Breach Intelligence

6,875

Total breached databases

In February 2015, the website of American nerdcore hip-hop artist MC Frontalot (frontalot.com) allegedly suffered a data breach. Reports suggest this dataset of approximately 27,000 records was exposed, including MD5 password hashes and their recovered plaintext passwords.
  • Data: Passwords
  • Records: 27,154
  • Lines: 27,154
  • Size: 1.26 MB
  • Passwords: MD5, MD5 Salted, Unknown, Plaintext
In September 2020, the used-Corvette classifieds website usedcorvettesonline.com allegedly suffered a data breach. Reports suggest the original dataset contained roughly 20,000 records including email addresses, phone numbers and MD5-hashed passwords. This indexed subset covers approximately 18,000 recovered password records.
  • Data: Passwords
  • Records: 18,405
  • Lines: 18,405
  • Size: 854.5 KB
  • Passwords: MD5, MD5 Salted
  • Cracked: 100%
immihelp.com allegedly suffered a data breach. immihelp.com is a US immigration information and resources website that hosts a community discussion forum. Reports suggest approximately 184,000 records were exposed, including passwords stored as vBulletin (salted MD5) hashes with cracked plaintext values.
  • Domain: immihelp.com
  • Country: United States
  • Category: Forums & Communities
  • Data: Passwords
  • Records: 184,257
  • Lines: 184,290
  • Size: 11.91 MB
  • Passwords: vBulletin, Plaintext
In September 2020, the US website of XADO (xado.us), an automotive lubricants and chemical additives brand, allegedly suffered a data breach. Reports suggest the exposed data included approximately 12,700 records containing email addresses, phone numbers and passwords. The dataset processed here comprises roughly 7,300 cracked MD5 password hashes with their recovered plaintext values.
  • Date: Sep 16, 2020
  • Domain: xado.us
  • Country: United States
  • Category: Automotive
  • Source: hashmob.net
  • Data: Passwords Geographic Locations
  • Records: 7,297
  • Lines: 7,297
  • Size: 335.02 KB
  • Passwords: MD5
  • Cracked: 100%
In September 2020, the US education site floridaedu.us allegedly suffered a data breach. Reports suggest the exposed data included email addresses, usernames and passwords stored as MD5 hashes. This dataset contains approximately 6,800 cracked account credentials recovered from the breach.
  • Data: Passwords Geographic Locations
  • Records: 6,800
  • Lines: 6,801
  • Size: 317.03 KB
  • Passwords: MD5
  • Cracked: 100%
In April 2019, the US-based luxury fashion e-commerce marketplace Moda Operandi (modaoperandi.com) allegedly suffered a data breach. Reports suggest that around 1.3 million records were exposed in the wider incident. This particular dataset contains approximately 107,000 DjangoSHA1 password hashes that have been cracked to their plaintext values, exposing account credentials.
  • Data: Passwords
  • Records: 107,386
  • Lines: 107,386
  • Size: 7.34 MB
  • Passwords: Django, Plaintext
iCracked allegedly suffered a data breach. iCracked was a US-based on-demand smartphone and device repair and buyback service. Reports suggest approximately 127 records were exposed, including passwords stored as BCrypt and WordPress (phpass) hashes.
  • Data: Passwords
  • Records: 127
  • Lines: 127
  • Size: 7.35 KB
  • Passwords: BCrypt, PHPass
  • Cracked: 100%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.