Breach Intelligence

3,511

Total breached databases

Sometime before 2019, servua.com (Universal Service Ukraine) allegedly suffered a data breach. servua.com is a Ukrainian online store selling spare parts and components for special and construction equipment. It has been reported that the exposed OpenCart store database contained fewer than 10 records, including email addresses, names, usernames, phone numbers, IP addresses, geographic locations, and salted SHA-1 password hashes.
  • Date: 2019
  • Domain: servua.com
  • Country: Ukraine
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames IP Addresses Site Activity
  • Records: 9
  • Lines: 133,573
  • Size: 26.71 MB
  • Passwords: SHA-1 Salted
  • Cracked: 0%
In March 2023, a private Ragnarok Online game server operating under the domain server.poring-service.com allegedly suffered a data breach. The server ran on the rAthena game emulator and catered primarily to a Thai player base. Reports suggest approximately 4,500 player accounts were exposed, including email addresses, usernames, plaintext passwords, IP addresses, genders, birthdates and in-game activity records.
  • Data: Email Addresses Passwords Usernames Genders IP Addresses Site Activity Birthdates
  • Records: 4,538
  • Lines: 548,227
  • Size: 30.44 MB
  • Passwords: Plaintext
Sometime in or after August 2022, Shopanel (shopanel.xyz), a Brazilian web-hosting and e-commerce management panel, allegedly suffered a data breach. Reports suggest a database containing approximately 12 records was exposed, including email addresses, names, phone numbers, government IDs (CPF/CNPJ), geographic locations, site activity, and bcrypt-hashed passwords.
  • Date: 2022
  • Domain: shopanel.xyz
  • Country: Brazil
  • Category: Technology
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Government IDs Site Activity
  • Records: 12
  • Lines: 2,032
  • Size: 174.31 KB
  • Passwords: BCrypt
  • Cracked: 0%
Sometime before 2023, the marketing and customer-relationship database of Urbania Developer, a Panamanian real estate developer, was allegedly exposed. Reports suggest the breach stemmed from a Mautic marketing-automation dump and affected approximately 9,900 individuals. The exposed data allegedly included email addresses, names, phone numbers, geographic locations, usernames, site activity, and a small number of administrator passwords stored as BCrypt and PHPass hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Site Activity
  • Records: 81,497
  • Lines: 815,214
  • Size: 343.06 MB
  • Passwords: BCrypt, PHPass
  • Cracked: 0%
Sometime before August 2022, the Indian digital payments platform SecurePe (securepe.in) allegedly suffered a data breach. SecurePe is an all-in-one portal offering multi-modal payment solutions such as AEPS, recharges and bill payments to a network of agents and retailers. Reports suggest the full database was leaked, exposing approximately 52,000 records. The compromised data allegedly included email addresses, usernames, names, phone numbers, SHA-1 hashed passwords, postal addresses, company details, bank account information and government identifiers (PAN / Aadhaar).
  • Date: Aug 3, 2022
  • Domain: securepe.in
  • Country: India
  • Category: Finance & Payments
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Bank Account Information Government IDs Site Activity Websites Company Information
  • Records: 53,148
  • Lines: 960,065
  • Size: 290.88 MB
  • Passwords: PHPass, SHA-1
  • Cracked: 0%
Sometime before 2022, the SBI General Insurance point-of-sale (POS) agent portal allegedly suffered a data breach. The platform, developed by the technology vendor Indicosmic, was used to register and train insurance agents across India. It has been reported that approximately 68,000 records were exposed, including email addresses, MD5-hashed passwords, names, phone numbers, dates of birth, genders, geographic locations, government identifiers such as Aadhaar and PAN numbers, bank account information, and usernames.
  • Date: 2022
  • Domain: sbi.co.in
  • Country: India
  • Category: Finance & Payments
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Bank Account Information Government IDs Genders Site Activity Company Information Birthdates
  • Records: 68,447
  • Lines: 313,367
  • Size: 2.79 GB
  • Passwords: MD5
  • Cracked: 0%
Sometime before August 2022, server.trades.lk allegedly suffered a data breach. server.trades.lk was a shared hosting server operated by the Sri Lankan IT company Synotec Holdings, hosting an online business directory (trades.lk) alongside several co-hosted applications including a matrimonial service, a freelancer marketplace, an e-commerce store and a language-learning platform. Reports suggest the exposed phpMyAdmin database export contained records for approximately 2,600 individuals. The compromised data allegedly included email addresses, usernames, names, phone numbers, dates of birth, genders, government identification numbers, geographic locations, site activity, and passwords stored as BCrypt, MD5 and SHA-512 hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs Genders Site Activity Birthdates
  • Records: 5,168
  • Lines: 93,769
  • Size: 12.29 MB
  • Passwords: BCrypt, MD5, SHA-512
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.