Breach Intelligence

6,875

Total breached databases

In 2016, the website mylloyd.com, a customer account portal associated with the Indian consumer-electronics brand Lloyd, allegedly suffered a data breach via SQL injection. Reports suggest approximately 30,000 accounts were exposed, including email addresses and plaintext passwords.
  • Date: Aug 23, 2016
  • Domain: mylloyd.com
  • Country: India
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords
  • Records: 30,698
  • Lines: 30,739
  • Size: 990.03 KB
  • Passwords: Plaintext
In 2015, keralapulayamatrimony.com, an Indian Joomla-based matrimonial matchmaking site serving the Pulaya/Cheramar community in Kerala, allegedly suffered a data breach. Reports suggest approximately 750 individuals were exposed, including names, gender, religion, physical addresses, phone numbers, email addresses, and a mix of plaintext and MD5-hashed passwords.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Genders Religions Site Activity Ethnicities
  • Records: 753
  • Lines: 7,439
  • Size: 777.34 KB
  • Passwords: Plaintext, MD5
In November 2020, Pluss.in, an Indian online plus-size clothing retailer, allegedly suffered a data breach as part of the Cit0day breach collection. Reports suggest approximately 25,000 individuals were exposed, including email addresses, MD5-hashed passwords, names, phone numbers, geographic locations, usernames, IP addresses, and birthdates.
  • Date: 2022
  • Domain: pluss.in
  • Country: India
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames IP Addresses Site Activity Birthdates
  • Records: 30,645
  • Lines: 476,616
  • Size: 107.88 MB
  • Passwords: MD5
  • Cracked: 0%
In 2023, a database belonging to the Institute of Company Secretaries of India (ICSI, icsi.edu) was allegedly leaked and shared on a hacking forum. The ICSI is the statutory professional body that regulates and certifies company secretaries in India. Reports suggest the breach exposed approximately 200,000 student registration records, along with a set of internal Active Directory account credentials. The compromised data allegedly included full names, email addresses, telephone numbers, postal addresses, genders and dates of birth.
  • Date: 2023
  • Domain: icsi.edu
  • Country: India
  • Category: Education
  • Data: Names Email Addresses Phone Numbers Physical Locations Geographic Locations Genders Birthdates Usernames Passwords
  • Records: 202,128
  • Lines: 202,271
  • Size: 162.03 MB
  • Passwords: NTLM
  • Cracked: 0%
In June 2023, the Indian online crafts and gifts store Excellentcrafts.in allegedly suffered a data breach exposing a Magento customer export. Reports suggest the file contained approximately 20,000 customer records, the majority of which were spam-bot registrations carrying only an email address; the genuine customer accounts additionally included full names, phone numbers, physical addresses, and account creation dates. No passwords were included in the exposed data.
  • Date: Jun 30, 2023
  • Domain: excellentcrafts.in
  • Threat Actor: Cosmmin
  • Country: India
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Government IDs Genders Site Activity Tax IDs Company Information Birthdates
  • Records: 19,733
  • Lines: 19,878
  • Size: 4.58 MB
  • Passwords: No
Sometime before 2019, the Indian industrial-products and scrap-metal company Variety Enterprise (varietyenterprise.in) allegedly suffered a data breach that was later published on a hacking forum. Reports suggest the exposed dataset was very small and contained an administrator account alongside a recruitment contact address. The compromised data allegedly included a username, a name, a plaintext password, an email address and geographic location details.
  • Date: 2019
  • Domain: varietyenterprise.in
  • Threat Actor: MER.DAXXEFTS
  • Country: India
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Geographic Locations Usernames
  • Records: 3
  • Lines: 10
  • Size: 8.73 KB
  • Passwords: Plaintext
Sometime before September 2022, a company database belonging to The Institute of Cost Accountants of India (ICMAI, icmai.in) was allegedly leaked and circulated on underground forums. ICMAI is a statutory professional accountancy body in India that trains and certifies cost and management accountants. It has been reported that a 739-line company_database export was extracted, cataloguing organisations registered to offer training to CMA candidates. The dataset contains approximately 700 records, including company names, contact-person names, email addresses, phone numbers, postal addresses, and job/training information. No passwords were included.
  • Date: 2022
  • Domain: icmai.in
  • Threat Actor: Ribel
  • Country: India
  • Category: Professional & Corporate
  • Data: Email Addresses Names Phone Numbers Geographic Locations Job Information Company Information
  • Records: 736
  • Lines: 738
  • Size: 279.98 KB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.