Everyone gets pwned eventually – Breaking News & Latest Updates 2026
Skip to main content
R
Everyone gets pwned eventually.

After years of providing breach notifications and useful advice about how to avoid getting hacked, Have I Been Pwned operator Troy Hunt’s personal blog mailing list has become the source of a breach after he fell for a fake spam alert phishing attack this week. He has notified subscribers, and is following up for people who unsubscribed but still had data stored by his provider, Mailchimp.

Read the blog post for details on how they got him (listen to your password manager), how it could’ve been avoided (passkeys!), and what else there is to learn.

Screenshot of email reading “You signed up for notifications when emails on troyhunt.com were pwned in a data breach and unfortunately, it’s happened.”
TroyHunt.com on HIBP
Image: Troy Hunt (X)
Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.
Comments
Loading comments
Getting the conversation ready...