Breach Intelligence

6,195

Total breached databases

Sometime before 2025, the French free real-estate listing website Immo-Gratuit.com allegedly suffered a data breach. Reports suggest a threat actor extracted the site's `identite` user table via a blind SQL injection vulnerability. The breach allegedly exposed approximately 115 individuals — largely real-estate agents and private advertisers — including email addresses, plaintext passwords, first and last names, phone numbers, and estate-agency names.
  • Date: 2025
  • Domain: immo-gratuit.com
  • Threat Actor: civilement
  • Country: France
  • Category: Real Estate
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Company Information
  • Records: 252
  • Lines: 254
  • Size: 34.76 KB
  • Passwords: Plaintext
Sometime before June 2024, the Danish online store Hobnob Copenhagen (hobnobcopenhagen.dk) allegedly suffered a data breach. The affected data came from the store's WordPress/WooCommerce database. It has been reported that the data was published on a hacking forum. Reports suggest approximately 100 customers were exposed, including usernames, email addresses, full names, phone numbers, physical addresses, and hashed passwords.
  • Data: Email Addresses Usernames Passwords Names Phone Numbers Physical Locations
  • Records: 102
  • Lines: 103
  • Size: 12.07 KB
  • Passwords: Hashed
  • Cracked: 0%
In June 2024, the website of DKShops.dk, a Danish online shopping site, allegedly suffered a data breach that was published on a hacking forum. Reports suggest the exposed data came from the site's WordPress user table and affected approximately 20 individuals. The compromised records included email addresses, usernames, names, and hashed passwords (phpass).
  • Date: 2024
  • Domain: dkshops.dk
  • Country: Denmark
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Site Activity
  • Records: 20
  • Lines: 21
  • Size: 3.07 KB
  • Passwords: Hashed, PHPass
  • Cracked: 0%
In March 2025, AAA.co.il, an Israeli vacation-rental and lodging listings platform (villas, cabins and holiday suites), allegedly suffered a data breach. Reports suggest the exposed data, attributed to the actor BanyuwangiXploit, covered roughly 1,300 listing owner accounts and contacts. The data allegedly included listing/business names, contact email addresses, phone numbers, account usernames, and plaintext passwords.
  • Date: Mar 2025
  • Domain: aaa.co.il
  • Threat Actor: BanyuwangiXploit
  • Country: Israel
  • Category: Travel
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Company Information
  • Records: 4,155
  • Lines: 4,164
  • Size: 251.04 KB
  • Passwords: Plaintext
Sometime around or after 2022, Benetton Mexico — the United Colors of Benetton retail operation run in Mexico by Wolfsellers (wolfsellers.com / benettonmex.com) — allegedly suffered a data breach of its online store's customer database. Reports suggest the data was later shared on a hacking forum. It has been reported that approximately 15,700 customers were affected. The exposed records allegedly included email addresses, full names, dates of birth, genders, and — for a subset of customers — phone numbers, postal addresses, and Mexican RFC tax identifiers.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Government IDs Genders Site Activity Birthdates
  • Records: 15,742
  • Lines: 17,439
  • Size: 3.1 MB
  • Passwords: No
In October 2025, the Danish online candy and confectionery store Candystore.dk allegedly suffered a data breach. Reports suggest a threat actor exfiltrated the store's full customer and order database, exposing approximately 7,000 individuals. The compromised data reportedly included email addresses, full names, phone numbers, and physical delivery addresses. No passwords were included in the exposed data.
  • Date: Oct 17, 2025
  • Domain: candystore.dk
  • Threat Actor: @Satanic
  • Country: Denmark
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Site Activity Languages
  • Records: 9,140
  • Lines: 9,146
  • Size: 2.63 MB
  • Passwords: No
In August 2025, the website of a tennis club based in Pohang, South Korea (pohangtennis.net), allegedly suffered a data breach. Reports suggest that the site's legacy database was extracted via directory indexing, exposing data on approximately 130 individuals. The compromised data allegedly included member names, email addresses, phone numbers, home addresses, Korean resident registration numbers, IP addresses, bulletin-board posts and comments, and passwords — a small set of member account passwords in plaintext alongside MD5-hashed board-post passwords.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs IP Addresses Site Activity Messages
  • Records: 630
  • Lines: 4,957
  • Size: 1.18 MB
  • Passwords: MD5, Plaintext

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.