Dun & Bradstreet
March 15, 2017
•[ leak, misconfiguration, technology ]
A Dun & Bradstreet 52GB database containing about 33.6 million records with very specific details about each of the people involved from job title to email address is exposed.
Master Deeds
March 14, 2017
•[ leak, misconfiguration, finance ]
In March 2017, a 27GB database backup file named "Master Deeds" was sent to HIBP by a supporter of the project. Upon detailed analysis later that year, the file was found to contain the personal data of tens of millions of living and deceased South African residents. The data included extensive personal attributes such as names, addresses, ethnicities, genders, birth dates, government issued personal identification numbers and 2.2 million email addresses. At the time of publishing, it's alleged the data was sourced from Dracore Data Sciences (Dracore is yet to publicly confirm or deny the data was sourced from their systems). On 18 October 2017, the file was found to have been published to a publicly accessible web server where it was located at the root of an IP address with directory listing enabled. The file was dated 8 April 2015.
Welsh NHS
March 13, 2017
•[ leak, healthcare ]
Details of thousands of medical staff of Welsh NHS are stolen from a private contractor's computer server (Landauer). The breach happened in October 2016 and the total number of affected staff is 4,766.
Ster-Kinekor
March 9, 2017
•[ leak, misconfiguration, retail ]
In 2016, the South African cinema company Ster-Kinekor had a security flaw which leaked a large amount of customer data via an enumeration vulnerability in the API of their old website. Whilst more than 6 million accounts were leaked by the flaw, the exposed data only contained 1.6 million unique email addresses. The data also included extensive personal information such as names, addresses, birthdates, genders and plain text passwords.
Jorgie Porter
February 25, 2017
•[ leak ]
English actress and model Jorgie Porter is the latest victim of The Fappening hackers, who manage to steal her intimate pictures and videos and post them online.
Coachella Music Festival
February 22, 2017
•[ leak ]
Nearly one million Coachella accounts are reportedly currently up for sale on the dark web.
San Antonio Symphony
February 14, 2017
•[ hack, leak ]
Computer hackers break into the computer network for the San Antonio Symphony, stealing the names, birth dates, Social Security numbers, addresses and W-2 tax forms for about 250 employees.
Texas Department of Transportation
February 10, 2017
•[ leak, government ]
The Texas Department of Transportation says some personal information of employees was compromised last week due to a "security incident."
Sports Direct
February 8, 2017
•[ leak, retail ]
Sports Direct is accused to have suffered (and kept hidden) a data breach affecting 30,000 employees. The breach allegedly happened in September 2016.
Freedom Hosting II
February 3, 2017
•[ leak, technology ]
The Anonymous take down Freedom Hosting II, the largest repository of dark web sites. The hackers are able to steal 75 GB worth of files and 2.6 GB of databases.
DataCamp
January 30, 2017
•[ leak, education ]
In December 2018, the data science website DataCamp suffered a data breach of records dating back to January 2017. The incident exposed 760k unique email and IP addresses along with names and passwords stored as bcrypt hashes. In 2019, the data appeared listed for sale on a dark web marketplace (along with several other large breaches) and subsequently began circulating more broadly. The data was provided to HIBP by a source who requested it to be attributed to "BenjaminBlue@exploit.im".
AlphaBay
January 26, 2017
•[ leak, misconfiguration, technology ]
About 218,000 unencrypted private messages posted to the AlphaBay dark web marketplace are accessed and released to the public.
Ohio State Veterinary Medical Center
January 21, 2017
•[ leak, malware, education ]
A malware infection is to blame for a security breach that could put the personal information of up to 4,611 clients of the Ohio State Veterinary Medical Center in jeopardy.
Bowlmor AMF
January 20, 2017
•[ leak ]
Bowlmor AMF, the world's largest bowling center operator, says that it had a possible data breach at 21 of its more than 300 domestic locations in 12 states between Feb. 4 and March 19.
SwordFantasy
January 20, 2017
•[ leak, technology ]
In January 2019, the now defunct MMO and RPG game SwordFantasy suffered a data breach that exposed 2.7M unique email addresses. Other impacted data included username, IP address and salted MD5 password hashes.
Channel One
January 17, 2017
•[ leak, technology ]
Russian state television Channel One blames hackers for the leak online of the final episode of the BBC drama Sherlock a day before its actual planning.
Sentara Healthcare
January 16, 2017
•[ leak, healthcare ]
A cyber security breach at a third party vendor for Sentara Healthcare compromises the records of over 5,000 patients.
General Motors
January 12, 2017
•[ leak, manufacturing ]
Reports come out claiming that GM employees' names and social security numbers might have been exposed during a breach.
Thai governmental job portal
January 10, 2017
•[ hack, leak, government ]
The Anonymous kick off another run of #OpSingleGateway and take down multiple governmental job portals, leaking personal and sensitive details of officials and job seekers.
Sephora
January 9, 2017
•[ leak, retail ]
In approximately January 2017, the beauty store Sephora suffered a data breach. Impacting customers in South East Asia, Australia and New Zealand, 780k unique email addresses were included in the breach alongside names, genders, dates of birth, ethnicities and other personal information. The data was provided to HIBP by a source who requested it be attributed to "JimScott.Sec@protonmail.com".