Breach Intelligence

3,512

Total breached databases

In June 2019, a compilation titled "phdays.com" allegedly surfaced, comprising per-person dossiers that aggregate prior breach exposures of individuals associated with the Russian information-security community. Each file collates an individual's data drawn from numerous earlier breaches and combo lists. Reports suggest the compilation exposed approximately 70 individuals. The exposed data was limited to email addresses and geographic locations, with no passwords recovered.
  • Date: Jun 2019
  • Domain: phdays.com
  • Country: Russia
  • Category: Compilations & Combo lists
  • Data: Email Addresses Geographic Locations
  • Records: 69
  • Lines: 1,045
  • Size: 50.31 KB
  • Passwords: No
This dataset is a continuously growing collection of combo lists, automatically aggregated from public forums, Telegram channels, and other sources. It is not a single breach, but a compilation of email/username and password pairs bundled and redistributed for use in credential-stuffing attacks.
  • Category: Compilations & Combo lists
  • Data: Email Addresses Passwords Usernames
  • Records: 12,078,444,844
  • Lines: 13,196,241,941
  • Size: 801.85 GB
  • Passwords: Plaintext
In January 2016, a significant number of unpatched vBulletin forums were compromised by an actor known as "CrimeAgency." A total of approximately 140 forums had data, including usernames, email addresses, and passwords (predominantly stored as salted MD5 hashes), extracted and subsequently distributed.
  • Data: Email Addresses Passwords Usernames
  • Records: 1,904,361
  • Lines: 755,079
  • Size: 72.46 MB
  • Passwords: vBulletin
  • Cracked: 0%
In May 2023, a credential stuffing list of 6.3M Polish email address and password pairs appeared on a local forum. Likely obtained by malware running on victims' machines, each record included an email address and plain text password alongside the website the credentials were used on. The data included 1.2M unique email addresses.
  • Date: May 29, 2023
  • Country: Poland
  • Category: Compilations & Combo lists
  • Source: haveibeenpwned.com
  • Data: Email Addresses Passwords
  • Records: 5,890,000
  • Lines: 6,274,679
  • Size: 437.21 MB
  • Passwords: Plaintext
This collection is part of a larger series of data dumps, including Collections #1 through #5, which compiled email addresses and passwords from thousands of sources, from previously known data breaches and some new alleged breaches. Collection #1 alone contained about 2.7 billion records, including 1.2 billion unique email and password combinations, 773 million unique email addresses, and 21 million unique plaintext passwords. Additional collections, named Collections #2 through #5, along with "AP MYR&ZABUGOR #2" and "ANTIPUBLIC #1," were also discovered, significantly adding to the scope of compromised data​.
  • Data: Email Addresses Passwords
  • Records: 477,890,227
  • Lines: 479,310,893
  • Size: 14.11 GB
  • Passwords: Plaintext
In October 2020, 17 previously undisclosed data breaches were put up for sale, including one affecting Wongnai, a Thai service for finding restaurants, hotels, and attractions. The breach reportedly exposed nearly 4 million unique customer records. Among the compromised data were names, phone numbers, social media profiles, and passwords stored as MD5 hashes.
  • Data: Birthdates Email Addresses Geographic Locations IP Addresses Names Passwords Phone Numbers Social Profiles
  • Records: 4,298,301
  • Lines: 4,298,533
  • Size: 2.86 GB
  • Passwords: MD5
  • Cracked: 0%
Sometime around 2017, a compilation of data from multiple Malaysian sources was leaked. This massive data collection includes records from the telecommunications industry, financial institutions, government benefits, and more, aimed at Malaysian citizens and residents. Reports suggest the breach involved approximately 158 million lines of data, with about 54 million unique phone numbers. Among the compromised data were names, phone numbers, physical locations, and government ID numbers.
  • Date: 2017
  • Country: Malaysia
  • Category: Compilations & Combo lists
  • Data: Names Phone Numbers Physical Locations Government IDs
  • Records: 158,036,649
  • Lines: 158,036,650
  • Size: 29.2 GB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.