Breach Intelligence

6,875

Total breached databases

On May 1, 2024, a threat actor known as "USDoD" reportedly leaked a dataset referred to as the “USA Criminal Records” database, containing approximately 70 million records. The breach, shared on underground forums, included sensitive information such as names, birthdates, physical locations, genders, ethnicities, physical descriptions, and criminal record details including arrest and conviction data. No passwords were included.
  • Date: May 2024
  • Threat Actor: USDoD
  • Country: United States
  • Category: Government
  • Data: Birthdates Criminal Information Ethnicities Genders Names Physical Descriptions Physical Locations
  • Records: 70,324,591
  • Lines: 70,324,592
  • Size: 21.62 GB
  • Passwords: No
In 2009 the USA Boat Owners database was first discovered containing 2.9 million boat owners all around the country. This leak was not found anywhere publicly on the internet before being leaked here and therefore has been marked as Exclusive.
  • Date: 2009
  • Domain: usa.gov
  • Country: United States
  • Category: Government
  • Data: Birthdates Email Addresses Names Physical Locations Usernames
  • Records: 2,247,660
  • Lines: 2,247,669
  • Size: 291.37 MB
  • Passwords: No
In June 2020, the digital banking app Dave suffered a data breach which exposed 7.5 million rows of data and subsequently appeared for public download on a hacking forum. The breach exposed extensive personal information including almost 3 million unique email addresses alongside names, dates of birth, encrypted social security numbers and passwords stored as bcrypt hashes.
  • Data: Birthdates Email Addresses Names Passwords Phone Numbers Physical Locations Social Security Numbers
  • Records: 7,516,584
  • Lines: 7,516,691
  • Size: 4.04 GB
  • Passwords: BCrypt
  • Cracked: 21%
In December 2011, "Anonymous" attacked the global intelligence company known as "Stratfor" and consequently disclosed a veritable treasure trove of data including hundreds of gigabytes of email and tens of thousands of credit card details which were promptly used by the attackers to make charitable donations (among other uses). The breach also included 860,000 user accounts complete with email address, time zone, some internal system data and MD5 hashed passwords with no salt.
  • Data: Credit Card Information Email Addresses Names Passwords Phone Numbers Physical Locations Usernames
  • Records: 860,160
  • Lines: 860,162
  • Size: 193.55 MB
  • Passwords: MD5
  • Cracked: 95%
In May 2024, the Neiman Marcus Group, Inc. - American integrated luxury retailer was breached by @ShinyHunters and after the company's refusal to pay the ransom, the data was published on forums. The leak contained data on more than 40 million customers and included over 29.7 million unique email addresses, account balances, browser user agent details, credit cards, dates of birth, gift cards, IP addresses, names, payment histories, payment methods, phone numbers, physical addresses. ShinyHunters themselves explained the leak like this - "Neiman Marcus didn't pay the small fee for deletion, hiding behind legal terms they invented; so we decided Neiman Marcus can pay $200 million in fines instead, we are giving for free the hottest base (of the hour)".
  • Date: Apr 14, 2024
  • Threat Actor: ShinyHunters
  • Country: United States
  • Category: E-commerce & Retail
  • Source: haveibeenpwned.com
  • Data: Birthdates Credit Card Information Email Addresses IP Addresses Names Order Information Phone Numbers Physical Locations
  • Records: 159,806,032
  • Lines: 159,806,066
  • Size: 79.34 GB
  • Passwords: Plaintext
This is the official American Social Security Death Master File dated October of 2011, originally provided by "crazyoldfart" from the now defunct RaidForums. It contains Social Security Numbers, Full Names and Dates of Death and Birth.
  • Date: 2011
  • Domain: ssa.gov
  • Country: United States
  • Category: Government
  • Data: Birthdates Date of Death Names Social Security Numbers
  • Records: 85,822,194
  • Lines: 85,822,194
  • Size: 8.07 GB
  • Passwords: No
In 2003, a dataset titled “USA Business & Investor” was reportedly leaked, containing approximately 8,190,841 records. The data appeared to include information from businesses and investors across the United States. Among the compromised data were email addresses, phone numbers, fax numbers, physical locations, websites, company details, and financial information. No passwords were included. While the specific source of the leak remains unclear, the dataset has circulated under the assumption that it originated from a U.S. government or business-related database.
  • Date: 2003
  • Domain: usa.gov
  • Country: United States
  • Category: Professional & Corporate
  • Data: Company Information Email Addresses Fax Numbers Financial Information Phone Numbers Physical Locations Websites
  • Records: 8,190,747
  • Lines: 8,190,841
  • Size: 1.46 GB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.