Breach Intelligence

6,875

Total breached databases

Sometime in or after 2017, the website cszpytma.strony.prz.edu.pl, an academic project site hosted on the web platform of the Rzeszów University of Technology in Poland, allegedly suffered a data breach. Reports suggest the exposed data consisted of a small number of administrator accounts, including usernames, email addresses, registration dates, IP addresses, and passwords stored as MD5 hashes.
  • Data: Email Addresses Passwords Usernames IP Addresses Site Activity
  • Records: 2
  • Lines: 545
  • Size: 873.05 KB
  • Passwords: MD5
  • Cracked: 0%
Sometime before 2021, the Polish online tire retailer Gold-Gum (gold-gum.pl) allegedly suffered a data breach. Gold-Gum is an e-commerce store, built on the KQS.store platform, that sells retreaded and budget vehicle tires. Reports suggest the exposed dump contained approximately 7,800 unique customer records, including email addresses, MD5-hashed passwords, full names, phone numbers, postal and geographic address details, IP addresses, and company information such as business names and tax identification numbers.
  • Date: 2021
  • Domain: gold-gum.pl
  • Country: Poland
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations IP Addresses Tax IDs Company Information
  • Records: 115,789
  • Lines: 280,955
  • Size: 26.96 MB
  • Passwords: MD5
  • Cracked: 0%
Sometime in 2019, Tibia.net.pl, a platform related to the online game Tibia, experienced a data breach exposing approximately 440,292 records. Among the compromised data were email addresses and hashed passwords.
  • Data: Email Addresses Passwords
  • Records: 301,466
  • Lines: 301,466
  • Size: 8.29 MB
  • Passwords: Plaintext, vBulletin
In June 2016, the Polish Minecraft server network Craftapple.pl allegedly suffered a data breach of its MyBB community forum. Reports suggest the exposed data contained approximately 9,000 distinct users, including email addresses, usernames, MyBB-hashed passwords with salts, IP addresses, birthdates and registration details.
  • Data: Email Addresses Passwords Geographic Locations Usernames IP Addresses Site Activity Social Profiles Websites Birthdates
  • Records: 12,835
  • Lines: 143,685
  • Size: 60.95 MB
  • Passwords: MyBB
  • Cracked: 0%
In September 2019, the Polish torrent site AgusiQ-Torrents.pl allegedly suffered a data breach. Reports suggest approximately 90,000 member records were exposed, including email addresses, usernames, IP addresses, dates of activity, and passwords stored as MD5 hashes.
  • Data: Email Addresses Passwords Geographic Locations Usernames Genders IP Addresses Site Activity Social Profiles Birthdates
  • Records: 90,401
  • Lines: 180,909
  • Size: 40.42 MB
  • Passwords: MD5
  • Cracked: 83%
Sometime around August 2017, the Polish Minecraft servers Onlypvp.pl and Pvpbonsko.pl allegedly suffered a data breach. Reports suggest the exposed data was taken from the servers' AuthMe authentication database. It has been reported that approximately 23,000 players were affected, with exposed records including usernames, salted SHA-256 password hashes, IP addresses, geographic locations and in-game activity.
  • Data: Passwords Geographic Locations Usernames IP Addresses Site Activity
  • Records: 23,748
  • Lines: 23,792
  • Size: 3.46 MB
  • Passwords: SHA-256 Salted
  • Cracked: 0%
In August 2016, Selino.pl, a Polish e-commerce platform for custom-printed clothing and personalized apparel, allegedly suffered a data breach. Reports suggest that data belonging to approximately 10,000 individuals was exposed. The compromised information allegedly included email addresses, names, usernames, phone numbers, geographic locations, IP addresses, company information, and passwords stored as MD5 and SHA-1 hashes.
  • Date: Aug 2016
  • Domain: selino.pl
  • Country: Poland
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames IP Addresses Company Information
  • Records: 37,523
  • Lines: 660,229
  • Size: 65.66 MB
  • Passwords: MD5, SHA-1
  • Cracked: 1588%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.