Pi-hole Data Breach (2025)
If you are a customer of Pi-hole, here’s what’s now in circulation.
In July 2025, a vulnerability in the GiveWP WordPress plugin exposed the names and email addresses of approximately 30k donors to the Pi-hole network-wide ad blocking project. Pi-hole subsequently self-submitted the list of impacted donors to HIBP.
On July 30, 2025, a vulnerability in the GiveWP WordPress plugin exposed the names and email addresses of roughly 30,000 donors to the Pi-hole ad-blocking project.
Watch Pi-hole
Get alerted the next time Pi-hole files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Pi-hole’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Pi-hole, the popular open-source network-wide ad blocker, disclosed that donor information held through its donation platform was accessed without authorization. The project team self-submitted the exposed records to Have I Been Pwned, confirming the breach scope. Available reporting describes the incident as limited to donor names and email addresses, with no indication that financial details, passwords, or technical infrastructure were compromised. The vulnerability originated in the GiveWP plugin used on the Pi-hole website, and the organization acted quickly to notify affected individuals.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
Why This Matters for You and Your Family
When your name and email appear in a breach list, it becomes easier for spammers, scammers, and more determined actors to target you. Even a modest data set like this one can serve as the starting point for phishing emails that look legitimate because they reference your support for a project you actually care about. For families, the risk extends beyond annoyance: children’s accounts sometimes share family email domains or parent names, creating a bridge between a seemingly harmless donation record and gaming profiles or school-related logins. 30,000 affected donors means thousands of households now face elevated junk mail, credential-stuffing attempts, and potential doxxing chains that begin with one public leak.
The Doxxing and Identity-Chain Implications
Names paired with emails are high-value connectors in today’s data ecosystem. Once an attacker links your email to a Pi-hole donation, they can test that same email across dozens of other services, gaming platforms, and social accounts. Public reporting indicates these credential leaks frequently cascade into account takeovers, especially on services that do not enforce strong authentication. Gaming accounts belonging to you or your children are particularly vulnerable because kids often reuse simplified passwords or email addresses tied to family domains. The result is an identity chain that can expose home addresses, phone numbers, and relationships far beyond the original breach. DoxxScan by GalaxyWarden specializes in mapping these connections across 13.1 billion+ breach records and more than 100 platforms, revealing how one exposed donation can ripple into multiple accounts.
What to Do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, with cleanup handled by the service.
- Rotate the password you used for the Pi-hole donation anywhere else it is reused and enable two-factor authentication through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring so the next breach exposing your data is caught within hours instead of months.
- Cover the household with DoxxScan family coverage that extends to dependents and children’s gaming accounts that chain back to the same addresses or emails.
- Let remediation specialists manage takedown requests across data brokers and exposed records on your behalf.
The Pi-hole incident illustrates how even well-intentioned community projects can inadvertently place your personal information at risk. Acting promptly on exposed credentials and establishing ongoing visibility into new leaks gives you and your family a measurable advantage. Start your DoxxScan trial today to gain continuous monitoring across 13.1B+ breach records and 100+ platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that includes children’s gaming accounts.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…
Harvard University Alumni & Donor Data Breach — November 2025
ShinyHunters (Scattered Lapsus$ Hunters) dumped ~115,000 sensitive records from Harvard's Alumni Aff…
Coupang South Korea E-Commerce Breach — November 2025
34 million Coupang customers had names, emails, phones, and addresses exposed after an overseas serv…