Breach Intelligence

6,875

Total breached databases

Sometime before December 2019, the US-based trading education company Van Tharp Institute (vantharp.com) allegedly suffered a data breach of its Magento online store. The data later surfaced as part of the Cit0day breach collection. It has been reported that approximately 2,400 customer records were exposed, including email addresses, first and last names, account activity dates and salted SHA-256 password hashes.
  • Date: Dec 17, 2019
  • Domain: vantharp.com
  • Country: United States
  • Category: Education
  • Data: Email Addresses Passwords Names Site Activity
  • Records: 2,439
  • Lines: 2,439
  • Size: 773.79 KB
  • Passwords: SHA-256 Salted
  • Cracked: 0%
In March 2018, the US online food store lecoqcuisine.com allegedly suffered a data breach. Reports suggest approximately 4,000 customer records were exposed, including email addresses, names, phone numbers, geographic locations and salted MD5 password hashes.
  • Date: Mar 15, 2018
  • Domain: lecoqcuisine.com
  • Country: United States
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations
  • Records: 4,120
  • Lines: 4,128
  • Size: 588.25 KB
  • Passwords: MD5 Salted
  • Cracked: 0%
In May 2014, the online store holmeslumber.com allegedly suffered a data breach. Reports suggest the breach was later distributed as part of the Cit0day collection. Approximately 5,900 customer records were exposed, including email addresses, first and last names, and salted SHA-256 password hashes.
  • Date: May 19, 2014
  • Domain: holmeslumber.com
  • Country: United States
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names
  • Records: 5,887
  • Lines: 5,887
  • Size: 742.53 KB
  • Passwords: SHA-256 Salted
  • Cracked: 0%
In 2014, a snapshot of the State of Alabama's voter registration database (last updated around April 2014) was compiled and later redistributed on underground forums as part of a broader U.S. voter-data compilation. Alabama voter records are a matter of public record, but the aggregated dataset allegedly exposed personal information for approximately 130,000 registered voters. The compromised records allegedly included full names, residential and mailing addresses, dates of birth, genders, phone numbers, voter registration dates, and party affiliation.
  • Date: Apr 28, 2014
  • Domain: alabama.gov
  • Country: United States
  • Category: Government
  • Data: Names Phone Numbers Geographic Locations Genders Site Activity Birthdates
  • Records: 132,787
  • Lines: 132,788
  • Size: 30.51 MB
  • Passwords: No
In 2018, a voter registration database for the U.S. state of Utah was allegedly made available on a hacking forum. Reports suggest the records of approximately 730,000 registered voters were exposed. The exposed data allegedly included full names, residential addresses, dates of birth, phone numbers and political party affiliation. Voter roll data of this kind is generally obtainable as public record, though its aggregation and distribution raises privacy concerns.
  • Date: 2018
  • Domain: utah.gov
  • Country: United States
  • Category: Government
  • Data: Names Phone Numbers Geographic Locations Birthdates Political Affiliation
  • Records: 731,639
  • Lines: 731,639
  • Size: 350.83 MB
  • Passwords: No
In November 2020, the community forum of Memoria Press (memoriapress.com), a US classical-education and homeschool curriculum publisher, was allegedly compromised as part of the Cit0day breach collection. Reports suggest approximately 4,000 records were exposed, including email addresses, usernames, IP addresses and passwords stored as bcrypt and vBulletin hashes.
  • Date: Nov 2020
  • Domain: memoriapress.com
  • Country: United States
  • Category: Forums & Communities
  • Data: Email Addresses Passwords Usernames IP Addresses
  • Records: 4,081
  • Lines: 4,081
  • Size: 552.12 KB
  • Passwords: BCrypt, vBulletin
  • Cracked: 0%
In November 2015, a snapshot of the State of Florida's voter registration database (dated 9 November 2015) was compiled and later redistributed on underground forums as part of a broader U.S. voter-data compilation. Florida voter records are a matter of public record, but the aggregated dataset allegedly exposed personal information for approximately 13.1 million registered voters across the state's counties. The compromised records allegedly included full names, residential and mailing addresses, dates of birth, genders, voter registration dates, party affiliation, and — for a subset of voters — phone numbers and email addresses.
  • Date: Nov 9, 2015
  • Domain: florida.gov
  • Country: United States
  • Category: Government
  • Data: Email Addresses Names Phone Numbers Geographic Locations Genders Site Activity Birthdates
  • Records: 13,120,868
  • Lines: 13,120,868
  • Size: 1.91 GB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.