Little Monsters
January 1, 2017
•[ leak ]
In approximately January 2017, the Lady Gaga fan site known as "Little Monsters" suffered a data breach that impacted 1 million accounts. The data contained usernames, email addresses, dates of birth and bcrypt hashes of passwords.
CloudPets
January 1, 2017
•[ leak, ransomware, misconfiguration ]
In January, the maker of teddy bears that record children's voices and sends them to family and friends via the internet CloudPets left their database publicly exposed and it was subsequently downloaded by external parties (the data was also subject to 3 different ransom demands). 583k records were provided to HIBP via a data trader and included email addresses and bcrypt hashes, but the full extent of user data exposed by the system was over 821k records and also included children's names and references to portrait photos and voice recordings.
Victory Phones
January 1, 2017
•[ leak, misconfiguration, technology ]
In January 2017, the automated telephony services company Victory Phones left a Mongo DB database publicly facing without a password. Subsequently, 213GB of data was downloaded by an unauthorised party including names, addresses, phone numbers and over 166k unique email addresses.
Russian America
January 1, 2017
•[ leak, misconfiguration, technology ]
In approximately 2017, the website for Russian speakers in America known as Russian America suffered a data breach. The incident exposed 183k unique records including names, email addresses, phone numbers and passwords stored in both plain text and as MD5 hashes. Russian America was contacted about the breach but did not respond.
River City Media Spam List
January 1, 2017
•[ leak, misconfiguration ]
In January 2017, a massive trove of data from River City Media was found exposed online. The data was found to contain almost 1.4 billion records including email and IP addresses, names and physical addresses, all of which was used as part of an enormous spam operation. Once de-duplicated, there were 393 million unique email addresses within the exposed data.
Hub4Tech
January 1, 2017
•[ leak, sqlinjection, education ]
On an unknown date in approximately 2017, the Indian training and assessment service known as Hub4Tech suffered a data breach via a SQL injection attack. The incident exposed almost 37k unique email addresses and passwords stored as unsalted MD5 hashes. No response was received from Hub4Tech when contacted about the incident.
Heathrow Airport
January 1, 2017
•[ leak ]
lost / stolen media
Unknown Organization
December 31, 2016
•[ hack, leak, government ]
In name of #OpSingleGateway Gh0s7 hacks the Thailand's National Statistical Office (nso.go.th) and dumps the leaked data.
GS Polymers, Inc.
December 28, 2016
•[ leak ]
The Dark Overlord claims to have hacked GS Polymers, Inc. and leaks some internal data.
Unknown Organization
December 27, 2016
•[ hack, leak, government ]
Anonymous hacks the official website of the Thai LA consulate (thaiconsulatela.org) and defaces its homepage with a brief message against the arrest of 9 suspects. The group also leaks the data of 900 records.
Unknown Organization
December 19, 2016
•[ hack, leak, education ]
Cryptolulz666 hacks the database of the Indian Institute of Technology Kharagpur, the second of the country and leaks a part of the 12,000 users.
Anti Public Combo List
December 16, 2016
•[ leak, misconfiguration ]
In December 2016, a huge list of email address and password pairs appeared in a "combo list" referred to as "Anti Public". The list contained 458 million unique email addresses, many with multiple different passwords hacked from various online systems. The list was broadly circulated and used for "credential stuffing", that is attackers employ it in an attempt to identify other online systems where the account owner had reused their password. For detailed background on this incident, read Password reuse, credential stuffing and another billion records in Have I Been Pwned.
PayAsUGym
December 15, 2016
•[ hack, leak, misconfiguration ]
In December 2016, an attacker breached PayAsUGym's website exposing over 400k customers' personal data. The data was consequently leaked publicly and broadly distributed via Twitter. The leaked data contained personal information including email addresses and passwords hashed using MD5 without a salt.
Frederick County Public Schools
December 14, 2016
•[ leak, education ]
Data on about 1,000 former students in Frederick County Public Schools in Maryland was likely exposed in a data breach that occurred prior to 2010 but which was only discovered in September of this year.
Vijay Mallya
December 9, 2016
•[ hack, leak, technology ]
Indian tycoon Vijay Mallya's Twitter account appears to have been hacked. The alleged hackers hijack Mallya's account and are currently leaking the industrialist's personal and sensitive information.
DailyMotion
December 5, 2016
•[ leak, technology ]
An unknown hacker extracts 85.2 million unique email addresses and usernames from video-sharing site Dailymotion, one of the biggest video platforms in the world.
Appalachian State University
December 3, 2016
•[ leak, education ]
A group called AppState Leaks releases the data of 1,768 student from Appalachian State University.
FashionFantasyGame
December 1, 2016
•[ leak, misconfiguration, technology ]
In late 2016, the fashion gaming website Fashion Fantasy Game suffered a data breach. The incident exposed 2.3 million unique user accounts and corresponding MD5 password hashes with no salt. The data was contributed to Have I Been Pwned courtesy of rip@creep.im.