Breach Intelligence

6,875

Total breached databases

DDSign 2009

Sensitive
Sometime around or after 2009, the South Korean banner and signage design/printing company DDSign (ddsign.co.kr) allegedly suffered a data breach. Reports suggest the site's member and order database was exposed, affecting approximately 1,500 customers. The compromised data included names, usernames, email addresses, plaintext passwords, phone numbers, physical addresses, IP addresses, and Korean resident registration numbers (national IDs).
  • Date: 2009
  • Domain: ddsign.co.kr
  • Country: South Korea
  • Category: Design
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs IP Addresses Site Activity
  • Records: 1,989
  • Lines: 118,989
  • Size: 18.07 MB
  • Passwords: Plaintext
Sometime before 2026, hanarologis.co.kr — the website of a South Korean 'HereNow' (herenow.co.kr) community and shop focused on new-science and energy topics — allegedly had its database exposed and published for free on a hacking forum. Reports suggest data on approximately 8,000 members was affected, allegedly including usernames, real names, email addresses, phone numbers, MySQL-hashed passwords, and community post and comment content dating back to the early 2000s.
  • Data: Email Addresses Usernames Names Phone Numbers Passwords Messages Site Activity
  • Records: 9,746
  • Lines: 50,768
  • Size: 45.65 MB
  • Passwords: MySQL
  • Cracked: 0%
Sometime around or after 2021, the South Korean e-commerce site daouwood.co.kr, operated by the wood and timber trading company Daou Trading (다우통상), allegedly suffered a data breach. Reports suggest the site's member and order database was exposed, affecting approximately 2,700 customers. The compromised data included names, usernames, email addresses, plaintext passwords, phone numbers, physical addresses, and company information.
  • Date: 2021
  • Domain: daouwood.co.kr
  • Country: South Korea
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Site Activity Company Information
  • Records: 6,840
  • Lines: 7,080
  • Size: 3.07 MB
  • Passwords: Plaintext
In 2024, the Republic of Korea branch of the Family Federation for World Peace and Unification (FFWPU, ffwp.or.kr) — the religious organization also known as the Unification Church — allegedly had its membership database exposed. Reports suggest the leak comprised two member-roster snapshots (2023 and 2024) covering roughly 1.2 million members, including full names, dates of birth, gender, home and postal addresses, phone numbers, and a small number of passport numbers, along with extensive religious-affiliation details.
  • Date: 2024
  • Domain: ffwp.or.kr
  • Country: South Korea
  • Category: Non-Profit & Charities
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Government IDs Genders Birthdates
  • Records: 2,223,627
  • Lines: 2,223,634
  • Size: 836.77 MB
  • Passwords: No
Sometime before 2026, NEOB2B (neob2b.co.kr), a South Korean B2B e-commerce/wholesale platform, allegedly suffered a data breach. Reports suggest the exposed data covered roughly 500 member accounts, including names, usernames, email addresses, phone numbers, postal addresses, business registration (tax) numbers and company information, along with AES-encrypted account passwords.
  • Domain: neob2b.co.kr
  • Country: South Korea
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Tax IDs Company Information
  • Records: 541
  • Lines: 153,616
  • Size: 51.97 MB
  • Passwords: Unknown
A member and order database belonging to the South Korean online shop Waplez.com was allegedly leaked, later redistributed on hacking forums. The exposed data, whose order records date to around 2015, reportedly included customer names, email addresses, phone numbers, postal addresses and some order/payment details. No passwords were included.
  • Date: 2015
  • Domain: waplez.com
  • Country: South Korea
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Bank Account Information
  • Records: 1,565
  • Lines: 200,023
  • Size: 45.15 MB
  • Passwords: No
In August 2025, the website of a tennis club based in Pohang, South Korea (pohangtennis.net), allegedly suffered a data breach. Reports suggest that the site's legacy database was extracted via directory indexing, exposing data on approximately 130 individuals. The compromised data allegedly included member names, email addresses, phone numbers, home addresses, Korean resident registration numbers, IP addresses, bulletin-board posts and comments, and passwords — a small set of member account passwords in plaintext alongside MD5-hashed board-post passwords.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs IP Addresses Site Activity Messages
  • Records: 630
  • Lines: 4,957
  • Size: 1.18 MB
  • Passwords: MD5, Plaintext

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.