Breach Intelligence

2,841

Total breached databases

DiskUnion, a Japanese record chain retailer and music distributor, experienced a data breach that affected 702k consumers around June 2022. Email addresses, full names, residential addresses, phone numbers, and plaintext passwords were all exposed in the incident.
  • Data: The exact data fields compromised in the diskunion.net 2022 breach are still under review. Updates will be published when confirmed.
  • Imported:
  • Passwords: ?
In December 2016, the forum for the public blockchain-based distributed computing platform Ethereum reportedly suffered a data breach. The incident exposed over 16,000 unique email addresses, along with IP addresses, private forum messages, and passwords, most of which were hashed with bcrypt.
  • Data: Email Addresses IP Addresses Messages Passwords Site Activity Usernames
  • Imported:
  • Passwords: BCrypt
  • Cracked: 0%
27 Region (Хабаровске) We are waiting for you 24 hours a day. Popular, official forum in Khabarovsk 27Region.Ru suffered a data breach exposing 42k email addresses, usernames and passwords etc.
  • Domain: 27region.ru
  • Country: Russia
  • Category: News & Media
  • Records Announced: 42,170
  • Data: The types of personal information exposed in the 27region.ru (Хабаровске) breach are not yet confirmed. This entry will be updated once verified sources provide details.
  • Imported:
  • Passwords: ?
In March 2019, the multiplayer platform game Everybody Edits suffered a data breach. The incident exposed 871k unique email addresses alongside usernames and IP addresses. The data was subsequently distributed online across a collection of files.
  • Data: Email Addresses IP Addresses Usernames
  • Imported:
  • Passwords: WordPress
  • Cracked: 0%
Metropolis shopping center is one of the largest modern shopping centers in Moscow. More than 360 shops and restaurants, a cinema, shops mall experienced a data leak that affected 80k members in 2022. Phones, email addresses, names were among the data exposed.
  • Data: The exact data fields compromised in the Metropolis.moscow (ТЦ МЕТРОПОЛИС) 2022 breach are still under review. Updates will be published when confirmed.
  • Imported:
  • Passwords: ?
In October 2022, the GTA mod menu provider RealDudesInc suffered a data breach that exposed over 100k email addresses (many of which are temporary guest account addresses). The breach also included usernames and bcrypt password hashes.
  • Data: Email Addresses Passwords Usernames
  • Imported:
  • Number of lines: 2,258,181
  • Size: 76.1 MB
  • Passwords: BCrypt
  • Cracked: 3%
In August 2020, Experian South Africa suffered a data breach which exposed the personal information of tens of millions of individuals. Only 1.3M of the records contained email addresses, whilst most contained government issued identity numbers, names, addresses, occupations and employers, amongst other person information.
  • Date: Aug 19, 2020
  • Country: South Africa
  • Category: Data Brokers
  • Records Announced: 1,284,637
  • Source: haveibeenpwned.com
  • Data: Company Information Email Addresses Government IDs Job Information Names Phone Numbers
  • Imported:
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.