Breach Intelligence

6,875

Total breached databases

Sometime before 2026, the school platform Lingshi (school.lingshi.com) allegedly suffered a data breach. It has been reported that a threat actor extracted a database containing information on approximately 30 students. The exposed records reportedly included names, phone numbers, account balances, and registration dates.
  • Date: 2026
  • Domain: lingshi.com
  • Threat Actor: DarkArm6
  • Country: China
  • Category: Education
  • Data: Names Phone Numbers Balances
  • Records: 31
  • Lines: 31
  • Size: 2.18 KB
  • Passwords: ?
Lanyux 2025

Lanyux 2025

Sensitive
In January 2025, the Chinese dating platform Lanyu (lanyux.cn) allegedly suffered a data breach. It has been reported that a WeChat user index was subsequently published on a hacking forum. The incident allegedly affected approximately 33,000 individuals, with the exposed records limited to usernames and, for a small number of accounts, self-written profile bios. No passwords were included in the exposed data.
  • Date: Jan 2025
  • Domain: lanyux.cn
  • Country: China
  • Category: Dating
  • Data: Usernames Bios
  • Records: 33,322
  • Lines: 33,322
  • Size: 7.33 MB
  • Passwords: No
In February 2025, the Chinese automotive parts B2B platform Yiqilian (yiqilian.biz) allegedly suffered a data breach. The platform serves auto repair shops and workshops across China. It has been reported that a customer database was subsequently published on a hacking forum. The incident allegedly affected approximately 37,000 individuals, with the compromised records including names, phone numbers, bcrypt-hashed passwords and, for most accounts, the corresponding plaintext passwords.
  • Date: Feb 2025
  • Domain: yiqilian.biz
  • Country: China
  • Category: Automotive
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Social Profiles
  • Records: 37,436
  • Lines: 37,436
  • Size: 49.64 MB
  • Passwords: BCrypt, Plaintext
Sometime before August 2025, QQ Mail (mail.qq.com), the free email service operated by the Chinese technology company Tencent, allegedly suffered a data breach. Reports suggest the data was subsequently published on a hacking forum. The exposed data reportedly contained approximately 4.8 million records, including email addresses, usernames, real names, phone numbers, physical addresses, and genders. No passwords were included in the exposed data.
  • Date: Aug 22, 2025
  • Domain: mail.qq.com
  • Threat Actor: N1KA
  • Country: China
  • Category: Technology
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Usernames Genders
  • Records: 5,368,000
  • Lines: 5,368,001
  • Size: 459.72 MB
  • Passwords: No
In August 2019, the Chinese social networking website 51.com (later rebranded xx5-in.com) allegedly suffered a data breach. 51.com was one of China's largest social networking platforms during the mid-2000s. Reports suggest approximately 41.8 million user accounts were exposed. The compromised data included email addresses, usernames, full names, plaintext passwords, genders, geographic locations, government ID numbers, IP addresses, and site activity.
  • Date: Aug 2019
  • Domain: xx5-in.com
  • Country: China
  • Category: Social Media & Communication
  • Data: Email Addresses Passwords Names Physical Locations Geographic Locations Usernames Government IDs Genders IP Addresses Site Activity Social Profiles
  • Records: 43,123,993
  • Lines: 43,144,137
  • Size: 9.92 GB
  • Passwords: Plaintext
Sometime around 2022, Haijiao (haijiao.com), a Chinese adult discussion forum, allegedly had its user database exposed. Reports suggest the data covered approximately 15.7 million user accounts and included email addresses, usernames, bcrypt-hashed passwords, registration dates and last-login IP addresses. The dataset was later circulated publicly on a data-breach forum.
  • Data: Email Addresses Passwords Phone Numbers Geographic Locations Usernames IP Addresses Site Activity
  • Records: 15,760,043
  • Lines: 15,760,043
  • Size: 10.26 GB
  • Passwords: BCrypt
  • Cracked: 0%
In February 2017, the Chinese regional site of surveillance-camera manufacturer Arecont Vision (arecontvision.cn) allegedly suffered a data breach via SQL injection. Reports suggest approximately 36,000 user records were exposed, many belonging to security-industry distributors and integrators. The data compromised includes email addresses and MD5 password hashes.
  • Data: Email Addresses Passwords
  • Records: 36,576
  • Lines: 36,581
  • Size: 2 MB
  • Passwords: MD5
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.