Breach Intelligence

6,874

Total breached databases

In May 2024, a data leak occurred from the Tamil Nadu Police Facial Recognition Portal (frs.tnpolice.gov.in), affecting 896,391 records. The breach included approximately 37k unique emails, as well as ages, genders, government issued IDs, names, police station details, phone numbers, physical addresses, and usernames. The data breach was executed by the user known as Valerie.
  • Date: May 2024
  • Domain: frs.tnpolice.gov.in
  • Threat Actor: Valerie
  • Country: India
  • Category: Law Enforcement
  • Data: Email Addresses Names Phone Numbers Physical Locations Usernames Government IDs Genders Ages
  • Records: 158,178
  • Lines: 249,169
  • Size: 19.01 MB
  • Passwords: No
In 2023, Pratham Institute, a non-profit organization in India focused on education and skills development for underserved communities, allegedly experienced a data breach. Reports suggest the breach exposed information on approximately 300,000 users. Among the compromised data were names, mobile numbers, email addresses, educational details, and school names. Passwords were stored as MD5 and bcrypt hashes.
  • Date: 2023
  • Domain: iifm.co.in
  • Country: India
  • Category: Education
  • Data: Email Addresses Passwords Names Phone Numbers IP Addresses Profile Photos Education Personal Information
  • Records: 928,717
  • Lines: 13,723,030
  • Size: 3.76 GB
  • Passwords: BCrypt, MD5
  • Cracked: 0%
In November 2024, Sharan-India, a prominent Indian health company, experienced a data breach affecting 240,000 users. The breach was carried out by users IntelBroker and EnergyWeaponUser. Compromised data includes a variety of personal and contact information such as names, addresses, phone numbers, company affiliations, email addresses, and usernames. Sharan-India is a known entity providing health-related services in India.
  • Date: Nov 2024
  • Domain: sharan-india.org
  • Threat Actor: IntelBroker, EnergyWeaponUser
  • Country: India
  • Category: Healthcare
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Usernames Job Information Personal Information
  • Records: 117,667
  • Lines: 290,950
  • Size: 26.73 MB
  • Passwords: No
Sometime before 2023, Vortexnetsol.com, an Indian internet service provider operating RADIUS-based broadband infrastructure, allegedly suffered a data breach. Reports suggest the exposed database contained session accounting records for approximately 15,500 subscribers, including usernames, assigned IP addresses, MAC addresses, and session timestamps.
  • Data: The data categories affected by the Vortexnetsol.com 2023 breach have not been disclosed yet. We will expand this section when details are released.
  • Records: 20,747,395
  • Lines: 12,687,382
  • Size: 2.64 GB
  • Passwords: ?
On April 13, 2021, Hopponworks.com, a food ordering app primarily used in India, reportedly suffered a data breach affecting approximately 49,293 users. Among the compromised data were email addresses, usernames, and passwords, which were stored in plaintext but encoded in base64.
  • Data: Email Addresses Passwords Usernames
  • Records: 49,089
  • Lines: 49,092
  • Size: 12.76 MB
  • Passwords: Plaintext
In November 2022, the Indian tender-search service TenderMines (tendermines.com) allegedly suffered a data breach. Reports suggest the exposed database contained approximately 73,000 individuals' records, including email addresses, full names, phone numbers, physical addresses, tax IDs (PAN), government IDs (Aadhaar) and company details, alongside a small number of mostly plaintext account passwords.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Government IDs Tax IDs Company Information
  • Records: 82,773
  • Lines: 228,499
  • Size: 33.33 MB
  • Passwords: Plaintext, BCrypt, MD5, SHA-1
In April 2024, the Indian digital learning platform Quest App allegedly suffered a data breach that was subsequently published on a hacking forum. Reports suggest the data of approximately 694,000 users was exposed, including email addresses, names, phone numbers, dates of birth, genders, marital statuses, site activity and passwords stored as MD5 and bcrypt hashes.
  • Date: Apr 2024
  • Domain: questapp.in
  • Threat Actor: DevEye
  • Country: India
  • Category: Education
  • Data: Email Addresses Passwords Names Phone Numbers Marital Statuses Genders Site Activity Birthdates
  • Records: 723,076
  • Lines: 1,540,696
  • Size: 602.94 MB
  • Passwords: BCrypt, MD5
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.