Breach Intelligence

6,875

Total breached databases

In 2015, Metropolitan State University (metrostate.edu), a public university in Saint Paul, Minnesota, allegedly suffered a data breach. Reports suggest the exposed data originated from the university's internal records warehouse, covering students, applicants, and staff. It has been reported that the breach affected approximately 100,000 individuals. The compromised data included email addresses, full names, birthdates, genders, ethnicities, geographic locations, phone numbers, job information, and a small number of Social Security numbers. The records did not contain account passwords.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Social Security Numbers Genders Job Information Birthdates Ethnicities
  • Records: 311,361
  • Lines: 588,635
  • Size: 70.63 MB
  • Passwords: No
Sometime around 2017, American Exchange Bank, a community bank based in Henryetta, Oklahoma, allegedly suffered a data breach. The compromised data originated from a Microsoft SQL Server database backup and reportedly exposed approximately 1,800 customer and staff records. It has been reported that the exposed information included email addresses, full names, Social Security numbers, dates of birth, phone numbers, postal addresses, and business tax identification numbers.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Social Security Numbers Tax IDs Job Information Birthdates
  • Records: 1,773
  • Lines: 1,775
  • Size: 141.34 KB
  • Passwords: ?
In March 2026, the American greeting card and gifts company Hallmark allegedly suffered a data breach after attackers reportedly gained access to data stored in its Salesforce environment and later published it following a failed extortion attempt. Reports suggest the incident affected approximately 1.8 million individuals across both Hallmark and the Hallmark+ streaming service. The exposed data is reported to have included email addresses, names, phone numbers, physical addresses and customer support tickets.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Genders Messages Company Information Birth Information
  • Records: 6,478,858
  • Lines: 6,554,421
  • Size: 9.18 GB
  • Passwords: ?
In April 2026, US home security firm ADT allegedly suffered a data breach attributed to the threat actor ShinyHunters, who reportedly listed the company as part of a "pay or leak" extortion attempt. Reports suggest approximately 5.5 million individuals were affected, with exposed data including email addresses, names, phone numbers and physical addresses. It has been reported that in a small percentage of cases, dates of birth and partial government-issued IDs such as the last four digits of Social Security numbers or Tax IDs were also included.
  • Data: Email Addresses Names Phone Numbers Physical Locations Government IDs Social Security Numbers Tax IDs Birthdates
  • Records: 10,687,718
  • Lines: 10,711,785
  • Size: 11.08 GB
  • Passwords: ?
In April 2026, the commercial real estate brokerage firm Marcus & Millichap was named as one of multiple alleged victims of the ShinyHunters hacking and extortion group. Data alleged to have been obtained from the company was subsequently released publicly and included 1.8M unique email addresses, along with names, phone numbers and employment-related information including employer, job title and physical company address. In their disclosure notice, Marcus & Millichap advised that data which may have been accessed appeared limited to "company forms, templates, marketing materials, and general contact information".
  • Data: Email Addresses Names Phone Numbers Physical Locations Job Information Company Information
  • Records: 29,908,889
  • Lines: 29,941,059
  • Size: 13.75 GB
  • Passwords: ?
In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign. The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part of a broader campaign targeting hundreds of organisations using the same method. The group later published tens of gigabytes of data they claimed included internal directory data, Salesforce records and Stripe payment logs. Among the 269k unique email addresses were names, phone numbers, physical addresses and partial payment card data including the last 4 digits, expiry dates and card brands. Kemper confirmed the incident and stated they had engaged third-party cybersecurity experts and notified law enforcement.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Usernames Credit Card Information Payment Information IP Addresses Job Information Birthdates
  • Records: 11,731,533
  • Lines: 13,179,126
  • Size: 4.51 GB
  • Passwords: ?
In May 2026, the dental benefits administrator DentaQuest was the target of a ShinyHunters "pay or leak" extortion campaign that resulted in the group publicly publishing hundreds of gigabytes of data allegedly obtained from the company. The data included 2.6M unique email addresses along with names, addresses and phone numbers. Much of the data appeared in healthcare enrollment files (ASC X12 transaction sets) containing Medicaid IDs, while additional data appeared in member records and related files. DentaQuest acknowledged "a cybersecurity incident involving unauthorized access to a limited portion of our network", and advised they had contained the attack and mitigated the threat.
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Government IDs Insurance Information Genders Birthdates
  • Records: 11,249,766
  • Lines: 11,249,904
  • Size: 1.55 GB
  • Passwords: ?

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.