Breach Intelligence

6,875

Total breached databases

Sometime before July 2026, OVP Software (ovpsoftware.es), a Madrid-based developer of ERP and business-management software for small and medium-sized enterprises, allegedly suffered a data breach of its WordPress website database. Reports suggest the exposed data contained roughly 70 to 80 records, including email addresses, usernames, names, and WordPress account password hashes (phpass). The bulk of the exposed emails were harvested from contact-form submissions and newsletter subscriptions.
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Site Activity
  • Records: 79
  • Lines: 238,038
  • Size: 70.33 MB
  • Passwords: PHPass
  • Cracked: 0%
In February 2024, Gilmar Offplan (gilmaroffplan.com) allegedly suffered a data breach. Gilmar Offplan is a real-estate business operating in the Costa del Sol area of Spain, and the exposed database appears to have catalogued property professionals and partner agencies. It has been reported that a SQL database export was extracted and circulated on underground forums. The dataset contains approximately 2,200 records, including email addresses, names, phone numbers, company information, and bcrypt-hashed passwords.
  • Date: Feb 2024
  • Domain: gilmaroffplan.com
  • Threat Actor: just1m
  • Country: Spain
  • Category: Real Estate
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Site Activity Company Information
  • Records: 5,219
  • Lines: 23,347
  • Size: 1.56 MB
  • Passwords: BCrypt
  • Cracked: 0%
Sometime before 2025, the Spanish dental supplies store SKS Dental (sksdental.es) allegedly suffered a data breach. Reports suggest the data was taken from the store's PrestaShop customer database and subsequently shared on a hacking forum. It has been reported that approximately 70 customers were affected, with the exposed data including names, email addresses, birthdates, postal addresses, phone numbers, national ID (DNI) numbers, genders, and BCrypt-hashed passwords.
  • Date: 2025
  • Domain: sksdental.es
  • Country: Spain
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Government IDs Genders Birthdates
  • Records: 123
  • Lines: 125
  • Size: 37.54 KB
  • Passwords: BCrypt
  • Cracked: 0%
Sometime before 2025, a WordPress development site belonging to DistriCenter (districenter.es), a Spanish textile and clothing distribution retailer, allegedly suffered a data breach. Reports suggest a small number of records were exposed, including email addresses, usernames, and phpass-hashed passwords.
  • Data: Email Addresses Passwords Names Usernames Geographic Locations Site Activity
  • Records: 11
  • Lines: 9,527
  • Size: 22.99 MB
  • Passwords: Hashed, PHPass
  • Cracked: 0%
Sometime before 2025, the Spanish online party-supplies and costume retailer Aire de Fiesta (airedefiesta.es) allegedly suffered a data breach. Reports suggest the exposed customer database contained approximately 131,000 records. The compromised data allegedly included email addresses, full names, dates of birth, and account creation details. No passwords were included in the exposed data.
  • Data: Email Addresses Names Geographic Locations Site Activity Birthdates
  • Records: 131,497
  • Lines: 131,498
  • Size: 11.14 MB
  • Passwords: No
Sometime before August 2026, Cromakit (cromakit.es), a Spanish online store distributing laboratory supplies and materials, allegedly suffered a data breach. The exposed data came from the store's WooCommerce/WordPress database and, according to reports, covered roughly 1,300 customers. It included email addresses, usernames, names, phone numbers, physical/billing addresses, company details, IP addresses, order/registration activity, and phpass-hashed account passwords.
  • Date: 2026
  • Domain: cromakit.es
  • Country: Spain
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames IP Addresses Site Activity Websites Company Information
  • Records: 7,696
  • Lines: 3,881,954
  • Size: 622.29 MB
  • Passwords: PHPass
  • Cracked: 0%
In 2025, publicly scraped user-profile data from Webrat.es, a Spanish online betting/gambling platform, was allegedly shared on a hacking forum. Reports suggest the dataset contained approximately 8,800 user profiles, including usernames, profile photo URLs, free-text bios (some listing Telegram/contact handles), account creation dates, deposit balances, roles, and ban history. No passwords or email addresses were included beyond a handful mentioned in bios.
  • Date: 2025
  • Domain: webrat.es
  • Threat Actor: Rennix921
  • Country: Spain
  • Category: Betting
  • Data: Email Addresses Names Geographic Locations Usernames Site Activity Profile Photos Bios
  • Records: 8,778
  • Lines: 105,337
  • Size: 1.81 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.