Breach Intelligence

6,480

Total breached databases

A Chinese social-engineering-database (SGK / 社工库) compilation aggregating credentials from dozens of distinct historical Chinese breaches (QQ.com, 163.com, Sina, Xiaomi, and others). Reports suggest approximately 178,111,159 records were exposed, including usernames, email addresses, and passwords stored as a mix of unidentified hash algorithms and salted hashes. This is a compilation, not a breach of any single service.
  • Date: 2014
  • Country: China
  • Category: Compilations & Combo lists
  • Data: Email Addresses Passwords Usernames
  • Records: 183,343,825
  • Lines: 183,344,966
  • Size: 11.89 GB
  • Passwords: Unknown
A generic email:password credential-stuffing / brute-force combo list distributed via a Telegram channel ("@BruteForce"), originally mislabeled with the GameStop brand. Reports suggest approximately 7,564,945 records were exposed, including email addresses and plaintext passwords, with no site-specific structure indicating an actual GameStop.com breach.
  • Category: Compilations & Combo lists
  • Data: Email Addresses Passwords Usernames
  • Records: 7,564,945
  • Lines: 7,564,972
  • Size: 250.14 MB
  • Passwords: Plaintext
Not a Jagex breach. A generic email:password credential-stuffing combo distributed under the Jagex brand name — Jagex/RuneScape log in by username, not email, and there is no confirmed Jagex breach of this shape. Reports suggest approximately 1,556,796 records are included.
  • Category: Compilations & Combo lists
  • Data: Email Addresses Passwords
  • Records: 1,556,796
  • Lines: 1,557,093
  • Size: 48.52 MB
  • Passwords: Plaintext
Not a PJM Interconnection system breach. An OSINT credential-aggregation of @pjm.com email addresses whose passwords/hashes are sourced from public combo compilations (AntiPublic, Collections, Exploit.in), padded with public HQ-address/phone enrichment. Reports suggest approximately 10,554 records are included.
  • Country: United States
  • Category: Compilations & Combo lists
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations
  • Records: 10,554
  • Lines: 42,302
  • Size: 6.94 MB
  • Passwords: Plaintext
Not a Hostinger breach. A generic email:password combo distributed under the Hostinger brand name, spanning many unrelated mail providers. Reports suggest approximately 312,099 records are included.
  • Category: Compilations & Combo lists
  • Data: Email Addresses Passwords Usernames
  • Records: 312,099
  • Lines: 312,132
  • Size: 9.65 MB
  • Passwords: Plaintext
Not a discrete 163.com corporate breach. A NetEase (163.com) domain-scoped credential OSINT compilation aggregating publicly-circulated email:password pairs. Reports suggest approximately 468,114 records are included, all Plaintext passwords.
  • Domain: 163.com
  • Country: China
  • Category: Compilations & Combo lists
  • Data: Email Addresses Passwords
  • Records: 468,114
  • Lines: 468,123
  • Size: 14.42 MB
  • Passwords: Plaintext
Not a Blogger breach. A generic email:password combo distributed under the Blogger brand name, including some synthetic-looking @blogger.com usernames Blogger never issues. Reports suggest approximately 1,624 records are included.
  • Category: Compilations & Combo lists
  • Data: Email Addresses Passwords
  • Records: 1,624
  • Lines: 1,624
  • Size: 60.93 KB
  • Passwords: Plaintext

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.