Breach Intelligence

6,875

Total breached databases

Sometime before 2024, GoldQuest Global (goldquestglobal.in), an Indian employee background-verification and screening services provider, allegedly suffered a data breach. Reports suggest the exposed database contained records of roughly 12,000 individuals undergoing background checks, including names, email addresses, phone numbers, residential addresses, employer/company names and the positions they applied for. No passwords were included.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Job Information Company Information
  • Records: 91,726
  • Lines: 228,213
  • Size: 75.42 MB
  • Passwords: No
In August 2024, Cyepro, an Indian software solutions company specializing in business process automation, data management, and software development, experienced a data breach. The incident reportedly exposed at least 100,410 records. Among the compromised data were names, email addresses, phone numbers, and geographic locations.
  • Date: Aug 2024
  • Domain: cyepro.com
  • Country: India
  • Category: Automotive
  • Data: Email Addresses Names Phone Numbers Geographic Locations Genders Job Information Company Information Birthdates
  • Records: 167,930
  • Lines: 993,709
  • Size: 295.93 MB
  • Passwords: No
A marketing/broadcast recipient list attributed to Accenture (accenture.com) was allegedly leaked. It has been reported that approximately 33,000 records were exposed, consisting of email addresses and full names tagged with an internal broadcast campaign label. The recipient addresses are overwhelmingly Indian consumer email accounts (Gmail, Yahoo India, Rediffmail), indicating an India-focused mailing list rather than Accenture employee data. No passwords were included.
  • Data: Email Addresses Names
  • Records: 32,826
  • Lines: 32,827
  • Size: 2.33 MB
  • Passwords: No
Sometime before 2021, LaakBot (laakbot.com), a mobile-app development company behind food-delivery and grocery apps, allegedly suffered a data breach. Reports suggest a dump of its development databases (spanning apps such as EaterShop and BuyGros) exposing several hundred customer, business-owner and administrator records, including email addresses, names, phone numbers, addresses, dates of birth, Social Security numbers, company details and plaintext passwords.
  • Date: 2021
  • Domain: laakbot.com
  • Country: India
  • Category: Technology
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Government IDs Social Security Numbers Company Information Birthdates
  • Records: 297
  • Lines: 7,986
  • Size: 613.54 KB
  • Passwords: Plaintext
Sometime before 2020, EaterShop (eatershop.com), a campus food and grocery-delivery mobile app, allegedly suffered a data breach. Reports suggest a backend database dump exposing several hundred customer, business-owner and administrator records, including email addresses, names, phone numbers, addresses, dates of birth, Social Security numbers, company details and plaintext passwords.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Government IDs Social Security Numbers Company Information Birthdates
  • Records: 191
  • Lines: 6,661
  • Size: 535.69 KB
  • Passwords: Plaintext
Sometime before 2023, a study-visa and immigration consultancy website based in Punjab, India (catalogued as aws-ec2.mysql.in) allegedly suffered a data breach. Reports suggest a residual database export was exposed, affecting approximately 5,000 records. The exposed data allegedly included names, email addresses, phone numbers, website enquiry submissions, and an administrator password stored in plaintext. A large share of the records originate from spam submissions to the site's public enquiry form.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Site Activity
  • Records: 4,967
  • Lines: 5,420
  • Size: 1.37 MB
  • Passwords: Plaintext
In February 2023, bollynest.me, a Bollywood/Hindi movie-download WordPress blog operating under the name "Tech4u", allegedly suffered a data breach of its database. Reports suggest the exposed WordPress data was limited in scope, centred on the site's single administrator account. The compromised data allegedly includes an email address, username, website, site activity and a password stored as a phpass hash.
  • Data: Email Addresses Passwords Usernames Site Activity Websites
  • Records: 7
  • Lines: 16,657
  • Size: 3.58 MB
  • Passwords: PHPass
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.