Breach Intelligence

6,875

Total breached databases

Sometime before May 2019, the online store at nutranextstage.com, associated with the US dietary-supplement and health-products company Nutranext (Wellnext Health), allegedly suffered a data breach. Reports suggest the exposed Magento customer database contained approximately 2,300 records, including email addresses, first and last names, account registration and activity dates, and salted SHA-256 password hashes.
  • Data: Email Addresses Passwords Names Site Activity Birthdates
  • Records: 2,321
  • Lines: 2,321
  • Size: 510.69 KB
  • Passwords: SHA-256 Salted
  • Cracked: 0%
Sometime before November 2020, the US online store wallysnatural.com allegedly suffered a data breach that surfaced as part of the Cit0day collection. Reports suggest approximately 4,000 customer records were exposed, including email addresses, first and last names, salted MD5 password hashes, phone numbers and postal addresses.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations
  • Records: 4,055
  • Lines: 4,386
  • Size: 731.38 KB
  • Passwords: MD5 Salted
  • Cracked: 0%
Sometime before September 2013, the US online store sweeperparts.net, a supplier of street-sweeper parts, allegedly suffered a data breach of its Magento store. It has been reported that approximately 1,600 customer records were exposed, including email addresses, first and last names and salted MD5 password hashes, with a small number also carrying phone numbers and addresses.
  • Date: Sep 19, 2013
  • Domain: sweeperparts.net
  • Country: United States
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations
  • Records: 1,588
  • Lines: 1,589
  • Size: 153.64 KB
  • Passwords: MD5 Salted
  • Cracked: 0%
Sometime before November 2020, the online magnifier/optical-aids store magnifier.com allegedly suffered a data breach that was later distributed as part of the Cit0day breach collection. It has been reported that approximately 235 genuine customer records were exposed, including email addresses, names, phone numbers, postal addresses and salted MD5 password hashes (spam-bot registrations in the raw dump were discarded).
  • Date: Nov 2020
  • Domain: magnifier.com
  • Country: United States
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations
  • Records: 235
  • Lines: 1,533
  • Size: 507.28 KB
  • Passwords: MD5 Salted
  • Cracked: 0%
Sometime before June 2017, the US online store godirectinc.com allegedly suffered a data breach. Reports suggest approximately 1,700 customer records were exposed, including email addresses, names, phone numbers, geographic locations and salted MD5 password hashes.
  • Date: Jun 9, 2017
  • Domain: godirectinc.com
  • Country: United States
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations
  • Records: 1,718
  • Lines: 1,768
  • Size: 243.71 KB
  • Passwords: MD5 Salted
  • Cracked: 0%
Sometime before November 2020, the US online adult/sex-toy store ussextoy.com allegedly suffered a data breach that was later distributed as part of the Cit0day breach collection. It has been reported that approximately 2,600 genuine customer records were exposed, including email addresses, names, phone numbers, postal addresses and salted MD5 password hashes (spam-bot registrations in the raw dump were discarded).
  • Date: Nov 2020
  • Domain: ussextoy.com
  • Country: United States
  • Category: Pornography
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations
  • Records: 2,634
  • Lines: 3,180
  • Size: 451.92 KB
  • Passwords: MD5 Salted
  • Cracked: 0%
Sometime before September 2018, the online store of Stronghold Safety Engineering (strongholdsafety.com), a US supplier of industrial machine-guarding and workplace-safety products and services, allegedly suffered a data breach. Reports suggest the exposed Magento customer database contained approximately 390 records, including email addresses, first and last names, account registration and activity dates, and salted SHA-256 password hashes.
  • Data: Email Addresses Passwords Names Site Activity
  • Records: 390
  • Lines: 390
  • Size: 89.36 KB
  • Passwords: SHA-256 Salted
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.