Breach Intelligence

3,512

Total breached databases

Sometime before August 2022, server.trades.lk allegedly suffered a data breach. server.trades.lk was a shared hosting server operated by the Sri Lankan IT company Synotec Holdings, hosting an online business directory (trades.lk) alongside several co-hosted applications including a matrimonial service, a freelancer marketplace, an e-commerce store and a language-learning platform. Reports suggest the exposed phpMyAdmin database export contained records for approximately 2,600 individuals. The compromised data allegedly included email addresses, usernames, names, phone numbers, dates of birth, genders, government identification numbers, geographic locations, site activity, and passwords stored as BCrypt, MD5 and SHA-512 hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs Genders Site Activity Birthdates
  • Records: 5,168
  • Lines: 93,769
  • Size: 12.29 MB
  • Passwords: BCrypt, MD5, SHA-512
  • Cracked: 0%
Sometime before January 2023, the WooCommerce-based online store ainaascollection.com, hosted on infrastructure operated by a Pakistani web-hosting and development provider, allegedly suffered a data breach. It has been reported that a full server database export was exposed, covering the store's WordPress users, mail-server accounts and associated business records. Reports suggest that around 140 individuals were affected across roughly 400 records. The exposed data allegedly included email addresses, names, usernames, phone numbers, geographic locations, company information, websites, genders, site activity and passwords stored in a mix of bcrypt, PHPass and MD5crypt formats.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Genders Site Activity Websites Company Information
  • Records: 370
  • Size: 25.66 MB
  • Passwords: BCrypt, MD5Crypt, PHPass
  • Cracked: 0%
Sometime before 2023, SenseGiz allegedly suffered a data breach. SenseGiz is an Indian IoT company providing BLE sensor devices and a workplace safety and contact-tracing platform. It has been reported that a database exposing approximately 1,000 individuals was compromised. The exposed data allegedly included email addresses, names, phone numbers, geographic locations, site activity, and a plaintext password.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Site Activity
  • Records: 1,069
  • Lines: 10,093,881
  • Size: 1.01 GB
  • Passwords: Plaintext
Sometime before March 2023, the Hungarian shared web-hosting server behind kgymp.hu (server.jeck.hu) allegedly suffered a data breach. Reports suggest the compromised SQL dump exposed the mail, WordPress and Joomla account databases of several small Hungarian websites hosted on the server. Approximately 600 records covering several hundred individuals were affected, including email addresses, usernames, names, passwords (a mix of DES, MD5, BCrypt, PHPass and salted MD5 hashes), geographic locations and site activity.
  • Date: 2023
  • Domain: kgymp.hu
  • Country: Hungary
  • Category: Non-Profit & Charities
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Site Activity Company Information
  • Records: 586
  • Lines: 39,663
  • Size: 8.12 MB
  • Passwords: BCrypt, DES, MD5, MD5 Salted, PHPass
  • Cracked: 0%
Sometime around 2021, Proyecto Pura Vida, a Spanish-language online psychology and counseling platform, allegedly suffered a data breach. Reports suggest approximately 2,500 records were exposed. The compromised data allegedly included email addresses, plaintext passwords, names, job information, and birthdates, along with free-text survey responses describing personal and family situations.
  • Data: Email Addresses Passwords Names Job Information Birthdates
  • Records: 2,495
  • Lines: 3,273
  • Size: 654.68 KB
  • Passwords: Plaintext
Sometime before 2022, the SENATI-associated web application hosted on the pasajero.tech platform allegedly suffered a data breach. SENATI is Peru's National Service for Industrial Work Training. Reports suggest approximately 9,000 records were exposed, including email addresses, BCrypt-hashed passwords, full names, phone numbers, government-issued identification numbers, geographic locations, and site activity data.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Government IDs Site Activity
  • Records: 9,000
  • Lines: 45,202
  • Size: 5.01 MB
  • Passwords: BCrypt
  • Cracked: 0%
Sometime after January 2022, Isolic Infotech (isolic.com) allegedly suffered a data breach. Isolic Infotech is a software development and digital marketing company. Reports suggest a small WordPress database export was exposed, containing a handful of records including email addresses, usernames, hashed passwords (PHPass and MD5), personal websites, and site activity data.
  • Data: Email Addresses Passwords Usernames Site Activity Websites
  • Records: 4
  • Lines: 6,026
  • Size: 740.37 KB
  • Passwords: MD5, PHPass
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.