Breach Intelligence

6,874

Total breached databases

In 2026, SPUTNIK (sputnik64.ru), a Russian food retail chain founded in Saratov in 2006, allegedly suffered a data breach affecting its customer loyalty program. Reports suggest the data was subsequently published on a hacking forum. The exposed data reportedly contained approximately 120,000 records, including names, phone numbers and dates of birth. No passwords were included in the exposed data.
  • Date: Mar 10, 2026
  • Domain: sputnik64.ru
  • Threat Actor: X0Frankenstein
  • Country: Russia
  • Category: Food
  • Data: Names Phone Numbers Geographic Locations Birthdates
  • Records: 119,956
  • Lines: 119,956
  • Size: 9.29 MB
  • Passwords: No
In February 2026, a database associated with Miltor (miltor.ru), a Russian online retail and merchant platform, was allegedly leaked and appeared online. Reports suggest the exposed dataset contained approximately 2.4 million records of merchants and contacts. The compromised information reportedly includes email addresses, phone numbers, full names, and shop/company names. No passwords were present in the leaked data.
  • Date: Feb 2026
  • Domain: miltor.ru
  • Country: Russia
  • Category: Data Brokers
  • Data: Email Addresses Names Phone Numbers Geographic Locations Company Information
  • Records: 2,425,977
  • Lines: 2,425,978
  • Size: 157.8 MB
  • Passwords: No
COM23.ru 2026

COM23.ru 2026

Sensitive
In May 2026, the Russian delivery service COM23.ru allegedly suffered a data breach after an unsecured directory containing Sberbank payment-gateway transaction logs was exposed. Reports suggest that approximately 59,000 unique payment transaction records were exposed. The compromised information reportedly included cardholder names, masked card numbers (BIN and last four digits), card expiration dates and customer IP addresses. No passwords were included in the exposed data.
  • Date: May 2026
  • Domain: com23.ru
  • Country: Russia
  • Category: Logistics & Transportation
  • Data: Names Phone Numbers Geographic Locations Credit Card Information Payment Information IP Addresses
  • Records: 59,397
  • Lines: 3,488,677
  • Size: 88.28 MB
  • Passwords: No
In January 2019, the Russian caller-ID and spam-blocking service NumBuster (numbuster.com) allegedly suffered a data breach. NumBuster is a mobile application that identifies unknown callers using a crowd-sourced database of phone numbers and user-submitted contact names. Reports suggest approximately 103 million records were exposed, containing phone numbers, crowd-sourced contact names, and geographic region tags. No passwords were included in the dataset.
  • Date: Jan 13, 2019
  • Domain: numbuster.com
  • Country: Russia
  • Category: Telecommunications
  • Data: Names Phone Numbers Geographic Locations
  • Records: 103,253,419
  • Lines: 103,253,420
  • Size: 8.22 GB
  • Passwords: No
Sometime before 2023, the Russian furniture and mattress retailer Askona (askona.ru) allegedly suffered a data breach. Reports suggest the incident exposed a customer database of approximately 440,000 individuals. The exposed data included names, email addresses, phone numbers, genders, and passwords stored as salted MD5 hashes.
  • Date: 2023
  • Domain: askona.ru
  • Country: Russia
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Genders Site Activity
  • Records: 480,530
  • Lines: 480,893
  • Size: 248.97 MB
  • Passwords: MD5 Salted, SHA-512 Salted
  • Cracked: 0%
In May 2025, a dataset scraped from AFY.ru, a Russian real estate portal listing property agents and agencies, was allegedly published. Reports suggest the data covered approximately 117,000 agent profiles and consisted of publicly listed professional directory information, including full names, phone numbers, service regions and free-text business descriptions. No email addresses or passwords were included.
  • Date: May 2025
  • Domain: afy.ru
  • Country: Russia
  • Category: Real Estate
  • Data: Names Phone Numbers Physical Locations Geographic Locations Company Information
  • Records: 117,751
  • Lines: 133,398
  • Size: 28.11 MB
  • Passwords: No
Forex Club is a Russian retail forex and CFD broker that has primarily served Russian-speaking traders in Russia and the CIS region since the late 1990s. It has been reported that forexclub.com allegedly suffered a data breach. Approximately 37,531 records were affected, with data including names, email addresses, phone numbers, and regions of residence.
  • Data: Email Addresses Names Phone Numbers Geographic Locations
  • Records: 200,171
  • Lines: 37,531
  • Size: 9.89 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.