Tangerine
Disclosed Feb 28, 20242 years ago243,462 accountsUnverified
In February 2024, the Australian Telco Tangerine suffered a data breach that exposed over 200k customer records . Attributed to a legacy customer database, the data included physical and email addresses, names, phone numbers and dates of birth. Whilst the Tangerine login process involves sending a one-time password after entering an email address and phone number, it previously used a traditional password which was also exposed as a bcrypt hash.
What is known
| People affected | 243,462 (accounts in the leaked data, per Have I Been Pwned) |
|---|---|
| Disclosed | Feb 28, 2024 |
| Happened | Feb 18, 2024 |
| Attack | Not stated |
| Data exposed | Dates of birth, Emails, Names, Passwords, Phone numbers, Addresses |
| Sector | Tech |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
| Check your email | Have I Been Pwned |
Sources
| Source | |
|---|---|
| Have I Been Pwned: Tangerinehaveibeenpwned.com · Aggregator | Aggregator |
Notices filed
| Where | Filed | People |
|---|---|---|
| Have I Been Pwnedaccounts in the data | Feb 28, 2024 | 243,462 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Have I Been Pwned). Record counts are as reported. Not legal advice.