Data breach
Digimon
- Records
- 4,833,468
- Breach date
- 5 September 2016Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 4 more reported
- Email addresses4,830,597
- IP addresses1,817,512
- CountriesReported, not counted
- StatesReported, not counted
- CitiesReported, not counted
- NamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In September 2016, a large set of email delivery logs tied to the domain digimon.co.in was exposed, most likely through an unsecured MongoDB database. Our investigation team estimates the indexed dataset contains about 4.8 million rows, with roughly 4.83 million email addresses and about 1.82 million IP addresses among them. The service itself stopped running shortly after the exposure, and its exact nature remains unclear. Security researchers have concluded it was probably a bulk mail service, possibly built on the PowerMTA software, used to deliver spam. According to the breach listing maintained by Mozilla Monitor, the underlying logs also included email messages and recipient names, along with email subjects and tracking data such as opens and clicks. No passwords are known to be part of the exposed records.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
September 5, 2016: Logs from a service believed to be digimon.co.in were exposed, likely through an unprotected MongoDB instance, according to Mozilla Monitor.
September 28, 2018: The incident was added to Mozilla Monitor's breach database after being discovered and verified.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses and IP addresses.
Reporting from DeHashed indicates the underlying database also held geographic details such as country, state, and city tied to recipients, as well as logs of email opens and click activity. Mozilla Monitor's listing additionally includes email messages and names.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because the exposed data centers on email addresses rather than passwords, the main risks are indirect. Anyone whose address appears in the logs can expect more spam and phishing email, since the dataset reads like a ready-made mailing list. Attackers often use real addresses from leaks like this to send convincing scam messages, fake delivery notices, or fraudulent invoices.
The IP addresses in the records reveal the internet service provider and approximate location of the network that received the mail. On its own, an IP address is not a direct path into someone's accounts, but combined with an email address it can make phishing attempts look more credible and help scammers personalize their messages.
There is no indication that passwords, payment details, or government identifiers were exposed in this incident. The practical danger is targeted social engineering rather than direct account takeover.
What Should You Do If You Were Affected?
If you believe your email address appeared in these logs, a few steps can lower your risk:
Treat unexpected emails with suspicion, especially anything asking you to click a link, open an attachment, or confirm account details. Verify claims independently before responding.
Enable two-factor authentication on your email account and other important services, so a phishing attempt alone cannot compromise them.
Check whether any of your accounts were touched in other breaches and change any reused passwords. This incident exposed no passwords, but many people appear in multiple leaked datasets.
Mark persistent spam as junk and consider filtering rules. If the address you used with this service is heavily abused, a new email address for sensitive accounts is a reasonable option.
There is no indication that the operator of digimon.co.in issued a public notification about the exposure, and the service itself went offline shortly after the logs were obtained.
