Breach Intelligence

6,875

Total breached databases

In October 2018, the cryptocurrency advertising network Coinzilla (coinzilla.com) allegedly suffered a data breach. Reports suggest the exposed user database contained approximately 51,000 records, including email addresses, usernames, first and last names, account balances, and passwords stored as MD5 hashes.
  • Data: Email Addresses Passwords Names Usernames Financial Information Site Activity
  • Records: 51,356
  • Lines: 51,747
  • Size: 10.9 MB
  • Passwords: MD5
  • Cracked: 0%
Sometime before 2025, the Brazilian radio station Rádio Onda Sul (radioondasul.com.br) allegedly suffered a data breach of its WordPress site. Reports suggest a small number of accounts were exposed — approximately 10 individuals — including email addresses, usernames, and passwords stored as WordPress (phpass) hashes.
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Site Activity Websites
  • Records: 12
  • Lines: 4,897
  • Size: 1.19 MB
  • Passwords: PHPass
  • Cracked: 0%
In March 2025, the French marketing and customer-service company Vitalis (vitalis.fr) allegedly suffered a data breach. Reports suggest the incident occurred on 18 March 2025 via an SQL injection attack against its customer database, exposing approximately 202,500 records. The compromised data allegedly included names, email addresses, phone numbers, and company information. No passwords were reported as part of the exposed data.
  • Date: Mar 18, 2025
  • Domain: vitalis.fr
  • Country: France
  • Category: Professional & Corporate
  • Data: Email Addresses Names Phone Numbers Geographic Locations Company Information
  • Records: 202,568
  • Lines: 202,569
  • Size: 6.06 MB
  • Passwords: No
Crypto.com USA Leads allegedly consists of a marketing lead list of roughly 1 million individuals in the United States, circulated on hacking forums as being associated with the cryptocurrency platform crypto.com. Reports suggest the data was compiled and resold rather than obtained from a confirmed platform breach. The exposed records include email addresses, first and last names, phone numbers, and a US geographic scope, with no passwords present.
  • Domain: crypto.com
  • Country: United States
  • Category: Cryptocurrency
  • Data: Email Addresses Names Phone Numbers Geographic Locations
  • Records: 1,048,575
  • Lines: 175,937
  • Size: 58.65 MB
  • Passwords: No
Sometime before 2026, BitBox — the cryptocurrency hardware wallet made by the Swiss company Shift Crypto (shiftcrypto.ch) — allegedly suffered a data breach affecting its customer and newsletter CRM. Reports suggest the exposed data covers roughly 20,000 individuals with records dating from around 2020 to 2022. The compromised records reportedly include names, email addresses, phone numbers, usernames, IP addresses, order information and account activity. No passwords or wallet secrets were included in the exposed data.
  • Date: 2026
  • Domain: shiftcrypto.ch
  • Country: Switzerland
  • Category: Cryptocurrency
  • Data: Email Addresses Names Phone Numbers Geographic Locations Usernames Order Information IP Addresses Site Activity Job Information
  • Records: 20,852
  • Lines: 20,853
  • Size: 6.15 MB
  • Passwords: No
Sometime before 2025, a threat actor using the handle Soral allegedly leaked a dataset scraped from H1 (h1.co), a global healthcare technology and data-analytics company that maintains a worldwide directory of medical professionals. Reports suggest the dataset covers approximately 2 million medical professionals across many countries (France-dominant, alongside India, the Philippines, Pakistan and others). The compromised information reportedly includes full names, genders, cities and countries, medical specialties, workplaces, diplomas and professional biographies. No passwords or contact credentials were included.
  • Date: 2025
  • Domain: h1.co
  • Threat Actor: Soral
  • Category: Healthcare
  • Data: Names Geographic Locations Genders Profile Photos Job Information Company Information
  • Records: 2,064,071
  • Lines: 2,064,071
  • Size: 3.03 GB
  • Passwords: No
In January 2024, a full backup of Alexandria University (alexu.edu.eg) was allegedly leaked. Alexandria University is a large public university in Alexandria, Egypt. Reports suggest the exposed database dumps contained records for approximately 114,000 students, alumni, academic staff and employees. The compromised data allegedly included full names (in Arabic), Egyptian national ID numbers, birthdates, genders, phone numbers, physical addresses, job and department information, email addresses and usernames, alongside a small number of associated site-account password hashes.
  • Date: Jan 2024
  • Domain: alexu.edu.eg
  • Country: Egypt
  • Category: Education
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Government IDs Genders Social Profiles Job Information Birthdates
  • Records: 116,624
  • Lines: 5,210,167
  • Size: 1.14 GB
  • Passwords: PHPass
  • Cracked: 57800%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.