Breach Intelligence

6,875

Total breached databases

Sometime before 2025, valutazioneimmobile.online, an Italian real-estate valuation lead-generation website, allegedly suffered a data breach. Reports suggest a threat actor compromised the site's WordPress admin, defaced its pages and exported a database of customer valuation leads. It has been reported that the leak exposed approximately 183 individuals, with data including full names, email addresses, phone numbers, physical addresses and property details. Records in the dump date from 2022.
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Site Activity
  • Records: 183
  • Lines: 184
  • Size: 36.33 KB
  • Passwords: No
Sometime before 2026, the Italian website istituti-religiosi.org, a directory and booking platform for religious institutes offering guest accommodation, allegedly suffered a data breach. Reports suggest an attacker extracted the site's login database after gaining access. The indexed portion of the leak exposed approximately 230 account records, with compromised data including usernames and passwords stored both in plaintext and as SHA-512 hashes.
  • Data: Passwords Usernames
  • Records: 230
  • Lines: 260
  • Size: 49.26 KB
  • Passwords: SHA-512, Plaintext
In 2023, the Italian web-hosting company Webtoo / Hostingtoo (webtoo.it, hostingtoo.it) allegedly suffered a data breach of the WordPress databases it hosted for multiple customer sites. Reports suggest the exposed data covered approximately 14,000 individuals and included email addresses, usernames, real names, and WordPress (phpass) and MD5 password hashes.
  • Date: 2023
  • Domain: webtoo.it
  • Country: Italy
  • Category: Technology
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Site Activity Websites
  • Records: 17,371
  • Lines: 3,262,636
  • Size: 878.44 MB
  • Passwords: PHPass, MD5
  • Cracked: 0%
Sometime around 2026, the Italian energy retailer Unica S.p.A. (unicaspa.it) allegedly suffered a data breach. Unica is an Italian company that sells electricity and gas to end customers. Reports suggest its back-office and reporting database — spanning 2018 to 2026 — was exposed, including customer and contact records, sales-agent and administrator details, physical and geographic locations, email addresses, phone numbers, Italian tax codes (codice fiscale), and financial/billing information. The exposed customer-facing records number in the tens of thousands (with millions of additional non-personal accounting and supply-point rows). No passwords were included.
  • Date: 2026
  • Domain: unicaspa.it
  • Threat Actor: DaOnlySpark
  • Country: Italy
  • Category: Industry
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Financial Information Government IDs
  • Records: 35,963
  • Lines: 12,608,703
  • Size: 1.59 GB
  • Passwords: No
Sometime before 2025, Steca Energia (stecaenergia.it), an Italian gas and energy utility operated by Skianet in the Marche region, allegedly suffered a data breach. Reports suggest a full SQL database was published for free on a hacking forum. It has been reported that the exposed data covered approximately 1,200 registered customers and companies, including full names, email addresses, phone numbers, physical addresses, Italian tax codes (codice fiscale), VAT numbers, and a small set of staff login accounts with MySQL password hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs Company Information Birthdates
  • Records: 3,179
  • Lines: 1,730,779
  • Size: 400.58 MB
  • Passwords: MySQL
  • Cracked: 0%
Sometime before February 2026, WalutaTu (waluta.it), an Italian online platform providing certified market valuations for used cars, allegedly suffered a data breach. Reports suggest the exposed data comprised roughly 41,000 records including vehicle listings (license plates, VINs, make/model, registration dates) and the associated customer and lead contacts — full names, email addresses, phone numbers, physical addresses, Italian tax codes, IBANs, and dates of birth. No passwords were reported to have been exposed.
  • Date: Feb 2026
  • Domain: waluta.it
  • Country: Italy
  • Category: Automotive
  • Data: Email Addresses Names Phone Numbers Geographic Locations Bank Account Information Government IDs Company Information Birthdates License Plate Numbers Vehicle Information Registration Dates
  • Records: 37,427
  • Lines: 41,357
  • Size: 596.51 MB
  • Passwords: No
In May 2023, Forever Moto (forevermoto.it), an Italian online store selling motorcycle parts and accessories, allegedly suffered a data breach of its PrestaShop database that was shared on a hacking forum. Reports suggest the exposed data covered approximately 6,700 customers and included email addresses, first and last names, genders, phone numbers, postal and geographic locations, birthdates, Italian tax/ID numbers, account activity timestamps, and passwords hashed with bcrypt and MD5.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Government IDs Genders Site Activity Tax IDs Birthdates
  • Records: 26,032
  • Lines: 1,321,632
  • Size: 156.59 MB
  • Passwords: BCrypt, MD5
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.