Breach Intelligence

6,139

Total breached databases

In February 2026, data from an alleged full network compromise of Mobi UZ (Universal Mobile Systems), an Uzbek telecommunications operator, was published on a hacking forum. Reports suggest the actor gained domain-administrator access across the corporate Active Directory environment and exfiltrated internal systems following a failed extortion attempt. The indexed portion consists of roughly 3,000 employee Active Directory accounts with their NTLM password hashes, drawn from a directory-services credential dump; the actor also claimed to have taken customer registrations, identity documents and financial data from internal databases, which are not part of this indexed set.
  • Date: Feb 2026
  • Domain: mobi.uz
  • Threat Actor: ByteToBreach
  • Country: Uzbekistan
  • Category: Telecommunications
  • Data: Passwords Geographic Locations Usernames Financial Information Government IDs Personal Information
  • Records: 3,000
  • Lines: 5,263
  • Size: 451.28 KB
  • Passwords: NTLM
  • Cracked: 0%
In 2025, SDIS 34 (sdis34.fr), the Service Départemental d'Incendie et de Secours de l'Hérault — the public fire and emergency service for the Hérault department in France — allegedly had a personnel roster leaked and shared for free on a hacking forum. Reports suggest the file was published by a threat actor using the handle Wumpus Sec. Although the listing claimed around 5,900 staff records, the data contained roughly 60 distinct personnel entries (the rest being duplicated rows), including staff names, ranks, and fire-station assignments. No passwords were included in the data.
  • Date: 2025
  • Domain: sdis34.fr
  • Threat Actor: Wumpus Sec
  • Country: France
  • Category: Government
  • Data: Names Geographic Locations Job Information
  • Records: 60
  • Lines: 5,940
  • Size: 294.96 KB
  • Passwords: No
In September 2026, AudioBee (audiobee.ai), a crowdsourcing platform providing audio transcription, voice recording and translation services for AI training, allegedly suffered a data breach. It has been reported that an analytics/event export of the platform's users was taken and leaked. Reports suggest data on approximately 1.1 million users was affected. The exposed data allegedly included email addresses, names, phone numbers, genders, birthdates, geographic locations, IP addresses, languages, device information, and site activity. No passwords were included.
  • Date: Sep 5, 2026
  • Domain: audiobee.ai
  • Threat Actor: GoreTerminal
  • Category: Technology
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Genders IP Addresses Site Activity Birthdates Languages Device Information
  • Records: 1,188,699
  • Lines: 1,188,699
  • Size: 854.36 MB
  • Passwords: No
In June 2026, a database allegedly belonging to Avícola El Madroño S.A., a Colombian poultry company based in Bucaramanga, was published on a hacking forum. Reports suggest the actor gained access through an exposed, unauthenticated backup directory on a company server and exfiltrated the backoffice database. The leak contained roughly 171,000 records covering customers, suppliers and staff, including names, email addresses, phone numbers, Colombian identification numbers, physical addresses, company information, birthdates, and a small set of internal user accounts with plaintext passwords.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs Company Information Birthdates
  • Records: 171,106
  • Lines: 3,102,915
  • Size: 862.94 MB
  • Passwords: Plaintext
In 2026, Ressource'brie (ressourcebrie.fr), a French volunteer-run resource center and non-profit association dedicated to environmental protection and recycling, allegedly suffered a data breach. Reports suggest a full SQL database dump of its internal management, HR, and application systems was shared on a hacking forum. It has been reported that approximately 270 records were exposed, including names, email addresses, phone numbers, postal addresses, dates of birth, usernames, and bcrypt-hashed passwords.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Security Credentials Site Activity Birthdates
  • Records: 275
  • Lines: 189,844
  • Size: 25.22 MB
  • Passwords: BCrypt
  • Cracked: 0%
In 2025, journaux.fr, the main French website for the online sale of newspapers and magazines by issue or subscription, allegedly suffered a data breach. Reports suggest billing and delivery records were extracted and shared on a hacking forum. It has been reported that approximately 270,000 records were exposed, including full names, postal addresses, cities, postal codes, countries, and salutations. No passwords were included in the data.
  • Date: 2025
  • Domain: journaux.fr
  • Country: France
  • Category: News & Media
  • Data: Names Physical Locations Geographic Locations Genders Company Information
  • Records: 271,622
  • Lines: 271,622
  • Size: 180.28 MB
  • Passwords: No
Sometime before 2026, Castella-Sports.ch, a Swiss sporting goods retailer based in Bulle specializing in cycling, skiing and outdoor equipment, allegedly suffered a data breach. It has been reported that the company's full CRM system was exported, exposing customer, contact, supplier and employee records along with sales and communication data. Reports suggest data on roughly 21,000 individuals was affected. The exposed data allegedly included email addresses, names, genders, phone numbers, postal and geographic locations, order information, job information, and company information. No passwords were included.
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Order Information Genders Job Information Company Information
  • Records: 62,038
  • Lines: 3,183,513
  • Size: 541.63 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.