{
  "version": "https://jsonfeed.org/version/1.1",
  "title": "Data breaches (Have I Been Pwned)",
  "home_page_url": "https://haveibeenpwned.com/PwnedWebsites",
  "description": "Events collected by UnlimitedPipe 0.3.2",
  "_unlimitedpipe": {
    "schema": "unlimitedpipe.event/1",
    "generator": "UnlimitedPipe 0.3.2"
  },
  "items": [
    {
      "id": "f6babcc07b12c1057e44",
      "title": "LimeLeads: 17.8M accounts breached",
      "content_text": "In 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The incident exposed tens of millions of records of largely corporate contact data containing 17.8M unique email addresses, along with phone numbers, employers, job titles and geographic locations including state, city and postcode.",
      "date_published": "2026-09-22T08:02:37Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "f6babcc07b12c1057e44",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#LimeLeads",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "LimeLeads: 17.8M accounts breached",
            "item_type": "record",
            "summary": "added: LimeLeads: 17.8M accounts breached",
            "after": {
              "Name": "LimeLeads",
              "Domain": "limeleads.com",
              "BreachDate": "2019-08-01",
              "AddedDate": "2026-09-22T08:02:37Z",
              "ModifiedDate": "2026-09-22T08:02:37Z",
              "PwnCount": 17838396,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Email addresses",
                "Employers",
                "Geographic locations",
                "Job titles",
                "Phone numbers"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "17.8M",
              "title": "LimeLeads: 17.8M accounts breached",
              "summary": "In 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The incident exposed tens of millions of records of largely corporate contact data containing 17.8M unique email addresses, along with phone numbers, employers, job titles and geographic locations including state, city and postcode.",
              "published_at": "2026-09-22T08:02:37Z",
              "link": "https://haveibeenpwned.com/Breach/LimeLeads"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/LimeLeads"
    },
    {
      "id": "e50209434788b520b095",
      "title": "Burger King Russia: 3.1M accounts breached",
      "content_text": "In October 2024, news of a data breach exposing Burger King Russia customers broke following an August attack on the Mindbox marketing automation platform. The breach exposed 3.2M unique email addresses along with names, genders, dates of birth, phone numbers and approximate geolocations, with the data spanning 2018 to August 2024. Burger King Russia acknowledged the incident and advised it did not include payment or passport details.",
      "date_published": "2026-09-21T13:54:00Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "e50209434788b520b095",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#BurgerKingRussia",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Burger King Russia: 3.1M accounts breached",
            "item_type": "record",
            "summary": "added: Burger King Russia: 3.1M accounts breached",
            "after": {
              "Name": "BurgerKingRussia",
              "Domain": "burgerkingrus.ru",
              "BreachDate": "2024-08-25",
              "AddedDate": "2026-09-21T13:54:00Z",
              "ModifiedDate": "2026-09-21T13:54:00Z",
              "PwnCount": 3155792,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Dates of birth",
                "Email addresses",
                "Genders",
                "Geographic locations",
                "Names",
                "Phone numbers"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "3.1M",
              "title": "Burger King Russia: 3.1M accounts breached",
              "summary": "In October 2024, news of a data breach exposing Burger King Russia customers broke following an August attack on the Mindbox marketing automation platform. The breach exposed 3.2M unique email addresses along with names, genders, dates of birth, phone numbers and approximate geolocations, with the data spanning 2018 to August 2024. Burger King Russia acknowledged the incident and advised it did not include payment or passport details.",
              "published_at": "2026-09-21T13:54:00Z",
              "link": "https://haveibeenpwned.com/Breach/BurgerKingRussia"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/BurgerKingRussia"
    },
    {
      "id": "a20228e4e11d19ba6aa7",
      "title": "Chess.com (2026): 4.6M accounts breached",
      "content_text": "In August 2026, millions of records allegedly sourced from Chess.com were posted online. The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the email addresses had already appeared in previous data breaches, further supporting the scraping theory. Read more about scrapes and data breaches.",
      "date_published": "2026-09-13T13:09:11Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "a20228e4e11d19ba6aa7",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#Chess2026",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Chess.com (2026): 4.6M accounts breached",
            "item_type": "record",
            "summary": "added: Chess.com (2026): 4.6M accounts breached",
            "after": {
              "Name": "Chess2026",
              "Domain": "chess.com",
              "BreachDate": "2026-08-03",
              "AddedDate": "2026-09-13T13:09:11Z",
              "ModifiedDate": "2026-09-13T13:09:11Z",
              "PwnCount": 4653212,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Email addresses",
                "Geographic locations",
                "Names",
                "Usernames"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "4.6M",
              "title": "Chess.com (2026): 4.6M accounts breached",
              "summary": "In August 2026, millions of records allegedly sourced from Chess.com were posted online. The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data relating to users' Chess.com accounts. Analysis of the data suggested it had been obtained by scraping. When loaded into HIBP, 99% of the email addresses had already appeared in previous data breaches, further supporting the scraping theory. Read more about scrapes and data breaches.",
              "published_at": "2026-09-13T13:09:11Z",
              "link": "https://haveibeenpwned.com/Breach/Chess2026"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/Chess2026"
    },
    {
      "id": "a3fe0dd5cf6b808fa885",
      "title": "McKesson: 6.4M accounts breached",
      "content_text": "In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's…",
      "date_published": "2026-09-10T05:45:39Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "a3fe0dd5cf6b808fa885",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#McKesson",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "McKesson: 6.4M accounts breached",
            "item_type": "record",
            "summary": "added: McKesson: 6.4M accounts breached",
            "after": {
              "Name": "McKesson",
              "Domain": "mckesson.com",
              "BreachDate": "2026-08-21",
              "AddedDate": "2026-09-10T05:45:39Z",
              "ModifiedDate": "2026-09-10T05:45:39Z",
              "PwnCount": 6404340,
              "Attribution": null,
              "DisclosureUrl": "https://www.mckesson.com/utility/cybersecurity/customer-cybersecurity-information-center/",
              "DataClasses": [
                "Dates of birth",
                "Email addresses",
                "Employers",
                "Genders",
                "Names",
                "Personal health data",
                "Phone numbers",
