Breach Intelligence

6,875

Total breached databases

In December 2023, the P2P lending platform LenDenClub in India experienced a data breach. Reports suggest that the breach affected approximately 22 million users. Among the compromised data were unique email addresses, dates of birth, genders, marital statuses, names, occupations, phone numbers, physical addresses, religions, spoken languages, and unknown hash type passwords.
  • Date: Dec 2023
  • Domain: lendenclub.com
  • Threat Actor: KryptonZambie
  • Country: India
  • Category: Finance & Payments
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Genders Marital Statuses Religions Birthdates Job Information Site Activity Languages Device Information
  • Records: 22,284,018
  • Lines: 22,260,023
  • Size: 7.71 GB
  • Passwords: Unknown
In September 2013, the Indian bookings website known as Yatra had 5 million records exposed in a data breach. The data contained email and physical addresses, dates of birth and phone numbers along with both PINs and passwords stored in plain text. The site was previously reported as compromised on the Vigilante.pw breached database directory.
  • Data: Birthdates Email Addresses Names Passwords Phone Numbers Physical Locations Security Credentials
  • Records: 10,981,412
  • Lines: 10,984,489
  • Size: 883.64 MB
  • Passwords: Plaintext
In July 2018, the Indian self-drive car rental company Zoomcar suffered a data breach which was subsequently sold on a dark web marketplace in 2020. The breach exposed over 3.5M records including names, email and IP addresses, phone numbers and passwords stored as bcrypt hashes.
  • Data: Email Addresses IP Addresses Names Passwords Phone Numbers
  • Records: 3,589,906
  • Lines: 3,589,911
  • Size: 391.11 MB
  • Passwords: BCrypt
  • Cracked: 0%
In approximately December 2022, the Indian train ticket platform RailYatri suffered a data breach that included 31 million entries. The attack led to the exposure of data including Email addresses, Full names, Genders, Phone numbers and Locations.
  • Data: Email Addresses Genders Geographic Locations Names Phone Numbers
  • Records: 31,062,529
  • Lines: 31,062,672
  • Size: 12.12 GB
  • Passwords: No
In September 2017, Moneycontrol, an online Indian financial platform, allegedly suffered a data breach. The incident reportedly exposed 763,000 unique email addresses, said to be a subset of a larger breach affecting around 40 million accounts. Among the compromised data were geographic locations, phone numbers, genders, dates of birth, and passwords stored in plain text.
  • Data: Email Addresses Genders Geographic Locations Passwords Phone Numbers
  • Records: 773,807
  • Lines: 773,811
  • Size: 69.42 MB
  • Passwords: Plaintext
In May 2015, the Indian motoring website known as Gaadi had 4.3 million records exposed in a data breach. The data contained usernames, email and IP addresses, genders, the city of users as well as passwords stored in both plain text and as MD5 hashes. The site was previously reported as compromised on the Vigilante.pw breached database directory.
  • Data: Email Addresses Genders Geographic Locations IP Addresses Names Passwords Phone Numbers Usernames
  • Records: 4,485,195
  • Lines: 4,485,289
  • Size: 1.53 GB
  • Passwords: MD5, Plaintext
In November 2020, a collection of more than 23,000 allegedly breached websites known as Cit0day were made available for download on several hacking forums. The data consisted of 226M unique email address alongside password pairs, often represented as both password hashes and the cracked, plain text versions. Independent verification of the data established it contains many legitimate, previously undisclosed breaches.
  • Data: Email Addresses Passwords
  • Records: 614,556,967
  • Lines: 615,238,877
  • Size: 27.92 GB
  • Passwords: Plaintext

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.