Breach Intelligence

6,875

Total breached databases

In 2017, InstaFit, a platform associated with fitness and community engagement, experienced a data breach exposing over 700,000 user records. The leaked data primarily involved personal information of forum or community members, including names, email addresses, genders, and countries.
  • Date: Jul 4, 2017
  • Domain: instafit.com
  • Country: Mexico
  • Category: Healthcare
  • Data: Email Addresses Names Geographic Locations Genders
  • Records: 785,137
  • Lines: 785,138
  • Size: 31.03 MB
  • Passwords: No
Sometime before May 2026, InterLab (also operating as Biosystem, interlab.mx), a network of clinical diagnostic laboratories in Mexico, allegedly suffered a data breach. Reports suggest an attacker compromised a company server and exfiltrated data belonging to roughly 30 affiliated laboratories, subsequently publishing it for free on a hacking forum. It has been reported that the exposed data covers approximately 28,000 individuals and includes names, email addresses, phone numbers, geographic locations, birthdates, genders, government identifiers, blood-type and other health information, and company records. No passwords were included in the exposed data.
  • Date: 2026
  • Domain: interlab.mx
  • Country: Mexico
  • Category: Healthcare
  • Data: Email Addresses Names Phone Numbers Geographic Locations Government IDs Health Information Genders Company Information Birthdates
  • Records: 87,279
  • Lines: 756,197
  • Size: 122.23 MB
  • Passwords: No
In 2023, the Mexican e-commerce platform ClikStore (clikstore.com) allegedly suffered a data breach. It has been reported that a database containing customer and order records was exposed. Reports suggest the data of approximately 135,000 individuals was affected, including email addresses, names, genders, birth dates, phone numbers, postal addresses, and order information, along with some payment-card metadata. No account passwords were included in the exposed data.
  • Date: 2023
  • Domain: clikstore.com
  • Country: Mexico
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Geographic Locations Credit Card Information Order Information Genders Birthdates
  • Records: 912,480
  • Lines: 34,434,749
  • Size: 4.51 GB
  • Passwords: No
Sometime before January 2026, CONAFE (Consejo Nacional de Fomento Educativo), Mexico's federal National Council for Educational Development, allegedly suffered a data breach. Reports suggest a database containing approximately 560,000 records of students was exposed, spanning student directories across Mexican states and a scholarship applicant dataset for Quintana Roo. The compromised data allegedly included full names, CURP national identification numbers, dates of birth, genders, geographic locations, and parents'/guardians' names and CURPs, along with email addresses, phone numbers, home addresses, and bank account (CLABE) details for scholarship applicants. No passwords were reportedly included in the exposed data.
  • Date: 2026
  • Domain: conafe.gob.mx
  • Threat Actor: ALZ
  • Country: Mexico
  • Category: Education
  • Data: Email Addresses Names Phone Numbers Geographic Locations Government IDs Family Members Genders Birthdates
  • Records: 578,286
  • Lines: 23,506,605
  • Size: 484.54 MB
  • Passwords: No
At an unconfirmed date, Benetton Mexico (benettonmex.com), the Mexican online store of the Italian fashion brand Benetton, allegedly suffered a data breach of its Magento customer database. Reports suggest the exposed data contained records for approximately 15,700 customers, including email addresses, names, phone numbers, dates of birth, genders, physical addresses, and Mexican RFC tax identification numbers.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Government IDs Genders Site Activity Birthdates
  • Records: 15,742
  • Lines: 17,439
  • Size: 3.1 MB
  • Passwords: No
Sometime before May 2026, Compass Imaging Lab (compassimaginglab.com), a Mexican clinical laboratory, allegedly suffered a data breach that was published by an extortion actor after the lab reportedly declined to pay. Reports suggest the exposed data covered roughly 5,000 patients and included full names, email addresses, phone numbers, birth dates, and sensitive medical laboratory records — test dates, test types, and results (including positive infectious-disease results). No passwords were included in the exposed records.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Site Activity Birthdates Test date Test type Test result
  • Records: 5,441
  • Lines: 5,442
  • Size: 1.89 MB
  • Passwords: No
In 2026, the Instituto Tecnológico de la Laguna (ITL), a Mexican public technological institute in Torreón, Coahuila, allegedly suffered a data breach of its SCEITL school-control system. Reports suggest a threat actor exfiltrated the institute's database and published it. The exposed data includes information on approximately 1,700 applicants, students, and staff — full names, CURP national identity numbers, NSS social-security numbers, email addresses, phone numbers, physical addresses, dates of birth, and genders, along with a small set of administrative accounts with MD5 password hashes. No plaintext user passwords were included.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Government IDs Social Security Numbers Genders Birthdates Nationalities
  • Records: 2,932
  • Lines: 2,946
  • Size: 396.75 KB
  • Passwords: MD5
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.