Breach Intelligence

6,195

Total breached databases

CTP.eu, the corporate WordPress website of CTP N.V., a pan-European commercial and industrial real-estate developer, allegedly suffered a data breach. Reports suggest the exposed data contained records for approximately 40 website user accounts, mostly staff and administrators. The compromised information allegedly included usernames, email addresses, names, and passwords stored as WordPress phpass hashes.
  • Data: Email Addresses Passwords Names Usernames
  • Records: 40
  • Lines: 41
  • Size: 5.02 KB
  • Passwords: Hashed, PHPass
  • Cracked: 0%
Sometime before mid-2025, an employee payroll system belonging to the Banjarnegara Regency government in Central Java, Indonesia (baratrust.banjarnegarakab.go.id), allegedly suffered a data breach. Reports suggest that civil-service payroll archives were exposed, covering approximately 2,800 employees across multiple salary periods. The compromised data allegedly included full names, Indonesian civil-service identification numbers (NIP), job titles and classes, work units, gross and net salaries, TPP performance-allowance calculations, BPJS insurance contributions, and tax (PPh) figures. No passwords or email addresses were present.
  • Data: Names Geographic Locations Financial Information Government IDs Insurance Information Salaries Job Information
  • Records: 8,746
  • Lines: 7,576
  • Size: 1.09 MB
  • Passwords: No
QBD Group (qbd.eu), a European quality, compliance and engineering consultancy serving the life sciences and pharmaceutical industry, allegedly suffered a data breach of the user database behind its WordPress website. Reports suggest approximately 100 accounts were exposed, largely belonging to staff and consultants across the group's Belgian and Spanish operations. The compromised data reportedly included email addresses, usernames, full names, and passwords stored as WordPress phpass hashes.
  • Domain: qbd.eu
  • Category: Professional & Corporate
  • Data: Email Addresses Passwords Names Usernames Websites
  • Records: 116
  • Lines: 3,726
  • Size: 294.77 KB
  • Passwords: PHPass
  • Cracked: 0%
In August 2024, PT Sky Indonesia (sky.co.id), an Indonesian company, allegedly had a database extract published on a hacking forum by a threat actor using the handle "JATIM RedStorm Xploit." It has been reported that the exposed data included around 800 email addresses along with company and contact names, phone numbers, office and factory addresses, bank names and export-destination information. No passwords were included.
  • Date: 2024
  • Domain: sky.co.id
  • Threat Actor: JATIM RedStorm Xploit
  • Country: Indonesia
  • Category: Others
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Bank Account Information Company Information
  • Records: 1,068
  • Lines: 3,485
  • Size: 70.01 KB
  • Passwords: No
In 2026, the Grand Synagogue of Levallois (CCL Levallois, ccl-levallois.com) — a French Jewish community center in Levallois-Perret — allegedly suffered a data breach. Reports suggest an attacker exfiltrated the community's event/appointment calendar and member contact list, which were then shared on a hacking forum. It has been reported that the exposed data covered several hundred members. The compromised records allegedly included full names, email addresses, and phone numbers tied to religious and community events (Bar/Bat Mitzvah, Brit Mila, and other gatherings).
  • Data: Email Addresses Names Phone Numbers Geographic Locations
  • Records: 560
  • Lines: 563
  • Size: 148.06 KB
  • Passwords: No
Sometime before October 2024, the TJSLBU / UMKM (micro, small and medium enterprise) registry of the Pekalongan City government in Central Java, Indonesia (pekalongankota.go.id) allegedly suffered a data breach. Reports suggest the exposed database, attributed to the actor ZALCYBER, covered roughly 300 records spanning registered businesses, institutions and system user accounts. The data allegedly included business and owner names, Indonesian national identity numbers (NIK), email addresses, phone numbers, home and business addresses, geographic coordinates, genders, account usernames, and MD5-hashed passwords (some with recovered plaintext).
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Government IDs Genders Websites Company Information
  • Records: 263
  • Lines: 271
  • Size: 42.79 KB
  • Passwords: MD5, Plaintext
In November 2025, Myareal.ru, a Russian medical laboratory offering allergy testing, allegedly suffered a data breach. Reports suggest the exposed data originated from the lab's customer and test-order tables. It has been reported that over 300 individuals were affected, with the leaked data including full names, email addresses, phone numbers, delivery addresses, and allergy test results.
  • Date: Nov 2025
  • Domain: myareal.ru
  • Country: Russia
  • Category: Healthcare
  • Data: Email Addresses Names Phone Numbers Physical Locations Health Information
  • Records: 1,076
  • Lines: 1,082
  • Size: 149.55 KB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.