[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f32vevc0u54pmt":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":26,"seoTitle":16,"seoTitleEn":27,"seoDescription":16,"seoDescriptionEn":28,"logoUrl":29,"isVerified":4,"isSensitive":30,"isSpamList":30,"isMalware":30,"company":31},"68e3266eda11adda48825310","the-pi-hole","Pi-hole Data Breach","pi-hole","pi-hole.net","2025-07-30T00:00:00.000Z","2025-07-31T22:46:38.000Z","2026-07-03T23:23:17.190Z","2026-07-18T23:55:55.904Z","Third party breach","",[],29926,"known",null,"unknown","Medium",[24,25],"Email addresses","Names","\u003Cp>The Pi-hole data breach is related to the exposure of the names and email information of individuals who donated to the open-source network-wide ad-blocking project due to a plugin vulnerability in the July 2025 period. The scope includes approximately 29,926 donor records. This record was treated as an open-source donor contact data breach; the company, country, sector, website, and data class fields were realigned with the verified scope. Since the password or payment card field was not verified, a sensitive flag was not raised.\u003C\u002Fp>\u003Cp>The text was rewritten to directly explain risk, scope, and actions to the user. The website domain was kept in the format pi-hole.net; since no protocol was added, a format that would cause https to appear twice on the connection side was not used. The country was corrected to Global, and the sector to open source and network DNS blocking.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data seen in this record are email addresses and names. The password, payment card, or donation amount field was not verified. Unverified payment card, bank account, private message, health record, or additional profile fields were not added to the data class list; only supported fields were retained.\u003C\u002Fp>\u003Cp>Donor name and email information can be used in fake donation receipts, project announcements, or security update messages. An email address alone poses a risk of unwanted messages; when combined with phone number, address, IP, birth date, password, travel plans, partial card data, or device data, it makes it easier for an attacker to generate a personalized message for the user. The risk assessment was made based on this combined effect.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The scope was confirmed with the 29,926 donor records dated July 2025. Verified areas were preserved while unconfirmed areas were left out. The event was not combined with data sets of similar names, events from different periods of the same company, or incorrect industry references.\u003C\u002Fp>\u003Cp>Registration is limited to the pi-hole.net domain name and the donor list; users' network device data was not presented as if it had been breached. Domain name, company name, and industry information were kept in the narrowest accurate context possible. In places of uncertainty, verified flags or website domains were set accordingly; thus, users were not shown brand responsibility that was not certain.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>User groups at risk may be individuals who donate to the Pi-hole project or share their name and email on the donation form. Matching users should also evaluate other accounts where they use the same email, phone number, username, or password pattern outside the relevant service.\u003C\u002Fp>\u003Cp>Technical users can be more easily targeted with fake security update or donation receipt links. The risk of social engineering may increase if there is a corporate email, training account, hotel reservation, telecom subscription, gaming community, open source donation, or monitoring software context. Details that appear correct are not a guarantee of trust on their own.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should verify donation receipts, update, or security notification messages received in the name of Pi-hole through the official site. All accounts using the same password should be updated in records with a password field; in records without a password field, focus should be on the risks of email, phone, fake notifications, privacy, and identity matching.\u003C\u002Fp>\u003Cp>Instead of clicking on the links in the message, the address of the relevant service should be typed manually or the record in a trusted password manager should be used. Messages about shipping, account alerts, game rewards, support, donor notifications, travel reservations, security notifications, or subscription renewals should not be accepted without verification from an independent channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Using a separate email for donations to open source projects and not storing payment information reduces risk. Users should regularly clean up old accounts, unnecessary profile fields, repeated usernames, and old phone and address information. A unique password for each service and two-step verification where possible should be a basic rule.\u003C\u002Fp>\u003Cp>From the perspective of service providers, data minimization, strong password protection, monitoring of access logs, deletion of unnecessary fields, and readiness of user notification processes are required. Donation plugins and third-party forms require regular security audits. Accurate scope explanation is also part of the security work; exaggerated or incomplete information can mislead the user into taking the wrong action.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The user should primarily check with their email address in this record. If a match is found, it should be assumed that the name and email information can be used in project-themed messages; it should be noted that device or DNS data is not included in this record. Not finding a match does not completely rule out the use of a different email or the reuse of an old password; critical accounts should also be reviewed separately.\u003C\u002Fp>\u003Cp>This record remained verified; the scope was limited to donor communication data. In this arrangement, data fields were left as English canonical classes, the description visible to the user was written in Turkish and original, unverified fields were not added, and the sensitivity flag was used only when supported by the risk context.\u003C\u002Fp>","Pi-hole Data Breach (29.9 Thousand Reported Records)","Pi-hole Data Breach. 29.9 Thousand reported records were reported. Reported data: Email addresses, Names. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002Fpi_hole_net.webp",false,{"name":32,"sector":33,"country":34,"website":10,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":20},"Pi-hole","Open Source \u002F Network DNS Blocking","Global"]