Breach Intelligence

6,875

Total breached databases

In September 2026, the French telematics and fleet-management provider Ekolis (ekolis-eu.com) allegedly suffered a data breach. Ekolis supplies connected-device and telematics solutions for the trucking and logistics industry. Reports suggest the incident was carried out by an actor using the handle 4me1 and exposed data on approximately 25,000 individuals across several exported files. The exposed data allegedly included names, email addresses, usernames, job and department information, physical addresses, employer/carrier names, and associated vehicle and location records.
  • Date: Sep 5, 2026
  • Domain: ekolis-eu.com
  • Threat Actor: 4me1
  • Country: France
  • Category: Logistics & Transportation
  • Data: Email Addresses Names Physical Locations Geographic Locations Usernames Site Activity Job Information Company Information Vehicle Information
  • Records: 30,037
  • Lines: 5,383
  • Size: 1.16 MB
  • Passwords: No
Sometime before September 2026, the French company Vision2i (vision2i.fr) allegedly suffered a data breach. Reports suggest the exposed data originated from the site's WordPress database, including its user accounts and email-subscriber contacts. It has been reported that approximately 10 individuals were affected, with the leaked data including email addresses, names, usernames, and hashed passwords (PHPass).
  • Date: Sep 2026
  • Domain: vision2i.fr
  • Threat Actor: Sophia
  • Country: France
  • Category: Professional & Corporate
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Site Activity
  • Records: 10
  • Lines: 15,804
  • Size: 72.31 MB
  • Passwords: PHPass
  • Cracked: 0%
In 2026, the French online doctor directory MedecinFrance (medecinfrance.com) allegedly had its database scraped and published. MedecinFrance is a public directory listing physicians practicing in France. It has been reported that around 74,000 practitioner records were exposed. The exposed data allegedly includes doctors' names, medical specialties, practice addresses and postal codes, phone numbers and public profile URLs. No passwords or account credentials were included.
  • Date: 2026
  • Domain: medecinfrance.com
  • Threat Actor: cyberjuif
  • Country: France
  • Category: Healthcare
  • Data: Names Phone Numbers Physical Locations Geographic Locations Websites Job Information
  • Records: 74,486
  • Lines: 670,375
  • Size: 23.07 MB
  • Passwords: No
Sometime before 2025, Ma Boutique Chrétienne (maboutiquechretienne.com), a French Christian online store selling books, media, clothing and religious objects (operated by Les Éditions Bethesda), allegedly suffered a data breach. Reports suggest a PrestaShop database of approximately 2,800 customers was exposed. The exposed data reportedly included email addresses, names, phone numbers, postal addresses, genders, IP addresses and bcrypt- and MD5-hashed passwords.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Genders IP Addresses Site Activity
  • Records: 3,297
  • Lines: 143,112
  • Size: 81.65 MB
  • Passwords: BCrypt, MD5
  • Cracked: 0%
In August 2026, the French land-surveying geoportal Geofoncier (geofoncier.fr) allegedly suffered a data breach. Geofoncier is the national platform used by France's licensed land surveyors (géomètres-experts) to catalog surveying deeds and professional records. It has been reported that an authenticated account with API access was used to extract the dataset, which reportedly comprises approximately 4.2 million records. The exposed data allegedly includes names, email addresses, phone numbers, physical and geographic locations, genders, and company information for surveyors, offices, and firms.
  • Date: Aug 30, 2026
  • Domain: geofoncier.fr
  • Threat Actor: ZeroBytes
  • Country: France
  • Category: Real Estate
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Genders Company Information
  • Records: 4,226,008
  • Lines: 4,226,008
  • Size: 6.48 GB
  • Passwords: No
Sometime before 2026, the French real-estate developer Valraiso (valraiso.fr) allegedly suffered a data breach. Reports suggest the exposed customer database contained approximately 1,100 records, including first and last names, email addresses, and mobile phone numbers. No passwords were included in the exposed data.
  • Date: 2025
  • Domain: valraiso.fr
  • Country: France
  • Category: Others
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations
  • Records: 1,094
  • Lines: 1,094
  • Size: 60.6 KB
  • Passwords: No
Sometime before 2025, bdsmsutra.com, a French-language BDSM and fetish dating/community website, allegedly suffered a data breach. Reports suggest approximately 31,000 records were exposed, including email addresses, member names, and MD5-hashed passwords.
  • Data: Email Addresses Passwords Names Site Activity
  • Records: 31,252
  • Lines: 31,258
  • Size: 5.58 MB
  • Passwords: MD5
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.