# Have I Been Pwned Breaches Catalog Scraper (`parseforge/hibp-breaches-catalog-scraper`) Actor

Pull the entire Have I Been Pwned breach catalog with company logos, breach dates, account counts, and the categories of data exposed like email addresses, passwords, and IP addresses. Filter by domain or fetch one breach by name. Built for breach awareness and security research.

- **URL**: https://apify.com/parseforge/hibp-breaches-catalog-scraper.md
- **Developed by:** [ParseForge](https://apify.com/parseforge) (community)
- **Categories:** Automation, Developer tools, Other
- **Stats:** 13 total users, 1 monthly users, 91.4% runs succeeded, 1 bookmarks
- **User rating**: No ratings yet

## Pricing

from $3.00 / 1,000 results

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.
Since this Actor supports Apify Store discounts, the price gets lower the higher subscription plan you have.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

![ParseForge Banner](https://github.com/ParseForge/apify-assets/blob/ad35ccc13ddd068b9d6cba33f323962e39aed5b2/banner.jpg?raw=true)

## 🛡 Have I Been Pwned Breaches Catalog Scraper

> 🚀 **Export the full Have I Been Pwned breach catalog in one run.** Pull all 1,001+ documented data breaches with company logos, breach dates, account counts, and the exact categories of data exposed.

Have I Been Pwned (HIBP) is the most widely trusted public registry of known data breaches, maintained by security researcher Troy Hunt. This Actor reads the public breach catalog and turns it into clean, structured records you can analyze, monitor, and feed into your own security tooling. It is built for defensive security work and breach awareness, not for looking up individual people.

**Coverage:** every breach in the public HIBP catalog (over 1,001 entries at last refresh), including the company logo, the date the breach occurred, when it was added to HIBP, the number of accounts affected, a full description, and the list of data classes exposed such as email addresses, passwords, IP addresses, and phone numbers. You can list the entire catalog, filter by a single domain, or pull one breach by name.

| 🎯 Target Audience | 💡 Primary Use Cases |
|---|---|
| Security analysts and blue teams | Track new and historical breaches affecting your domains |
| Threat intelligence researchers | Build a structured breach dataset for analysis |
| Compliance and risk teams | Evidence gathering for vendor and third party risk reviews |
| Developers and data engineers | Power dashboards, alerts, and awareness tooling |

### 📋 What the HIBP Breaches Catalog Scraper does

This Actor connects to the public Have I Been Pwned breach catalog and returns structured breach records. It supports three modes:

- **All breaches** lists every breach in the catalog.
- **Breaches by domain** returns only the breaches tied to a domain you provide, for example `adobe.com`.
- **Single breach by name** fetches one breach by its HIBP name, for example `Adobe` or `LinkedIn`.

Each record leads with the breached company logo and includes the breach date, the number of accounts affected, a description, and the categories of data exposed. The Actor only reads the breach catalog, which is public and keyless. It never looks up individual email addresses or accounts.

### 📊 Data fields

Each record includes: `breachDate`, `dataClasses`, `domain`, `imageUrl`, `isVerified`, `name`, `pwnCount`, `results`, `scrapedAt`, `title`. These field names come straight from the actor's dataset schema, so what you see here is what lands in your dataset.

### 🚀 How to use

1. **Create a free Apify account** using [this sign up link](https://console.apify.com/sign-up?fpr=vmoqkp).
2. Open the HIBP Breaches Catalog Scraper.
3. Pick a mode. Leave it on `all` to list the entire catalog, or choose `domain` or `breach` and fill the matching field.
4. Set `maxItems` if you want fewer records, then click **Start**.
5. Download your results or connect them to another app through the Apify API and integrations.

### 🔗 Recommended Actors

- [CISA KEV Scraper](https://apify.com/parseforge/cisa-kev-scraper) for known exploited vulnerabilities.
- [NIST NVD CVE Scraper](https://apify.com/parseforge/nist-nvd-cve-scraper) for the national vulnerability database.
- [URLhaus Malware URLs Scraper](https://apify.com/parseforge/urlhaus-malware-urls-scraper) for malicious URL intelligence.
- [Feodo Tracker C2 Scraper](https://apify.com/parseforge/feodo-tracker-c2-scraper) for botnet command and control servers.
- [GitHub Security Advisories Scraper](https://apify.com/parseforge/github-security-advisories-scraper) for open source advisories.

> 💡 **Pro Tip:** browse the complete [ParseForge collection](https://apify.com/parseforge).

> **⚠️ Disclaimer:** independent tool, not affiliated with Have I Been Pwned. Only publicly available breach catalog data is collected. This Actor is intended for defensive security, breach awareness, and research, and does not perform lookups of individual people.

### 🆘 Need Help?

If you hit a bug, have questions about setup, or need a scraper we haven't built yet, open our [contact form](https://tally.so/r/BzdKgA) or write to parseforge@protonmail.com. We also take on paid custom data projects.

For faster answers, join our [Discord](https://parseforge.co/discord). It's the best place to get support and suggest new actors.

# Actor input Schema

## `mode` (type: `string`):

What to fetch from the Have I Been Pwned breach catalog. 'All breaches' lists every breach. 'By domain' returns only breaches tied to a domain. 'Single breach' fetches one breach by its name.

## `domain` (type: `string`):

Only used when Mode is 'Breaches by domain'. A domain to filter breaches by, for example 'adobe.com'. Leave empty for other modes.

## `breachName` (type: `string`):

Only used when Mode is 'Single breach by name'. The exact breach Name as used by Have I Been Pwned, for example 'Adobe' or 'LinkedIn'. Leave empty for other modes.

## `maxItems` (type: `integer`):

How many breaches to collect per run.

## Actor input object example

```json
{
  "mode": "all",
  "maxItems": 10
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "maxItems": 10
};

// Run the Actor and wait for it to finish
const run = await client.actor("parseforge/hibp-breaches-catalog-scraper").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "maxItems": 10 }

# Run the Actor and wait for it to finish
run = client.actor("parseforge/hibp-breaches-catalog-scraper").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print("💾 Check your data here: https://console.apify.com/storage/datasets/" + run["defaultDatasetId"])
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "maxItems": 10
}' |
apify call parseforge/hibp-breaches-catalog-scraper --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "command": "npx",
            "args": [
                "mcp-remote",
                "https://mcp.apify.com/?tools=parseforge/hibp-breaches-catalog-scraper",
                "--header",
                "Authorization: Bearer <YOUR_API_TOKEN>"
            ]
        }
    }
}

```

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/c9xF3ntWcLS1a8IF7/builds/RUefbebNBQO9YETL3/openapi.json
