The June 2025 data breach
On 9 June 2025 CatWatchful suffered a data breach. A SQL injection vulnerability allowed customer email addresses and passwords — stored in plain text — to be extracted from our systems.
Have I Been Pwned recorded the incident on 3 July 2025, covering 61,641 accounts, and classified it as a sensitive breach: you can only look it up by verifying you own that email address. TechCrunch and Malwarebytes, among others, reported on it at the time.
There is no elegant way to say this: those passwords should never have been stored in plain text, and that query should never have been reachable without authentication. If you had an account before July 2025, change that password — and change it anywhere else you reused it.
Read the full account: what happened, what we changed and what you can do