•[ leak, technology ]
Telefnica investigates the claims of a possible cyberattack occurred in March that allowed criminals to access more than 2 million records of clients and collaborators of the company.
Life360
March 1, 2024
•[ leak, misconfiguration, technology ]
In July 2024, data scraped from a misconfigured Life360 API was posted online after being obtained several months earlier. The records included 443k unique email addresses and in most cases, corresponding names and phone numbers (some records were null or obfuscated). Life360 promptly notified impacted users after the incident was discovered.
Mr. Green Gaming
March 1, 2024
•[ leak, technology ]
In March 2024, the online games community Mr. Green Gaming suffered a data breach that exposed 27k user records. Acknowledged on their Discord server, the incident exposed email and IP addresses, usernames, geographic locations and dates of birth.
Chunghwa Telecom
February 29, 2024
•[ espionage, leak, government ]
The Taiwan ministry of national defense says that threat actors stole sensitive information including military and government documents from Chunghwa Telecom, Taiwans largest telecom company and sold it on the dark web.
SurveyLama
February 29, 2024
•[ leak, technology ]
SurveyLama suffers a data breach in February 2024, which exposes the sensitive data of 4.4 million users.
Dohman, Akerlund & Eddy
February 28, 2024
•[ leak, healthcare ]
Accounting firm Dohman, Akerlund & Eddy ("DA&E") announces a data incident that impacted some protected health information of 82,000 people.
Greater Amsterdam School District
February 23, 2024
•[ leak, education ]
The Greater Amsterdam School District discloses that a data breach potentially led to the unauthorized access of protected student information.
Maryville
February 21, 2024
•[ leak, healthcare ]
Maryville, which operates several addiction recovery centers around South Jersey, announces it was the victim of a data breach that accessed Social Security numbers and other personal information,
Tangerine
February 18, 2024
•[ leak, misconfiguration, technology ]
In February 2024, the Australian Telco Tangerine suffered a data breach that exposed over 200k customer records. Attributed to a legacy customer database, the data included physical and email addresses, names, phone numbers and dates of birth. Whilst the Tangerine login process involves sending a one-time password after entering an email address and phone number, it previously used a traditional password which was also exposed as a bcrypt hash.
DemandScience (formerly Pure Incubation)
February 15, 2024
•[ leak, government ]
The business contact information for 122 million people circulating since February 2024 is now confirmed to have been stolen from DemandScience, a B2B demand generation platform.
Undisclosed Meta contractor
February 13, 2024
•[ leak, hack, technology ]
The IntelBroker threat actor leals 200,000 records on a hacker forum, claiming they contain the mobile phone numbers, email addresses, and other personal information of Facebook Marketplace users.
Elector
February 12, 2024
•[ government, leak, technology ]
Researchers from Resecurity identify a data leak of 6,453,254 Israeli voter records due to the breach of Elector, an Israeli software application used to manage political campaigns.
Iraq Independent High Electoral Commission (IHEC)
February 12, 2024
•[ leak, government ]
Researchers from Resecurity identify an individual who claimed to be selling a 21.58 database containing information about 24.3 million Iraqi citizens.
Doxbin (TOoDA)
February 12, 2024
•[ leak ]
In February 2025, the "doxing" website Doxbin was compromised by a group calling themselves "TOoDA" and the data dumped publicly. Included in the breach were 336k unique email addresses alongside usernames. The data was provided to HIBP by a source who requested it be attributed to "emo.rip".
Japanese Ministry of Foreign Affairs
February 5, 2024
•[ leak, espionage, government ]
A government source reveals that classified Japanese diplomatic documents were leaked after a Chinese cyberattacks on the Ministry of Foreign Affairs.
State Street
February 4, 2024
•[ leak, finance ]
State Street files a notice of data breach after discovering that an unauthorized party was able to access confidential information in the companys possession.
Hewlett Packard Enterprise
February 1, 2024
•[ leak, technology ]
Hewlett Packard Enterprise (HPE) is investigating a potential new breach after a threat actor put allegedly stolen data up for sale on a hacking forum, claiming it contains HPE credentials and other sensitive information.
SurveyLama
February 1, 2024
•[ leak, technology ]
In February 2024, the paid survey website SurveyLama suffered a data breach that exposed 4.4M customer email addresses. The incident also exposed names, physical and IP addresses, phone numbers, dates of birth and passwords stored as either salted SHA-1, bcrypt or argon2 hashes. When contacted about the incident, SurveyLama advised that they had already "notified the users by email".
Emmanuel College
January 31, 2024
•[ leak, education ]
Emmanuel College files a notice of data breach after discovering that a cybersecurity incident affected the personal information of nearly 90k individuals.