                "Physical addresses"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": true,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "6.4M",
              "title": "McKesson: 6.4M accounts breached",
              "summary": "In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses among other personal and corporate data attributes. The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff and healthcare provider contacts. In McKesson's disclosure notice, the company advised it had identified unauthorised access to \"certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units\", but had \"reasonable assurance of no ongoing unauthorized activity\".",
              "published_at": "2026-09-10T05:45:39Z",
              "link": "https://haveibeenpwned.com/Breach/McKesson"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/McKesson"
    },
    {
      "id": "161ab145fd389db931c4",
      "title": "Manchester Airports Group: 8.8M accounts breached",
      "content_text": "In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services. The incident was later claimed by the FulcrumSec hacking group, who subsequently published email addresses and phone numbers relating to 8.8M customers of Manchester, Stansted and East Midlands airports. The data contained personal information relating to airport services, including vehicle registrations and parking history, Fast Track purchases and lounge bookings. In their disclosure notice, MAG…",
      "date_published": "2026-09-02T07:36:59Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "161ab145fd389db931c4",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#ManchesterAirportsGroup",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Manchester Airports Group: 8.8M accounts breached",
            "item_type": "record",
            "summary": "added: Manchester Airports Group: 8.8M accounts breached",
            "after": {
              "Name": "ManchesterAirportsGroup",
              "Domain": "magairports.com",
              "BreachDate": "2026-08-27",
              "AddedDate": "2026-09-02T07:36:59Z",
              "ModifiedDate": "2026-09-02T23:59:05Z",
              "PwnCount": 8849657,
              "Attribution": null,
              "DisclosureUrl": "https://mediacentre.magairports.com/mag-statement-on-cyber-security-incident/",
              "DataClasses": [
                "Browser user agent details",
                "Email addresses",
                "Geographic locations",
                "IP addresses",
                "Names",
                "Phone numbers",
                "Purchases",
                "Vehicle registration plates"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "8.8M",
              "title": "Manchester Airports Group: 8.8M accounts breached",
              "summary": "In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services. The incident was later claimed by the FulcrumSec hacking group, who subsequently published email addresses and phone numbers relating to 8.8M customers of Manchester, Stansted and East Midlands airports. The data contained personal information relating to airport services, including vehicle registrations and parking history, Fast Track purchases and lounge bookings. In their disclosure notice, MAG advised that \"at no point has passenger safety or aviation security been compromised\".",
              "published_at": "2026-09-02T07:36:59Z",
              "link": "https://haveibeenpwned.com/Breach/ManchesterAirportsGroup"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/ManchesterAirportsGroup"
    },
    {
      "id": "354f7f432d4dbe9741e8",
      "title": "Questel: 1.2M accounts breached",
      "content_text": "In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses…",
      "date_published": "2026-09-01T04:49:35Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "354f7f432d4dbe9741e8",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#Questel",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Questel: 1.2M accounts breached",
            "item_type": "record",
            "summary": "added: Questel: 1.2M accounts breached",
            "after": {
              "Name": "Questel",
              "Domain": "questel.com",
              "BreachDate": "2026-08-01",
              "AddedDate": "2026-09-01T04:49:35Z",
              "ModifiedDate": "2026-09-01T04:55:05Z",
              "PwnCount": 1226209,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Email addresses",
                "Employers",
                "Job titles",
                "Names",
                "Phone numbers",
                "Physical addresses",
                "Support tickets"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "1.2M",
              "title": "Questel: 1.2M accounts breached",
              "summary": "In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact information associated with sales leads, support cases and marketing activities, with 1.2M unique email addresses. The data also included names, employers and job titles, along with physical addresses and phone numbers.",
              "published_at": "2026-09-01T04:49:35Z",
              "link": "https://haveibeenpwned.com/Breach/Questel"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/Questel"
    },
    {
      "id": "2f9002d33693df8b8a20",
      "title": "Carhartt: 12.9M accounts breached",
      "content_text": "In August 2026, clothing retailer Carhartt was the target of a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained millions of synthetic records that did not relate to real individuals and were excluded from the breach.",
      "date_published": "2026-08-25T21:34:25Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "2f9002d33693df8b8a20",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#Carhartt",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Carhartt: 12.9M accounts breached",
            "item_type": "record",
            "summary": "added: Carhartt: 12.9M accounts breached",
            "after": {
              "Name": "Carhartt",
              "Domain": "carhartt.com",
              "BreachDate": "2026-08-13",
              "AddedDate": "2026-08-25T21:34:25Z",
              "ModifiedDate": "2026-08-25T21:34:25Z",
              "PwnCount": 12933413,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Email addresses",
                "Names",
                "Phone numbers",
                "Physical addresses"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "12.9M",
              "title": "Carhartt: 12.9M accounts breached",
              "summary": "In August 2026, clothing retailer Carhartt was the target of a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M unique email addresses, names, phone numbers and physical addresses. The published corpus also contained millions of synthetic records that did not relate to real individuals and were excluded from the breach.",
              "published_at": "2026-08-25T21:34:25Z",
              "link": "https://haveibeenpwned.com/Breach/Carhartt"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/Carhartt"
    },
    {
      "id": "066b6cf994888bac4036",
      "title": "NIUS: 6K accounts breached",
      "content_text": "In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly. The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type and expiry).",
      "date_published": "2026-08-23T22:25:44Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "066b6cf994888bac4036",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#NIUS",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "NIUS: 6K accounts breached",
            "item_type": "record",
            "summary": "added: NIUS: 6K accounts breached",
            "after": {
              "Name": "NIUS",
              "Domain": "nius.de",
              "BreachDate": "2025-07-13",
              "AddedDate": "2026-08-23T22:25:44Z",
