Breach Intelligence

6,875

Total breached databases

Lexipol 2025

Lexipol 2025

Sensitive
In February 2025, Lexipol (lexipol.com), a US company providing policy management and training systems for public-safety agencies, allegedly suffered a data breach attributed to the self-proclaimed "Puppygirl Hacker Polycule". Reports suggest the exposed data contained roughly 670,000 records of law-enforcement, fire and other first-responder personnel across US agencies, including names, email addresses, system-generated usernames, and passwords stored as MD5 or SHA-256 hashes.
  • Date: Feb 11, 2025
  • Domain: lexipol.com
  • Threat Actor: Puppygirl Hacker Polycule
  • Country: United States
  • Category: Law Enforcement
  • Source: haveibeenpwned.com
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Site Activity
  • Records: 670,692
  • Lines: 863,292
  • Size: 1.66 GB
  • Passwords: MD5, SHA-256
  • Cracked: 0%
In May 2024, the customer databases of several US Audi dealerships — including Audi Albany, Audi Atlanta, Audi Farmington Hills, Audi Long Beach, Audi West Palm Beach and Audi Burlington — allegedly suffered a data breach. Reports suggest around 21,900 dealership customer records (largely automotive repair and body-shop businesses) were exposed. It has been reported that the compromised data included business/customer names, postal addresses, phone numbers, email addresses and sales/order information. No passwords were included.
  • Date: May 2024
  • Domain: audi.com
  • Country: United States
  • Category: Automotive
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Order Information Company Information
  • Records: 21,867
  • Lines: 22,366
  • Size: 3.68 MB
  • Passwords: No
Visit Yakima (visityakima.com), the tourism and visitors' bureau for the Yakima Valley in Washington State, USA, allegedly had a database exposed after its website was defaced. It has been reported that approximately 35,000 sweepstakes/getaway entry records were leaked, covering around 6,600 distinct entrants and including email addresses, first and last names, phone numbers, ZIP codes, and entry dates. No passwords were included.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Site Activity
  • Records: 35,289
  • Lines: 35,297
  • Size: 8.59 MB
  • Passwords: No
In August 2025, TraxNYC (traxnyc.com), a New York-based luxury custom jewelry brand, allegedly suffered a data breach of its customer order database. Reports suggest the data of approximately 120,000 customers was exposed across roughly 182,000 order records. The exposed information allegedly included full names, email addresses, phone numbers, shipping addresses, and order details (dates, status, and product information). The dataset contained no passwords.
  • Date: Aug 2025
  • Domain: traxnyc.com
  • Threat Actor: wikkid
  • Country: United States
  • Category: E-commerce & Retail
  • Data: Email Addresses Phone Numbers Physical Locations Order Information Personal Information
  • Records: 182,317
  • Lines: 182,327
  • Size: 49.79 MB
  • Passwords: No
In September 2026, the American energy utility CenterPoint Energy (centerpointenergy.com) allegedly suffered a data breach. Reports suggest the data was obtained by abusing a poorly protected company API, and that approximately 6.7 million customer records were exposed. The compromised data allegedly includes email addresses, full names, phone numbers, physical service and billing addresses, account and billing details, driving license numbers, and the last four digits of Social Security numbers. No passwords were included in the exposed data.
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Financial Information Government IDs Social Security Numbers Site Activity Driving License Numbers
  • Records: 6,718,261
  • Lines: 6,734,901
  • Size: 1.62 GB
  • Passwords: No
Roadtrippers (roadtrippers.com), a United States-based road-trip planning website and mobile application, allegedly suffered a data breach. Reports suggest a database of user account credentials was exposed, with the full dataset totalling roughly 2.5 million records. This file contains a cracked subset of approximately 433,500 records, consisting of bcrypt password hashes recovered to plaintext passwords.
  • Data: Passwords
  • Records: 433,534
  • Lines: 433,534
  • Size: 31.97 MB
  • Passwords: BCrypt
  • Cracked: 100%
lakerstats.com allegedly suffered a data breach. lakerstats.com was a Los Angeles Lakers basketball statistics and fan community website with a vBulletin discussion forum. Reports suggest approximately 33,000 records were exposed, including passwords stored as vBulletin and salted MD5 hashes with cracked plaintext values.
  • Data: Passwords
  • Records: 33,077
  • Lines: 33,077
  • Size: 1.84 MB
  • Passwords: vBulletin, MD5 Salted, Plaintext

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.