
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
oxfam.org.au
What happened
In January 2021, Oxfam Australia was the victim of a data breach which exposed 1.8M unique email addresses of supporters of the charity. The data was put up for sale on a popular hacking forum and also included names, phone numbers, addresses, genders and dates of birth. A small number of people also had partial credit card data exposed (the first 6 and last 3 digits of the card, plus card type and expiry) and in some cases the bank name, account number and BSB were also exposed. The data was subsequently made freely available on the hacking forum later the following month.
Data exposed
Frequently asked questions
The Oxfam data breach occurred on January 20, 2021. It was added to Have I Been Pwned's breach catalog on March 2, 2021.
1,834,006 accounts were affected by the Oxfam data breach, according to Have I Been Pwned's records.
The Oxfam breach exposed the following data types: Bank account numbers, Dates of birth, Email addresses, Genders, Names, Partial credit card data, Payment histories, Phone numbers, Physical addresses.
Yes. Have I Been Pwned has verified the Oxfam breach, meaning there's confirmed evidence the exposed data is genuine and tied to real accounts.
Use KazaSec's free Email Breach Checker (/tools/breach-check) to check whether a specific email address has surfaced in the Oxfam breach, or any other known breach — the tool never stores what you search.
Our free Email Breach Checker tells you whether a specific email address has surfaced in this breach — or any other known breach — without ever storing what you search.
Check your email →Talk to us about this
We help organizations find and fix the gaps that lead to a breach, before they do.