Breach Intelligence

6,236

Total breached databases

In November 2023, the Idaho National Laboratory (INL), a US Department of Energy national laboratory (inl.gov), allegedly suffered a data breach. The hacktivist group SiegedSec claimed responsibility for exfiltrating human-resources records from the lab's Oracle HR system. Reports suggest the stolen data was published on a hacking forum. The leak allegedly exposed approximately 37,000 current and former employees, with compromised data including full names, email addresses, Social Security numbers, dates of birth, home addresses, gender, marital status, employment details and account records.
  • Date: Nov 2023
  • Domain: inl.gov
  • Threat Actor: SiegedSec
  • Country: United States
  • Category: Government
  • Source: ransomware.live
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Usernames Government IDs Social Security Numbers Relationship Statuses Genders Site Activity Job Information Birthdates Date of Death
  • Records: 99,993
  • Lines: 1,313,150
  • Size: 205.39 MB
  • Passwords: No
Sometime before April 2026, badjourney.app, an AI "undressing" / deepfake-nudify website, allegedly suffered a data breach. According to the actor who published it, the site was compromised in early 2026. Reports suggest the exposed data covered approximately 15,000 users and included email addresses, display names, bcrypt-hashed passwords (with salts), Telegram IDs, Firebase UIDs, session and password-reset tokens, referral chains, and avatar URLs.
  • Date: 2026
  • Domain: badjourney.app
  • Threat Actor: imaloser
  • Category: Pornography
  • Data: Email Addresses Passwords Names Security Credentials Site Activity Social Profiles
  • Records: 15,043
  • Size: 6.77 MB
  • Passwords: BCrypt
  • Cracked: 0%
Sometime before 2023, the Ukrainian news website ReplyUA.net allegedly suffered a data breach. ReplyUA.net is a Ukrainian-language online news portal built on the DataLife Engine CMS. Reports suggest the site's user database was extracted and later shared on a hacking forum. The leak allegedly exposed approximately 140 registered users, with compromised data including email addresses, usernames, full names, cities, registration dates, IP addresses, and passwords stored as BCrypt and MD5 hashes.
  • Date: 2023
  • Domain: replyua.net
  • Country: Ukraine
  • Category: News & Media
  • Data: Email Addresses Passwords Names Geographic Locations IP Addresses
  • Records: 139
  • Lines: 1,824,866
  • Size: 1.37 GB
  • Passwords: BCrypt, MD5
  • Cracked: 0%
Sometime before 2026, SDIS04 (sdis04.fr) allegedly suffered a data breach. SDIS04 is the official Fire and Rescue Service of the Alpes-de-Haute-Provence department in France. Reports suggest a personnel database was exposed, containing roughly 145 firefighter records. The exposed data reportedly includes full names, ranks, email addresses, phone numbers, home addresses, dates and places of birth, genders, and next-of-kin contact details. No passwords were included.
  • Date: 2026
  • Domain: sdis04.fr
  • Threat Actor: ChimeraZ, Cybernox
  • Country: France
  • Category: Government
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Genders Job Information Birthdates Nationalities
  • Records: 145
  • Lines: 144
  • Size: 72.68 KB
  • Passwords: No
Sometime around 2025, ordal.co.id — an Indonesian business-consulting firm — allegedly had its WordPress database exposed. Reports suggest the leak covered a small number of site accounts and contacts. It has been reported that the compromised records included email addresses, usernames, display names, and bcrypt-hashed passwords.
  • Date: 2025
  • Domain: ordal.co.id
  • Country: Indonesia
  • Category: Professional & Corporate
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Site Activity Websites
  • Records: 12
  • Lines: 28,904
  • Size: 16.95 MB
  • Passwords: BCrypt, Hashed
  • Cracked: 0%
Sometime before 2026, NEOB2B (neob2b.co.kr), a South Korean B2B e-commerce/wholesale platform, allegedly suffered a data breach. Reports suggest the exposed data covered roughly 500 member accounts, including names, usernames, email addresses, phone numbers, postal addresses, business registration (tax) numbers and company information, along with AES-encrypted account passwords.
  • Domain: neob2b.co.kr
  • Country: South Korea
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Tax IDs Company Information
  • Records: 541
  • Lines: 153,616
  • Size: 51.97 MB
  • Passwords: Unknown
Sometime before August 2026, Cromakit (cromakit.es), a Spanish online store distributing laboratory supplies and materials, allegedly suffered a data breach. The exposed data came from the store's WooCommerce/WordPress database and, according to reports, covered roughly 1,300 customers. It included email addresses, usernames, names, phone numbers, physical/billing addresses, company details, IP addresses, order/registration activity, and phpass-hashed account passwords.
  • Date: 2026
  • Domain: cromakit.es
  • Country: Spain
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames IP Addresses Site Activity Websites Company Information
  • Records: 7,696
  • Lines: 3,881,954
  • Size: 622.29 MB
  • Passwords: PHPass
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.