Breach Intelligence

6,874

Total breached databases

In 2017, a membership spreadsheet from the Rhode Island Golf Association (Rigalinks, rigalinks.org) in the United States was allegedly exposed. It has been reported that around 14,000 golfer records were affected. The source spreadsheet held names, email addresses, home addresses, dates of birth and gender; the recovered and indexed data consists of full names and email addresses. No passwords were included in the dataset.
  • Data: Email Addresses Names
  • Records: 14,449
  • Lines: 683,381
  • Size: 11.79 MB
  • Passwords: No
In July 2026, Groomit (groomit.me), a US-based mobile pet-grooming booking platform connecting pet owners with on-demand groomers across the United States and Canada, allegedly suffered a data breach. The exposed data was a Segment/Amplitude analytics export covering approximately 37,300 unique users, and reports suggest it included email addresses, first and last names, phone numbers, ZIP/postal codes, cities and regions, IP addresses, device identifiers and device details, and account signup and activity dates. No passwords were included in the leak.
  • Date: Jul 28, 2026
  • Domain: groomit.me
  • Threat Actor: GoreTurbine
  • Country: United States
  • Category: Animals & Pets
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations IP Addresses Site Activity Languages Device Identifiers Device Information
  • Records: 43,870
  • Lines: 1,099,102
  • Size: 30.07 MB
  • Passwords: No
In August 2026, customer analytics data from ZIPS Cleaners (321zips.com) was allegedly published on a hacking forum. ZIPS Cleaners is a U.S. dry cleaning and garment-care company offering laundry, alterations, and pickup and delivery services through its retail locations and a customer-facing app. It has been reported that the exposed dataset, an analytics event export covering users from late 2024 to 2026, contained approximately 66,700 unique customer profiles. Each profile allegedly included an email address, and where available a phone number, IP address, geographic location (city, region, country), device and operating-system details, and language. No passwords were included in the exposed data.
  • Date: Aug 15, 2026
  • Domain: 321zips.com
  • Threat Actor: GoreTurbine
  • Country: United States
  • Category: Professional & Corporate
  • Data: Email Addresses Phone Numbers Physical Locations Geographic Locations IP Addresses Languages Device Information
  • Records: 66,710
  • Lines: 66,710
  • Size: 58.18 MB
  • Passwords: No
In March 2026, a Pipedrive CRM export belonging to the recruiting operation of Jitasa (itasa.is), a US-based non-profit accounting and bookkeeping firm, was allegedly leaked. Reports suggest the data covered approximately 24,000 job candidates and included names, email addresses, phone numbers, and recruiting notes. The data was allegedly published on a hacking forum. No passwords were included in the leak.
  • Date: Mar 2026
  • Domain: itasa.is
  • Country: United States
  • Category: Professional & Corporate
  • Data: Email Addresses Names Phone Numbers Geographic Locations Site Activity Profile Photos Company Information
  • Records: 24,565
  • Lines: 31,218
  • Size: 8.36 MB
  • Passwords: No
In October 2025, the American Public University System (apus.edu), a United States online university, allegedly suffered a data breach affecting its student mentorship platform. Reports suggest a threat actor exfiltrated and published a database of approximately 59,000 student records. The exposed data allegedly included full names, usernames, email addresses, programs of study and degree information, and last-login activity; no passwords were included.
  • Date: Oct 2025
  • Domain: apus.edu
  • Threat Actor: wikkid
  • Country: United States
  • Category: Education
  • Data: Email Addresses Names Usernames Site Activity Education
  • Records: 59,615
  • Lines: 59,618
  • Size: 148.48 MB
  • Passwords: No
Sometime before May 2022, the United States firearms and ammunition retailer Wright Arms (wrightarms.com) allegedly suffered a data breach. Reports suggest the compromised WooCommerce database was published on a hacking forum, exposing approximately 900 customers. The exposed data allegedly included email addresses, names, usernames, phone numbers, geographic locations, order information, and passwords stored as PHPass hashes.
  • Date: May 2022
  • Domain: wrightarms.com
  • Threat Actor: Chucky
  • Country: United States
  • Category: Weapons
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Order Information Site Activity Company Information
  • Records: 2,696
  • Lines: 280,902
  • Size: 92.6 MB
  • Passwords: PHPass
  • Cracked: 0%
In September 2023, LearningRx (learningrx.com), a US-based brain-training and cognitive-skills franchise, allegedly suffered a data breach. Reports suggest a database exported from the company's CRM and website was posted online, containing approximately 787,000 records. It has been reported that the exposed data included email addresses, full names, phone numbers, physical and geographic locations, dates of birth, ages, genders, and account activity timestamps. No passwords were included in the leaked dataset.
  • Date: Sep 2023
  • Domain: learningrx.com
  • Threat Actor: Chucky
  • Country: United States
  • Category: Education
  • Data: Email Addresses Names Phone Numbers Geographic Locations Genders Site Activity Birthdates Ages
  • Records: 787,206
  • Lines: 18,772,273
  • Size: 3.26 GB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.