Breach Intelligence

6,875

Total breached databases

In 2025, the Russian home and garden retail chain Darvin (darvin-market.ru) allegedly suffered a data breach. It has been reported that a dataset containing both customer and staff records was exposed. The breach reportedly affected approximately 63,000 individuals, with exposed data including email addresses, usernames, names, phone numbers, geographic locations, job information, site activity, and passwords stored as salted MD5 and SHA-512 crypt hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Site Activity Job Information
  • Records: 66,507
  • Lines: 66,988
  • Size: 257.34 MB
  • Passwords: MD5 Salted, SHA-512 Salted
  • Cracked: 0%
Sometime before 2022, Pikabu (pikabu.ru), a popular Russian entertainment and content-sharing community platform, allegedly suffered a data breach. Reports suggest a list containing approximately 1 million records of Russian and Belarusian users was posted online. It has been reported that the exposed data included usernames, phone numbers, and email addresses. No passwords were included in the leaked dataset.
  • Date: 2025
  • Domain: pikabu.ru
  • Country: Russia
  • Category: Forums & Communities
  • Data: Email Addresses Phone Numbers Geographic Locations Usernames
  • Records: 1,026,996
  • Lines: 1,026,996
  • Size: 32.46 MB
  • Passwords: No
Sometime around 2023, Cheryomushki (cheryomushki.ru), a Russian online retailer of lingerie and textile goods, allegedly suffered a data breach of its OpenCart store database. Reports suggest data belonging to approximately 34,000 customers was exposed, including email addresses, names, phone numbers, cities, IP addresses, and salted SHA-1 password hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations IP Addresses Site Activity
  • Records: 48,453
  • Lines: 658,041
  • Size: 68.35 MB
  • Passwords: Hashed, SHA-1 Salted
  • Cracked: 0%
In May 2023, the Russian clothing retailer Gloria Jeans (gloria-jeans.ru) allegedly suffered a data breach. Reports suggest approximately 3.1 million customer records were exposed. The compromised data allegedly included email addresses, phone numbers, full names, and dates of birth.
  • Date: May 2023
  • Domain: gloria-jeans.ru
  • Country: Russia
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Birthdates
  • Records: 6,324,159
  • Lines: 6,324,159
  • Size: 884.23 MB
  • Passwords: No
In June 2025, Black Star Wear (blackstarwear.ru), a Russian streetwear fashion brand, allegedly suffered a data breach exposing its customer and order databases. Reports suggest the data was subsequently published on a hacking forum. The exposed data reportedly covered approximately 207,000 unique customers, including names, email addresses, phone numbers, order and delivery details, IP addresses and salted SHA-1 password hashes.
  • Date: Jun 15, 2025
  • Domain: blackstarwear.ru
  • Country: Russia
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Order Information IP Addresses Site Activity
  • Records: 549,994
  • Lines: 550,039
  • Size: 426.81 MB
  • Passwords: SHA-1 Salted
  • Cracked: 0%
In 2025, a database attributed to Sovcombank (sovcombank.ru), one of Russia's largest banks, was allegedly published on a hacking forum. It has been reported that the dataset held roughly 131,000 customer records. The compromised data reportedly included full names, dates and places of birth, phone numbers, email addresses, Russian passport series and numbers, home addresses, marital status, pension amounts, and the names and phone numbers of spouses and additional contacts.
  • Date: 2025
  • Domain: sovcombank.ru
  • Country: Russia
  • Category: Finance & Payments
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Financial Information Government IDs Passports Family Members Marital Statuses Relationship Statuses Birthdates Places of Birth
  • Records: 131,223
  • Lines: 131,223
  • Size: 38.77 MB
  • Passwords: No
In November 2022, the Russian courier and logistics service Grastin (grastin.ru) allegedly suffered a data breach that reportedly compromised approximately 1.58 million records dating from August 2021 to 2022. It has been reported that the data was initially shared on Telegram before appearing on several hacking forums. The compromised information reportedly includes full names, email addresses, phone numbers, and physical delivery addresses. No passwords were present in the leaked data.
  • Date: Nov 2022
  • Domain: grastin.ru
  • Country: Russia
  • Category: Logistics & Transportation
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations
  • Records: 1,581,126
  • Lines: 1,581,127
  • Size: 229.34 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.