Breach Intelligence

6,875

Total breached databases

Sometime before May 2022, the business management system hosted at costadigital.cl allegedly suffered a data breach. The exposed data originated from a Dolibarr ERP installation belonging to a Mexican distribution company. Reports suggest approximately 27,000 records were exposed, including email addresses, company and contact names, physical addresses, phone numbers, and a small number of MD5-hashed staff account passwords.
  • Date: May 19, 2022
  • Domain: costadigital.cl
  • Country: Mexico
  • Category: Professional & Corporate
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Company Information
  • Records: 26,964
  • Lines: 10,706,271
  • Size: 1.69 GB
  • Passwords: MD5
  • Cracked: 0%
Sometime before March 2023, the Mexican mobile virtual network operator Chuliphone (chuliphone.com) allegedly suffered a data breach. Chuliphone is a prepaid mobile carrier operating on Mexico's Altan Redes wholesale network. Reports suggest the exposed database contained records for approximately 30,000 subscribers, including names, email addresses, phone numbers, physical and geographic location details, company billing information, and salted and bcrypt-hashed passwords.
  • Date: Mar 5, 2023
  • Domain: chuliphone.com
  • Country: Mexico
  • Category: Telecommunications
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Company Information
  • Records: 769,309
  • Lines: 1,133,736
  • Size: 265.28 MB
  • Passwords: BCrypt, Hashed Salted
  • Cracked: 0%
Sometime around 2023, CECyTE Morelos (Colegio de Estudios Científicos y Tecnológicos del Estado de Morelos), a public technical upper-secondary education institution in the state of Morelos, Mexico, allegedly suffered a data breach of its WordPress, Moodle and Nextcloud systems. Reports suggest approximately 18,000 records were exposed, including email addresses, names, usernames, IP addresses, geographic locations, phone numbers, and passwords stored as BCrypt and PHPass hashes.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Usernames IP Addresses
  • Records: 28,543
  • Lines: 2,312,258
  • Size: 327.9 MB
  • Passwords: BCrypt, PHPass
  • Cracked: 0%
In March 2023, the Moodle learning-management platform of the Instituto Tecnológico Superior de Atlixco (atlixco.tecnm.mx), a public higher-education institute in Atlixco, Puebla, Mexico, part of the Tecnológico Nacional de México (TecNM) network, allegedly suffered a data breach. Reports suggest that approximately 800 records were exposed, including email addresses, usernames, full names, bcrypt-hashed passwords, IP addresses, geographic locations, and languages.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames IP Addresses Job Information Languages Bios
  • Records: 821
  • Lines: 324,003
  • Size: 70.18 MB
  • Passwords: BCrypt
  • Cracked: 0%
Sometime before 2019, BBVA México (bbva.mx) allegedly suffered a data breach. BBVA México is the largest commercial bank in Mexico, formerly known as BBVA Bancomer and part of the Spanish banking group BBVA. It has been reported that the exposed dataset contained approximately 3.3 million records. Reports suggest the compromised data included full names, phone numbers, geographic locations, credit card information, and genders. No passwords were included in the dataset.
  • Date: 2019
  • Domain: bbva.mx
  • Country: Mexico
  • Category: Finance & Payments
  • Data: Names Phone Numbers Geographic Locations Credit Card Information Genders
  • Records: 3,294,517
  • Lines: 3,294,526
  • Size: 589.2 MB
  • Passwords: No
Sometime before 2023, the Mexican Instituto Nacional Electoral (INE) for the state of Campeche allegedly suffered a data breach. INE is Mexico's autonomous federal electoral authority, responsible for the national electoral roll and voter credentials. Reports suggest the exposed dataset contained approximately 645,000 records of registered voters, including full names, residential addresses, postal codes, genders, birthdates, and government identifiers (CURP). No passwords were included in the exposed data.
  • Date: 2023
  • Domain: ine.mx
  • Country: Mexico
  • Category: Government
  • Data: Names Geographic Locations Government IDs Genders Birthdates
  • Records: 645,222
  • Lines: 630,139
  • Size: 109.24 MB
  • Passwords: No
Sometime before 2019, a server in Guatemala linked to a Mexican embassy of Mexico's Ministry of Foreign Affairs (Secretaría de Relaciones Exteriores, sre.gob.mx) allegedly suffered a data breach. Reports suggest the exposed data was a Linux system password file containing approximately 57 records, including usernames, geographic locations, and salted SHA-512 password hashes.
  • Date: 2019
  • Domain: sre.gob.mx
  • Threat Actor: 0x55Taylor
  • Country: Mexico
  • Category: Government
  • Data: Passwords Geographic Locations Usernames
  • Records: 57
  • Lines: 64
  • Size: 2.47 KB
  • Passwords: SHA-512 Salted
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.