Sports Direct
February 8, 2017
•[ leak, retail ]
Sports Direct is accused to have suffered (and kept hidden) a data breach affecting 30,000 employees. The breach allegedly happened in September 2016.
Freedom Hosting II
February 3, 2017
•[ leak, technology ]
The Anonymous take down Freedom Hosting II, the largest repository of dark web sites. The hackers are able to steal 75 GB worth of files and 2.6 GB of databases.
DataCamp
January 30, 2017
•[ leak, education ]
In December 2018, the data science website DataCamp suffered a data breach of records dating back to January 2017. The incident exposed 760k unique email and IP addresses along with names and passwords stored as bcrypt hashes. In 2019, the data appeared listed for sale on a dark web marketplace (along with several other large breaches) and subsequently began circulating more broadly. The data was provided to HIBP by a source who requested it to be attributed to "BenjaminBlue@exploit.im".
AlphaBay
January 26, 2017
•[ leak, misconfiguration, technology ]
About 218,000 unencrypted private messages posted to the AlphaBay dark web marketplace are accessed and released to the public.
Ohio State Veterinary Medical Center
January 21, 2017
•[ leak, malware, education ]
A malware infection is to blame for a security breach that could put the personal information of up to 4,611 clients of the Ohio State Veterinary Medical Center in jeopardy.
Bowlmor AMF
January 20, 2017
•[ leak ]
Bowlmor AMF, the world's largest bowling center operator, says that it had a possible data breach at 21 of its more than 300 domestic locations in 12 states between Feb. 4 and March 19.
SwordFantasy
January 20, 2017
•[ leak, technology ]
In January 2019, the now defunct MMO and RPG game SwordFantasy suffered a data breach that exposed 2.7M unique email addresses. Other impacted data included username, IP address and salted MD5 password hashes.
Channel One
January 17, 2017
•[ leak, technology ]
Russian state television Channel One blames hackers for the leak online of the final episode of the BBC drama Sherlock a day before its actual planning.
Sentara Healthcare
January 16, 2017
•[ leak, healthcare ]
A cyber security breach at a third party vendor for Sentara Healthcare compromises the records of over 5,000 patients.
General Motors
January 12, 2017
•[ leak, manufacturing ]
Reports come out claiming that GM employees' names and social security numbers might have been exposed during a breach.
Thai governmental job portal
January 10, 2017
•[ hack, leak, government ]
The Anonymous kick off another run of #OpSingleGateway and take down multiple governmental job portals, leaking personal and sensitive details of officials and job seekers.
Sephora
January 9, 2017
•[ leak, retail ]
In approximately January 2017, the beauty store Sephora suffered a data breach. Impacting customers in South East Asia, Australia and New Zealand, 780k unique email addresses were included in the breach alongside names, genders, dates of birth, ethnicities and other personal information. The data was provided to HIBP by a source who requested it be attributed to "JimScott.Sec@protonmail.com".
Little Monsters
January 1, 2017
•[ leak ]
In approximately January 2017, the Lady Gaga fan site known as "Little Monsters" suffered a data breach that impacted 1 million accounts. The data contained usernames, email addresses, dates of birth and bcrypt hashes of passwords.
CloudPets
January 1, 2017
•[ leak, ransomware, misconfiguration ]
In January, the maker of teddy bears that record children's voices and sends them to family and friends via the internet CloudPets left their database publicly exposed and it was subsequently downloaded by external parties (the data was also subject to 3 different ransom demands). 583k records were provided to HIBP via a data trader and included email addresses and bcrypt hashes, but the full extent of user data exposed by the system was over 821k records and also included children's names and references to portrait photos and voice recordings.
Victory Phones
January 1, 2017
•[ leak, misconfiguration, technology ]
In January 2017, the automated telephony services company Victory Phones left a Mongo DB database publicly facing without a password. Subsequently, 213GB of data was downloaded by an unauthorised party including names, addresses, phone numbers and over 166k unique email addresses.
Russian America
January 1, 2017
•[ leak, misconfiguration, technology ]
In approximately 2017, the website for Russian speakers in America known as Russian America suffered a data breach. The incident exposed 183k unique records including names, email addresses, phone numbers and passwords stored in both plain text and as MD5 hashes. Russian America was contacted about the breach but did not respond.
River City Media Spam List
January 1, 2017
•[ leak, misconfiguration ]
In January 2017, a massive trove of data from River City Media was found exposed online. The data was found to contain almost 1.4 billion records including email and IP addresses, names and physical addresses, all of which was used as part of an enormous spam operation. Once de-duplicated, there were 393 million unique email addresses within the exposed data.
Hub4Tech
January 1, 2017
•[ leak, sqlinjection, education ]
On an unknown date in approximately 2017, the Indian training and assessment service known as Hub4Tech suffered a data breach via a SQL injection attack. The incident exposed almost 37k unique email addresses and passwords stored as unsalted MD5 hashes. No response was received from Hub4Tech when contacted about the incident.
Heathrow Airport
January 1, 2017
•[ leak ]
lost / stolen media