Breach Intelligence

6,875

Total breached databases

Sometime before 2023, the UK online retailer MyChoice (mychoice.co.uk), which sold household appliances, allegedly suffered a data breach. Reports suggest the exposed data, comprising customer records and order exports, affected approximately 115,000 individuals. The compromised information allegedly included email addresses, full names, phone numbers, physical and geographic locations, and order details. No passwords were included in the exposed data.
  • Date: 2023
  • Domain: mychoice.co.uk
  • Country: United Kingdom
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Order Information Company Information
  • Records: 208,273
  • Lines: 242,507
  • Size: 59.92 MB
  • Passwords: ?
Sometime before 2016, the University of Greenwich (gre.ac.uk) allegedly suffered a data breach. The University of Greenwich is a public university based in London, United Kingdom. Reports suggest the exposed data originated from a collection of internal databases covering students, staff, external examiners and course management systems. Approximately 22,000 individuals were affected, with exposed records including email addresses, names, usernames, phone numbers, genders, birthdates, geographic locations and passwords stored in plaintext and as SHA-256 hashes.
  • Date: 2016
  • Domain: gre.ac.uk
  • Country: United Kingdom
  • Category: Education
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Genders Birthdates
  • Records: 11,575,459
  • Lines: 12,088,800
  • Size: 1.33 GB
  • Passwords: Plaintext, SHA-256
In September 2024, data allegedly taken from the UK ticketing service Central Tickets (centraltickets.co.uk) was publicly posted to a hacking forum. Central Tickets is a members-only platform offering discounted tickets to theatre and live events. Reports suggest the breach occurred several months earlier, and it has been reported that the exposed data covered roughly 723,000 customers across a larger set of around 2.8 million email addresses. The compromised records reportedly included email addresses, names, phone numbers, IP addresses, device information and order details, alongside passwords stored as unsalted SHA-1 and bcrypt hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Order Information IP Addresses Device Information
  • Records: 32,238,505
  • Lines: 33,028,999
  • Size: 3.24 GB
  • Passwords: SHA-1, BCrypt
  • Cracked: 0%
In March 2024, England Cricket's icoachcricket coaching platform, operated by the England and Wales Cricket Board (ECB), allegedly suffered a data breach. Reports suggest that approximately 43,000 records were exposed, including email addresses and passwords stored as bcrypt or salted MD5 hashes.
  • Data: Email Addresses Passwords
  • Records: 43,388
  • Lines: 43,406
  • Size: 5.45 MB
  • Passwords: BCrypt, MD5 Salted
  • Cracked: 0%
In April 2008 (some reports suggest 2007), the UK online gambling and bingo site Foxy Bingo allegedly suffered a data breach. Reports suggest the exposed records were subsequently sold and traded. This partial dataset contains approximately 292,000 records, including usernames and passwords stored in plaintext.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Usernames Balances Genders Site Activity Birthdates
  • Records: 292,665
  • Lines: 292,680
  • Size: 7.3 MB
  • Passwords: Plaintext
In July 2024, AnimeLeague disclosed a data breach affecting its services. The compromised data was posted for sale on a popular hacking forum and consisted of two databases: one containing event registration records and another comprising a dump of the phpBB bulletin board. Among the exposed information were usernames, private messages, dates of birth, purchase records, and approximately 192,000 unique email addresses. Passwords were stored in various hashed formats, including SHA-1, salted MD5, and bcrypt.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Order Information IP Addresses Site Activity Messages Company Information Birthdates
  • Records: 554,351
  • Lines: 8,995,310
  • Size: 1.02 GB
  • Passwords: BCrypt, MD5, MD5 Salted, SHA-1, SHA-1 Salted
  • Cracked: 0%
In December 2020, UK energy supplier People's Energy (peoplesenergy.co.uk) allegedly suffered a data breach. Reports suggest the incident exposed roughly 7GB of files relating to approximately 359,000 individuals. The exposed data is reported to have included email addresses, names, phone numbers, physical addresses, dates of birth and genders, along with a smaller set of staff email addresses and BCrypt password hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Genders Birthdates
  • Records: 3,885,698
  • Lines: 8,076,400
  • Size: 6.79 GB
  • Passwords: BCrypt
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.