Breach Intelligence

6,875

Total breached databases

In May 2022, ipaidabribe.com allegedly suffered a data breach. ipaidabribe.com is an Indian anti-corruption initiative by the non-profit Janaagraha, where citizens report incidents of bribery. Reports suggest the breach exposed approximately 8,500 individuals. The compromised data allegedly included email addresses, names, usernames, phone numbers, IP addresses, geographic locations, websites, site activity, and hashed passwords (MD5, MD5Crypt and PHPass).
  • Date: May 19, 2022
  • Domain: ipaidabribe.com
  • Threat Actor: Chucky
  • Country: India
  • Category: Non-Profit & Charities
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames IP Addresses Site Activity Websites
  • Records: 52,492
  • Lines: 8,494,311
  • Size: 1.95 GB
  • Passwords: MD5, MD5Crypt, PHPass
  • Cracked: 0%
In early 2023, the Institute of Professional Banking (ipbindia.com) allegedly suffered a data breach. IPB is an Indian vocational training institute offering post-graduate banking and finance certification courses across multiple centres in India. Reports suggest that a database backup exposing roughly 14,000 individuals was compromised, including email addresses, names, phone numbers, birthdates, genders, geographic locations, usernames, IP addresses, company information, and passwords stored as PHPass and SHA-1 hashes.
  • Date: Feb 2023
  • Domain: ipbindia.com
  • Country: India
  • Category: Education
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Genders IP Addresses Site Activity Websites Company Information Birthdates
  • Records: 42,756
  • Lines: 990,530
  • Size: 201.84 MB
  • Passwords: PHPass, SHA-1
  • Cracked: 0%
Sometime before 2022, IndiaToHome (indiatohome.com) allegedly suffered a data breach. IndiaToHome is a small online store built on the PrestaShop e-commerce platform. Reports suggest a small number of records were exposed, including approximately 16 email addresses along with names, a birthdate, genders, site activity data, and passwords stored as BCrypt and MD5 hashes.
  • Data: Email Addresses Passwords Names Genders Site Activity Birthdates
  • Records: 18
  • Lines: 16,858
  • Size: 6.37 MB
  • Passwords: BCrypt, MD5
  • Cracked: 0%
Sometime before 2023, the Indian logistics platform Hypertech Logistics (hypertechlogistics.com) allegedly suffered a data breach. Hypertech Logistics is a business-to-business freight and transport platform that connects industries with transporters for shipment bidding and order management. It has been reported that the exposed database contained approximately 5,900 records. The compromised data reportedly included email addresses, names, phone numbers, geographic locations, company information, government identification numbers, bank account details, and passwords stored as bcrypt hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Bank Account Information Government IDs Company Information
  • Records: 5,886
  • Lines: 297,734
  • Size: 64.19 MB
  • Passwords: BCrypt
  • Cracked: 0%
Sometime before 2022, the Indian data-intelligence platform HowIndiaLives (howindialives.com) allegedly suffered a data breach. HowIndiaLives is a data-journalism and public-data company that maintains a searchable subscription database of India's socioeconomic and government data. It has been reported that the exposed data affected approximately 6,600 individuals and included email addresses, usernames, names, phone numbers, company information, geographic locations, and passwords stored as BCrypt, MD5, and PHPass hashes.
  • Data: Email Addresses Passwords Phone Numbers Geographic Locations Usernames Company Information
  • Records: 13,312
  • Lines: 8,123,407
  • Size: 739.83 MB
  • Passwords: BCrypt, MD5, PHPass
  • Cracked: 0%
In 2022, HostingPapa (hostingpapa.in), an Indian web hosting and reseller hosting provider, allegedly suffered a data breach in which a full database dump was exposed. Reports suggest the compromised data contained records relating to approximately 500 individuals, including email addresses, names, phone numbers, physical addresses, usernames, government IDs, IP addresses, company information, and passwords stored as bcrypt, phpass, and MD5 hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs IP Addresses Site Activity Websites Company Information
  • Records: 10,172
  • Lines: 474,126
  • Size: 117.49 MB
  • Passwords: BCrypt, MD5, PHPass
  • Cracked: 0%
In February 2023, HashTech India, an Indian web-development and software company based in Tamil Nadu, allegedly suffered a data breach when a database dump of its hosting server was leaked. Reports suggest the export bundled dozens of client application databases — spanning matrimony and CRM platforms, a solar-installation programme, and other services — exposing approximately 208,000 records. The exposed data allegedly included email addresses, names, phone numbers, usernames, dates of birth, gender, geographic locations, family member names, job and company information, health details, IP addresses, and passwords stored as plaintext, MD5, and PHPass hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Financial Information Family Members Health Information Genders IP Addresses Websites Job Information Company Information Birthdates
  • Records: 208,380
  • Lines: 729,733
  • Size: 2.67 GB
  • Passwords: Plaintext, MD5, PHPass, Unknown

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.