The Oxfam Breach Means Scammers Could Be Impersonating the Charity to 1.98 Million Donors
HEROIC analysts flagged the Oxfam breach after tracking its appearance on hacking forums where the database was first offered for sale and later released for free. The breach occured in January 2021 and exposed 1,980,271 supporter records from the Australian arm of this global nonprofit organization. The leaked data includes full names, email addresses, phone numbers, birthdays, and gender, all recieved by threat actors who circulated the database across underground communities targeting Australian donors.
How Full Names, Birthdays, and Phone Numbers Enable Identity Fraud Against Oxfam Donors
The Oxfam breach exposed a complete personal identity profile for nearly 2 million individuals. Attackers who hold this data can use full names, birthdays, phone numbers, and email addresses to impersonate victims in identity verification processes, SIM swap attacks, and account recovery requests. Nonprofit donors are partcularly attractive targets for charity scam campaigns, where fraudsters impersonate organizations to solicit additional payments from people whose contact details confirm they have donated before. This data also feeds directly into broader identity theft operations.
What Was Exposed in the Oxfam Breach
- Email Address
- Phone Number
- First Name
- Last Name
- Birthday
- Gender
Why a Nonprofit Breach Affecting 1.98 Million People Is a Long-Term Threat
The Oxfam database was first put up for sale on a hacking forum before being released freely, meaning it has been accessable to any threat actor at no cost since early 2021. Data of this scale and personal depth is routinely aggregated with other breach datasets to build comprehensive victim profiles used in credential stuffing, phishing, financial fraud, and identity theft. Donors who gave personal information to support a charitable cause now face ongoing risk of targeted scams and social engineering attacks years after the original breach.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to an organization's data systems and extracts stored user records. Nonprofit organizations are frequent targets because they hold large, detailed supporter databases but often operate with limited cybersecurity budgets. Once extracted, the data is sold or distributed on hacking forums. Large-scale breaches like Oxfam are particularly valuable because the volume and detail of personal records make them useful for a wide range of downstream attacks, from phishing campaigns to synthetic identity fraud.
Check If Your Data Was Exposed
HEROIC's free breach scanner checks your email address against a database of over 400 billion compromised records, including the Oxfam breach. Run a free check now to see if your personal information was part of this 1.98 million record leak and find out what steps you should take to protect yourself.
Breach Breakdown
1,980,271 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds