Troy Hunt
banner
troyhunt.com
Troy Hunt
@troyhunt.com
Founder & CEO of @haveibeenpwned.com, the most trusted name in data breach intelligence. Speaker, blogger, Microsoft Regional Director. Gold Coast, Australia.
Reposted by Troy Hunt
New scrape: Last month, 4.6M email addresses from Chess[.]com were posted online with names, usernames and country, among other data. 99% were already in @haveibeenpwned.com, supporting the theory the data was scraped. Read more: haveibeenpwned.com/Breach/Chess...
Have I Been Pwned: Chess.com (2026) Data Breach
In August 2026, millions of records allegedly sourced from Chess.com were posted online. The data contained 7.3M rows with 4.6M unique email addresses, along with usernames, names, countries and data ...
haveibeenpwned.com
September 13, 2026 at 1:31 PM
Weekly update is up! Breach Perception v. Reality: AI, Vishing, Odido, Manchester Airports Group, Sophistication, Published Keys, etc: www.troyhunt.com/weekly-updat...
Weekly Update 521: Breach Perception v. Reality
I think what really resonates with me this week is being able to completely turn the tables on perceptions around things like AI being the big bad hacking tool the news would have you believe.…
www.troyhunt.com
September 12, 2026 at 1:58 AM
Going live with my weekly vid in 10 mins! Breach Perception v. Reality: AI, Vishing, Odido, Manchester Airports Group, Sophistication, Published Keys, etc youtube.com/live/TaAe3hI...
Weekly Update 521: Breach Perception v. Reality
AI, Vishing, Odido, Manchester Airports Group, Sophistication, Published Keys, etc
youtube.com
September 10, 2026 at 10:20 PM
Reposted by Troy Hunt
New sensitive breach: McKesson was targeted in a ShinyHunters extortion campaign last month. Allegedly sourced data was later published with 6.4M emails from marketing campaigns, patients, staff and others. 66% were already in @haveibeenpwned.com. More: haveibeenpwned.com/Breach/McKes...
Have I Been Pwned: McKesson Data Breach
In August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published a substantial corpus of data they alleg...
haveibeenpwned.com
September 10, 2026 at 5:54 AM
Four years of exposure 😮
They exposed data on 8.8 million people with no exploit, no malware, and no access to MAG’s servers.

Three server-side API keys sat in public JavaScript for 4+ years and FulcrumSec found them. They could have modified and deleted data too.

scotthelme.co.uk/no-hacking-r...
No Hacking Required: The Manchester Airports Group Data Breach
On 27 August 2026, Manchester Airports Group told customers that "an unauthorised third party" had stolen their data. Car park bookings, lounge bookings, Fast Track purchases for airport security and…
scotthelme.co.uk
September 7, 2026 at 9:43 AM
Weekly update is up! The Unscripted Edition: No agenda, all impromptu, here's what I'm up to, AMA, etc: www.troyhunt.com/weekly-updat...
Weekly Update 520: The Unscripted Edition
I've started playing around with YouTube's "create video thumbnail", which hopefully will give me back a bit of time in my day (it used to be a manual job in Photoshop) and be a bit more interesting.…
www.troyhunt.com
September 6, 2026 at 11:33 PM
I'm live! Weekly Update 520: The Unscripted Edition: No agenda, all impromptu, here's what I'm up to, AMA, etc: youtube.com/live/JKra_rE...
https://youtube.com/live/JKra_rEaNWw?feature=share
youtube.com
September 4, 2026 at 8:06 PM
Reposted by Troy Hunt
New breach: Manchester Airports Group was breached last month, with FulcrumSec later publishing 8.7M email addresses. Data included phone numbers, vehicle registrations, parking history and airport purchases. 62% were already in @haveibeenpwned. More: haveibeenpwned.com/Breach/Manch...
Have I Been Pwned: Manchester Airports Group Data Breach
In August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services. The incident was later claimed by the FulcrumSec hacking group, who subsequently published email addre...
haveibeenpwned.com
September 2, 2026 at 7:43 AM
Weekly update is up! Breaches & Data Integrity: Synthetic Data in Breaches; Email Address != Person; Ridiculous Security for “Cyber Broken” Copenhagen: www.troyhunt.com/weekly-updat...
Weekly Update 519: Breaches & Data Integrity
It does feel like I've bitten off too much and am now chewing like crazy this week. The 3D printing talk with Elle in Oslo, the "normal" NDC infosec talk, the cyber-broken talk with Scott in…
www.troyhunt.com
September 1, 2026 at 11:35 PM
Going live with my weekly vid in 10 mins! Breaches & Data Integrity: Synthetic Data in Breaches; Email Address != Person; Ridiculous Security for “Cyber Broken” Copenhagen youtube.com/live/IGCiGo6...
Weekly Update 519: Breaches & Data Integrity
Synthetic Data in Breaches; Email Address != Person; Ridiculous Security for “Cyber Broken” Copenhagen
youtube.com
August 31, 2026 at 10:35 PM
Just blogged: It's very easy to pull email addresses from a data breach and make claims about scope that are completely wrong. Like - MASSIVELY wrong - for example: www.troyhunt.com/a-cautionary...
A Cautionary Tale About Data Breach Claims, Verification and Carhartt
You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it…
www.troyhunt.com
August 25, 2026 at 11:35 PM
Reposted by Troy Hunt
New breach: Carhartt was the target of a ShinyHunters extortion campaign earlier this month. Data allegedly obtained from the company was later published, including 12.9M unique email addresses. 83% were already in @haveibeenpwned.com. Read more: haveibeenpwned.com/Breach/Carha...
