Breach Intelligence

6,874

Total breached databases

In 2025, the Chinese film and video industry community site CineHello (cinehello.com, also known as 影视工业网 / 107cine) allegedly suffered a data breach. Reports suggest data on approximately 1 million members was exposed. The compromised information reportedly includes email addresses, usernames, real names, hashed and some plaintext passwords, phone numbers, geographic locations, genders, physical addresses, personal websites, and account activity timestamps.
  • Date: 2025
  • Domain: cinehello.com
  • Country: China
  • Category: Forums & Communities
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Genders Site Activity Websites
  • Records: 1,202,613
  • Lines: 1,202,617
  • Size: 154.95 MB
  • Passwords: MD5, SHA-1, Plaintext
In October 2016, the Chinese third-party Android app and game store Muzhiwan (muzhiwan.com) allegedly suffered a data breach. Reports suggest that around 4.9 million user records were exposed in the wider incident, including usernames, email addresses and salted vBulletin password hashes. This particular dataset contains approximately 3.07 million of those hashes that have been cracked to their plaintext values, exposing account passwords.
  • Data: Passwords
  • Records: 3,072,843
  • Lines: 3,072,843
  • Size: 174.86 MB
  • Passwords: MD5, vBulletin, Plaintext
A Chinese social-engineering-database (SGK / 社工库) compilation aggregating credentials from dozens of distinct historical Chinese breaches (QQ.com, 163.com, Sina, Xiaomi, and others). Reports suggest approximately 178,111,159 records were exposed, including usernames, email addresses, and passwords stored as a mix of unidentified hash algorithms and salted hashes. This is a compilation, not a breach of any single service.
  • Date: 2014
  • Country: China
  • Category: Compilations & Combo lists
  • Data: Email Addresses Passwords Usernames
  • Records: 183,343,825
  • Lines: 183,344,966
  • Size: 11.89 GB
  • Passwords: Unknown
12306.cn 2014

12306.cn 2014

Sensitive
In December 2014, 12306.cn, the official online train-ticket booking platform of China Railway, allegedly suffered a data breach. Reports suggest approximately 4.3 million records were exposed, including passenger full names and national identity (身份证) numbers, along with a set of user accounts containing email addresses, usernames, phone numbers, and plaintext passwords.
  • Date: Dec 2014
  • Domain: 12306.cn
  • Country: China
  • Category: Travel
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs
  • Records: 4,264,005
  • Lines: 4,264,005
  • Size: 221.73 MB
  • Passwords: Plaintext
Not a discrete 163.com corporate breach. A NetEase (163.com) domain-scoped credential OSINT compilation aggregating publicly-circulated email:password pairs. Reports suggest approximately 468,114 records are included, all Plaintext passwords.
  • Domain: 163.com
  • Country: China
  • Category: Compilations & Combo lists
  • Data: Email Addresses Passwords
  • Records: 468,114
  • Lines: 468,123
  • Size: 14.42 MB
  • Passwords: Plaintext
In 2024, the hacking group ByteMeCrew claimed responsibility for a data breach targeting On-Running, an international shoe brand. The attackers alleged that they obtained 220,000 lines of employee and customer data, including email addresses, phone numbers, and passwords.
  • Date: 2024
  • Domain: on-running.cn
  • Threat Actor: ByteMeCrew
  • Country: China
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Genders Site Activity Job Information Birthdates
  • Records: 218,808
  • Lines: 236,234
  • Size: 115.39 MB
  • Passwords: BCrypt
  • Cracked: 0%
In August 2026, Longka Yigou (card.jinkakj.com), a Chinese card-rental platform hosted on Alibaba Cloud, allegedly suffered a full backend database breach. Reports suggest the platform was compromised through weak administrator credentials and a known vulnerability, exposing its entire production database and cloud storage. The exposed data reportedly covered approximately 1,700 registered customers and thousands of rental orders, and included real names, Chinese national ID numbers, mobile phone numbers, home addresses, MD5 password hashes, login IP addresses, order and payment records, live SMS verification codes, and facial-liveness photographs.
  • Date: Aug 15, 2026
  • Domain: card.jinkakj.com
  • Threat Actor: exfilar
  • Country: China
  • Category: Finance & Payments
  • Data: Passwords Names Phone Numbers Physical Locations Geographic Locations Government IDs Genders IP Addresses Site Activity
  • Records: 50,630
  • Lines: 50,630
  • Size: 82.99 MB
  • Passwords: MD5
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.