Breach Intelligence

6,875

Total breached databases

In early 2026, data belonging to Laboratoire des Pyrénées et des Landes (labos-pyrenees.fr), a French veterinary and analysis laboratory, was allegedly leaked and published on a hacking forum. Reports suggest the exposed records relate to the laboratory's client extranet. Approximately 700 records were allegedly exposed, including email addresses, plaintext extranet passwords, contact names, company names, phone numbers and physical addresses.
  • Date: Mar 23, 2026
  • Domain: labos-pyrenees.fr
  • Threat Actor: Cybernox
  • Country: France
  • Category: Healthcare
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Company Information
  • Records: 716
  • Lines: 715
  • Size: 244.38 KB
  • Passwords: Plaintext
In 2026, WiziShop allegedly suffered a data breach. WiziShop and Dropizi are French e-commerce platforms that help entrepreneurs create and manage online stores. Reports suggest the exposed dataset contained roughly 510,000 store invoice records covering approximately 21,000 merchant stores, including store/company names, physical addresses, and order information. No user passwords were included.
  • Date: 2026
  • Domain: wizishop.com
  • Country: France
  • Category: E-commerce & Retail
  • Data: Email Addresses Physical Locations Geographic Locations Order Information Site Activity Company Information
  • Records: 511,631
  • Lines: 511,630
  • Size: 127.15 MB
  • Passwords: No
In June 2026, the attendee database of Hellfest, the annual heavy metal and rock music festival held in Clisson, France, was allegedly leaked. Reports suggest the data was obtained via a third-party service and made publicly available on a hacking forum. Approximately 1,900 records were allegedly exposed, including email addresses, full names, phone numbers, physical addresses, genders, birthdates and nationalities. No passwords were included.
  • Date: Jun 2026
  • Domain: hellfest.fr
  • Threat Actor: Saturne
  • Country: France
  • Category: Streaming & Entertainment
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Genders Site Activity Birthdates Nationalities
  • Records: 1,887
  • Lines: 1,887
  • Size: 174.05 KB
  • Passwords: No
LBP-TM 2026

LBP-TM 2026

Sensitive
In January 2026, a French consumer marketing database associated with the domain lbp-tm.fr was allegedly leaked. Reports suggest it contained approximately 1.1 million records of parents and expecting families, apparently compiled for maternity and newborn marketing. The exposed information allegedly included full names, salutations, postal addresses, multiple phone numbers, email addresses, and — as family data — children's first names and dates of birth. As the dataset exposes information relating to minors, it is treated as sensitive.
  • Date: Jan 2026
  • Domain: lbp-tm.fr
  • Threat Actor: Saturne
  • Country: France
  • Category: Data Brokers
  • Data: Email Addresses Names Phone Numbers Physical Locations Family Members
  • Records: 1,101,704
  • Lines: 1,101,704
  • Size: 420.1 MB
  • Passwords: ?
Monogram Paris (monogramparis.com), a French personalized-jewelry and accessories e-commerce brand, allegedly suffered a data breach of its customer database. It has been reported that approximately 33,000 customer records were exposed, consisting of email addresses and password hashes. The passwords were stored as a mix of bcrypt and unsalted MD5 hashes, consistent with a PrestaShop-style store that migrated its hashing scheme.
  • Data: Email Addresses Passwords
  • Records: 35,650
  • Lines: 35,650
  • Size: 3.38 MB
  • Passwords: BCrypt, MD5
  • Cracked: 0%
In July 2026, Lions Clubs France (lions-france.org), the French national body of the Lions Clubs volunteer service organisation, allegedly suffered a data breach. Reports suggest a member directory was scraped, exposing over 11,000 members. It has been reported that the compromised data included names, email addresses, phone numbers, birth dates, postal addresses and Lions club affiliations. No passwords were included.
  • Date: Jul 2026
  • Domain: lions-france.org
  • Threat Actor: Saturne
  • Country: France
  • Category: Non-Profit & Charities
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Company Information Birthdates
  • Records: 23,897
  • Lines: 23,897
  • Size: 11.17 MB
  • Passwords: No
Sometime before 2025, Lire Demain (lire-demain.fr), the school and institutional network of the French publisher Éditions Auzou which supplies children's books, kamishibai and educational tools to schools, early-childhood facilities and local authorities, allegedly suffered a data breach. Reports suggest a customer export of roughly 4,600 records was exposed. The compromised data allegedly included the customer institutions' names and addresses, contact email addresses, phone numbers and order information. No passwords were included.
  • Data: Email Addresses Phone Numbers Physical Locations Geographic Locations Company Information
  • Records: 4,613
  • Lines: 4,615
  • Size: 990.02 KB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.