              "ModifiedDate": "2026-08-23T22:25:44Z",
              "PwnCount": 6090,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Bank account numbers",
                "Email addresses",
                "Names",
                "Partial credit card data",
                "Physical addresses",
                "Purchases"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": true,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "6K",
              "title": "NIUS: 6K accounts breached",
              "summary": "In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly. The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type and expiry).",
              "published_at": "2026-08-23T22:25:44Z",
              "link": "https://haveibeenpwned.com/Breach/NIUS"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/NIUS"
    },
    {
      "id": "028cd5093f051dbc180f",
      "title": "Golf Canada: 568K accounts breached",
      "content_text": "In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). It remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability.",
      "date_published": "2026-08-22T07:17:23Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "028cd5093f051dbc180f",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#GolfCanada",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Golf Canada: 568K accounts breached",
            "item_type": "record",
            "summary": "added: Golf Canada: 568K accounts breached",
            "after": {
              "Name": "GolfCanada",
              "Domain": "golfcanada.ca",
              "BreachDate": "2026-05-14",
              "AddedDate": "2026-08-22T07:17:23Z",
              "ModifiedDate": "2026-09-05T20:02:16Z",
              "PwnCount": 568972,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Dates of birth",
                "Email addresses",
                "Genders",
                "Geographic locations",
                "Names",
                "Usernames"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "568K",
              "title": "Golf Canada: 568K accounts breached",
              "summary": "In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). It remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability.",
              "published_at": "2026-08-22T07:17:23Z",
              "link": "https://haveibeenpwned.com/Breach/GolfCanada"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/GolfCanada"
    },
    {
      "id": "9d66ea7e5e169aaa62bd",
      "title": "Oz Hair and Beauty: 1.9M accounts breached",
      "content_text": "In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations (suburb and postcode) and purchases.",
      "date_published": "2026-08-19T03:15:00Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "9d66ea7e5e169aaa62bd",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#OzHairAndBeauty",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Oz Hair and Beauty: 1.9M accounts breached",
            "item_type": "record",
            "summary": "added: Oz Hair and Beauty: 1.9M accounts breached",
            "after": {
              "Name": "OzHairAndBeauty",
              "Domain": "ozhairandbeauty.com",
              "BreachDate": "2026-08-15",
              "AddedDate": "2026-08-19T03:15:00Z",
              "ModifiedDate": "2026-08-19T03:15:00Z",
              "PwnCount": 1988331,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Email addresses",
                "Geographic locations",
                "Names",
                "Phone numbers",
                "Purchases"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "1.9M",
              "title": "Oz Hair and Beauty: 1.9M accounts breached",
              "summary": "In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations (suburb and postcode) and purchases.",
              "published_at": "2026-08-19T03:15:00Z",
              "link": "https://haveibeenpwned.com/Breach/OzHairAndBeauty"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/OzHairAndBeauty"
    },
    {
      "id": "7122494959e1a3afd4a0",
      "title": "Fanlore: 144K accounts breached",
      "content_text": "In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.",
      "date_published": "2026-08-19T02:09:16Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "7122494959e1a3afd4a0",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#Fanlore",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Fanlore: 144K accounts breached",
            "item_type": "record",
            "summary": "added: Fanlore: 144K accounts breached",
            "after": {
              "Name": "Fanlore",
              "Domain": "fanlore.org",
              "BreachDate": "2026-08-06",
              "AddedDate": "2026-08-19T02:09:16Z",
              "ModifiedDate": "2026-08-19T02:09:16Z",
              "PwnCount": 144520,
              "Attribution": null,
              "DisclosureUrl": "https://www.transformativeworks.org/fanlore-security-incident/",
              "DataClasses": [
                "Email addresses",
                "Names",
                "Passwords",
                "Usernames"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "144K",
              "title": "Fanlore: 144K accounts breached",
              "summary": "In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.",
              "published_at": "2026-08-19T02:09:16Z",
              "link": "https://haveibeenpwned.com/Breach/Fanlore"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/Fanlore"
    },
    {
      "id": "c4543cb236db6bc17758",
      "title": "RingCentral: 1.5M accounts breached",
      "content_text": "In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addresses and phone numbers. In their disclosure notice, RingCentral advised that the incident affected \"a limited portion of RingCentral customers\" and that it was communicating directly with those…",
      "date_published": "2026-08-13T10:54:40Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "c4543cb236db6bc17758",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#RingCentral",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "RingCentral: 1.5M accounts breached",
            "item_type": "record",
            "summary": "added: RingCentral: 1.5M accounts breached",
            "after": {
              "Name": "RingCentral",
              "Domain": "ringcentral.com",
              "BreachDate": "2026-07-27",
              "AddedDate": "2026-08-13T10:54:40Z",
              "ModifiedDate": "2026-08-13T10:54:40Z",
              "PwnCount": 1596490,
              "Attribution": "https://www.ringcentral.com/trust-center/security-bulletin.html",
              "DisclosureUrl": null,
              "DataClasses": [
                "Email addresses",
                "Names",
                "Phone numbers",
                "Physical addresses"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "1.5M",
              "title": "RingCentral: 1.5M accounts breached",
              "summary": "In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addresses and phone numbers. In their disclosure notice, RingCentral advised that the incident affected \"a limited portion of RingCentral customers\" and that it was communicating directly with those affected.",
              "published_at": "2026-08-13T10:54:40Z",
              "link": "https://haveibeenpwned.com/Breach/RingCentral"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/RingCentral"
    },
    {
      "id": "ef93ad235b8b86a9bbde",
      "title": "Alcon: 218K accounts breached",
      "content_text": "In August 2026, the Alcon eye care company was named in a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and physical address.",
