LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Pi-hole Data Breach (2025)

MEDIUM severityConfirmedHow we verify

Pi-hole Data Breach (2025): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 30, 2025

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Pi-hole Data Breach (2025)

Reported July 30, 2025. Approximately 30K people affected.

MEDIUM
Severity
30K
People affected
2
Data types exposed
July 30, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Pi-hole disclosed a data breach on July 30, 2025, exposing the email addresses and names of approximately 30,000 users. Individuals who may have an account with the service are advised to verify their exposure and change their credentials if necessary.

Severity & verification
MEDIUM severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Pi-hole Data Breach (2025) breach?
30K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In the mid-2020s threat landscape, software supply-chain and third-party plugin vulnerabilities remain a recurring source of data exposure for open-source projects and their communities. Even modest donor lists can surface when a widely used component is compromised, turning routine fundraising pages into unintended collection points for personal contact information.

Public reporting dated 30 July 2025 states that a vulnerability in the GiveWP WordPress plugin exposed the names and email addresses of approximately 30 000 donors to the Pi-hole network-wide ad-blocking project. Pi-hole subsequently self-submitted the list of impacted donors to Have I Been Pwned. The precise technical details of the vulnerability and the exact window of exposure remain limited in public accounts.

Breaking down the breach

According to the reported summary, the incident involved a vulnerability in the GiveWP WordPress plugin that affected Pi-hole’s donor records. Approximately 30 000 individuals who had contributed to the project had their names and email addresses exposed. The organisation itself later submitted the affected list to Have I Been Pwned, confirming the scale and the data types involved. No further public detail has been released on the exact date the vulnerability was exploited, the method of access beyond the plugin flaw, or any additional systems that may have been involved. Attribution to a specific threat actor has not been made in available reporting.

How a breach like this happens

Incidents of this type commonly begin with a security flaw in a third-party component—such as a popular WordPress donation or form plugin—that an organisation has installed to handle payments or contact collection. Attackers scan for known or newly disclosed weaknesses in these plugins, then exploit them to extract database tables that store form submissions. Because donation plugins routinely capture name and email fields, those two data types are frequently the first to leave the system. Once extracted, the records may be sold, posted, or simply left in a location that later becomes public. Organisations that discover the exposure often choose to notify breach-notification services so that affected people can check their own status. No specific group has been named in connection with the Pi-hole case, and the general pattern described here is drawn from typical plugin-related exposures rather than from any claim about this event.

Pi-hole and its sector

Pi-hole is an open-source network-level advertisement and tracker blocking project widely used by individuals and small organisations to filter unwanted traffic on home and office networks. Projects of this kind typically rely on voluntary donations to fund development, infrastructure and community support. Donor records therefore form a natural administrative dataset: names and email addresses collected through a WordPress-based giving page. Because the project serves a privacy-conscious user base, any exposure of supporter contact details carries particular weight; donors may reasonably expect that their support for a privacy tool would not itself become a source of personal-data leakage. In the broader open-source and network-security sector, similar donor or contributor lists are common and have occasionally appeared in other incidents involving third-party plugins or misconfigured web applications.

What was likely exposed

The facts name two data types as exposed: email addresses and names. Public reporting does not list additional fields such as postal addresses, payment-card numbers, IP addresses or donation amounts. Organisations that operate donation pages typically hold at least the information required to process and acknowledge gifts; beyond the confirmed fields, the exact contents of the Pi-hole donor records remain unconfirmed. Readers should therefore treat only the named data types as established.

Why it matters

For the individuals affected, the primary risks are phishing and social-engineering attempts that reference their support for Pi-hole or that use the exposed email addresses as targeting vectors. Names paired with emails can also be used to craft more convincing messages or to cross-reference other public data sets. For the project itself, the incident creates a trust and communication burden: supporters must be informed, and the organisation must demonstrate that the underlying plugin vulnerability has been addressed. Because Pi-hole markets itself as a privacy-enhancing tool, any leakage of supporter data can undermine confidence even when the volume of records is modest by commercial standards. No financial loss figures or secondary misuse of the data have been reported in the available facts.

What to do if you're exposed

If you have donated to Pi-hole and believe your name and email may be among the approximately 30 000 records, treat the address as known to unauthorised parties. Change any passwords that reuse that email as a username, enable multi-factor authentication wherever possible, and remain alert for unsolicited messages that mention the project or request further personal details. Monitor financial accounts only if you later learn that payment data was also involved—an outcome not indicated by current reporting. Readers can run a free exposure scan of their email address against known breach data sets to determine whether their information has already surfaced. Keep records of any suspicious contact and report it to the relevant platform or local authorities if it escalates beyond ordinary phishing.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyPi-hole security record
74/100
DoxxScan™ · Moderate doxx risk
B 80Good record

1 reported incident on record.

See Pi-hole’s full breach history →

More recent breaches

Pass'Sport Data Breach (2025)December 17, 2025APOIA.se Data Breach (2025)December 16, 2025SoundCloud Data Breach (2025)December 15, 2025Under Armour Data Breach (2025)November 17, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Pi-hole Data Breach (2025) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram