Breach Intelligence

6,875

Total breached databases

Sometime in late 2024, Inmakes Learning Hub (inmakeslh.in), an Indian ed-tech and IT-training provider, allegedly had student records extracted from its learning-management admin panel. Reports suggest approximately 1,600 student records were exposed. The compromised data reportedly included students' full names, email addresses, mobile phone numbers, and enrolment timestamps.
  • Date: 2024
  • Domain: inmakeslh.in
  • Threat Actor: SUK4M4L1NG
  • Country: India
  • Category: Education
  • Data: Email Addresses Names Phone Numbers Site Activity
  • Records: 1,600
  • Lines: 1,600
  • Size: 574.85 KB
  • Passwords: No
Sometime before 2025, LEAD School (leadschool.in), an Indian school-management and EdTech platform, allegedly suffered a data breach. Reports suggest a student records export was exposed, relating to approximately 900 students. The exposed data included students' full names, dates of birth, genders, home addresses and pincodes, and the names and phone numbers of their parents and guardians. No passwords were included. A companion teachers file referenced in the disclosure was not part of the processed data.
  • Date: 2025
  • Domain: leadschool.in
  • Threat Actor: SHADOWBYT3$
  • Country: India
  • Category: Education
  • Data: Names Phone Numbers Physical Locations Family Members Genders Birthdates
  • Records: 896
  • Lines: 897
  • Size: 178.5 KB
  • Passwords: ?
In 2023, Centurion University of Technology and Management (cutm.ac.in), a private university in India, allegedly suffered a breach of its WordPress site database that was shared on a hacking forum. Reports suggest the exposed `wp_users` table contained approximately 8,000 accounts, largely faculty and staff, including email addresses, usernames, display names, registration dates, and passwords hashed with WordPress phpass (with a subset of legacy MD5 hashes).
  • Date: 2023
  • Domain: cutm.ac.in
  • Country: India
  • Category: Education
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Site Activity Websites
  • Records: 7,976
  • Lines: 8,077
  • Size: 1.27 MB
  • Passwords: MD5, PHPass, WordPress
  • Cracked: 0%
Sometime before February 2026, EduSphere (edusphere.in), an Indian education ERP platform, allegedly suffered a data breach exposing student records belonging to Andhra University. Reports suggest the exposed data covered approximately 46,000 students and included email addresses, full names, phone numbers, dates of birth, and physical addresses. No passwords were reported to have been exposed.
  • Date: Feb 2026
  • Domain: edusphere.in
  • Threat Actor: CrowStealer
  • Country: India
  • Category: Education
  • Data: Email Addresses Names Phone Numbers Geographic Locations Birthdates
  • Records: 46,152
  • Lines: 46,160
  • Size: 12.97 MB
  • Passwords: No

CWSLGDS 2025

Sensitive
Sometime before 2025, cwslgds.in, a website belonging to a major railway maintenance facility (Carriage Workshop Lallaguda) under Indian Railways' South Central Railway zone, allegedly suffered a data breach. Reports suggest a threat actor published an internal employee database of approximately 2,800 railway workers. The exposed data reportedly included full names, fathers' names, dates of birth, genders, designations and departments, employment type, residential addresses, and work mobile numbers.
  • Date: 2025
  • Domain: cwslgds.in
  • Country: India
  • Category: Government
  • Data: Names Phone Numbers Physical Locations Geographic Locations Family Members Genders Site Activity Job Information Birthdates
  • Records: 2,777
  • Lines: 2,777
  • Size: 453.13 KB
  • Passwords: No
In January 2024, Indradhanush Gas Grid Limited (IGGL, iggl.co.in), an Indian natural gas pipeline joint venture, allegedly suffered a data breach reportedly caused by a compromised third-party service. It has been reported that a recruitment dataset of approximately 1,300 job applicants was exposed. The compromised data allegedly included full names, email addresses, phone numbers, dates of birth, gender, home addresses, and educational qualifications. No passwords were included in the exposed data.
  • Date: Jan 2024
  • Domain: iggl.co.in
  • Threat Actor: Tanaka
  • Country: India
  • Category: Government
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Genders Job Information Birthdates Education
  • Records: 1,336
  • Lines: 1,337
  • Size: 417.88 KB
  • Passwords: No
Sometime before June 2023, the Indian ethnic clothing e-commerce store Ethnigo (ethnigo.com) allegedly suffered a data breach. It has been reported that a customer and order database was subsequently published on hacking forums. The incident allegedly affected approximately 42,000 individuals, with the compromised records including email addresses, names, phone numbers, physical addresses, order information and company details. No passwords were included in the exposed data.
  • Date: Jun 2023
  • Domain: ethnigo.com
  • Country: India
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Geographic Locations Order Information Site Activity Company Information Birthdates
  • Records: 60,154
  • Lines: 110,275
  • Size: 18.95 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.