Breach Intelligence

6,480

Total breached databases

Psiho is the label attached to a leaked dataset whose original source site has not been confirmed. It has been alleged that the data represents a compilation of breached login credentials. Reports suggest approximately 880,000 accounts are included, with data consisting of email addresses and plaintext passwords.
  • Category: Compilations & Combo lists
  • Data: Email Addresses Passwords
  • Records: 883,706
  • Lines: 883,706
  • Size: 27.33 MB
  • Passwords: Plaintext
At an unconfirmed date, a compiled list of approximately 1,600 personal contact records was allegedly posted on a hacking forum. Reports suggest the data was aggregated from multiple sources rather than obtained from a single-site breach. The exposed records allegedly included names, company names, international postal addresses (primarily US and Canada), phone numbers, email addresses, and salted MD5 password hashes.
  • Category: Compilations & Combo lists
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Company Information
  • Records: 1,645
  • Lines: 1,644
  • Size: 220.63 KB
  • Passwords: MD5 Salted
  • Cracked: 0%
This dataset is a compilation of approximately 46,000 credentials in email and MD5-hashed-password format. The addresses span many providers and country domains, and no single breached source could be attributed. It is alleged to circulate as a standalone credential dump. The data exposed includes email addresses and MD5 password hashes.
  • Category: Compilations & Combo lists
  • Data: Email Addresses Passwords
  • Records: 46,007
  • Lines: 46,007
  • Size: 2.53 MB
  • Passwords: MD5
  • Cracked: 0%
In June 2019, a compilation titled "phdays.com" allegedly surfaced, comprising per-person dossiers that aggregate prior breach exposures of individuals associated with the Russian information-security community. Each file collates an individual's data drawn from numerous earlier breaches and combo lists. Reports suggest the compilation exposed approximately 70 individuals. The exposed data was limited to email addresses and geographic locations, with no passwords recovered.
  • Date: Jun 2019
  • Domain: phdays.com
  • Country: Russia
  • Category: Compilations & Combo lists
  • Data: Email Addresses Geographic Locations
  • Records: 69
  • Lines: 1,045
  • Size: 50.31 KB
  • Passwords: No
This dataset is a continuously growing collection of combo lists, automatically aggregated from public forums, Telegram channels, and other sources. It is not a single breach, but a compilation of email/username and password pairs bundled and redistributed for use in credential-stuffing attacks.
  • Category: Compilations & Combo lists
  • Data: Email Addresses Passwords Usernames
  • Records: 12,078,444,844
  • Lines: 13,196,241,941
  • Size: 801.85 GB
  • Passwords: Plaintext
In January 2016, a significant number of unpatched vBulletin forums were compromised by an actor known as "CrimeAgency." A total of approximately 140 forums had data, including usernames, email addresses, and passwords (predominantly stored as salted MD5 hashes), extracted and subsequently distributed.
  • Data: Email Addresses Passwords Usernames
  • Records: 1,904,361
  • Lines: 755,079
  • Size: 72.46 MB
  • Passwords: vBulletin
  • Cracked: 0%
In May 2023, a credential stuffing list of 6.3M Polish email address and password pairs appeared on a local forum. Likely obtained by malware running on victims' machines, each record included an email address and plain text password alongside the website the credentials were used on. The data included 1.2M unique email addresses.
  • Date: May 29, 2023
  • Country: Poland
  • Category: Compilations & Combo lists
  • Source: haveibeenpwned.com
  • Data: Email Addresses Passwords
  • Records: 5,890,000
  • Lines: 6,274,679
  • Size: 437.21 MB
  • Passwords: Plaintext

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.