Breach Intelligence

6,874

Total breached databases

In November 2021, the online lending marketplace LendingTree suffered a data breach. The breach included Email addresses, Full names, Full addresses, Phone numbers, IP addresses, Loan type, Loan cost. In total, 200k users were affected.
  • Data: Email Addresses Financial Information IP Addresses Names Phone Numbers Physical Locations
  • Records: 200,662
  • Lines: 200,703
  • Size: 42.58 MB
  • Passwords: No
In December 2020, the Oklahoma state Tourism and Recreation Department suffered a data breach. The incident exposed 637k email addresses across a variety of tables including age ranges against brochure orders and dates of birth against contest entries. Genders, names and physical addresses were also exposed.
  • Data: Ages Birthdates Email Addresses Genders Names Physical Locations
  • Records: 1,456,000
  • Lines: 2,796,313
  • Size: 369.53 MB
  • Passwords: No
On September 11, 2022, OakBend Medical Center, a hospital in the United States accessible via oakbendmedcenter.org, suffered a significant data breach. Reports indicate that approximately 1.1 million patient records were leaked, amounting to 1,116,472 lines of data in a CSV file with a total size of 991.28 MB. The exposed information reportedly included sensitive personal and medical details such as names, sex, dates of birth, Social Security Numbers, physical addresses, phone numbers, race, religion, medical record numbers, and hospital visit details. Additionally, the leaked data contained health-related information like allergies, diagnoses and medication preferences.
  • Date: 2022
  • Country: United States
  • Category: Healthcare
  • Data: Ages Birthdates Consumption Habits Email Addresses Ethnicities Genders Geographic Locations Health Information Languages Names Physical Descriptions Religions Social Security Numbers
  • Records: 1,122,712
  • Lines: 1,122,714
  • Size: 991.28 MB
  • Passwords: No
In November 2015, the US internet and cable TV provider Comcast suffered a data breach that exposed 590k customer email addresses and plain text passwords. A further 27k accounts appeared with home addresses with the entire data set being sold on underground forums.
  • Data: Email Addresses Passwords Physical Locations
  • Records: 617,560
  • Lines: 617,560
  • Size: 19.67 MB
  • Passwords: Plaintext
Approximately in June 2024, Los Angeles Unified School District suffered a data breach that exposed over.The breach exposed data including over 24 million data contains over 2 million unique email addresses and also contains students, parents and staff members ages, dates of birth, education levels, ethnicities, family members' names, family structure, genders, government issued IDs (SSN's), home ownership statuses, income levels, job titles, names, net worths, phone numbers, physical addresses, school grades (class levels), spoken languages and usernames.The leak also included various social statuses of students, such as poverty, homelessness, migrant status, etc.
  • Date: Jun 2024
  • Country: United States
  • Category: Education
  • Data: Ages Balances Birthdates Education Email Addresses Ethnicities Family Members Financial Information Genders Government IDs Job Information Languages Marital Statuses Names Phone Numbers Physical Locations Real Estate Information Usernames
  • Records: 24,210,785
  • Lines: 24,210,787
  • Size: 9.55 GB
  • Passwords: No
DoorDash data from 2019 was leaked, affecting both US and Canadian users. The leak exposed records including phone numbers, email addresses, account credits, and subscription statuses. The breach affected 253,644 individuals.
  • Date: 2019
  • Domain: doordash.com
  • Country: United States
  • Category: E-commerce & Retail
  • Data: Email Addresses Phone Numbers Government IDs
  • Records: 240,612
  • Lines: 253,682
  • Size: 173.22 MB
  • Passwords: No
Approximately between 2022-2023, the U.S. Environmental Protection Agency (https://www.epa.gov/) suffered a data breach impacting over 8.5 million users and exposing personal and sensitive information of its customers and contractors. A hacker operating under the pseudonym @USDoD claimed responsibility and released the EPA's global contact database on a dark web forum. The leaked database contained three zipped files with approximately 500MB of data in CSV formats, holding common fields such as "Zipcodes," "Full names," "Phone numbers," "Email addresses," and "County, City, States," as well as additional fields in each file.
  • Date: 2023
  • Domain: epa.gov
  • Threat Actor: USDoD
  • Country: United States
  • Category: Government
  • Data: Email Addresses Job Information Names Phone Numbers Physical Locations
  • Records: 8,497,246
  • Lines: 8,497,247
  • Size: 1.53 GB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.