Breach Intelligence

6,871

Total breached databases

In 2023, the Indian career and campus-recruitment platform Triedge (triedge.in) allegedly suffered a data breach. Triedge connects students and recent graduates in India with internships, training and job opportunities. Reports suggest the exposed data covered approximately 160,000 individuals and included email addresses, names, phone numbers, geographic locations, genders, birthdates, IP addresses, site-activity timestamps, and MD5-hashed passwords.
  • Date: 2023
  • Domain: triedge.in
  • Country: India
  • Category: Education
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Genders IP Addresses Site Activity Birthdates
  • Records: 1,247,585
  • Lines: 7,077,887
  • Size: 1.74 GB
  • Passwords: MD5
  • Cracked: 0%
In January 2025, the Alumni & Corporate Relations portal of the Indian Institute of Technology Madras (acr.iitm.ac.in) allegedly suffered a data breach. Reports suggest a full database dump was leaked, exposing records on roughly 200,000 alumni and associated individuals across hundreds of tables. The compromised data reportedly included names, email addresses, phone numbers, physical addresses, employers and job titles, usernames, and account passwords (phpass hashes and some base64-encoded plaintext).
  • Date: Jan 21, 2025
  • Domain: acr.iitm.ac.in
  • Threat Actor: W1ndStre4m
  • Country: India
  • Category: Education
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Websites Job Information Company Information
  • Records: 242,273
  • Lines: 12,136,504
  • Size: 1.61 GB
  • Passwords: PHPass, Plaintext
In 2024, a threat actor known as Satanic leaked a database of roughly 4.6 million user accounts, published under the name ACC Limited (acclimited.com). The exported data has the schema of an Indian video-streaming / OTT application (subscription plans, connected devices such as Roku, Firestick and Chromecast, and parental controls). The exposed data reportedly included around 4.57 million unique email addresses, along with mobile numbers, names, dates of birth, genders, short bios and bcrypt-hashed passwords.
  • Date: 2024
  • Domain: acclimited.com
  • Threat Actor: Satanic
  • Country: India
  • Category: Industry
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Genders Site Activity Birthdates Bios
  • Records: 4,624,530
  • Lines: 4,624,554
  • Size: 1.22 GB
  • Passwords: BCrypt
  • Cracked: 0%
In July 2025, TuteeHub (tuteehub.com), an Indian ed-tech and online exam-preparation platform, allegedly had the subscriber lists from its MailWizz email-marketing system leaked. Reports suggest approximately 300,000 individuals were exposed, including email addresses and, for some records, names, geographic locations and IP addresses. No passwords were included.
  • Date: Jul 4, 2025
  • Domain: tuteehub.com
  • Country: India
  • Category: Education
  • Data: Email Addresses Names Geographic Locations IP Addresses
  • Records: 303,450
  • Lines: 2,375,382
  • Size: 332.72 MB
  • Passwords: No
In 2023, a large database associated with the Indian IT and business-consulting firm Actiknow (actiknow.com) was allegedly leaked. The dump appears to be a multi-application hosting backup containing dozens of the company's client applications, so its structure was highly heterogeneous. Reports suggest it exposed personal data including email addresses, names, phone numbers, physical and geographic locations, and job/company information; roughly 33,000 unique email addresses were recovered.
  • Date: 2023
  • Domain: actiknow.com
  • Country: India
  • Category: Professional & Corporate
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Job Information Company Information
  • Records: 32,818
  • Lines: 5,533,081
  • Size: 3.52 GB
  • Passwords: No
Sometime before 2025, Niobooks (niobooks.in), an Indian accounting and invoicing SaaS platform for small businesses, allegedly suffered a data breach. Reports suggest the exposed PostgreSQL dump contained approximately 500 account holders alongside business records, including email addresses, names, phone numbers, company details, PAN and GST tax identifiers, bank account information, and bcrypt-hashed administrator passwords.
  • Date: 2025
  • Domain: niobooks.in
  • Country: India
  • Category: Finance & Payments
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Bank Account Information Payment Information Government IDs Websites Company Information
  • Records: 771,300
  • Lines: 10,405,304
  • Size: 4.24 GB
  • Passwords: Bcrypt
  • Cracked: 0%
Sometime before 2023, Sunsky India (sunskyindia.com), an Indian cable-TV and broadband software provider, allegedly suffered a data breach. Reports suggest the exposed SQL dump contained approximately 47,000 individuals — largely National Apprenticeship Promotion Scheme (NAPS) candidate records — including email addresses, names, phone numbers, genders, geographic locations, educational qualifications, and plaintext passwords.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Genders Company Information Birthdates Education
  • Records: 156,098
  • Lines: 10,252,628
  • Size: 2.4 GB
  • Passwords: Plaintext

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.