Breach Intelligence

6,875

Total breached databases

In approximately January 2017, the Brazilian OpenTibia private server CaterOT allegedly suffered a data breach that exposed records of approximately 87,000 users. The compromised data included email addresses, usernames, dates of birth, genders, geographic locations, and passwords stored as SHA-1 hashes.
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Genders Site Activity Birthdates
  • Records: 84,589
  • Lines: 125,774
  • Size: 30.96 MB
  • Passwords: SHA-1
  • Cracked: 0%
Sometime before 2019, Hippo, a Brazilian supermarket chain based in Florianópolis, Santa Catarina, allegedly suffered a data breach affecting its online store at hippo.com.br. Reports suggest approximately 30,000 records were exposed, including email addresses, MD5-hashed passwords, names, phone numbers, geographic locations, government IDs, birthdates, genders, relationship statuses, and other profile information.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs Relationship Statuses Genders Site Activity Company Information Birthdates
  • Records: 30,325
  • Lines: 63,646
  • Size: 16.2 MB
  • Passwords: MD5
  • Cracked: 0%
In June 2022, the website vinci.com.br, operated by Vinci, a major wine importer in Brazil, allegedly suffered a data breach impacting approximately 25,000 clients. Reports suggest that data compromised in the breach included full names, email addresses, geographic locations, government IDs (CPF), and payment card information (hashed), while no passwords were exposed.
  • Date: Jun 2022
  • Domain: vinci.com.br
  • Country: Brazil
  • Category: E-commerce & Retail
  • Data: Names Geographic Locations Credit Card Information Government IDs Site Activity Tax IDs
  • Records: 26,004
  • Lines: 26,045
  • Size: 25.28 MB
  • Passwords: No
In August 2019, Clube do Ingresso, an online platform for purchasing tickets for various events in Brazil, allegedly suffered a data breach. It has been reported that approximately 85,000 records were compromised. The exposed data includes email addresses, passwords hashed in MD5, names, geographic locations, genders, tax IDs, and birthdates.
  • Data: Email Addresses Passwords Names Geographic Locations Genders Tax IDs Birthdates
  • Records: 85,376
  • Lines: 85,561
  • Size: 27.72 MB
  • Passwords: MD5
  • Cracked: 0%
In 2019, the Brazilian online platform Belvitta, which specializes in the sale of dermocosmetics products, allegedly experienced a data breach. Reports suggest that approximately 13,211 records were compromised during this incident. The data exposed includes email addresses, passwords encrypted with MD5 and salted, names, phone numbers, and geographic locations.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations
  • Records: 13,211
  • Lines: 44,177
  • Size: 3.01 MB
  • Passwords: MD5 Salted
  • Cracked: 0%
In 2022, TracknMe, a Brazilian company specializing in GPS tracking and fleet management services, allegedly experienced a data breach. Reports suggest that approximately 124,964 records were compromised. The data exposed included email addresses, passwords, names, and phone numbers.
  • Date: 2022
  • Domain: tracknme.com.br
  • Country: Brazil
  • Category: Logistics & Transportation
  • Data: Email Addresses Passwords Names Phone Numbers
  • Records: 124,964
  • Lines: 124,997
  • Size: 30.85 MB
  • Passwords: Unknown
In December 2021, the Brazilian platform Atleta's Now, which serves as an online community for sports enthusiasts and influencers, allegedly suffered a data breach. Reports suggest that approximately 62,890 records were compromised in this incident. The data exposed included email addresses, names, phone numbers, physical locations, genders, birthdates, and passwords, with the passwords being stored using PHPass hashing.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Genders Birthdates
  • Records: 62,890
  • Lines: 62,983
  • Size: 19.63 MB
  • Passwords: Hashed, PHPass
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.