Breach Intelligence

6,875

Total breached databases

Medicati 2026

Medicati 2026

Sensitive
In 2026, Medicati (medicati.com), a Mexican medical laboratory and clinic management platform based in Monterrey, allegedly suffered a data breach. Reports suggest a threat actor exfiltrated patient records after a failed extortion attempt against the company and threatened to publish the data. The exposed records covered approximately 2,200 patients and allegedly included full names, dates of birth, genders, phone numbers, email addresses and clinical/laboratory test information; no passwords were included.
  • Date: 2026
  • Domain: medicati.com
  • Threat Actor: Alameda_Slim
  • Country: Mexico
  • Category: Healthcare
  • Data: Email Addresses Names Phone Numbers Geographic Locations Genders Site Activity Birthdates
  • Records: 2,232
  • Lines: 10,292
  • Size: 4.4 MB
  • Passwords: No
Sometime before 2026, Mexitravels allegedly suffered a data breach. Mexitravels is a Mexican travel agency based in Puerto Vallarta. Reports suggest that the breach exposed approximately 5,000 individuals. The exposed data allegedly included names, email addresses, phone numbers, plaintext passwords and company/tax details.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs Company Information Personal Information Travel Habits
  • Records: 20,656
  • Lines: 1,983,505
  • Size: 970.32 MB
  • Passwords: Plaintext
In 2026, the Comisión del Agua del Estado de México (CAEM), the water commission of the State of Mexico, allegedly suffered a large data breach of its SIAF financial-administration and SIGED document-management systems that was subsequently published on a hacking forum. Reports suggest the exposed data spanned hundreds of database tables covering 1997–2026 and included full personnel records for roughly 10,500 employees — names, CURP and RFC tax/government IDs, home addresses, phone numbers, emails, bank accounts and CLABE numbers, marital status, gender, ISSEMYM/ISSSTE social-security identifiers and salary/employment history — alongside supplier and official contact records, general-ledger and payroll financial data, water-consumption debt tied to taxpayers, and a set of recovered system credentials.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Bank Account Information Financial Information Government IDs Social Security Numbers Marital Statuses Relationship Statuses Genders Site Activity Tax IDs Salaries Company Information Birthdates
  • Records: 11,147
  • Lines: 13,300
  • Size: 9.93 MB
  • Passwords: BCrypt
  • Cracked: 0%
In 2023, Alquimia Digital (alquimiadigital.mx), a Mexican SPEI electronic-payments and banking-as-a-service platform, allegedly suffered a data breach that was subsequently published on a hacking forum. Reports suggest the exposed database contained the platform's account holders and legal representatives — including names, email addresses, phone numbers, RFC/CURP tax and government IDs, dates of birth, genders and physical addresses — alongside millions of SPEI transfer records exposing bank account numbers (CLABE), beneficiary details and financial transaction information.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Bank Account Information Payment Information Financial Information Government IDs Genders Tax IDs Company Information Birthdates
  • Records: 3,397,547
  • Lines: 27,738,413
  • Size: 14.09 GB
  • Passwords: No
In May 2025, Dico (dico.com.mx) allegedly suffered a data breach. Dico (Muebles Dico) is a Mexican furniture retailer. Reports suggest a database of customer order records was exposed, covering roughly 64,000 unique customers across around 141,000 transactions. The exposed data includes full names, email addresses, billing and shipping addresses, and order and payment details. No passwords were included in the exposed data.
  • Data: Email Addresses Names Physical Locations Geographic Locations Payment Information Order Information Shipment Information
  • Records: 141,054
  • Lines: 457,535
  • Size: 45.81 MB
  • Passwords: No
In November 2022, the Mexican online store Reyco.com.mx allegedly suffered a data breach, with the full customer database subsequently shared on a hacking forum. Reports suggest that approximately 17,000 customer records were exposed. The compromised data allegedly included email addresses, names, phone numbers, geographic locations and site activity. No passwords were included in the exposed data.
  • Date: Nov 23, 2022
  • Domain: reyco.com.mx
  • Country: Mexico
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Geographic Locations Site Activity
  • Records: 17,195
  • Lines: 40,741
  • Size: 8.06 MB
  • Passwords: No
In November 2022, a hosting backup belonging to activitiescabo.com allegedly suffered a data breach. The company operates activities, tours, and transportation booking services in Los Cabos, Mexico across several related brands. Reports suggest the exposed data spanned dozens of bundled databases and affected approximately 2,100 individuals, including email addresses, names, and passwords stored as MD5, phpass, and bcrypt hashes, alongside customer reservation details.
  • Data: Email Addresses Passwords Names Geographic Locations Usernames
  • Records: 3,520
  • Lines: 88,011
  • Size: 10.25 MB
  • Passwords: BCrypt, MD5, PHPass
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.