All breaches
Oxfam data breach1.8M accounts compromised on 2021-01-20
Verified
Oxfam (oxfam.org.au) was the source of a data breach dated 2021-01-20, exposing 1,834,006 accounts. The details below are mirrored from Have I Been Pwned and reflect the source's account of the incident at the time of publication.
Incident Report
| Target Organization | Oxfam |
|---|---|
| Source Name | Oxfam |
| Domain | oxfam.org.au |
| Breach Date | 2021-01-20 |
| Added to HIBP | 2021-03-02 |
| Accounts Compromised | 1,834,006(1.8M) |
| Data Exposed | Bank account numbersDates of birthEmail addressesGendersNamesPartial credit card dataPayment historiesPhone numbersPhysical addresses |
| Status | Verified by HIBP |
Description
In January 2021, Oxfam Australia was the victim of a data breach which exposed 1.8M unique email addresses of supporters of the charity. The data was put up for sale on a popular hacking forum and also included names, phone numbers, addresses, genders and dates of birth. A small number of people also had partial credit card data exposed (the first 6 and last 3 digits of the card, plus card type and expiry) and in some cases the bank name, account number and BSB were also exposed. The data was subsequently made freely available on the hacking forum later the following month.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

