Breach Intelligence

6,139

Total breached databases

In 2026, Lenormant.fr allegedly suffered a data breach. Lenormant is a French company specializing in the sale and distribution of agricultural equipment, machinery, tools, spare parts, and professional equipment. It has been reported that the breach originated from the company's BlgCloud CRM platform. Reports suggest approximately 60,000 records were exposed, including email addresses, names, phone numbers, postal addresses, job titles, and genders. No passwords were included in the exposed data.
  • Date: 2026
  • Domain: lenormant.fr
  • Country: France
  • Category: Professional & Corporate
  • Data: Email Addresses Names Phone Numbers Geographic Locations Genders Job Information
  • Records: 309,122
  • Lines: 256,606
  • Size: 1.66 GB
  • Passwords: No
In August 2026, the e-commerce product research and ad-spying platform Minea (minea.com) allegedly suffered a data breach. Reports suggest a dataset of approximately 533,000 unique user profiles was exposed, alongside a much larger set of associated user activity records. The exposed profile data reportedly included email addresses, IP addresses, geographic locations (city, country, region), device information, language, and site activity. It has been reported that no passwords were included in the leaked profiles.
  • Date: Aug 28, 2026
  • Domain: minea.com
  • Threat Actor: BoneT4p
  • Category: Technology
  • Data: Email Addresses Geographic Locations Financial Information Government IDs IP Addresses Site Activity Languages Device Information
  • Records: 533,162
  • Lines: 21,640,036
  • Size: 617.44 MB
  • Passwords: No
In mid-2024, the Bank of Tanzania (bot.go.tz), Tanzania's central bank, allegedly suffered a data breach affecting its Financial Service Providers registry. Reports suggest the exported records of approximately 3,600 licensed financial service providers (largely microcredit and microfinance companies) were exposed, including company names, contact email addresses, phone numbers, physical and postal addresses, tax identification numbers, and geographic locations. No passwords were included in the exposed data.
  • Date: Jun 2024
  • Domain: bot.go.tz
  • Country: Tanzania
  • Category: Finance & Payments
  • Data: Email Addresses Phone Numbers Geographic Locations Site Activity Company Information
  • Records: 3,663
  • Lines: 98,906
  • Size: 3.65 MB
  • Passwords: No
Sometime before February 2026, Al Akhawayn University (AUI), a leading private university based in Ifrane, Morocco, allegedly suffered a data breach. Reports suggest a database containing approximately 4,000 records of students and staff was exposed. The compromised data allegedly included names, email addresses, and geographic location information. No passwords were reportedly included in the exposed data.
  • Date: 2026
  • Domain: aui.ma
  • Country: Morocco
  • Category: Education
  • Data: Email Addresses Names Geographic Locations
  • Records: 4,029
  • Lines: 4,030
  • Size: 181.77 KB
  • Passwords: No
Sometime before 2026, Dream.co.nz, a New Zealand-based consumer business, allegedly suffered a data breach. Reports suggest a customer database was exposed and subsequently offered on a hacking forum. It has been reported that approximately 16,000 individuals were affected. The exposed data reportedly included email addresses, full names, phone numbers, physical addresses, genders, dates of birth, and IP addresses. No passwords were included in the dataset.
  • Date: 2026
  • Domain: dream.co.nz
  • Country: New Zealand
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Genders IP Addresses Birthdates
  • Records: 16,765
  • Lines: 16,766
  • Size: 1.96 MB
  • Passwords: No
Sometime before September 2022, data attributed to a compromise of Rosmorrechflot (the Russian Federal Agency for Sea and Inland Water Transport, morflot.gov.ru) was published on a hacking forum. Reports suggest the actor obtained Active Directory credentials and an internal staff directory. The indexed data covers roughly 250 intranet directory entries with employee names, usernames, email addresses, phone numbers and job titles, alongside around 1,300 Active Directory account NTLM hashes and a set of cracked password hashes. A separately claimed 'shop4vip' user table was hosted elsewhere and is not part of this indexed set.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Job Information
  • Records: 1,422
  • Lines: 2,121
  • Size: 272.74 KB
  • Passwords: MD5, NTLM, Plaintext
Sometime around 2026, RupaRupa (ruparupa.com), an Indonesian online retailer of home, furniture, appliance and lifestyle products, allegedly suffered a data breach. It has been reported that a set of registered customer records was leaked; while the seller claimed around 1.1 million records, the circulated dataset contains roughly 12,000 customers (about 7,000 with email addresses). The exposed data allegedly included names, email addresses, phone numbers, dates of birth, and genders. No passwords were included.
  • Date: 2026
  • Domain: ruparupa.com
  • Threat Actor: LionDataMarket
  • Country: Indonesia
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Geographic Locations Government IDs Genders Birthdates
  • Records: 11,963
  • Lines: 11,963
  • Size: 777.95 KB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.