Breach Intelligence

6,875

Total breached databases

Sometime around 2020, the South Korean peer-to-peer lending and investment platform Modua (mouda.kr) allegedly suffered a data breach. Modua was a fintech service that also offered a neighborhood-doctor healthcare-loan program. Reports suggest that data belonging to approximately 22,000 individuals was exposed. The compromised information reportedly included email addresses, BCrypt-hashed passwords, phone numbers, usernames, geographic locations, and site activity data.
  • Date: 2020
  • Domain: modua.kr
  • Country: South Korea
  • Category: Finance & Payments
  • Data: Email Addresses Passwords Phone Numbers Geographic Locations Usernames Site Activity
  • Records: 378,357
  • Lines: 1,122,108
  • Size: 212.03 MB
  • Passwords: BCrypt
  • Cracked: 0%
In 2022, 2dub.me (투덥), a South Korean voice-dubbing social platform where users recorded audio over video clips, allegedly suffered a data breach. Reports suggest that approximately 143,000 user accounts were exposed, including email addresses, usernames, geographic locations, and site activity data.
  • Date: 2022
  • Domain: 2dub.me
  • Country: South Korea
  • Category: Social Media & Communication
  • Data: Email Addresses Geographic Locations Usernames Site Activity
  • Records: 152,669
  • Lines: 152,670
  • Size: 25.77 MB
  • Passwords: No
Sometime in 2022, Difinition (difinition.co.kr), a South Korean digital education platform providing learning management services for students and teachers, allegedly suffered a data breach exposing its Elasticsearch infrastructure. Reports suggest approximately 25 user records were affected, with the data including email addresses, usernames, phone numbers, birth dates, genders, geographic locations, and site activity logs.
  • Data: Email Addresses Phone Numbers Geographic Locations Usernames Genders Site Activity Birthdates
  • Records: 25
  • Lines: 94,571
  • Size: 3.29 MB
  • Passwords: No
In 2020, Shop.7xx.org, a Korean multi-merchant e-commerce platform, allegedly suffered a data breach. Reports suggest that approximately 46,000 individuals were affected, with exposed data including email addresses, MD5 password hashes, full names, phone numbers, postal codes, Korean addresses, and usernames. The dataset also contains corporate account records with company names, tax IDs, and fax numbers.
  • Date: 2020
  • Domain: shop.7xx.org
  • Country: South Korea
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Site Activity Company Information Fax Numbers
  • Records: 45,684
  • Lines: 45,690
  • Size: 7.09 MB
  • Passwords: MD5
  • Cracked: 1942%
In 2022, DV Consulting (dvconsulting.org), a South Korean software consultancy that developed a family cafe and entertainment center management platform, allegedly suffered a data breach. Reports suggest approximately 5,000 individuals were affected, with exposed data including email addresses, bcrypt and MD5 password hashes, full names, usernames, phone numbers, geographic addresses, genders, and dates of birth.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Genders Site Activity Birthdates
  • Records: 6,037
  • Lines: 859,330
  • Size: 69.53 MB
  • Passwords: BCrypt, MD5
  • Cracked: 0%
In 2023, the Korean website Acoc.kr (acoc.kr) allegedly suffered a data breach. Reports suggest approximately 8,000 user records were exposed, including email addresses, MD5-hashed passwords, usernames, full names, birthdates, and account activity dates.
  • Date: 2023
  • Domain: acoc.kr
  • Country: South Korea
  • Category: Others
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Site Activity Birthdates
  • Records: 8,029
  • Lines: 34,481
  • Size: 3.16 MB
  • Passwords: MD5
  • Cracked: 0%
Sometime before May 2023, Zeosis (zeosis.com) allegedly suffered a data breach. Zeosis is a South Korean technology company providing custom CMS (FSCX framework) hosting for businesses, universities, and government-affiliated organizations. Reports suggest the leaked dataset was published on the Nulled hacking forum by a user known as "zxcv16" and contained data from approximately 25,000 individuals across more than 100 customer databases. The compromised information includes email addresses, BCrypt and MD5 passwords, names, usernames, phone numbers, geographic locations, IP addresses, birthdates, employment and education details, websites, and site activity metadata.
  • Date: 2023
  • Domain: zeosis.com
  • Threat Actor: zxcv16
  • Country: South Korea
  • Category: Technology
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames IP Addresses Site Activity Websites Job Information Company Information Birthdates Education
  • Records: 303,033
  • Lines: 13,070,425
  • Size: 3.05 GB
  • Passwords: BCrypt, MD5
  • Cracked: 28056%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.