      "date_published": "2026-08-09T10:04:34Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "ef93ad235b8b86a9bbde",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#Alcon",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Alcon: 218K accounts breached",
            "item_type": "record",
            "summary": "added: Alcon: 218K accounts breached",
            "after": {
              "Name": "Alcon",
              "Domain": "alcon.com",
              "BreachDate": "2026-08-01",
              "AddedDate": "2026-08-09T10:04:34Z",
              "ModifiedDate": "2026-08-09T10:04:34Z",
              "PwnCount": 218395,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Email addresses",
                "Names",
                "Phone numbers",
                "Physical addresses"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "218K",
              "title": "Alcon: 218K accounts breached",
              "summary": "In August 2026, the Alcon eye care company was named in a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and physical address.",
              "published_at": "2026-08-09T10:04:34Z",
              "link": "https://haveibeenpwned.com/Breach/Alcon"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/Alcon"
    },
    {
      "id": "bba1ceecdadb379849f3",
      "title": "Brinks Home: 732K accounts breached",
      "content_text": "In July 2026, Brinks Home was targeted in a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks staff such as name, phone numbers and physical addresses. The data also included purchases from Brinks along with partial credit card data (last 4 digits, card type and expiry). In Brinks' disclosure notice, they…",
      "date_published": "2026-08-08T10:44:52Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "bba1ceecdadb379849f3",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#BrinksHome",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Brinks Home: 732K accounts breached",
            "item_type": "record",
            "summary": "added: Brinks Home: 732K accounts breached",
            "after": {
              "Name": "BrinksHome",
              "Domain": "brinkshome.com",
              "BreachDate": "2026-07-13",
              "AddedDate": "2026-08-08T10:44:52Z",
              "ModifiedDate": "2026-08-08T10:44:52Z",
              "PwnCount": 732162,
              "Attribution": null,
              "DisclosureUrl": "https://brinkshome.com/cybersecurity-update",
              "DataClasses": [
                "Dates of birth",
                "Email addresses",
                "Names",
                "Partial credit card data",
                "Phone numbers",
                "Physical addresses",
                "Purchases"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "732K",
              "title": "Brinks Home: 732K accounts breached",
              "summary": "In July 2026, Brinks Home was targeted in a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks staff such as name, phone numbers and physical addresses. The data also included purchases from Brinks along with partial credit card data (last 4 digits, card type and expiry). In Brinks' disclosure notice, they acknowledged the incident and risk of disclosure, and advised that they would notify impacted parties \"consistent with applicable law\".",
              "published_at": "2026-08-08T10:44:52Z",
              "link": "https://haveibeenpwned.com/Breach/BrinksHome"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/BrinksHome"
    },
    {
      "id": "853a3a9c3fc679d43ab3",
      "title": "Exact Sciences: 10.8M accounts breached",
      "content_text": "In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters \"pay or leak\" extortion campaign. The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10.9M unique email addresses belonging to customers, patients and healthcare providers, along with names, addresses, phone numbers and health records. Abbott subsequently published a public notice advising that \"some of…",
      "date_published": "2026-08-07T06:27:29Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "853a3a9c3fc679d43ab3",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#ExactSciences",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Exact Sciences: 10.8M accounts breached",
            "item_type": "record",
            "summary": "added: Exact Sciences: 10.8M accounts breached",
            "after": {
              "Name": "ExactSciences",
              "Domain": "exactsciences.com",
              "BreachDate": "2026-07-15",
              "AddedDate": "2026-08-07T06:27:29Z",
              "ModifiedDate": "2026-08-07T06:27:29Z",
              "PwnCount": 10869543,
              "Attribution": null,
              "DisclosureUrl": "https://www.abbott.com/en-us/corpnewsroom/diagnostics-testing/abbott-statement-on-cyber-incident-in-cancer-diagnostics-business",
              "DataClasses": [
                "Dates of birth",
                "Email addresses",
                "Genders",
                "Names",
                "Personal health data",
                "Phone numbers",
                "Physical addresses"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": true,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "10.8M",
              "title": "Exact Sciences: 10.8M accounts breached",
              "summary": "In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters \"pay or leak\" extortion campaign. The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10.9M unique email addresses belonging to customers, patients and healthcare providers, along with names, addresses, phone numbers and health records. Abbott subsequently published a public notice advising that \"some of the impacted files contain personal information and/or personal health information\" and that more specific information would follow once their review of the incident was complete. For context, Exact Sciences is the maker of the Cologuard at-home colorectal cancer screening test.",
              "published_at": "2026-08-07T06:27:29Z",
              "link": "https://haveibeenpwned.com/Breach/ExactSciences"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/ExactSciences"
    },
    {
      "id": "c81e849cc09281cd5c6b",
      "title": "Inter-Con Security: 276K accounts breached",
      "content_text": "In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign. The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompassed a combination of contacts, internal users and leads.",
      "date_published": "2026-08-05T23:39:01Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "c81e849cc09281cd5c6b",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#InterConSecurity",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Inter-Con Security: 276K accounts breached",
            "item_type": "record",
            "summary": "added: Inter-Con Security: 276K accounts breached",
            "after": {
              "Name": "InterConSecurity",
              "Domain": "icsecurity.com",
              "BreachDate": "2026-06-18",
              "AddedDate": "2026-08-05T23:39:01Z",
              "ModifiedDate": "2026-08-05T23:39:01Z",
              "PwnCount": 276114,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Email addresses",
                "Employers",
                "Job titles",
                "Names",
                "Phone numbers",
                "Physical addresses"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "276K",
              "title": "Inter-Con Security: 276K accounts breached",
              "summary": "In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign. The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompassed a combination of contacts, internal users and leads.",
              "published_at": "2026-08-05T23:39:01Z",
              "link": "https://haveibeenpwned.com/Breach/InterConSecurity"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/InterConSecurity"
