Breach Intelligence

6,875

Total breached databases

In 2019, the US mobile payment service Venmo allegedly had millions of public transaction records scraped through its open API. Venmo is a peer-to-peer payment app owned by PayPal that, at the time, exposed transaction participants and details publicly by default. It has been reported that the data was harvested to highlight the privacy implications of these default settings. The exposed information covered approximately 7 million individuals and included usernames, display names, profile photos, and short user bios. No passwords or email addresses were exposed.
  • Date: Jun 2019
  • Domain: venmo.com
  • Threat Actor: Dan Salmon
  • Country: United States
  • Category: Finance & Payments
  • Data: Names Usernames Profile Photos Bios
  • Records: 14,101,436
  • Lines: 7,078,288
  • Size: 13.12 GB
  • Passwords: ?
In November 2021, QRS Healthcare Solutions allegedly suffered a data breach affecting its patient portal and phpBB-based user system. QRS Healthcare Solutions is a US-based healthcare software provider serving medical clinics primarily in the southeastern United States. Reports indicate the breach exposed data belonging to approximately 179,000 users, including full names, usernames, email addresses, phone numbers, physical addresses, genders, birthdates, government IDs, social security numbers, insurance information, IP addresses, and passwords stored as MD5 hashes.
  • Date: Nov 2021
  • Domain: qrshs.com
  • Country: United States
  • Category: Healthcare
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Government IDs Social Security Numbers Insurance Information Genders IP Addresses Websites Birthdates
  • Records: 14,469,428
  • Lines: 14,733,623
  • Size: 1.96 GB
  • Passwords: Hashed, MD5
  • Cracked: 0%
In January 2021, rworld.com, a website serving real estate agents across Broward, Palm Beaches, and St. Lucie in Florida, allegedly suffered a data breach. Reports suggest the exposed database contained approximately 83,000 records covering around 22,000 distinct individuals. The compromised data reportedly included email addresses, genders, IP addresses, and passwords stored as MD5 hashes.
  • Date: Jan 2021
  • Domain: rworld.com
  • Threat Actor: vfa
  • Country: United States
  • Category: Real Estate
  • Data: Email Addresses Passwords Genders IP Addresses
  • Records: 83,879
  • Lines: 83,930
  • Size: 7.09 MB
  • Passwords: MD5
  • Cracked: 0%
In January 2021, the American online firearms marketplace Guns.com allegedly suffered a data breach that was subsequently published on a hacking forum. Reports suggest the incident exposed approximately 375,000 unique individuals, with the leaked data including email addresses, usernames, names, phone numbers, physical and geographic locations, dates of birth, order and gun-purchase information, partial credit card details, and passwords stored as bcrypt hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Credit Card Information Order Information Birthdates
  • Records: 1,763,127
  • Lines: 15,181,857
  • Size: 5.27 GB
  • Passwords: BCrypt, MD5, SHA-256 Salted
  • Cracked: 26%
Sometime before 2013, the online soccer retailer Soccerone.com allegedly suffered a data breach, reportedly through SQL injection against its website. It has been reported that the exposed data covered roughly 1,700 individuals and included email addresses, plaintext passwords, names, phone numbers, geographic locations, usernames, and partial credit card information.
  • Date: 2013
  • Domain: soccerone.com
  • Country: United States
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Credit Card Information
  • Records: 2,195
  • Lines: 2,205
  • Size: 477.79 KB
  • Passwords: Plaintext
Sometime before 2019, US-based RF and microwave power amplifier manufacturer Empower RF Systems (empowerrf.com) allegedly suffered a data breach. It has been reported that the breach stemmed from a SQL injection of the company's website database, exposing a customer and contact list of approximately 7,600 individuals. The compromised data included email addresses, usernames, and geographic location details. No passwords were exposed in the affected records.
  • Date: 2019
  • Domain: empowerrf.com
  • Country: United States
  • Category: Industry
  • Data: Email Addresses Geographic Locations Usernames
  • Records: 7,660
  • Lines: 7,664
  • Size: 271.39 KB
  • Passwords: No
In January 2021, the US lead-generation and data-broker company Astoria Company allegedly suffered a data breach. Reports suggest the wider dataset, discovered by Night Lion Security, contained over 11 million unique email addresses, though Astoria Company subsequently disputed that the data originated from its services. This partial file, reportedly leaked by Vinny Troia, exposed approximately 1,500 individuals. The compromised data reportedly included email addresses, names, physical and IP addresses, phone numbers, dates of birth, employment and income details, and in some cases Social Security numbers, financial information, and health-related data.
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Credit Card Information Bank Account Information Financial Information Government IDs Social Security Numbers Health Information Consumption Habits Insurance Information IP Addresses Job Information Company Information Birthdates
  • Records: 2,665
  • Lines: 22,837,114
  • Size: 15.19 GB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.