Have I Been Pwned: Carhartt Data Breach
In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the company including 12.9M ...
haveibeenpwned.com
August 25, 2026 at 9:54 PM
Weekly update is up! IoT Doorlock Nirvana with UniFi: All the UniFi Access Bits: Door Hub, Electric Strike, Drop Bolts, Readers, NFC Cards, Buttons, (and Much More): www.troyhunt.com/weekly-updat...
Weekly Update 518: IoT Doorlock Nirvana with UniFi
I genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've worked out how to put it all into a residential house and have it make sense. There are a few basic…
www.troyhunt.com
August 24, 2026 at 7:42 AM
Reposted by Troy Hunt
New sensitive breach: German news service NIUS had 6k unique email addresses exposed in a breach last year. Data also included names, physical addresses, purchases and partial payment details. 51% were already in @haveibeenpwned.com. Read more: haveibeenpwned.com/Breach/NIUS
Have I Been Pwned: NIUS Data Breach
In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly. The data included 6k unique email addresses along with names, physical addresses and payment d...
haveibeenpwned.com
August 23, 2026 at 10:31 PM
Reposted by Troy Hunt
New breach: Golf Canada had 569k unique email addresses allegedly obtained from its service around the middle of this year. Data also included name, DoB, gender and appx geographic location. 76% were already in @haveibeenpwned.com. Read more: haveibeenpwned.com/Breach/GolfC...
Have I Been Pwned: Golf Canada Data Breach
In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates o...
haveibeenpwned.com
August 22, 2026 at 7:23 AM
Going live with my weekly vid in 5 mins! All the UniFi Access Bits: Door Hub, Electric Strike, Drop Bolts, Readers, NFC Cards, Buttons, (and Much More) youtube.com/live/bQuSoBA...
Weekly Update 518: IoT Doorlock Nirvana with UniFi
All the UniFi Access Bits: Door Hub, Electric Strike, Drop Bolts, Readers, NFC Cards, Buttons, (and Much More)
youtube.com
August 20, 2026 at 9:40 PM
Reposted by Troy Hunt
New breach: Oz Hair and Beauty was targeted in an xpl0itrs extortion attack this week. Data allegedly obtained in the attack was subsequently leaked, including 2M email addresses and other personal data. 73% were already in @haveibeenpwned.com. Read more: haveibeenpwned.com/Breach/OzHai...
Have I Been Pwned: Oz Hair and Beauty Data Breach
In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the company, which included ...
haveibeenpwned.com
August 19, 2026 at 3:17 AM
Reposted by Troy Hunt
New breach: Fanlore suffered a breach earlier this month exposing 145k unique email addresses. Data also included usernames and passwords stored as either MD5 or PBKDF2 hashes. 23% were already in @haveibeenpwned.com. Read more: haveibeenpwned.com/Breach/Fanlore
Have I Been Pwned: Fanlore Data Breach
In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along...
haveibeenpwned.com
August 19, 2026 at 2:14 AM
Weekly update is up! Cyber Ransoms: Ransom Payments, Legalities, Reporting, Class Actions (and Everything Else) www.troyhunt.com/weekly-updat...
Weekly Update 517: Cyber Ransoms
The current ransomware situation is a bit of a kludge (deep breath): a lot of ransomware (which often doesn't even involve "ware", it's just extortion) is carried out by kids who successfully make a…
www.troyhunt.com
August 18, 2026 at 7:57 AM
Going live with my weekly vid in 10 mins! Cyber Ransoms: Ransom Payments, Legalities, Reporting, Class Actions (and Everything Else) youtube.com/live/OYYI3uH...
Weekly Update 517: Cyber Ransoms
Ransom Payments, Legalities, Reporting, Class Actions (and Everything Else)
youtube.com
August 16, 2026 at 10:40 PM
Reposted by Troy Hunt
New breach: RingCentral was targeted in a ShinyHunters extortion attack last month. The group subsequently published 1.6M email addresses and other personal info allegedly from the company. 44% were already in @haveibeenpwned.com. Read more: haveibeenpwned.com/Breach/RingC...
Have I Been Pwned: RingCentral Data Breach
In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they claimed was obt...
haveibeenpwned.com
August 13, 2026 at 11:00 AM
Weekly update is up! Live From Vietnam: ShinyHunters Ramping Back Up; New Breaches: Inter-Con Security, Exact Sciences, Brinks Home; The Breach Pipeline www.troyhunt.com/weekly-updat...
Weekly Update 516: Live From Vietnam
A little wind noise, a little connectivity flakiness, and a little lip-sync issues from YouTube, but look at that view! 🤩 Back to business, it's the Brinks Home FAQ I found most interesting this…
www.troyhunt.com
August 12, 2026 at 11:31 PM
While everyone is stressing out about the latest scary AI news, kids are just picking up the phone, asking for access to your data and being infinity times more successful than the machines 🤷‍♂️
Cyber insurer (Chatham house forbids me from saying who) at BH CISO summit: “so far this year 0 payouts for claims even remotely connected to a AI-driven breach, 85% of payouts related to social engineering”. Sobering statistic.
August 10, 2026 at 3:03 AM
Reposted by Troy Hunt
New breach: Alcon was targeted in a ShinyHunters extortion campaign, with data allegedly from the eye care company published this month. It included 218k email addresses and largely corporate B2B contact info. 49% were already in @haveibeenpwned.com. More: haveibeenpwned.com/Breach/Alcon
haveibeenpwned.com
August 9, 2026 at 10:08 AM