Breach Intelligence

6,874

Total breached databases

In 2022, Upside Down Cake (upsidedowncake.ru), a Russian cafe-confectionery offering delivery of meals, cakes and pastries, allegedly suffered a data breach. Reports suggest the incident exposed approximately 14,500 records, including email addresses, names, phone numbers, geographic locations and password hashes (bcrypt and salted MD5).
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Site Activity
  • Records: 14,509
  • Lines: 14,530
  • Size: 4.04 MB
  • Passwords: BCrypt, MD5 Salted
  • Cracked: 0%
In 2021, Meat&Buns, a food delivery service based in Balashikha, Russia, allegedly experienced a data breach. Reports suggest that the breach may have affected approximately 1,200 records. The compromised data includes email addresses, passwords (hashed with MD5), names, phone numbers, geographic locations, usernames, IP addresses, and site activity.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames IP Addresses Site Activity
  • Records: 1,174
  • Lines: 1,178
  • Size: 272.43 KB
  • Passwords: MD5
  • Cracked: 103802%
In 2006, Bankir.Ru, a Russian information agency specializing in financial market information, allegedly experienced a data breach. Reports suggest that approximately 40,000 records were compromised, including email addresses, usernames, passwords, geographic locations, IP addresses, site activity, social profiles, websites, and birthdates.
  • Date: 2006
  • Domain: bankir.ru
  • Country: Russia
  • Category: Finance & Payments
  • Data: Email Addresses Passwords Geographic Locations Usernames IP Addresses Site Activity Social Profiles Websites Birthdates
  • Records: 39,902
  • Lines: 39,970
  • Size: 16.8 MB
  • Passwords: vBulletin
  • Cracked: 0%
In 2016, the gaming website Dontcraft.ru allegedly experienced a data breach. Reports suggest that the breach involved user records and passwords, with approximately 246,000 records exposed. The compromised data includes email addresses, usernames, hashed passwords (SHA-256 Salted), geographic locations, IP addresses, and site activity.
  • Data: Email Addresses Passwords Geographic Locations Usernames IP Addresses Site Activity
  • Records: 246,178
  • Lines: 247,105
  • Size: 43.22 MB
  • Passwords: SHA-256 Salted
  • Cracked: 98%
In October 2022, the website sogaz-life.ru, owned by SOGAZ-Life Insurance Company, was allegedly compromised by pro-Ukrainian hackers who made a partial SQL dump of its database publicly available. Reports suggest that the dump contains approximately 49,999 lines of data, while the hacker claims the full database may include around 700,000 lines. The leaked data includes email addresses, names, phone numbers, geographic locations, genders, job information, and site activity. The passwords are hashed using SHA-512 with salt.
  • Date: 2022
  • Domain: sogaz-life.ru
  • Country: Russia
  • Category: Finance & Payments
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Genders Site Activity Job Information Company Information
  • Records: 49,968
  • Lines: 50,244
  • Size: 31.52 MB
  • Passwords: SHA-512 Salted, Unknown
In 2017, Procapital.ru, a Russian forum focused on Forex trading and investments, allegedly experienced a data breach. Reports suggest that approximately 124,000 records were compromised, which included email addresses, usernames, passwords, IP addresses, geographic locations, site activity, social profiles, and associated websites.
  • Date: 2017
  • Domain: procapital.ru
  • Country: Russia
  • Category: Finance & Payments
  • Data: Email Addresses Passwords Geographic Locations Usernames IP Addresses Site Activity Social Profiles Websites
  • Records: 124,221
  • Lines: 125,604
  • Size: 58.91 MB
  • Passwords: vBulletin
  • Cracked: 0%
In 2016, the Russian website wh-satano.ru, which has been established for over 11 years and is known for offering private cheats for online games, allegedly experienced a data breach. Reports suggest that approximately 1,100 records were compromised, including email addresses, usernames, geographic locations, site activity, and passwords stored in BCrypt format.
  • Date: 2016
  • Domain: satano.ru
  • Country: Russia
  • Category: Gaming
  • Data: Email Addresses Passwords Geographic Locations Usernames Site Activity
  • Records: 1,076
  • Lines: 1,120
  • Size: 580.89 KB
  • Passwords: BCrypt
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.