Bevel Keys Research Index

Popular websites with known breaches

A popularity-led ranking of 9 major consumer websites with direct matches in the Have I Been Pwned breach catalog.

Initial research release · Updated September 16, 2026

100popular sites reviewed
9with documented password exposure
12matched breach incidents
706,035,825reported account records in password-exposing breaches

What the ranking means

The cost of a stolen password is not equal everywhere.

Email, financial, cloud, shopping, and identity accounts can expose private data, payment methods, or access to other services. This index prioritizes where a strong, unique password matters most.

A high rank does not mean a company is currently insecure. It means the account is valuable, widely used, connected to sensitive information, associated with relevant public breach history, or difficult to recover after compromise.

The index

Popular sites with known breaches

9 sites shown

RankWebsiteCategoryHIBP site breachesBreach yearsPassword-exposed account recordsPriorityWorkflow
1 Facebookfacebook.com Social & Community 2 2023, 2019 77,267* 94.13 YELLOW
2 LinkedInlinkedin.com Social & Community 3 2023, 2021, 2012 164,611,595 93.78 YELLOW
3 SHEINshein.com Shopping & Marketplaces 1 2018 39,086,762 70.39 ORANGE
4 Epic Gamesepicgames.com Gaming 1 2016 251,661 62.64 ORANGE
5 PlayStation Networkplaystation.com Gaming 1 2011 37,103 61.29 ORANGE
6 Dropboxdropbox.com Work & Productivity 1 2012 68,648,009 49.14 YELLOW
7 Canvacanva.com Work & Productivity 1 2019 137,272,116 46.59 ORANGE
8 Adobeadobe.com Work & Productivity 1 2013 152,445,165 43.74 ORANGE
9 MyFitnessPalmyfitnesspal.com Health & Fitness 1 2018 143,606,147 35.29 ORANGE

* Facebook Marketplace: HIBP indexed 77,267 unique email addresses from a leaked file reported to contain about 200,000 rows. The incident section below explains the distinction and links to the source.

Incident record

How each breach happened and what followed

Record counts are HIBP's affected-account figures unless a note says otherwise. These summaries distinguish confirmed findings from allegations and unknown causes. Legal outcomes describe documented public actions found during this review, not legal advice or a guarantee that no other litigation exists.

2023

Facebook Marketplace

77,267 unique emails / about 200,000 rows records

What caused it

The dataset was allegedly taken from systems used by a Meta contractor. Public reporting does not establish the precise intrusion method, and HIBP notes that the bcrypt hashes may not correspond to the listed Facebook accounts.

What followed

About 200,000 Marketplace records were posted to a hacking forum in 2024. HIBP indexed 77,267 unique email addresses from that larger file. The data included bcrypt hashes, but reporting found no indication that the hashes belonged to the corresponding Facebook accounts. No enforcement action or class settlement specific to this dataset was identified in this review.

Evidence: HIBP / reporting · HIBP breach catalog

2012

LinkedIn

164,611,595 records

What caused it

LinkedIn did not publicly establish the initial intrusion vector. The stolen passwords were stored as unsalted SHA-1 hashes, allowing most to be cracked rapidly after the dataset surfaced in 2016.

What followed

LinkedIn reset affected passwords. A U.S. class action alleging inadequate safeguards and misleading security promises settled for $1.25 million; the settlement covered eligible U.S. Premium subscribers and required security improvements.

Evidence: Breach analysis · Settlement · HIBP breach catalog

2018

SHEIN

39,086,762 records

What caused it

A malicious third party gained access to parent company Zoetop's systems and exfiltrated customer credentials. New York investigators later cited inadequate monitoring, vulnerability management, password handling, and incident response.

What followed

New York's attorney general found that Zoetop understated the breach and failed to notify all affected consumers. In 2022, Zoetop agreed to pay $1.9 million and maintain a comprehensive information-security program.

Evidence: New York attorney general · HIBP breach catalog

2016

Epic Games forums

251,661 records

What caused it

The Unreal Engine forum breach was attributed in contemporary reporting to a SQL-injection vulnerability in the vBulletin forum software. Exposed passwords were salted MD5 hashes.

What followed

Epic invalidated affected forum passwords and advised users who reused them to change passwords elsewhere. No major public regulatory penalty or class settlement specific to this incident was identified in this review.

Evidence: Incident reporting · HIBP breach catalog

2011

Sony

37,103 records

What caused it

The HIBP record used here centers on a SQL-injection attack against Sony Pictures that exposed plaintext passwords. It is related to Sony's wider series of 2011 incidents but is not the same dataset as the approximately 77 million-account PlayStation Network breach.

