Skip to content

Tangerine

Disclosed Feb 28, 20242 years ago243,462 accountsUnverified

In February 2024, the Australian Telco Tangerine suffered a data breach that exposed over 200k customer records . Attributed to a legacy customer database, the data included physical and email addresses, names, phone numbers and dates of birth. Whilst the Tangerine login process involves sending a one-time password after entering an email address and phone number, it previously used a traditional password which was also exposed as a bcrypt hash.

What is known

People affected243,462 (accounts in the leaked data, per Have I Been Pwned)
DisclosedFeb 28, 2024
HappenedFeb 18, 2024
AttackNot stated
Data exposedDates of birth, Emails, Names, Passwords, Phone numbers, Addresses
SectorTech
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Check your emailHave I Been Pwned

Sources

Source
Have I Been Pwned: Tangerinehaveibeenpwned.com · Aggregator

Notices filed

WhereFiledPeople
Have I Been Pwnedaccounts in the dataFeb 28, 2024243,462
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Have I Been Pwned). Record counts are as reported. Not legal advice.

Everything about Tangerine

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.