    },
    {
      "id": "6417db42b41341d1fea0",
      "title": "SplitVPN: 865K accounts breached",
      "content_text": "In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).",
      "date_published": "2026-08-01T05:29:26Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "6417db42b41341d1fea0",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#SplitVPN",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "SplitVPN: 865K accounts breached",
            "item_type": "record",
            "summary": "added: SplitVPN: 865K accounts breached",
            "after": {
              "Name": "SplitVPN",
              "Domain": "splitvpn.io",
              "BreachDate": "2026-07-21",
              "AddedDate": "2026-08-01T05:29:26Z",
              "ModifiedDate": "2026-08-01T05:29:26Z",
              "PwnCount": 865336,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Device information",
                "Email addresses",
                "Geographic locations",
                "IP addresses",
                "Partial credit card data"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "865K",
              "title": "SplitVPN: 865K accounts breached",
              "summary": "In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).",
              "published_at": "2026-08-01T05:29:26Z",
              "link": "https://haveibeenpwned.com/Breach/SplitVPN"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/SplitVPN"
    },
    {
      "id": "3165782f416fa14b6f17",
      "title": "Houston City College: 831K accounts breached",
      "content_text": "In June 2026, Houston City College was the target of a ShinyHunters \"pay or leak\" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and other personal information relating to both current students and alumni.",
      "date_published": "2026-07-28T06:05:24Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "3165782f416fa14b6f17",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#HoustonCityCollege",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Houston City College: 831K accounts breached",
            "item_type": "record",
            "summary": "added: Houston City College: 831K accounts breached",
            "after": {
              "Name": "HoustonCityCollege",
              "Domain": "hccs.edu",
              "BreachDate": "2026-06-16",
              "AddedDate": "2026-07-28T06:05:24Z",
              "ModifiedDate": "2026-07-28T06:05:24Z",
              "PwnCount": 831642,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Academic records",
                "Citizenship statuses",
                "Dates of birth",
                "Email addresses",
                "Genders",
                "Names",
                "Phone numbers",
                "Physical addresses"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "831K",
              "title": "Houston City College: 831K accounts breached",
              "summary": "In June 2026, Houston City College was the target of a ShinyHunters \"pay or leak\" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and other personal information relating to both current students and alumni.",
              "published_at": "2026-07-28T06:05:24Z",
              "link": "https://haveibeenpwned.com/Breach/HoustonCityCollege"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/HoustonCityCollege"
    },
    {
      "id": "b7e568e87e47e24166a0",
      "title": "Suno: 55.2M accounts breached",
      "content_text": "In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year. The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a small portion of the corpus, the breach also included tens of thousands of Stripe records relating to purchases, containing names, physical addresses, purchase amounts and partial credit card data including the card…",
      "date_published": "2026-07-20T19:49:51Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "b7e568e87e47e24166a0",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#Suno",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Suno: 55.2M accounts breached",
            "item_type": "record",
            "summary": "added: Suno: 55.2M accounts breached",
            "after": {
              "Name": "Suno",
              "Domain": "suno.com",
              "BreachDate": "2025-11-25",
              "AddedDate": "2026-07-20T19:49:51Z",
              "ModifiedDate": "2026-07-20T19:49:51Z",
              "PwnCount": 55282226,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Email addresses",
                "Names",
                "Partial credit card data",
                "Phone numbers",
                "Physical addresses",
                "Purchases"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "55.2M",
              "title": "Suno: 55.2M accounts breached",
              "summary": "In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year. The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a small portion of the corpus, the breach also included tens of thousands of Stripe records relating to purchases, containing names, physical addresses, purchase amounts and partial credit card data including the card type, expiry date and last 4 digits. The company advised that \"Suno does not have access to customers' full credit card numbers in Stripe\".",
              "published_at": "2026-07-20T19:49:51Z",
              "link": "https://haveibeenpwned.com/Breach/Suno"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/Suno"
    },
    {
      "id": "b5fe58109302faedb500",
      "title": "Paidwork: 23.2M accounts breached",
      "content_text": "In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale. Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The breach also included a broad range of other data relating to the operation of the platform including user profile data, banking information, payout history for workers and passwords stored as bcrypt hashes.",
      "date_published": "2026-07-19T22:57:18Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "b5fe58109302faedb500",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#Paidwork",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Paidwork: 23.2M accounts breached",
            "item_type": "record",
            "summary": "added: Paidwork: 23.2M accounts breached",
            "after": {
              "Name": "Paidwork",
              "Domain": "paidwork.com",
              "BreachDate": "2026-03-29",
              "AddedDate": "2026-07-19T22:57:18Z",
              "ModifiedDate": "2026-07-19T22:57:18Z",
              "PwnCount": 23272765,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Bank account numbers",
                "Dates of birth",
                "Device information",
                "Education levels",
                "Email addresses",
                "Financial transactions",
                "Genders",
                "IP addresses",
                "Names",
                "Passwords",
                "Personal interests",
                "Phone numbers",
                "Physical addresses",
                "Profile photos"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "23.2M",
              "title": "Paidwork: 23.2M accounts breached",
              "summary": "In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale. Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The breach also included a broad range of other data relating to the operation of the platform including user profile data, banking information, payout history for workers and passwords stored as bcrypt hashes.",
              "published_at": "2026-07-19T22:57:18Z",
              "link": "https://haveibeenpwned.com/Breach/Paidwork"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/Paidwork"
    },
    {
      "id": "4f642033fdeed9fd4dc9",
