RedBus
October 18, 2016
•[ leak, technology ]
Online travel giant Ibibo Group-owned ticketing platform RedBus confirms to have been subject to a cyber attack that might have exposed the email addresses of some of its customers.
Modern Business Systems (MBS)
October 13, 2016
•[ leak, technology ]
Over 58 million customer records are stolen and leaked online. Data includes names, email and postal addresses, phone numbers, IP addresses and more.
Modern Business Solutions
October 8, 2016
•[ leak, misconfiguration, technology ]
In October 2016, a large Mongo DB file containing tens of millions of accounts was shared publicly on Twitter (the file has since been removed). The database contained over 58M unique email addresses along with IP addresses, names, home addresses, genders, job titles, dates of birth and phone numbers. The data was subsequently attributed to "Modern Business Solutions", a company that provides data storage and database hosting solutions. They've yet to acknowledge the incident or explain how they came to be in possession of the data.
Pont3
October 6, 2016
•[ leak, misconfiguration, retail ]
Pont3, an Australian event organizer, reveals that an unauthorized party had gained access to its mailing list account and downloaded data about individuals that subscribed to various events organized by the company in the past.
Pokémon Negro
October 1, 2016
•[ leak, technology ]
In approximately October 2016, the Spanish Pokmon site Pokmon Negro suffered a data breach. The attack resulted in the disclosure of 830k accounts including email and IP addresses along with plain text passwords. Pokmon Negro did not respond when contacted about the breach.
newseasims
September 30, 2016
•[ leak, technology ]
A hacker going by the handle of "Websites Hunter" hacks newseasims.com, a website that offers custom content for Sims video games from Electronic Arts, and leaks personal details of 118,000 customers/users.
feverclan
September 29, 2016
•[ hack, leak ]
pr0jekkt hacks feverclan.com and dumps the data of 50,000 users.
Justdate.com
September 29, 2016
•[ leak, technology ]
An alleged breach of the dating website Justdate.com began circulating in approximately September 2016. Comprised of over 24 million records, the data contained various personal attributes such as email addresses, dates of birth and physical locations. However, upon verification with HIBP subscribers, only a fraction of the data was found to be accurate and no account owners recalled using the Justdate.com service. This breach has consequently been flagged as fabricated; it's highly unlikely the data was sourced from Justdate.com.
Michelle Obama
September 22, 2016
•[ leak, government ]
An image purported to be a scanned copy of U.S. first lady Michelle Obama's passport is leaked online alongside personal emails said to belong to a low-level White House staffer who worked with Hillary Clinton's presidential campaign.
vDoS
September 8, 2016
•[ hack, leak, ddos ]
vDos, a "booter" service that has earned in excess of $600,000 over the past two years helping customers coordinate more than 150,000 DDoS attacks is massively hacked, spilling secrets about tens of thousands of paying customers and their targets.
uuu9
September 6, 2016
•[ leak, technology ]
In September 2016, data was allegedly obtained from the Chinese website known as uuu9.com and contained 7.5M accounts. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains email addresses and user names. Read more about Chinese data breaches in Have I Been Pwned.
Brazzers
September 5, 2016
•[ leak, misconfiguration, technology ]
Nearly 800,000 accounts for popular porn site Brazzers have been exposed in a data breach.
Digimon
September 5, 2016
•[ leak, misconfiguration, technology ]
In September 2016, over 16GB of logs from a service indicated to be digimon.co.in were obtained, most likely from an unprotected Mongo DB instance. The service ceased running shortly afterwards and no information remains about the precise nature of it. Based on enquiries made via Twitter, it appears to have been a mail service possibly based on PowerMTA and used for delivering spam. The logs contained information including 7.7M unique email recipients (names and addresses), mail server IP addresses, email subjects and tracking information including mail opens and clicks.
NemoWeb
September 4, 2016
•[ leak, misconfiguration, technology ]
In September 2016, almost 21GB of data from the French website used for "standardised and decentralized means of exchange for publishing newsgroup articles" NemoWeb was leaked from what appears to have been an unprotected Mongo DB. The data consisted of a large volume of emails sent to the service and included almost 3.5M unique addresses, albeit many of them auto-generated. Multiple attempts were made to contact the operators of NemoWeb but no response was received.
Armenian National Security Service
September 2, 2016
•[ hack, leak, government ]
Azerbaijani hacktivists from Anti-Armenia Team leak the passport details of foreign visitors to Armenia and more after breaking into Armenian government servers.
NetProspex
September 1, 2016
•[ leak, misconfiguration, technology ]
In 2016, a list of over 33 million individuals in corporate America sourced from Dun & Bradstreet's NetProspex service was leaked online. D&B believe the targeted marketing data was lost by a customer who purchased it from them. It contained extensive personal and corporate information including names, email addresses, job titles and general information about the employer.
Unknown Organization
August 31, 2016
•[ leak, healthcare ]
The Al Zahra Private Medical Centre is hacked by an individual calling himself websites-hunter, who dumps the database online.
MDPI
August 30, 2016
•[ leak, misconfiguration, education ]
In August 2016, the Swiss scholarly open access publisher known as MDPI had 17.5GB of data obtained from an unprotected Mongo DB instance. The data contained email exchanges between MDPI and their authors and reviewers which included 845k unique email addresses. MDPI have confirmed that the system has since been protected and that no data of a sensitive nature was impacted. As such, they concluded that notification to their subscribers was not necessary due to the fact that all their authors and reviewers are available online on their website.
The Equation Group
August 16, 2016
•[ leak, government ]
An anonymous group calling itself Shadow Brokers publishes what it claims are sophisticated software tools belonging to an elite team of hackers tied to the US National Security Agency known as "The Equation Group".
GeekedIn
August 15, 2016
•[ leak, misconfiguration, technology ]
In August 2016, the technology recruitment site GeekedIn left a MongoDB database exposed and over 8M records were extracted by an unknown third party. The breached data was originally scraped from GitHub in violation of their terms of use and contained information exposed in public profiles, including over 1 million members' email addresses. Full details on the incident (including how impacted members can see their leaked data) are covered in the blog post on 8 million GitHub profiles were leaked from GeekedIn's MongoDB - here's how to see yours.