Breach Intelligence

6,874

Total breached databases

Sometime before 2023, the US consumer marketing database sold by EmailDataPlus (emaildataplus.com) was allegedly made available online. EmailDataPlus is a data broker that sells consumer email marketing lists. Reports suggest the dataset contained approximately 26 million records of US consumers, including email addresses, full names, phone numbers, postal addresses, genders and dates of birth. No passwords were included.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Genders Birthdates
  • Records: 27,394,131
  • Lines: 27,394,160
  • Size: 2.37 GB
  • Passwords: No
In February 2023, Sun West Mortgage Company (swmc.com) allegedly suffered a data breach. Sun West Mortgage is a United States-based mortgage lender and loan servicer. Reports suggest the exposure of approximately 350,000 individuals, primarily mortgage-industry recruitment leads, brokers, and borrower contacts. The compromised data allegedly included email addresses, names, phone numbers, physical addresses, company information, and IP addresses. No passwords were included.
  • Date: Feb 24, 2023
  • Domain: swmc.com
  • Country: United States
  • Category: Finance & Payments
  • Data: Email Addresses Names Phone Numbers Geographic Locations IP Addresses Websites Company Information
  • Records: 575,298
  • Lines: 6,242,562
  • Size: 2.34 GB
  • Passwords: No
In February 2026, Mercer Advisors (merceradvisors.com), a United States registered investment adviser and wealth-management firm, allegedly suffered a data breach. Reports suggest that a large export of the firm's Salesforce CRM was compromised, with over 5 million records offered and more than 1.3 million containing personal information. It has been reported that approximately 326,000 individuals were affected, with exposed data including names, email addresses, phone numbers, birthdates, geographic locations, genders, and internal corporate and client-relationship information. No passwords were included in the exposed data.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Genders Company Information Birthdates
  • Records: 2,351,837
  • Lines: 5,769,885
  • Size: 2.15 GB
  • Passwords: No
In 2025, data from TrendingCustom (trendingcustom.com), a US-based e-commerce store selling personalized print-on-demand products, allegedly appeared on a hacking forum. Reports suggest an order export containing approximately 5,800 customers was exposed, including names, email addresses, phone numbers, physical shipping and billing addresses, and order and shipment details. The data did not include passwords.
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Order Information Site Activity Shipment Information
  • Records: 7,527
  • Lines: 7,527
  • Size: 28.71 MB
  • Passwords: No
In March 2023, TruckerSucker.com, an adult masculine-oriented dating and webcam community, allegedly suffered a data breach. Reports suggest approximately 85,000 individuals were exposed, including email addresses, usernames, names, and account passwords stored as salted MD5 hashes and, on the webcam module, plaintext.
  • Data: Email Addresses Passwords Names Usernames Websites
  • Records: 449,940
  • Lines: 8,074,045
  • Size: 6.64 GB
  • Passwords: MD5 Salted, Plaintext
In 2023, the cash-logistics and ATM cash-management platform Armorsign (armorsign.com) allegedly suffered a data breach. Reports suggest a database exported from the company's application was leaked. While the dump was large (around 5 million rows of operational routing, delivery and vault records), the exposed personal data was limited: roughly 700 user accounts, including email addresses, usernames and bcrypt-hashed passwords.
  • Date: 2023
  • Domain: armorsign.com
  • Country: United States
  • Category: Logistics & Transportation
  • Data: Email Addresses Passwords Geographic Locations Usernames Site Activity
  • Records: 751
  • Lines: 5,184,919
  • Size: 2.42 GB
  • Passwords: BCrypt
  • Cracked: 0%
In 2024, the United States jewelry retailer Slate & Tell (shopslateandtell.com) allegedly suffered a data breach. Slate & Tell is an online jewelry store specializing in personalized and gemstone pieces. Reports suggest the exposed database contained the records of approximately 358,000 customers, with data including email addresses, first and last names, postal and billing addresses, phone numbers, and passwords stored as MD5 hashes.
  • Date: 2024
  • Domain: shopslateandtell.com
  • Threat Actor: Chucky
  • Country: United States
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Site Activity Nationalities
  • Records: 529,184
  • Lines: 11,265,299
  • Size: 2.14 GB
  • Passwords: MD5
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.