Breach Intelligence

6,139

Total breached databases

In March 2025, data belonging to Éclaireuses et Éclaireurs de France (EEDF), a French secular co-educational Scouting association, was allegedly leaked. Reports suggest that the records of approximately 44,000 members were exposed, including full names, email addresses, phone numbers, postal addresses, dates and places of birth, genders, and professions, as well as the contact details of members' legal guardians. The data was subsequently shared on a hacking forum.
  • Date: Mar 2025
  • Domain: eedf.fr
  • Country: France
  • Category: Others
  • Data: Email Addresses Names Phone Numbers Geographic Locations Genders Job Information Birthdates
  • Records: 44,156
  • Lines: 44,201
  • Size: 1.8 MB
  • Passwords: No
In August 2026, the email productivity service RightInbox (rightinbox.com) allegedly suffered a data breach. RightInbox is a Gmail add-on that lets users schedule emails, set reminders, and track email opens. Reports suggest that approximately 121,000 unique user profiles were exposed, including email addresses, IP addresses, geographic locations (city, region, country), device and browser information, and language preferences. The data was subsequently made available for free on a hacking forum.
  • Date: Aug 29, 2026
  • Domain: rightinbox.com
  • Threat Actor: BoneT4p
  • Category: Technology
  • Data: Email Addresses Geographic Locations IP Addresses Languages Device Information
  • Records: 121,616
  • Lines: 2,675,554
  • Size: 69.53 MB
  • Passwords: No
In 2026, a database belonging to the Institut Pemerintahan Dalam Negeri (IPDN, ipdn.ac.id), an Indonesian government institute under the Ministry of Home Affairs, was allegedly leaked. It has been reported that the data originated from two of the institute's web platforms (a WordPress site and a custom content-management system). The exposed data includes a small set of staff administrator accounts with MD5-hashed passwords, an administrative activity log of usernames and IP addresses, and website commenter records containing names, email addresses and IP addresses. In total the data of roughly 190 individuals was affected.
  • Date: 2026
  • Domain: ipdn.ac.id
  • Country: Indonesia
  • Category: Education
  • Data: Email Addresses Passwords Names Geographic Locations Usernames IP Addresses Site Activity Websites Job Information
  • Records: 4,145
  • Lines: 4,157
  • Size: 829.88 KB
  • Passwords: MD5
  • Cracked: 0%
In 2026, a dataset belonging to Politeknik Kesehatan Solo (poltekkes-solo.ac.id), an Indonesian health polytechnic, was allegedly leaked. It has been reported that the data originated from a community-service (KKN) program participant export. Reports suggest approximately 4,700 student records were exposed, including full names, genders, faculty and study-program details, postal addresses, and phone numbers. No passwords were included in the exposed data.
  • Data: Names Phone Numbers Geographic Locations Genders Personal Information
  • Records: 4,691
  • Lines: 1,144
  • Size: 341.04 KB
  • Passwords: No
In November 2025, AFPPCD-IDF, a French professional training association for dental assistants based in the Île-de-France (Paris) region, allegedly suffered a data breach after its extranet was compromised. The exposed data, publicly disclosed in January 2026, allegedly contained around 24,000 records of trainees and apprentices. The compromised information allegedly included names, email addresses, phone numbers, postal addresses, dates and places of birth, genders, and French social security numbers (NIR). No passwords were reportedly included in the exposed data.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Social Security Numbers Genders Birthdates
  • Records: 24,868
  • Lines: 24,868
  • Size: 18.15 MB
  • Passwords: No
In 2023, the Mexican e-commerce platform ClikStore (clikstore.com) allegedly suffered a data breach. It has been reported that a database containing customer and order records was exposed. Reports suggest the data of approximately 135,000 individuals was affected, including email addresses, names, genders, birth dates, phone numbers, postal addresses, and order information, along with some payment-card metadata. No account passwords were included in the exposed data.
  • Date: 2023
  • Domain: clikstore.com
  • Country: Mexico
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Geographic Locations Credit Card Information Order Information Genders Birthdates
  • Records: 912,480
  • Lines: 34,434,749
  • Size: 4.51 GB
  • Passwords: No
Sometime before October 2024, Chiva Immobilier (chiva-immobilier.fr), a French real estate agency based in Aurillac (later rebranded Laforêt Aurillac), allegedly suffered a data breach. Reports suggest the website's database was exposed, affecting property sellers, prospective buyers who submitted inquiries, newsletter/alert subscribers, and job applicants. The compromised data allegedly included names, email addresses, phone numbers, geographic locations, and, for a small number of administrator accounts, SHA-256 password hashes and a plaintext password. Approximately 1,200 unique individuals were affected.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations
  • Records: 2,432
  • Lines: 357,451
  • Size: 18.92 MB
  • Passwords: SHA-256, Plaintext

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.