2017 — Experian
147M records — SSN + DOB + FULL ADDRESS EXPOSED
Partial SSN (●●●-●●-4817), date of birth, and full home address leaked. Combined with name data from other breaches, enables complete identity theft and credit fraud.
SSN
full address
DOB
email
2015 — MyFitnessPal
150M records — PLAINTEXT password exposed
Plaintext password discovered alongside email, username (jdoe_runner), and IP address. Password later found reused on Canva and Zynga.
email
username
plaintext pw
2019 — Canva
139M records — Password hash + address leaked
Email and bcrypt hash exposed along with geographic location (Los Angeles, CA). Combined with Experian data confirms exact home address.
email
hashed pw
address
2019 — Zynga
218M records — Phone number first exposed
Phone number (555-010-0199) appeared for the first time, linking mobile identity to email. Enables SIM swap attacks.
email
phone
2021 — LinkedIn
700M records — Full professional identity compromised
Username (johndoe-dev), full name, phone, employer, and SHA-256 hashed password. Confirms employment at Tech Innovations Inc.
username
full name
phone
hashed pw
2023 — Whitepages Scrape
Public records — Family members + home address indexed
Full home address, relatives (Karen Doe, Michael Doe), and phone numbers scraped from public records. Combined with breach data creates complete family profile.
home address
relatives
family phones
2020 — Wattpad
271M records — Name + address confirmed
Full name and geographic data corroborated across breaches. Together with Gravatar exposure, provides public-facing identity linkage.
full name
address