      "title": "Fluke: 821K accounts breached",
      "content_text": "In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present.",
      "date_published": "2026-07-15T08:01:04Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "4f642033fdeed9fd4dc9",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#Fluke",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Fluke: 821K accounts breached",
            "item_type": "record",
            "summary": "added: Fluke: 821K accounts breached",
            "after": {
              "Name": "Fluke",
              "Domain": "fluke.com",
              "BreachDate": "2026-07-01",
              "AddedDate": "2026-07-15T08:01:04Z",
              "ModifiedDate": "2026-07-15T08:01:04Z",
              "PwnCount": 821100,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Email addresses",
                "Employers",
                "Job titles",
                "Names",
                "Physical addresses",
                "Support tickets"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "821K",
              "title": "Fluke: 821K accounts breached",
              "summary": "In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present.",
              "published_at": "2026-07-15T08:01:04Z",
              "link": "https://haveibeenpwned.com/Breach/Fluke"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/Fluke"
    },
    {
      "id": "31bfaccaeb5c833243a6",
      "title": "Goose Creek: 6.5M accounts breached",
      "content_text": "In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers, claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contained 6.6M unique email addresses along with names, phone numbers, physical addresses, order IDs and total spent. The data appears to have been obtained from the company's Shopify instance. Goose Creek is aware of the…",
      "date_published": "2026-07-15T05:03:14Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "31bfaccaeb5c833243a6",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#GooseCreek",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Goose Creek: 6.5M accounts breached",
            "item_type": "record",
            "summary": "added: Goose Creek: 6.5M accounts breached",
            "after": {
              "Name": "GooseCreek",
              "Domain": "goosecreek.com",
              "BreachDate": "2026-06-09",
              "AddedDate": "2026-07-15T05:03:14Z",
              "ModifiedDate": "2026-07-15T05:13:10Z",
              "PwnCount": 6574121,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Email addresses",
                "Names",
                "Phone numbers",
                "Physical addresses",
                "Purchases"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "6.5M",
              "title": "Goose Creek: 6.5M accounts breached",
              "summary": "In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers, claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contained 6.6M unique email addresses along with names, phone numbers, physical addresses, order IDs and total spent. The data appears to have been obtained from the company's Shopify instance. Goose Creek is aware of the reports but was unable to provide Have I Been Pwned with any further information at the time of publication.",
              "published_at": "2026-07-15T05:03:14Z",
              "link": "https://haveibeenpwned.com/Breach/GooseCreek"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/GooseCreek"
    },
    {
      "id": "54757440c9e13f8bb884",
      "title": "Glendale Community College: 793K accounts breached",
      "content_text": "In June 2026, Glendale Community College was the target of a ShinyHunters \"pay or leak\" extortion campaign. Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, addresses, phone numbers, Social Security numbers and other information relating to student enrolments. In its disclosure notice, the college advised that \"the potentially impacted information may vary for each individual…",
      "date_published": "2026-07-11T10:40:09Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "54757440c9e13f8bb884",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#GlendaleCommunityCollege",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Glendale Community College: 793K accounts breached",
            "item_type": "record",
            "summary": "added: Glendale Community College: 793K accounts breached",
            "after": {
              "Name": "GlendaleCommunityCollege",
              "Domain": "glendale.edu",
              "BreachDate": "2026-06-15",
              "AddedDate": "2026-07-11T10:40:09Z",
              "ModifiedDate": "2026-07-11T10:40:09Z",
              "PwnCount": 793925,
              "Attribution": null,
              "DisclosureUrl": "https://glendale.edu/about-gcc/communications/update/",
              "DataClasses": [
                "Academic records",
                "Dates of birth",
                "Email addresses",
                "Genders",
                "Government issued IDs",
                "Names",
                "Phone numbers",
                "Physical addresses"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "793K",
              "title": "Glendale Community College: 793K accounts breached",
              "summary": "In June 2026, Glendale Community College was the target of a ShinyHunters \"pay or leak\" extortion campaign. Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, addresses, phone numbers, Social Security numbers and other information relating to student enrolments. In its disclosure notice, the college advised that \"the potentially impacted information may vary for each individual and may include all or just one of the above-listed types of information\".",
              "published_at": "2026-07-11T10:40:09Z",
              "link": "https://haveibeenpwned.com/Breach/GlendaleCommunityCollege"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/GlendaleCommunityCollege"
    },
    {
      "id": "ab6210b4987fe9e4dfe8",
      "title": "Moody Bible Institute: 2.3M accounts breached",
      "content_text": "In June 2026, Moody Bible Institute was targeted by a ShinyHunters \"pay or leak\" extortion campaign. Over 2.3M unique email addresses and other personal data were later published publicly, including names, physical addresses, phone numbers, dates of birth and other information relating to donors, supporters, students and alumni. In their disclosure notice, Moody advised that they had \"engaged both internal and external cybersecurity experts to thoroughly investigate the matter\".",
      "date_published": "2026-07-03T16:03:25Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "ab6210b4987fe9e4dfe8",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#MoodyBibleInstitute",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Moody Bible Institute: 2.3M accounts breached",
            "item_type": "record",
            "summary": "added: Moody Bible Institute: 2.3M accounts breached",
            "after": {
              "Name": "MoodyBibleInstitute",
              "Domain": "moody.edu",
              "BreachDate": "2026-06-15",
              "AddedDate": "2026-07-03T16:03:25Z",
              "ModifiedDate": "2026-07-03T16:03:25Z",
              "PwnCount": 2303416,
              "Attribution": null,
              "DisclosureUrl": "https://www.moodybible.org/news/2026/data-investigation/",
              "DataClasses": [
                "Dates of birth",
                "Email addresses",
                "Genders",
                "Marital statuses",
                "Names",
                "Phone numbers",
                "Physical addresses"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "2.3M",
              "title": "Moody Bible Institute: 2.3M accounts breached",
