Skip to main content
Back to overview
High

Doxbin Scrape Data Breach Exposes 435,000 Email Addresses

On January 24, 2025, a data breach involving the 'doxing' service Doxbin resulted in the scraping of approximately 435,000 email addresses.

Key points

  • 435,784 email addresses were scraped from Doxbin on January 24, 2025.
  • Doxbin is a service where personal information of third parties is often disclosed.
  • The data was provided to Have I Been Pwned by a source named 'oathnet.ru'.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Threat source not confirmed

03

Potential impact

Potential fraud or account takeover risk

Confidentiality

Published
Jan 24, 2025
Updated
Jul 1, 2026
Confidence
High
Evidence
1 source

Structured assessment

Signal analysis

It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch phishing, executive impersonation and account-takeover exposure.

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

DoxbinData DisclosureEmail Addresses On JanuaryDoxbinHave I Been Pwned

Quick context

Questions about this signal

What happened in this signal?

On January 24, 2025, a data breach involving the 'doxing' service Doxbin resulted in the scraping of approximately 435,000 email addresses. The data was provided to Have I Been Pwned by a source attributed to 'oathnet.ru'. This incident poses risks of phishing attacks, identity theft, and other security concerns for affected individuals.

When was this signal reported?

Shadow Tier lists Jan 24, 2025 as the signal date.

Which organization is connected to this signal?

Doxbin is the organization connected to this public signal.

Explore Doxbin
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence