Breach Intelligence

6,873

Total breached databases

In July 2025, a threat actor known as Satanic allegedly published the full database of Anudip Foundation (anudip.org), an Indian non-profit that provides digital and technology skills training to underserved youth. Reports suggest the exposed data covered approximately 106,000 student enrollment records, including full names, email addresses, phone numbers, dates of birth, physical addresses, government identity numbers (PAN/Aadhaar), gender, marital status, religion and employment details. No passwords were included.
  • Date: Jul 2025
  • Domain: anudip.org
  • Threat Actor: Satanic
  • Country: India
  • Category: Education
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Government IDs Marital Statuses Relationship Statuses Genders Religions Job Information Company Information Birthdates Nationalities
  • Records: 106,055
  • Lines: 116,385
  • Size: 47.71 MB
  • Passwords: No
Trell (trell.co) is an Indian social lifestyle and short-video sharing platform. It has been alleged that user data from the platform was exposed in a data breach. Reports suggest approximately 333,000 accounts were affected, with data including email addresses and plaintext passwords.
  • Domain: trell.co
  • Country: India
  • Category: Social Media & Communication
  • Data: Email Addresses Passwords
  • Records: 332,961
  • Lines: 333,017
  • Size: 10.96 MB
  • Passwords: Plaintext
hmps.in is associated with an online community for chartered accountants and other professionals in India. The site has allegedly suffered a data breach, with reports indicating that approximately 126,000 user records were exposed, including email addresses and passwords.
  • Date: 2019
  • Domain: hmps.in
  • Country: India
  • Category: Professional & Corporate
  • Data: Email Addresses Passwords
  • Records: 146,286
  • Lines: 146,288
  • Size: 4.87 MB
  • Passwords: Plaintext
Sometime before 2022, the TVS Motor dealer and roadside-assistance CRM operated at tvsmdealers.co.in allegedly suffered a data breach. The platform managed two-wheeler dealer accounts and vehicle roadside-assistance and insurance policies across India. Reports suggest that data on approximately 750,000 individuals was exposed, including names, email addresses, phone numbers, birthdates, genders, geographic locations, company information, government identifiers and MD5-hashed passwords.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Government IDs Genders Company Information Birthdates
  • Records: 771,972
  • Lines: 3,046,663
  • Size: 1.3 GB
  • Passwords: MD5
  • Cracked: 0%
Sometime before 2022, olx.in — an Indian insurance point-of-sale (POSP) and dealer/agent management platform (GIIB/MyPOS) — allegedly suffered a data breach. Reports suggest data on approximately 55,000 individuals was exposed, including email addresses, MD5-hashed passwords, usernames, names, mobile phone numbers, geographic locations, birthdates, genders, government IDs (Aadhaar/PAN), bank account information and company details.
  • Date: 2022
  • Domain: olx.in
  • Country: India
  • Category: Finance & Payments
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Bank Account Information Government IDs Genders Site Activity Company Information Birthdates
  • Records: 55,349
  • Lines: 263,525
  • Size: 47.87 MB
  • Passwords: MD5
  • Cracked: 0%
In 2023, masteracademyindia.co.in, an Indian education/coaching academy running a WordPress website, allegedly had a portion of its data exposed. Reports suggest a small number of records were affected — around 40 individuals — including email addresses, names and IP addresses of site commenters, and a store administrator account with a phpass-hashed password.
  • Data: Email Addresses Passwords Names Geographic Locations Usernames IP Addresses Site Activity Websites
  • Records: 52
  • Lines: 24,263
  • Size: 29.69 MB
  • Passwords: PHPass
  • Cracked: 0%
Sometime before 2022, MyMFNow (mymfnow.com), an Indian mutual-fund distribution platform, allegedly suffered a data breach. It has been reported that the exposed database contained roughly 1,700 individuals. Reports suggest the compromised data included names, email addresses, mobile numbers, MD5 password hashes, postal addresses, dates of birth, genders, PAN and Aadhaar identification numbers, and mutual-fund folio and bank details.
  • Date: 2022
  • Domain: mymfnow.com
  • Country: India
  • Category: Finance & Payments
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Government IDs Genders Birthdates
  • Records: 1,863
  • Lines: 177,544
  • Size: 137.3 MB
  • Passwords: MD5
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.