Breach Intelligence

2,843

Total breached databases

Approximately between 2022-2023, the U.S. Environmental Protection Agency (https://www.epa.gov/) suffered a data breach impacting over 8.5 million users and exposing personal and sensitive information of its customers and contractors. A hacker operating under the pseudonym @USDoD claimed responsibility and released the EPA's global contact database on a dark web forum. The leaked database contained three zipped files with approximately 500MB of data in CSV formats, holding common fields such as "Zipcodes," "Full names," "Phone numbers," "Email addresses," and "County, City, States," as well as additional fields in each file.
  • Date: 2023
  • Domain: epa.gov
  • Threat Actor: USDoD
  • Country: United States
  • Category: Government
  • Records Announced: 8,446,999
  • Data: Email Addresses Job Information Names Phone Numbers Physical Locations
  • Imported:
  • Records Imported: 8,497,246
  • Number of lines: 8,497,247
  • Size: 1.53 GB
  • Passwords: No
Tigo 2023

Tigo 2023

Sensitive
In mid-2023, Tigo, a Chinese video chat platform, allegedly suffered a data breach after 300GB of data containing more than 100 million records was discovered. The dataset, dating back to March 2023, reportedly included over 700,000 unique names. Among the compromised information were usernames, email addresses, IP addresses, genders, profile photos, and private messages.
  • Data: Device Information Email Addresses Genders Geographic Locations IP Addresses Messages Names Profile Photos Usernames
  • Imported:
  • Records Imported: 5,519,795
  • Number of lines: 5,519,797
  • Size: 157.36 MB
  • Passwords: No
In January 2018, PropTiger, an Indian property website, allegedly suffered a data breach that exposed a 3.46GB database file. The data, which surfaced on a popular hacking forum two years later, reportedly contained user records and login histories with more than 2 million unique customer email addresses. Among the compromised information were names, dates of birth, genders, IP addresses, and passwords stored as MD5 hashes.
  • Data: Birthdates Device Information Email Addresses Genders IP Addresses Names Passwords
  • Imported:
  • Records Imported: 7,971,626
  • Number of lines: 20,051,981
  • Size: 2.72 GB
  • Passwords: MD5
  • Cracked:
In January 2021, the Indian wedding planning platform WedMeGood suffered a data breach that exposed 1.3 million customers. The breach exposed 41.5GB of data including email and physical addresses, names, genders, phone numbers and password hashes.
  • Data: Email Addresses Genders Names Passwords Phone Numbers Physical Locations
  • Imported:
  • Records Imported: 1,624,742
  • Number of lines: 4,683,466
  • Size: 1.06 GB
  • Passwords: Hashed
  • Cracked:
In November 2021, the Indonesian real estate website Travelio suffered a data breach that exposed over 470k customer accounts. The data included email addresses, names, password hashes, phone numbers and for some accounts, dates of birth, physical address and Facebook auth tokens.
  • Data: Birthdates Email Addresses Names Passwords Phone Numbers Physical Locations Security Credentials
  • Imported:
  • Records Imported: 474,198
  • Number of lines: 474,315
  • Size: 278.54 MB
  • Passwords: Hashed
  • Cracked: