[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwi9j6er3b874":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":31,"seoTitle":32,"seoTitleEn":33,"seoDescription":32,"seoDescriptionEn":34,"logoUrl":35,"isVerified":4,"isSensitive":4,"isSpamList":36,"isMalware":36,"company":37},"68e3266eda11adda48825224","Havenly","Havenly Data Breach","havenly","havenly.com","2020-06-25T00:00:00.000Z","2020-08-01T01:53:40.000Z","2026-07-29T11:13:00.741Z","Third party breach","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhavenly-discloses-data-breach-after-13m-accounts-leaked-online\u002F",[15],1369180,"known",null,"records","Critical",[23,24,25,26,27,28,29,30],"Email addresses","Names","Phone numbers","Geographic locations","Login names","Site usage data","Password hashes","Possible payment-card last four digits","\u003Cp>\u003Cstrong>The 2020 Havenly data breach\u003C\u002Fstrong> was acknowledged by the company after approximately 1.3 million records were posted on a forum. BleepingComputer reported seeing login names, full names, emails, phones, ZIP codes, site-usage data, and MD5-hashed passwords in a sample. Havenly was contacted on July 27, 2020 and five days later logged out customers, required password resets, and issued notifications. The company said it did not store complete card numbers, although the last four digits may have appeared in some records.\u003C\u002Fp>\u003Cp>public breach source instead reports 1,369,180 unique emails under a June 25 catalogue date and a narrower field list that includes SHA-1 password hashes. The MD5 and SHA-1 claims conflict; no single algorithm should be treated as established until the raw password columns are authenticated. The 1,369,180 figure is a unique-email measure, not people or raw rows, and June 25 is not proven to be the exact attack date.\u003C\u002Fp>\u003Cp>The two-part local import processed 1,362,325 email lines and produced 1,362,324 unique email associations in the live index, 6,856 below public breach source's measure. Passwords, login names, phones, locations, usage data, and card fragments are not locally searchable. Missing source files and the one-line processing-to-index difference remain unreconciled.\u003C\u002Fp>\u003Cp>A private result can establish only that the controlled email occurs in the local email subset attributed to Havenly. It cannot establish identity, account or customer ownership, design-service or purchase interest, home or location details, a password, field co-occurrence, compromise, or misuse. Havenly's forced reset should have invalidated the Havenly password; only people who reused a recovered old password elsewhere should replace it there.\u003C\u002Fp>","","Havenly Data Breach (1.4 Million Records)","Havenly Data Breach. 1.4 Million records were reported. Reported data: Email addresses, Names, Phone numbers. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002Fhavenly_com.webp",false,{"name":7,"sector":38,"country":39,"website":10,"websiteArchiveUrl":32,"websiteStatus":32,"websiteCheckedAt":19},"Interior design and home decor","United States"]