              "summary": "In June 2026, Moody Bible Institute was targeted by a ShinyHunters \"pay or leak\" extortion campaign. Over 2.3M unique email addresses and other personal data were later published publicly, including names, physical addresses, phone numbers, dates of birth and other information relating to donors, supporters, students and alumni. In their disclosure notice, Moody advised that they had \"engaged both internal and external cybersecurity experts to thoroughly investigate the matter\".",
              "published_at": "2026-07-03T16:03:25Z",
              "link": "https://haveibeenpwned.com/Breach/MoodyBibleInstitute"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/MoodyBibleInstitute"
    },
    {
      "id": "6ed926f516226af47541",
      "title": "Sysco: 2.6M accounts breached",
      "content_text": "In June 2026, the food distribution company Sysco was targeted by a ShinyHunters \"pay or leak\" extortion campaign. Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact information including names, phone numbers, physical addresses, internal job titles, and customer feedback.",
      "date_published": "2026-06-28T15:57:29Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "6ed926f516226af47541",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#Sysco",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Sysco: 2.6M accounts breached",
            "item_type": "record",
            "summary": "added: Sysco: 2.6M accounts breached",
            "after": {
              "Name": "Sysco",
              "Domain": "sysco.com",
              "BreachDate": "2026-06-15",
              "AddedDate": "2026-06-28T15:57:29Z",
              "ModifiedDate": "2026-06-28T15:57:29Z",
              "PwnCount": 2691852,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Customer feedback",
                "Email addresses",
                "Employers",
                "Job titles",
                "Names",
                "Phone numbers",
                "Physical addresses",
                "Usernames"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "2.6M",
              "title": "Sysco: 2.6M accounts breached",
              "summary": "In June 2026, the food distribution company Sysco was targeted by a ShinyHunters \"pay or leak\" extortion campaign. Data was subsequently published containing 2.7M unique email addresses belonging to staff and customers. The data also contained largely corporate contact information including names, phone numbers, physical addresses, internal job titles, and customer feedback.",
              "published_at": "2026-06-28T15:57:29Z",
              "link": "https://haveibeenpwned.com/Breach/Sysco"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/Sysco"
    },
    {
      "id": "ffe0f47a81bb17f7e3aa",
      "title": "American Tower: 216K accounts breached",
      "content_text": "In June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published data allegedly taken from the company containing more than 200k unique email addresses belonging to employees, contractors, customers, and leads. Exposed data also included names, addresses, and phone numbers.",
      "date_published": "2026-06-26T07:17:23Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "ffe0f47a81bb17f7e3aa",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#AmericanTower",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "American Tower: 216K accounts breached",
            "item_type": "record",
            "summary": "added: American Tower: 216K accounts breached",
            "after": {
              "Name": "AmericanTower",
              "Domain": "americantower.com",
              "BreachDate": "2026-06-12",
              "AddedDate": "2026-06-26T07:17:23Z",
              "ModifiedDate": "2026-06-26T07:22:10Z",
              "PwnCount": 216601,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Email addresses",
                "Job titles",
                "Names",
                "Phone numbers",
                "Physical addresses"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "216K",
              "title": "American Tower: 216K accounts breached",
              "summary": "In June 2026, telecommunications tower infrastructure company American Tower was the target of a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published data allegedly taken from the company containing more than 200k unique email addresses belonging to employees, contractors, customers, and leads. Exposed data also included names, addresses, and phone numbers.",
              "published_at": "2026-06-26T07:17:23Z",
              "link": "https://haveibeenpwned.com/Breach/AmericanTower"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/AmericanTower"
    },
    {
      "id": "0e38a485f1252f7d6665",
      "title": "Madison Square Garden Sports: 9.7M accounts breached",
      "content_text": "In June 2026, the sports and entertainment company Madison Square Garden Sports was the target of a ShinyHunters \"pay or leak\" extortion campaign. The group later published the alleged data, which included almost 10M unique email addresses spanning staff and customers, along with extensive personal, employment and customer relationship information.",
      "date_published": "2026-06-24T13:02:33Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "0e38a485f1252f7d6665",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#MadisonSquareGardenSports",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Madison Square Garden Sports: 9.7M accounts breached",
            "item_type": "record",
            "summary": "added: Madison Square Garden Sports: 9.7M accounts breached",
            "after": {
              "Name": "MadisonSquareGardenSports",
              "Domain": "msgsports.com",
              "BreachDate": "2026-06-05",
              "AddedDate": "2026-06-24T13:02:33Z",
              "ModifiedDate": "2026-06-24T13:02:33Z",
              "PwnCount": 9796738,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Customer service records",
                "Email addresses",
                "Names",
                "Phone numbers",
                "Physical addresses"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "9.7M",
              "title": "Madison Square Garden Sports: 9.7M accounts breached",
              "summary": "In June 2026, the sports and entertainment company Madison Square Garden Sports was the target of a ShinyHunters \"pay or leak\" extortion campaign. The group later published the alleged data, which included almost 10M unique email addresses spanning staff and customers, along with extensive personal, employment and customer relationship information.",
              "published_at": "2026-06-24T13:02:33Z",
              "link": "https://haveibeenpwned.com/Breach/MadisonSquareGardenSports"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/MadisonSquareGardenSports"
    },
    {
      "id": "243ae8ef52e4bee9484e",
      "title": "JCPenney: 368K accounts breached",
      "content_text": "In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters \"pay or leak\" extortion campaign. Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed records indicated they primarily related to internal HR systems and impacted current and former employees. The data included 368k corporate and personal email addresses, names, dates of birth, Social Security…",
      "date_published": "2026-06-20T03:02:45Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "243ae8ef52e4bee9484e",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#JCPenney",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "JCPenney: 368K accounts breached",
            "item_type": "record",
            "summary": "added: JCPenney: 368K accounts breached",
            "after": {
              "Name": "JCPenney",
