Breach Intelligence

6,875

Total breached databases

In December 2011, the Chinese online dating platform Baihe.com allegedly suffered a data breach as part of a larger wave of Chinese website compromises. Baihe.com, founded in 2005 and operated by Baihe Network Company, was known for incorporating Sesame Credit data into its matchmaking services. Reports suggest approximately 10.8 million individual records were exposed, including email addresses, usernames, names, phone numbers, and passwords stored as MD5 hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Genders IP Addresses Site Activity
  • Records: 10,874,107
  • Lines: 10,874,110
  • Size: 1.01 GB
  • Passwords: MD5
  • Cracked: 99%
nxTomo Games is a game development company based out of Hong Kong. It specializes in developing games based on strategy, action, sports, and card genres. It develops games for Android and iOS platforms. One of the games developed by the company is "BFB".
  • Data: The data categories affected by the Bfb.nxtomogames.com 2021 breach have not been disclosed yet. We will expand this section when details are released.
  • Records: 2,338,991
  • Lines: 2,339,060
  • Size: 1.13 GB
  • Passwords: ?
In mid-2011, data was allegedly obtained from the Chinese engineering website known as Civil Online and contained 7.8M accounts. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains email and IP addresses, user names and MD5 password hashes.
  • Data: Email Addresses IP Addresses Passwords Site Activity Usernames
  • Records: 13,499,276
  • Lines: 13,499,329
  • Size: 3.8 GB
  • Passwords: MD5
  • Cracked: 100%
In December 2020, a dataset allegedly containing information on members of the Chinese Communist Party (CCP) was leaked, reportedly exposing approximately 1,956,732 records. The data appeared to originate from a Shanghai-based server and included names, birthdates, genders, ethnicities, government-issued ID numbers, phone numbers, physical locations, places of birth, education, and company affiliations. No passwords were included. The leak resurfaced in April 2024 when the threat actor known as "USDoD" published the dataset on a popular hacking forum.
  • Date: 2020
  • Threat Actor: USDoD
  • Country: China
  • Category: Government
  • Data: Birthdates Company Information Education Ethnicities Genders Government IDs Names Phone Numbers Physical Locations Places of Birth
  • Records: 1,956,731
  • Lines: 1,956,732
  • Size: 278.9 MB
  • Passwords: No
In early 2018, the chinese cryptocurrency mining website was breached. This website concentrated on selling cryptocurrency hardware and software to many mining operations. Please keep in mind there are no passwords leaked with this breach.
  • Date: 2018
  • Domain: bitmain.com
  • Country: China
  • Category: Cryptocurrency
  • Data: Geographic Locations Names Phone Numbers Physical Locations Usernames
  • Records: 102,091
  • Lines: 102,092
  • Size: 15.53 MB
  • Passwords: No
In approximately 2012, it's alleged that the Chinese email service known as 126 suffered a data breach that impacted 6.4 million subscribers. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains email addresses and plain text passwords.
  • Data: Email Addresses Passwords
  • Records: 7,297,670
  • Lines: 7,297,719
  • Size: 200.6 MB
  • Passwords: Plaintext
In approximately 2017, it's alleged that the Chinese gaming site known as TGBUS suffered a data breach that impacted over 10 million unique subscribers. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains usernames, email addresses and salted MD5 password hashes and was provided with support from dehashed.com.
  • Data: Email Addresses Passwords Usernames
  • Records: 12,966,100
  • Lines: 12,966,124
  • Size: 1.56 GB
  • Passwords: vBulletin
  • Cracked: 83%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.