Breach Intelligence

6,875

Total breached databases

Sometime in or before 2023, the French holiday-rental platform MediaVacances (mediavacances.com), which lists apartments, houses and cottages for holiday stays, allegedly suffered a data breach. The exposed dataset consisted of around 256,000 customer invoices. Reports suggest the invoices contained customer names, postal addresses, invoice/order details, and payment method information. No passwords were included.
  • Data: Names Geographic Locations Payment Information Order Information Site Activity
  • Records: 256,776
  • Lines: 256,778
  • Size: 188.29 MB
  • Passwords: No
Sometime before 2025, the French student-housing rental platform Adele.org allegedly suffered a data breach exposing tenant rental-application files (dossiers). Reports suggest that data belonging to more than 260,000 individuals — applicants together with their co-applicants and guarantors — was exposed. The compromised information reportedly included full names, email addresses, phone numbers, postal addresses, nationalities and, according to the threat actor, scanned identity documents such as national ID cards, passports and health cards. No passwords were included in the exposed data.
  • Date: 2025
  • Domain: adele.org
  • Country: France
  • Category: Real Estate
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Government IDs Health Information Genders Nationalities
  • Records: 418,013
  • Lines: 233,012
  • Size: 220.36 MB
  • Passwords: No
Sometime before 2025, data associated with the French national health agency Agence Régionale de Santé (ARS) was allegedly exposed. Reports suggest the data was a registry of approximately 233,000 French healthcare establishments and legal entities, derived from the FINESS directory. The compromised information reportedly included organisation names, French business registry identifiers (SIREN), business activity codes, postal addresses, switchboard phone numbers and, for some entries, contact email addresses. No passwords were included in the exposed data.
  • Date: 2025
  • Domain: ars.sante.fr
  • Country: France
  • Category: Healthcare
  • Data: Email Addresses Phone Numbers Physical Locations Geographic Locations Site Activity Tax IDs Company Information
  • Records: 233,837
  • Lines: 233,836
  • Size: 133 MB
  • Passwords: No
In May 2026, Woop (woopit.fr), a French B2B SaaS platform for last-mile delivery orchestration and logistics, allegedly suffered a data breach. Reports suggest the exposed database contained approximately 256,000 records of delivery customers. The compromised data allegedly included email addresses, names, phone numbers, and physical delivery addresses.
  • Date: May 2026
  • Domain: woopit.fr
  • Threat Actor: moxzey
  • Country: France
  • Category: Logistics & Transportation
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations
  • Records: 256,318
  • Lines: 256,318
  • Size: 23.38 MB
  • Passwords: No
In February 2026, Semitour Périgord, a French operator of tourist and heritage sites, allegedly had customer data exposed following a RansomHouse ransomware attack. The exposed records originated from the Irec Sas (irec.fr) ticketing platform used by the operator. Reports suggest the data affected approximately 148,000 customers, with records spanning from 2014 to early 2025. It has been reported that the compromised information included email addresses, full names, phone numbers, physical addresses, and company details. No passwords were exposed.
  • Date: Feb 2026
  • Domain: semitour.com
  • Threat Actor: RansomHouse
  • Country: France
  • Category: Travel
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Site Activity Company Information Birthdates
  • Records: 148,240
  • Lines: 148,240
  • Size: 33.1 MB
  • Passwords: No
In 2025, the French real-estate and student-housing group Nemea (nemea-groupe.com) allegedly suffered a data breach. Nemea operates residence and apartment-hotel brands across France. Reports suggest the breach exposed a large tenant and client database affecting approximately 280,000 individuals. The compromised data allegedly included names, email addresses, phone numbers, physical addresses, birthdates, genders, government-issued identity documents, company information, and plaintext passwords.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Government IDs Genders Company Information Birthdates
  • Records: 283,809
  • Lines: 342,765
  • Size: 154.11 MB
  • Passwords: Plaintext
Sometime in or before 2023, the French professional directory Mediamatis (mediamatis.com) allegedly suffered a data breach. Mediamatis operated a B2B platform connecting wealth-management advisers with product and service suppliers. Reports suggest data belonging to approximately 8,000 individuals was exposed, including email addresses, names, usernames, phone numbers, geographic locations, IP addresses, job information, social profiles, and passwords stored as BCrypt, PHPass, MD5, and salted MD5 hashes.
  • Date: 2023
  • Domain: mediamatis.com
  • Country: France
  • Category: Professional & Corporate
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames IP Addresses Site Activity Social Profiles Job Information
  • Records: 16,468
  • Lines: 809,039
  • Size: 200.57 MB
  • Passwords: BCrypt, MD5, MD5 Salted, PHPass
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.