What followed

The broader, separate PSN incident produced a roughly month-long outage, a £250,000 UK ICO fine, and a U.S. class settlement valued at about $15 million in games, services, and eligible identity-theft reimbursements. Those consequences should not be read as applying only to the 37,103 HIBP records shown here.

Evidence: HIBP record analysis · PSN settlement context · HIBP breach catalog

2012

Dropbox

68,648,009 records

What caused it

Dropbox said an employee reused a password that had been exposed in the LinkedIn breach, allowing an attacker to access a company account. The stolen dataset later proved to include email addresses and salted SHA-1 or bcrypt password hashes.

What followed

Dropbox forced password resets in 2016 for users who had not changed their password since mid-2012 and added further security controls. No major public fine or class settlement specific to this incident was identified in this review.

Evidence: Password-reset response · Incident scale · HIBP breach catalog

2019

Canva

137,272,116 records

What caused it

An attacker accessed Canva systems and stole user data. Passwords for users without social login were stored as bcrypt hashes; the company did not publicly establish a more specific intrusion vector in the sources reviewed.

What followed

Canva notified users, invalidated exposed credentials, and prompted password changes. No major public regulatory fine or class-action settlement specific to the 2019 incident was identified in this review.

Evidence: Canva incident notice · HIBP breach catalog

2013

Adobe

152,445,165 records

What caused it

Attackers penetrated Adobe's network; the exact entry method was not publicly established. Reversibly encrypted passwords and plaintext hints enabled extensive password recovery, while source code was also taken.

What followed

Adobe reset passwords and faced consolidated consumer litigation. The class settlement provided $5,000 to each named plaintiff and about $1.18 million in attorneys' fees. In 2016, Adobe also agreed to pay $1 million to 15 states and adopt stronger security practices.

Evidence: Password analysis · State settlement · HIBP breach catalog

2018

MyFitnessPal

143,606,147 records

What caused it

The initial intrusion vector was not publicly established. The breach exposed usernames, email and IP addresses, and a mix of older SHA-1 and newer bcrypt password hashes.

What followed

Under Armour notified users and required password changes. Consumer lawsuits alleged inadequate security, but at least one prominent case was sent to private arbitration under the app's terms; no broad public cash settlement fund was identified in this review. The data later appeared for sale online.

Evidence: Incident FAQ · Arbitration ruling · HIBP breach catalog

What to do now

A breach is history. Password reuse makes it present.

If you still use a password that appeared in a breach, attackers can try it against your email, banking, shopping, and other accounts. The practical response is to find exposed or reused passwords and replace them with a unique password for every account.

Bevel Keys Premium checks saved passwords with HIBP Pwned Passwords using k-anonymity. It sends only the first five characters of a SHA-1 hash—not your password, email, or username.

Your password stays in this browser. Only a five-character hash prefix is sent to HIBP.

  1. 01
    Scan for exposed passwords

    Identify saved passwords that appear in known password-leak datasets.

  2. 02
    Replace every reused copy

    If an exposed password was reused, change it everywhere—not only on the breached site.

  3. 03
    Use a unique generated password

    A different password for every account stops one breach from unlocking several services.

  4. 04
    Turn on MFA

    Use an authenticator app or passkey where available, especially for email and financial accounts.

Methodology

How the index was built

The priority score is led by consumer popularity, with secondary weight for the number and recency of direct website matches in the Have I Been Pwned catalog. Scores are relative within this first dataset and are not breach probabilities.

01

Public signalsPopularity and consumer relevance establish which accounts affect the most people.

02

Breach frequencyMore direct website matches add weight without overpowering popularity.

03

Breach recencyRecent catalog entries add more weight and can be filtered by year above.

04

Workflow researchPublic login and security paths were mapped without credentials, OTPs, cookies, or account changes.

Workflow key

Status describes our research, not site security.

YELLOW

The public workflow is substantially mapped, but a human checkpoint such as MFA may occur.

ORANGE

An authorized test account or human-guided research is still needed to validate the password-change path.

RED

The flow is identity-proofing, phone/device-bound, or otherwise unsuitable for blind automation.

“Password-exposed account records” totals the reported affected accounts for matched incidents where HIBP explicitly lists passwords among the compromised data. Sites whose matched incidents do not list password exposure are excluded. This is not a count of unique people or plaintext passwords; a person may appear in multiple incidents. Sources include Cloudflare Radar methodology, Tranco top-domain data, public account pages, and the Have I Been Pwned breach catalog.