Breach Intelligence

6,874

Total breached databases

Sometime in 2024, the Indian industrial equipment distributor Trice India (triceindia.in) allegedly suffered a data breach. Trice Enterprises operates as an authorised channel partner for industrial compressors, air dryers, bearings and related equipment. It has been reported that the exposed consumer data was subsequently published on a hacking forum. The incident allegedly affected approximately 38,000 individuals, with the compromised records including names, phone numbers and physical addresses. No passwords were included in the exposed data.
  • Data: Names Phone Numbers Physical Locations Geographic Locations Usernames
  • Records: 38,643
  • Lines: 38,643
  • Size: 4.99 MB
  • Passwords: No
Sometime in 2025, Indian corporate platform DoBigGPT allegedly suffered a data breach. DoBigGPT (dobiggpt.com) operates a corporate/CRM service serving Indian business users. Reports suggest the exposed database contained records for roughly 100,000 corporate users. The compromised information reportedly included full names, email addresses, phone numbers, company information, job titles, usernames, physical and geographic locations, device information, and hashed passwords (MD5 and bcrypt).
  • Date: 2025
  • Domain: dobiggpt.com
  • Threat Actor: Solonik
  • Country: India
  • Category: Technology
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Job Information Company Information Device Information
  • Records: 144,138
  • Lines: 1,574,391
  • Size: 456.51 MB
  • Passwords: BCrypt, MD5
  • Cracked: 0%
In August 2026, DreamChild (Garbh Sanskar, dreamchild.in), an Indian prenatal-wellness mobile app by Anantam Life Science, allegedly suffered a data breach exposing its user profiles. It has been reported that around 64,000 profiles were affected, including roughly 13,000 distinct phone numbers. The exposed data reportedly included names, phone numbers, IP addresses, geographic locations (city and region), device identifiers, and device details. Fields were sparsely populated across profiles. No passwords were included in the dataset.
  • Date: Aug 3, 2026
  • Domain: dreamchild.in
  • Country: India
  • Category: Healthcare
  • Data: Names Phone Numbers Geographic Locations IP Addresses Languages Device Identifiers Device Information
  • Records: 64,122
  • Lines: 64,122
  • Size: 67.75 MB
  • Passwords: No
In 2023, NCL Buildtek (nclbuildtek.com), an Indian building-materials and construction company, allegedly suffered a data breach of its internal CRM and employee database. Reports suggest the exposed data included email addresses, plaintext (base64-encoded) passwords, names, phone numbers, and physical addresses for roughly 3,000 employees and business contacts. The database was allegedly published on a hacking forum.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations
  • Records: 16,891
  • Lines: 89,533
  • Size: 35.72 MB
  • Passwords: Plaintext
Sometime before 2023, PPOBox allegedly suffered a data breach. PPOBox is an Indian package-forwarding and international shipping service. Reports suggest that the breach exposed approximately 289,000 individuals. The exposed data allegedly included names, email addresses, phone numbers, shipping addresses and shipment records.
  • Date: 2023
  • Domain: ppobox.com
  • Country: India
  • Category: Logistics & Transportation
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Site Activity Shipment Information
  • Records: 834,032
  • Lines: 1,970,126
  • Size: 8.63 GB
  • Passwords: MD5
  • Cracked: 100%

NAFPO HR 2023

Sensitive
Sometime around 2023, hr.nafpo.in — an Indian data-collection platform used by an agriculture and livelihood non-profit — allegedly had its database exposed and published on a hacking forum. The dump was largely composed of agronomic crop and field-survey records, alongside detailed profiles of program beneficiaries. Reports suggest data on approximately 400,000 individuals — farmers, students, and field staff — was exposed. It has been reported that the compromised information included names, phone numbers, Aadhaar national ID numbers, dates of birth, genders, parents' names, geographic details, and (for staff accounts) email addresses with SHA-256 or plaintext passwords.
  • Date: 2023
  • Domain: hr.nafpo.in
  • Country: India
  • Category: Education
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs Family Members Genders Birthdates Education
  • Records: 411,321
  • Lines: 4,559,942
  • Size: 1.71 GB
  • Passwords: SHA-256, Plaintext
In 2025, a database belonging to Voney (voney.in), an Indian pharmacy loyalty and rewards app for medical-store owners, was allegedly published on a hacking forum, with the underlying data dating back to around 2018. It has been reported that the breach affected roughly 152,000 users. The exposed records reportedly included names, email addresses, plaintext passwords, phone numbers, shop names, physical addresses, IP addresses, and, for a subset of users, bank account details and uploaded prescription information.
  • Date: 2025
  • Domain: voney.in
  • Threat Actor: N1KA
  • Country: India
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Bank Account Information IP Addresses Company Information Birthdates Device Information
  • Records: 462,672
  • Lines: 465,279
  • Size: 105.45 MB
  • Passwords: Plaintext

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.