Breach Intelligence

6,875

Total breached databases

In early 2023, the French company Pro Interactive (prointeractive.fr) allegedly suffered a data breach exposing its customer database. Reports suggest approximately 17,700 records were exposed, including email addresses, names, phone numbers, postal codes and account registration dates. No passwords were included.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Genders Site Activity
  • Records: 17,682
  • Lines: 17,683
  • Size: 3.13 MB
  • Passwords: No
In April 2026, Ledil Immobilier (ledil.immo), a French network of independent real estate agents, allegedly suffered a data breach. Reports suggest an export of the platform's search index was taken, exposing approximately 7,000 individuals — property buyers (acquéreurs) and the agency's own agents (mandataires). The compromised data allegedly included email addresses, full names and, for agents, phone numbers. No passwords were included.
  • Date: Apr 2026
  • Domain: ledil.immo
  • Threat Actor: 888
  • Country: France
  • Category: Real Estate
  • Data: Email Addresses Names Phone Numbers Geographic Locations Usernames Languages
  • Records: 7,134
  • Lines: 59,868
  • Size: 43.46 MB
  • Passwords: No
Sometime before 2022, interieur-jour.fr — the online store of Intérieur Jour, an interior-design retailer based in Lens, France running PrestaShop — allegedly suffered a data breach. The exposed dump is partial (truncated before the customer/order tables), yet reports suggest it still exposed the store's address book of approximately 6,400 customer and delivery records. The compromised data allegedly includes names, postal addresses, phone numbers, company details and a handful of email addresses. No password hashes were present in the exposed portion.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Site Activity Company Information
  • Records: 6,411
  • Lines: 103,666
  • Size: 22.66 MB
  • Passwords: No
Sometime before 2025, SOS Oxygène (sos-oxygene.com), a French home healthcare provider specializing in the 24/7 care of patients with respiratory and sleep disorders, allegedly suffered a data breach. Reports suggest a database of approximately 149,000 patient service records was exposed. The exposed information allegedly included patient and technician full names, and — for a subset of records — full postal addresses (street, postal code, and city) with geographic coordinates. A small number of email addresses were also present. As this exposes health-service data on individuals, it is treated as sensitive.
  • Data: Names Physical Locations
  • Records: 148,318
  • Lines: 149,109
  • Size: 48.3 MB
  • Passwords: No
Bureau Vallée (bureau-vallee.fr), a French office-supplies and stationery retail chain, allegedly suffered a data breach of its customer database. It has been reported that approximately 56,000 client records were exposed, including email addresses, individual and business names, phone numbers, physical addresses, French business identifiers (SIRET/SIREN and intra-community VAT numbers), and gender. The records cover both individual (Particulier) and business (Pro) customers.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Government IDs Genders Tax IDs Company Information Birthdates
  • Records: 55,948
  • Lines: 55,948
  • Size: 128.39 MB
  • Passwords: No
In June 2026, the public directory of the Ordre National des Pédicures-Podologues (ONPP), France's national regulatory body for the podiatry profession, hosted at onpp.fr, allegedly suffered a data breach. Reports suggest the professional directory was scraped, exposing approximately 8,000 registered podiatrists. The compromised data allegedly included full names, genders, practice street addresses, postal codes and cities. No passwords or email addresses were included; phone numbers were present only as encrypted tokens.
  • Date: Jun 2026
  • Domain: onpp.fr
  • Threat Actor: Saturne
  • Country: France
  • Category: Healthcare
  • Data: Names Phone Numbers Physical Locations Geographic Locations Genders
  • Records: 8,047
  • Lines: 8,047
  • Size: 2.43 MB
  • Passwords: No
In August 2026, the AEFE (Agence pour l'enseignement français à l'étranger, aefe.fr), the French government agency overseeing the worldwide network of French schools abroad, allegedly suffered a data breach. Reports suggest an attacker gained access to the internal staff directory via the SSO portal and scraped it, along with data from the internal messaging system, exposing approximately 30,000 individuals. It has been reported that the compromised data included names, email addresses, job titles, employing establishments, geographic locations and internal message content. No passwords were included.
  • Date: Aug 11, 2026
  • Domain: aefe.fr
  • Threat Actor: ZeroBytes
  • Country: France
  • Category: Education
  • Data: Email Addresses Names Geographic Locations Websites Messages Job Information Company Information
  • Records: 34,149
  • Lines: 514,360
  • Size: 46.05 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.