Data breach
HiAPK
- Records
- 13,867,206
- Breach date
- 1 January 2014Estimated
- Added
- 4 March 2025
What was exposed
1 type of data · 2 more reported
- Email addresses13,867,206
- PasswordsReported, not counted
- UsernamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In early 2014, HiAPK, a Chinese website that distributed Android apps and operated a large user forum, appears to have suffered a data breach affecting millions of its registered users. The indexed dataset contains 13,867,206 records, with an estimated breach date of January 1, 2014. The listing was added to the database on March 4, 2025, and no individual or group has publicly claimed responsibility for the breach. No statement from HiAPK confirming the incident has been located.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Independent breach trackers have carried records matching this incident for years. Mozilla Monitor lists the HiAPK breach as occurring on January 1, 2014, and Leaked.Domains describes the leak as involving an alleged breach of the Chinese Android store that impacted roughly 13.8 million unique subscribers. Neither tracker attributes the breach to a named attacker.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses.
External breach trackers describe additional fields in the circulating dataset. According to Mozilla Monitor, the compromised data includes usernames, email addresses, and passwords. Leaked.Domains further describes the password material as salted MD5 password hashes, a hashing format considered weak by modern standards because large numbers of such hashes can be cracked with widely available tools.
Not every individual is affected by every type of data listed here.
The investigation team's index could not confirm how many of the records include a usable email address, so the number of individuals directly identifiable by email in this dataset remains unknown.
What Are the Potential Risks for Affected Individuals?
Because the dataset centers on account credentials, the main risks are indirect but real. If your username and password from HiAPK appeared in this leak, attackers can test those same credentials against other websites in what is known as credential stuffing. Many people reuse passwords across services, so a single exposed password can unlock email, shopping, or social media accounts years later.
Even where passwords were hashed, salted MD5 is an aging and fast hashing algorithm, meaning attackers with time and computing power can recover a meaningful share of the original passwords. Exposed usernames and email addresses also fuel phishing: criminals can send messages that appear to come from a trusted app store or forum and trick recipients into handing over more information.
What Should You Do If You Were Affected?
If you had a HiAPK account, or used the same password elsewhere, take these steps:
Change your HiAPK password immediately if the account still exists, and change the password on any other account where you reused it.
Use long, unique passwords for each important account. A reputable password manager can generate and store them for you.
Turn on two-factor authentication wherever it is offered, especially for email, banking, and social media.
Be cautious with unexpected emails or messages referencing app downloads, account problems, or password resets. Do not click links or enter credentials from unsolicited messages.
Watch your accounts for signs of unauthorized logins and review statements for unfamiliar activity.
Because this breach is more than a decade old, the credentials may have circulated in criminal databases for years. Updating passwords now still reduces your risk, particularly if any old passwords are still in use anywhere today.