              "Domain": "jcpenny.com",
              "BreachDate": "2026-06-12",
              "AddedDate": "2026-06-20T03:02:45Z",
              "ModifiedDate": "2026-06-20T03:02:45Z",
              "PwnCount": 368418,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Dates of birth",
                "Email addresses",
                "Government issued IDs",
                "Job titles",
                "Names",
                "Phone numbers",
                "Physical addresses",
                "Usernames"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "368K",
              "title": "JCPenney: 368K accounts breached",
              "summary": "In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters \"pay or leak\" extortion campaign. Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed records indicated they primarily related to internal HR systems and impacted current and former employees. The data included 368k corporate and personal email addresses, names, dates of birth, Social Security numbers, phone numbers and home addresses.",
              "published_at": "2026-06-20T03:02:45Z",
              "link": "https://haveibeenpwned.com/Breach/JCPenney"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/JCPenney"
    },
    {
      "id": "1bef0374d18e68e8c75c",
      "title": "Ralph Lauren: 139K accounts breached",
      "content_text": "In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresses along with names, phone numbers, genders and age groups.",
      "date_published": "2026-06-18T22:48:34Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "1bef0374d18e68e8c75c",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#RalphLauren",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Ralph Lauren: 139K accounts breached",
            "item_type": "record",
            "summary": "added: Ralph Lauren: 139K accounts breached",
            "after": {
              "Name": "RalphLauren",
              "Domain": "ralphlauren.com",
              "BreachDate": "2026-06-11",
              "AddedDate": "2026-06-18T22:48:34Z",
              "ModifiedDate": "2026-06-18T22:48:34Z",
              "PwnCount": 139903,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Age groups",
                "Email addresses",
                "Genders",
                "Names",
                "Phone numbers"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": false,
              "IsSubscriptionFree": false,
              "IsStealerLog": false,
              "accounts": "139K",
              "title": "Ralph Lauren: 139K accounts breached",
              "summary": "In June 2026, fashion retailer Ralph Lauren was targeted in a ShinyHunters \"pay or leak\" extortion campaign. The group subsequently published hundreds of gigabytes of data they claimed was obtained from the organisation's Salesforce instance, including 140k unique email addresses along with names, phone numbers, genders and age groups.",
              "published_at": "2026-06-18T22:48:34Z",
              "link": "https://haveibeenpwned.com/Breach/RalphLauren"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/RalphLauren"
    },
    {
      "id": "ccb68ad97e7d4cce5acf",
      "title": "Operation Endgame 4.0: 4.3M accounts breached",
      "content_text": "On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation, a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust, the operation remediated almost 15,000 compromised websites and disrupted more than 100 servers and domains used to distribute malware. Authorities initially provided HIBP with 154k impacted email…",
      "date_published": "2026-06-18T20:08:06Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "ccb68ad97e7d4cce5acf",
          "source": "web",
          "type": "change",
          "key": "https://haveibeenpwned.com/api/v3/breaches#OperationEndgame4",
          "source_url": "https://haveibeenpwned.com/api/v3/breaches",
          "timestamp": null,
          "observed_at": "2026-09-26T00:24:24Z",
          "data": {
            "change": "added",
            "label": "Operation Endgame 4.0: 4.3M accounts breached",
            "item_type": "record",
            "summary": "added: Operation Endgame 4.0: 4.3M accounts breached",
            "after": {
              "Name": "OperationEndgame4",
              "Domain": "",
              "BreachDate": "2026-06-18",
              "AddedDate": "2026-06-18T20:08:06Z",
              "ModifiedDate": "2026-07-26T06:42:31Z",
              "PwnCount": 4348526,
              "Attribution": null,
              "DisclosureUrl": null,
              "DataClasses": [
                "Email addresses",
                "Passwords"
              ],
              "IsVerified": true,
              "IsFabricated": false,
              "IsSensitive": false,
              "IsRetired": false,
              "IsSpamList": false,
              "IsMalware": true,
              "IsSubscriptionFree": true,
              "IsStealerLog": false,
              "accounts": "4.3M",
              "title": "Operation Endgame 4.0: 4.3M accounts breached",
              "summary": "On 18 June 2026, the latest phase of Operation Endgame targeted the SocGholish malware operation, a prolific malware distribution network used to compromise systems and facilitate further cybercrime. Coordinated by international law enforcement agencies with support from Europol and Eurojust, the operation remediated almost 15,000 compromised websites and disrupted more than 100 servers and domains used to distribute malware. Authorities initially provided HIBP with 154k impacted email addresses and more than half a million previously unseen passwords. The following week, a further 4M email addresses and 9M passwords relating to the StealC malware operation also targeted by Operation Endgame were provided, followed by another 131k email addresses the following month, bringing the total to more than 4.3M unique email addresses.",
              "published_at": "2026-06-18T20:08:06Z",
              "link": "https://haveibeenpwned.com/Breach/OperationEndgame4"
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://haveibeenpwned.com/api/v3/breaches",
            "content_type": "application/json",
            "elapsed_ms": 406,
            "not_modified": false,
            "method": "json"
          },
          "provenance": [
            {
              "step": "web",
              "version": "0.3.2"
            },
            {
              "step": "filter",
              "version": "0.3.2",
              "args": {
                "expr": "IsVerified and not IsFabricated and not IsSpamList"
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "AddedDate"
                ],
                "reverse": true
              }
            },
            {
              "step": "limit",
              "version": "0.3.2",
              "args": {
                "count": 30
              }
            },
            {
              "step": "map",
              "version": "0.3.2",
              "args": {
                "assign": [
                  "accounts=replace(replace(\"\" + PwnCount, \"^(\\\\d+)(\\\\d)\\\\d{5}$\", \"\\\\1.\\\\2M\"), \"^(\\\\d+)\\\\d{3}$\", \"\\\\1K\")",
                  "title=Title + \": \" + accounts + \" accounts breached\"",
                  "summary=replace(Description, \"<[^>]+>\", \"\")",
                  "published_at=AddedDate",
                  "link=\"https://haveibeenpwned.com/Breach/\" + Name"
                ],
                "drop": [
                  "Description",
                  "LogoPath",
                  "Title"
                ]
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "key": "Name",
                "namespace": "data-breaches",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://haveibeenpwned.com/Breach/OperationEndgame4"
    }
  ]
}
