Breach Intelligence

6,236

Total breached databases

In March 2025, tophorny.com, a Taiwanese WooCommerce-based adult-content store, allegedly had its WordPress database and site backend exposed. Reports suggest the dump was published by a threat actor and includes the store's WordPress accounts and a single customer order. The exposed data covers a small number of accounts — email addresses, usernames, PHPass password hashes, and one customer's full name, delivery address in Taichung City and phone number. The store appears to have been newly launched with almost no customer base at the time of the breach.
  • Date: Mar 5, 2025
  • Domain: tophorny.com
  • Threat Actor: Solonik
  • Country: Taiwan
  • Category: Pornography
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Time Zones
  • Records: 10
  • Lines: 10,272
  • Size: 5.98 MB
  • Passwords: PHPass
  • Cracked: 0%
Sometime around January 2026, the private French movie-streaming site Legumier (hosted on madeinaudio.com) allegedly suffered a data breach. Reports suggest its member database was exposed, containing roughly 100 users. The exposed data reportedly includes email addresses, plaintext passwords, first and last names, account creation and last-access dates, and in some cases a Bitcoin address used for account credit. No password hashing was in use — credentials were stored in cleartext.
  • Data: Email Addresses Passwords Names Geographic Locations Cryptocurrency Information Site Activity
  • Records: 125
  • Lines: 702,459
  • Size: 33.32 MB
  • Passwords: Plaintext
Sometime before August 2026, the Supply Chain Academy learning-management platform of Morgan Sindall Group, a UK construction and regeneration group, allegedly suffered a data breach. Reports suggest that a backup database covering approximately 9,000 supplier and subcontractor users was exposed. The exposed data allegedly included names, email addresses, IP addresses, company information, site-activity records and account passwords stored as MD5 hashes.
  • Date: 2026
  • Domain: morgansindall.com
  • Threat Actor: Persistent
  • Country: United Kingdom
  • Category: Industry
  • Data: Email Addresses Passwords Names Geographic Locations IP Addresses Site Activity Company Information
  • Records: 17,794
  • Lines: 994,104
  • Size: 141.92 MB
  • Passwords: MD5
  • Cracked: 0%
In February 2026, the engineering-management and developer-productivity platform Hatica (haticahq.com) allegedly suffered a data breach. Hatica is a Sequoia-backed SaaS that integrates with GitHub, Jira, Slack and calendars to compute engineering-productivity metrics, and also operates the DixiApp (PyjamaHR) Slack standup bot and the Posium (QAKit) test-automation product on the same infrastructure. It has been reported that an exposed GitHub token was used to exfiltrate 75 private repositories along with production database dumps from these products. The exposed data reportedly included approximately 14,600 individuals' email addresses, alongside names, phone numbers, plaintext application passwords, job and company information, and — per the disclosure — financial and identity data.
  • Data: Email Addresses Passwords Names Phone Numbers Credit Card Information Bank Account Information Social Security Numbers Job Information Company Information
  • Records: 17,320
  • Lines: 184,040,031
  • Size: 5.83 GB
  • Passwords: Plaintext
In 2026, Njik.sa, a Saudi Arabian marketplace and services mobile app, allegedly suffered a data breach of its backend database, which was subsequently shared on a hacking forum. Reports suggest the exposed data contained records for approximately 14,000 users, including email addresses, usernames, names, phone numbers, dates of birth, genders, geographic locations, and bcrypt-hashed passwords.
  • Date: 2026
  • Domain: njik.sa
  • Country: Saudi Arabia
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Genders Birthdates
  • Records: 14,368
  • Lines: 96,021
  • Size: 13.61 MB
  • Passwords: BCrypt
  • Cracked: 0%
In April 2026, the entire mailbox of the National Center for HIV/AIDS, Dermatology and STD (NCHADS) — a public health agency under Cambodia's Ministry of Health (nchads.org / nchads.gov.kh) — was allegedly published by a threat actor. Reports suggest the dump contained the agency's email archive, exposing correspondence with roughly 3,400 distinct email addresses of staff, partner organisations and external contacts. It has been reported that the leaked data consisted of email messages, subject lines, attachment metadata and the addresses of all correspondents; no passwords were included.
  • Date: Apr 10, 2026
  • Domain: nchads.gov.kh
  • Threat Actor: NormalLeVrai
  • Country: Cambodia
  • Category: Healthcare
  • Data: Email Addresses Genders
  • Records: 3,359
  • Lines: 54,943
  • Size: 11.95 MB
  • Passwords: No
In August 2026, a database allegedly belonging to afitmw.com (Afrika Voices Archive), a Malawi-based academic and research archive, was published on a hacking forum. Reports suggest the exposed data affected several hundred individuals across multiple roles including registered users, students, employees, and collaborators. The compromised records reportedly included full names, email addresses, usernames, telephone numbers, personal addresses, organisation affiliations, and account details, together with passwords stored as bcrypt and argon2 hashes as well as some employee passwords held in plaintext.
  • Date: Aug 17, 2026
  • Domain: afitmw.com
  • Threat Actor: Keishell & noname8173
  • Country: Malawi
  • Category: Education
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Site Activity Company Information
  • Records: 431
  • Lines: 2,347
  • Size: 1.81 MB
  • Passwords: BCrypt, Hashed Salted, Plaintext

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.