Breach Intelligence

6,875

Total breached databases

In 2016, a list of over 33 million individuals in corporate America sourced from Dun & Bradstreet's NetProspex service was leaked online. D&B believe the targeted marketing data was lost by a customer who purchased it from them. It contained extensive personal and corporate information including names, email addresses, job titles and general information about the employer.
  • Data: Company Information Email Addresses Job Information Names Phone Numbers Physical Locations
  • Records: 45,657,645
  • Lines: 45,657,645
  • Size: 6.97 GB
  • Passwords: No
MatchUSA 2018

MatchUSA 2018

Sensitive
In January 2018, the US Based dating service MatchUSA suffered a data breach that impacted 208k users. The leak led to the exposure of data including Email addresses and Passwords stored in Plaintext.
  • Data: Email Addresses Passwords
  • Records: 208,539
  • Lines: 208,541
  • Size: 6.56 MB
  • Passwords: Plaintext
In March 2024, tens of millions of records allegedly breached from AT&T were posted to a popular hacking forum. Dating back to August 2021, the data was originally posted for sale before later being freely released. AT&T maintains that there has not been a breach of their systems and that the data originated from elsewhere. The incident exposed names, email and physical addresses, dates of birth, phone numbers and US social security numbers.
  • Data: Birthdates Email Addresses Government IDs Names Phone Numbers Physical Locations
  • Records: 73,481,539
  • Lines: 73,481,539
  • Size: 16.26 GB
  • Passwords: No
In July 2019, MGM Resorts International allegedly suffered a data breach affecting one of their cloud services. MGM Resorts is a major American hospitality and entertainment company that operates casino hotels including the MGM Grand, Bellagio, and Mandalay Bay in Las Vegas. Reports suggest approximately 10.6 million guest records were exposed, including names, email addresses, phone numbers, physical addresses, dates of birth, and genders. The breach was subsequently shared on a popular hacking forum in February 2020 where it was extensively redistributed.
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Genders Birthdates
  • Records: 10,613,129
  • Lines: 10,613,267
  • Size: 923.81 MB
  • Passwords: No
In April 2018, the textbook rental service Chegg suffered a data breach that impacted 40 million subscribers. The exposed data included email addresses, usernames, names and passwords stored as unsalted MD5 hashes.
  • Data: Email Addresses Names Passwords Usernames
  • Records: 37,417,079
  • Lines: 37,417,079
  • Size: 7.85 GB
  • Passwords: MD5
  • Cracked: 78%
In June 2023, the Tacoma-Pierce County Health Department announced a data breach of their Washington State Food Worker Card online training system. The breach was published to a popular hacking forum the year before and dated back to a 2018 database backup. Included in the data were 1.6M unique email addresses along with names, post codes, dates of birth and approximately 9.5k driver's licence numbers.
  • Data: Email Addresses Names Birthdates Geographic Locations Driving License Numbers
  • Records: 2,115,668
  • Lines: 2,115,669
  • Size: 369.42 MB
  • Passwords: No
A dataset consisting of around 44 million entries of car insurance data from the USA has been found online. The exact source and year of the breach remain unclear, but the records reportedly span several decades, including entries from 1986 to at least 2013. The exposed data includes sensitive information such as names, phone numbers, genders, license plate numbers, vehicle information, and physical addresses. Reports indicate that this dataset had previously been sold on a forum before being made publicly available. The origins and circumstances of the breach are still undetermined.
  • Date: 2023
  • Country: United States
  • Category: Automotive
  • Data: Names Phone Numbers Physical Locations Genders Vehicle Information License Plate Numbers
  • Records: 44,629,735
  • Lines: 44,629,735
  • Size: 5.77 GB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.