Breach Intelligence

6,875

Total breached databases

Sometime before May 2026, a database from the French professional-training document portal union-prof-asso.fr was allegedly leaked on a hacking forum. Reports suggest the exposed data was a document-download activity log covering approximately 420 distinct users — largely staff of GRETA training centres and other formation organisations — including their email addresses, associated organisation names and download timestamps. No passwords were included.
  • Data: Email Addresses Names Geographic Locations Site Activity Company Information
  • Records: 77,980
  • Lines: 11,102
  • Size: 8.62 MB
  • Passwords: No
Sometime before 2025, the Fédération Française de Ball-Trap (FFBT, ffbt.asso.fr) — the French national federation governing clay-target (clay pigeon) shooting — allegedly suffered a data breach. Reports attribute the incident to the threat actor PwnerSec, and suggest approximately 5,600 member accounts were exposed. The compromised data consisted of email addresses and passwords stored as SHA-1 hashes.
  • Date: 2025
  • Domain: ffbt.asso.fr
  • Threat Actor: PwnerSec
  • Country: France
  • Category: Sports
  • Data: Email Addresses Passwords
  • Records: 5,642
  • Lines: 5,642
  • Size: 356.7 KB
  • Passwords: SHA-1
  • Cracked: 0%
Sometime before 2025, imapper.tech (iMapper), a French web-connected 2D laser measurement solution for building professionals, allegedly suffered a data breach. Reports suggest a threat actor exploited a vulnerability in the company's Metabase analytics instance and exported its accounts table, exposing approximately 4,300 user records. The compromised data reportedly included email addresses, usernames, professions, preferred languages, and SHA-224 password hashes.
  • Date: 2025
  • Domain: imapper.tech
  • Country: France
  • Category: Technology
  • Data: Email Addresses Passwords Usernames Job Information Languages
  • Records: 4,288
  • Lines: 4,288
  • Size: 610.79 KB
  • Passwords: Unknown
Sometime before 2025, a user directory tied to Thales Group (thalesgroup.com) — a French multinational aerospace, defence and digital-security company — was allegedly exposed in a data breach. The data originated from a LuxTrust digital-signature identity platform used by the company and reportedly affected around 6,400 accounts. The exposed records included names, email addresses, phone numbers, and associated organisation names. No passwords were included in the data.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Company Information
  • Records: 6,362
  • Lines: 6,409
  • Size: 5.47 MB
  • Passwords: No
Sometime before late 2025, AMEPI (amepi.fr, also known as Amanda) allegedly suffered a data breach. AMEPI is a French cooperative platform used by real-estate agencies to share exclusive property listings. Reports suggest a database of property-visit records was published on a hacking forum, containing approximately 6,000 entries. The exposed data comprised the full names and civility of property visitors and accompanying agents, the real-estate agencies involved, property addresses and cities across France, visit dates and asking prices. No passwords or email addresses were included.
  • Date: 2025
  • Domain: amepi.fr
  • Country: France
  • Category: Real Estate
  • Data: Names Physical Locations Geographic Locations Genders Site Activity Company Information
  • Records: 5,994
  • Lines: 5,993
  • Size: 2.36 MB
  • Passwords: No
Sometime before 2025, ETAI (etai.fr), a French automotive technical-information publisher, allegedly suffered a data breach exposing a directory of subscribing garages and auto-repair businesses. Reports suggest approximately 6,600 records were exposed, with the compromised data including business names, French SIRET registration numbers, postal addresses, contact email addresses, phone numbers, and account passwords stored as SHA-1 hashes.
  • Date: 2025
  • Domain: etai.fr
  • Country: France
  • Category: Automotive
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Company Information
  • Records: 6,619
  • Lines: 6,618
  • Size: 4.16 MB
  • Passwords: SHA-1
  • Cracked: 0%
Sometime before 2025, JSHS (Jet Systems Helicopters Services, jshs.fr) allegedly suffered a data breach. JSHS is a French helicopter charter and aerial services company. Reports suggest a customer database of approximately 4,000 records was exposed, including full names, email addresses, phone numbers, postal addresses, genders and, for business customers, company names and tax (SIRET) identifiers. No passwords were included in the exposed data.
  • Date: 2025
  • Domain: jshs.fr
  • Country: France
  • Category: Logistics & Transportation
  • Data: Email Addresses Names Phone Numbers Geographic Locations Genders Company Information
  • Records: 4,190
  • Lines: 4,190
  • Size: 3.18 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.