Breach Intelligence

6,187

Total breached databases

In August 2026, the Altamira Municipal Government (altamira.gob.mx) in Mexico allegedly suffered a data breach that was published on a hacking forum by a group calling itself Cyberagentss. Reports suggest the exposed data came from the municipality's DIF official travel database and affected approximately 14 individuals. The compromised records included the names of government employees who travelled, along with trip destinations, dates, travel expenses, and reimbursement details. The attackers also claimed to have obtained the site's administrator credentials and an active session cookie.
  • Date: Aug 14, 2026
  • Domain: altamira.gob.mx
  • Threat Actor: Cyberagentss
  • Country: Mexico
  • Category: Government
  • Data: Names Geographic Locations Site Activity
  • Records: 23
  • Lines: 221
  • Size: 5.48 KB
  • Passwords: No
In September 2024, Smartmob.be allegedly suffered a data breach. Smartmob is a Belgian management platform for adapted transport services for people with reduced mobility (PMR), coordinating beneficiaries, drivers, trips and establishments in the Condroz/Huy region of Wallonia. It has been reported that the exposed database contained roughly 10,000 individuals. The compromised records allegedly included names, dates of birth, postal addresses, phone numbers, and — for a subset of staff accounts — email addresses and bcrypt-hashed passwords.
  • Date: Sep 5, 2024
  • Domain: smartmob.be
  • Country: Belgium
  • Category: Logistics & Transportation
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Site Activity Company Information Birthdates
  • Records: 10,257
  • Lines: 138,742
  • Size: 37.97 MB
  • Passwords: BCrypt
  • Cracked: 0%
In August 2025, MIN 2 Banda Aceh (min2bandaaceh.com), an Indonesian state Islamic elementary school, allegedly suffered a data breach. Reports suggest a student records database was published, exposing approximately 40 pupils' personal details including full names, genders, places and dates of birth, home addresses, religions, mobile phone numbers, parents' names and plaintext account passwords.
  • Date: Aug 19, 2025
  • Domain: min2bandaaceh.com
  • Threat Actor: Darkness./x404
  • Country: Indonesia
  • Category: Education
  • Data: Passwords Names Phone Numbers Physical Locations Geographic Locations Family Members Genders Religions Birthdates Places of Birth Education
  • Records: 38
  • Lines: 72
  • Size: 15.48 KB
  • Passwords: Plaintext
In November 2024, ADT Freight Services Australia Pty Ltd (adtfreight.com.au), a Melbourne-based international freight forwarder and customs agency, allegedly suffered a data breach attributed to the Sarcoma ransomware group. Reports suggest an extracted customer/organization directory of approximately 9,000 companies was exposed. The exposed data reportedly included company names, physical addresses, phone numbers and some contact email addresses. No passwords were included.
  • Data: Email Addresses Phone Numbers Physical Locations Geographic Locations Company Information
  • Records: 10,493
  • Lines: 9,085
  • Size: 3.05 MB
  • Passwords: No
In May 2023, Bank Syariah Indonesia (BSI), an Indonesian state-owned Islamic bank, was allegedly targeted by the LockBit 3.0 ransomware group, which exfiltrated internal data after the bank reportedly declined to pay a ransom. This dataset is the employee-directory portion of that breach and it has been reported to contain approximately 230 records with employee full names, corporate email addresses, phone numbers, office locations and job information. No passwords were included.
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Job Information
  • Records: 232
  • Lines: 236
  • Size: 140.17 KB
  • Passwords: No
Sometime before 2022, the Uganda MAAIF E-Extension System (maaif.go.ug), a digital agricultural extension platform operated by Uganda's Ministry of Agriculture, Animal Industry and Fisheries, allegedly suffered a data breach. Reports suggest the exposed data contained records for approximately 300 individuals, primarily extension officers and staff. The compromised information allegedly included names, email addresses, genders, job titles, and plaintext passwords.
  • Date: 2022
  • Domain: maaif.go.ug
  • Country: Uganda
  • Category: Government
  • Data: Email Addresses Passwords Names Genders Site Activity Job Information
  • Records: 414
  • Lines: 418
  • Size: 47.03 KB
  • Passwords: Plaintext
In September 2024, the French debt-collection agency Creancys Collect (creancyscollect.fr) allegedly suffered a data breach. Reports suggest a case-management export was exposed detailing individual debtors. It has been reported that approximately 5,900 records were affected, with the leaked data including debtors' full names, postal addresses, phone numbers, email addresses, dates and places of birth, and outstanding debt amounts.
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Financial Information Site Activity Birthdates Birth Information Date of Death
  • Records: 5,917
  • Lines: 5,918
  • Size: 1.25 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.