Breach Intelligence

6,875

Total breached databases

In approximately February 2020, The Chronicle of Higher Education allegedly suffered a data breach. The Chronicle is a leading American news source covering colleges, universities, and related issues in higher education. Reports suggest approximately 3.4 million user records were exposed, including email addresses, usernames, names, and passwords stored as DES and MD5Crypt hashes. The breach was attributed to the threat actor ShinyHunters and was subsequently shared on a popular hacking forum.
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Site Activity
  • Records: 3,447,842
  • Lines: 3,447,866
  • Size: 739.51 MB
  • Passwords: DES, MD5Crypt, Unknown
In March 2024, the Canadian discount store chain Giant Tiger Stores Limited (https://www.gianttiger.com/) suffered a data breach that exposed over 2.8 million clients. The breach includes over 2.8 million unique email addresses, names, phone numbers and physical addresses. The data was breached by @ShopifyGUY.
  • Data: Email Addresses Names Phone Numbers Physical Locations Site Activity
  • Records: 2,848,677
  • Lines: 199,272,000
  • Size: 5.93 GB
  • Passwords: No
On October 21, 2024, Hot Topic, Box Lunch, and Torrid suffered a major data breach, exposing the personal information of approximately 350 million customers. Data included names, emails, addresses, phone numbers, birth dates, loyalty and rewards details, as well as partial payment information.
  • Data: Birthdates Email Addresses Payment Information Phone Numbers
  • Records: 1,201,279,299
  • Lines: 1,201,279,303
  • Size: 347 GB
  • Passwords: No
In May 2016, BellaClear.com, a U.S.-based skincare website, experienced a data breach that reportedly affected approximately 328,000 users. Among the compromised data were real names, email addresses, physical addresses, and IP addresses.
  • Date: May 2016
  • Domain: bellaclear.com
  • Country: United States
  • Category: Healthcare
  • Data: Email Addresses Geographic Locations IP Addresses Names
  • Records: 327,320
  • Lines: 327,320
  • Size: 26.17 MB
  • Passwords: No
Sometime in 2022, a data breach exposed the personal information of approximately 1 million car owners in the United States. The leaked dataset, reportedly in CSV format and sized at 98.39 MB, included details such as full names, physical addresses (including city, state, and ZIP code), phone numbers, and vehicle information. Among the compromised vehicle data were the year, make, model, and VIN (Vehicle Identification Number) of the cars. The source of the leak remains unknown.
  • Date: 2022
  • Country: United States
  • Category: Automotive
  • Data: Names Physical Addresses Phone Numbers Vehicle Information
  • Records: 1,048,647
  • Lines: 1,048,648
  • Size: 98.39 MB
  • Passwords: No
Around January 30, 2023, the CLOP ransomware group exploited the CVE-2023-0669 vulnerability in the GoAnywhere server used by NationsBenefits, a healthcare and supplemental benefits provider. The breach reportedly exposed approximately 1,637,000 records. Among the compromised data were names, birthdates, genders, phone numbers, physical locations, relationship statuses, and tax identification numbers. No passwords were included.
  • Data: Birthdates Genders Names Phone Numbers Physical Locations Relationship Statuses Tax IDs
  • Records: 1,603,828
  • Lines: 1,637,569
  • Size: 506.72 MB
  • Passwords: No
Vertafore announced that information of 27.7 million Texas drivers has been accidentally exposed due to a human error in March 2020. The company disclosed this security breach this week, data was stored on an unsecured external storage service and they were accessed by an external party.“The files, which included driver information for licenses issued before February 2019, contained Texas driver license numbers, as well as names, dates of birth, addresses and vehicle registration histories. They did not contain any Social Security numbers or financial account information. No information misuse has been identified.”
  • Data: Birthdates Driving License Numbers Physical Locations Vehicle Information
  • Records: 30,070,951
  • Lines: 30,070,953
  • Size: 3.17 GB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.