Breach Intelligence

6,875

Total breached databases

In early 2014, the community website Pardeeville Car Show (pardeevillecarshow.com) allegedly suffered a data breach. The site, built on Drupal 6, hosted event registrations and photo galleries for an annual local car show in Pardeeville, Wisconsin. Reports indicate approximately 11,500 user records were exposed, including email addresses, usernames, geographic locations, site activity data, and MD5-hashed passwords.
  • Data: Email Addresses Passwords Geographic Locations Usernames Site Activity
  • Records: 11,390
  • Lines: 150,349
  • Size: 26.37 MB
  • Passwords: MD5
  • Cracked: 10%
Sometime before 2020, the Institute for Jewish Spirituality (IJS), at jewishspirituality.org, allegedly suffered a data breach. IJS is a U.S.-based non-profit organization offering Jewish meditation and mindfulness programs. Reports suggest approximately 2,000 records were exposed, including email addresses, names, phone numbers, geographic locations, usernames, site activity, company information, and bcrypt-hashed passwords.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Site Activity Company Information
  • Records: 2,082
  • Lines: 453,160
  • Size: 215.5 MB
  • Passwords: BCrypt
  • Cracked: 0%
Sometime in or before 2017, the Northwestern Medicine KOL database hosted at nm.org allegedly suffered a data breach. Reports suggest the dataset was an Aissel Solutions Key Opinion Leader (KOL) aggregator containing approximately 4,000 medical professionals' profiles across major US hospital networks, including Northwestern Medicine, Michigan Medicine, Duke Health, Henry Ford, Massachusetts General Hospital and Beth Israel Deaconess. The exposed records included names, work emails, phone numbers, specialties, biographies, geographic locations, social profiles, and a small set of internal staff accounts with BCrypt and PHPass password hashes.
  • Date: 2017
  • Domain: nm.org
  • Country: United States
  • Category: Data Brokers
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Genders Site Activity Social Profiles Websites Job Information Company Information
  • Records: 20,734
  • Lines: 79,682
  • Size: 114.77 MB
  • Passwords: BCrypt, PHPass
  • Cracked: 0%
Sometime in 2020, Maxtena (maxtena.com), a US-based manufacturer of GPS and satellite antenna products, allegedly suffered a data breach of its corporate WordPress website. Reports suggest approximately 38 individuals were affected, including staff and B2B distributor contacts. The compromised data included email addresses, usernames, names, PHPass password hashes, website URLs, and account activity dates.
  • Date: 2020
  • Domain: maxtena.com
  • Country: United States
  • Category: Technology
  • Data: Email Addresses Passwords Names Usernames Site Activity Websites
  • Records: 1,855
  • Lines: 32,027
  • Size: 12.03 MB
  • Passwords: PHPass
  • Cracked: 0%
In April 2015, the US-based whitewater rafting and adventure resort Adventures on the Gorge (adventuresonthegorge.com) allegedly suffered a data breach. Reports suggest the leak exposed approximately 10 individuals, including email addresses, usernames, names, IP addresses, site activity, and BCrypt-hashed passwords.
  • Data: Email Addresses Passwords Names Usernames IP Addresses Site Activity
  • Records: 36
  • Lines: 38,785
  • Size: 21.02 MB
  • Passwords: BCrypt
  • Cracked: 0%
In 2018, Lingerie Mart (lingeriemart.com), a US-based wholesale lingerie distributor serving retailers, allegedly suffered a data breach. Reports suggest approximately 23,000 records were exposed, including email addresses, names, usernames, phone numbers, geographic locations, IP addresses, company information, site activity records, and passwords stored as BCrypt and MD5 hashes.
  • Date: 2018
  • Domain: lingeriemart.com
  • Country: United States
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames IP Addresses Site Activity Company Information
  • Records: 71,477
  • Lines: 170,441
  • Size: 35.77 MB
  • Passwords: BCrypt, MD5
  • Cracked: 0%
In September 2011, the Ohio-based Nissan enthusiast forum Ohionissans.com allegedly suffered a data breach. The site was a community forum for Nissan owners and enthusiasts in Ohio, built on Simple Machines Forum (SMF). Reports suggest approximately 1,800 individuals were exposed, with the leaked data including email addresses, usernames, real names, SMF and MD5 password hashes, IP addresses, geographic locations, genders, birthdates, websites, and instant-messenger handles.
  • Date: Sep 2, 2011
  • Domain: ohionissans.com
  • Country: United States
  • Category: Automotive
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Genders IP Addresses Site Activity Social Profiles Websites Birthdates
  • Records: 5,803
  • Lines: 128,898
  • Size: 8.29 MB
  • Passwords: MD5, SMF
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.