[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f24jxhsyy5s0et":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":25,"seoTitle":14,"seoTitleEn":26,"seoDescription":14,"seoDescriptionEn":27,"logoUrl":28,"isVerified":4,"isSensitive":4,"isSpamList":29,"isMalware":29,"company":30},"68e3266eda11adda488251e4","freedom-hosting-ii","Freedom Hosting II Data Breach","fhostingesps6bly.onion","2017-01-31T00:00:00.000Z","2017-02-05T10:06:58.000Z","2026-07-29T11:40:53.262Z","Third party breach","",[],380830,"known",null,"unknown","High",[22,23,24],"Email addresses","Passwords","Usernames","\u003Cp>Freedom Hosting II was a service that provided free hosting for Tor hidden services. The breach that occurred in January 2017 exposed data belonging to thousands of hosted hidden services and affected username and password information along with approximately 381 thousand email addresses.\u003C\u002Fp>\u003Cp>This record is very sensitive because the nature of the hosted sites varies, and there have been serious illegal content allegations regarding some sites. The canonical data classes are email addresses, passwords, and usernames; however, other data may also have been affected depending on the hosted sites. Nevertheless, additional fields should not be added to this record without individual verification.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The data classes tracked in the Freedom Hosting II record should be treated as email addresses, password data, and usernames. Email addresses can be used for targeted phishing, password reset schemes, and account matching across different services. Password data directly increases the risk of account takeover, especially if the same password is reused on other services. Usernames can help link pseudonyms across different platforms and personalize social engineering messages.\u003C\u002Fp>\u003Cp>Even email and username information can undermine a person's expectation of anonymity in the context of secret service hosting. If password data is reused on other accounts, the risk can turn into broader account takeover attempts.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>This record is the Freedom Hosting II incident associated with the address fhostingesps6bly.onion. The scope should be limited to email addresses, password data, and usernames. The contents or private files of each hosted site should not be generalized for this record.\u003C\u002Fp>\u003Cp>Areas not present in this record should not be described as if they have leaked. Full payment card, bank information, official ID, private messages, health data, location data, password, or financial data should only be included in the risk assessment if they are explicitly present within the record. The text is based on verifiable data classes and the known boundaries of the event.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Individuals who run sites or have opened accounts on Freedom Hosting II, those who use the same username on different hidden services, users carrying anonymity risk, and account holders who reuse the same password on other services are at high risk.\u003C\u002Fp>\u003Cp>Users who use the same email address across different services, reuse old passwords, share their phone and address information on multiple platforms, or manage their financial and telecom accounts with the same contact information are at higher risk. Records involving credit, IBAN, card, or dark market contexts carry greater risk than normal commercial records.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users should update all accounts using the same password, review email addresses associated with hidden service or forum identities, and contact reliable support channels without responding to threat or blackmail messages.\u003C\u002Fp>\u003Cp>Users in the positive match field should renew their passwords on accounts where they use the same or similar passwords, enable two-step verification where possible, and check recent sessions. In records that do not contain passwords but include contact, address, credit, or bank details, care should be taken against unexpected calls, offers, support, invoice, and verification messages.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>In environments that require anonymity, real email addresses and reused passwords pose a permanent risk. Users should use separate identities, unique passwords, and minimal profile information; they should reduce links to old accounts.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is found in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result indicates that the email address is found within the Freedom Hosting II data. Since the record is highly sensitive, password security and identity differentiation should be evaluated together.\u003C\u002Fp>","Freedom Hosting II Data Breach (380.8 Thousand Reported Records)","Freedom Hosting II Data Breach. 380.8 Thousand reported records were reported. Reported data: Email addresses, Passwords, Usernames. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Ffhostingesps6bly_onion.webp",false,{"name":31,"sector":32,"country":33,"website":9,"websiteArchiveUrl":14,"websiteStatus":34,"websiteCheckedAt":35},"Freedom Hosting II","Hidden Service Hosting","Global","tor-only","2026-07-29T11:30:22.391Z"]