2026 ROBB shop — customer notices; password hashes taken; forced resets (HIBP/Troy Hunt)
Data compromised
Password hashes and account-related data per customer breach email; plaintext passwords not in dump per notice, but site forced password resets
Technical writeup
Verified customer notification pathway acknowledged by Troy Hunt / Have I Been Pwned context — September 5, 2026. ROBB shop (@ROBBshop) emailed customers about a data breach stating password hashes were taken while asserting plaintext passwords were not in the data, and forced password resets sitewide. Public national tally and full data-element list not published at catalog time. recordsAffected 0; companyConfirmed true.
Root cause
Account/database breach (customer notification; hashing algorithm not named publicly)