Breach Intelligence

6,142

Total breached databases

Sometime before May 2024, Tigo El Salvador (tigo.com.sv), one of the largest telecommunications operators in El Salvador, allegedly suffered a data breach affecting a subscriber database. It has been reported that the data was subsequently published on a hacking forum. Reports suggest approximately 43,000 subscribers were exposed, including full names, Salvadoran national identity document (DUI) numbers, and mobile phone numbers. No passwords or email addresses were included.
  • Date: 2024
  • Domain: tigo.com.sv
  • Threat Actor: drogado
  • Country: El Salvador
  • Category: Telecommunications
  • Data: Names Phone Numbers Geographic Locations Government IDs Driving License Numbers
  • Records: 50,950
  • Lines: 50,950
  • Size: 2.53 MB
  • Passwords: No
In September 2024, nnahra.org, the website of the National Native American Human Resources Association (NNAHRA), a United States non-profit organization, allegedly suffered a data breach. Reports suggest that a partial member database of approximately 160 members was exposed, including usernames, email addresses, plaintext passwords, and first and last names.
  • Date: Sep 2024
  • Domain: nnahra.org
  • Threat Actor: Spk
  • Country: United States
  • Category: Non-Profit & Charities
  • Data: Email Addresses Passwords Names Usernames
  • Records: 162
  • Lines: 59
  • Size: 12.58 KB
  • Passwords: Plaintext
Sometime before August 2026, coincustody.io, an Argentine online retailer of Trezor and Ledger cryptocurrency hardware wallets, allegedly suffered a data breach exposing its Shopify order database. Reports suggest that around 212 customer orders were exposed, covering approximately 110 unique customers, including full names, email addresses, phone numbers, home addresses, Argentine national identity/tax numbers (DNI/CUIT), order and payment details, and customer browser IP addresses.
  • Date: Aug 13, 2026
  • Domain: coincustody.io
  • Threat Actor: exfilar
  • Country: Argentina
  • Category: Cryptocurrency
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Financial Information Government IDs IP Addresses
  • Records: 278
  • Lines: 279
  • Size: 123.07 KB
  • Passwords: No
Sometime before August 2025, RexeStore (rexestore.com), a Philippine online bookstore operated by Rex Publishing, allegedly suffered a data breach affecting its customer database. It has been reported that a partial dump of the store's PrestaShop database was subsequently published on a hacking forum. Reports suggest approximately 4,800 customer address records were exposed, including full names, physical and delivery addresses, cities and postcodes, landline and mobile phone numbers, company names, and a small number of customer email addresses. No passwords were included.
  • Date: 2025
  • Domain: rexestore.com
  • Threat Actor: Agnes
  • Country: Philippines
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Government IDs Site Activity Company Information
  • Records: 4,840
  • Lines: 134,921
  • Size: 11.46 MB
  • Passwords: No
Sometime around 2024, the European online sports retailer Web-Sport (web-sport.eu) allegedly suffered a data breach. Web-Sport is a pan-European e-commerce store selling sportswear and footwear across its own site and marketplaces. Reports suggest a Magento order-export of approximately 749,000 order records was exposed, including customer names, billing and shipping addresses, order and payment information, and — for direct (non-marketplace) orders — email addresses. No passwords were included; many order rows carry synthetic marketplace-relay email addresses rather than real inboxes.
  • Date: 2024
  • Domain: web-sport.eu
  • Threat Actor: @Satanic
  • Category: Sports
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Payment Information Order Information Site Activity
  • Records: 749,192
  • Lines: 755,793
  • Size: 324.97 MB
  • Passwords: No
In January 2025, Telekom Slovenije (telekom.si), a leading telecommunications provider in Slovenia, allegedly suffered a data breach carried out by a threat actor with no ransom demands made. Reports suggest the exfiltrated data — largely internal Jira issue trackers, support tickets, project files and an employee/contractor directory — exposed approximately 1,300 distinct email addresses along with employee names and usernames. The compromised material also included classified documents and business files.
  • Date: Jan 2025
  • Domain: telekom.si
  • Threat Actor: Rey
  • Country: Slovenia
  • Category: Telecommunications
  • Data: Email Addresses Names Usernames Company Information
  • Records: 416,046
  • Lines: 5,294,230
  • Size: 335.89 MB
  • Passwords: No
Sometime before July 2026, Shree Transport (shreetransport.co), an Indian logistics and goods-transport company, allegedly suffered a data breach affecting its internal bank and ledger management database. It has been reported that the database was subsequently published on a hacking forum. Reports suggest the dump exposed banking and financial records alongside personal data — including staff account emails, bcrypt-hashed and plaintext passwords, employee and dealer names, mobile numbers, Indian PAN and GST identifiers, bank account and IFSC details, and transport ledger records covering dealers, truck drivers, and companies.
  • Date: 2026
  • Domain: shreetransport.co
  • Threat Actor: Sensitive2025
  • Country: India
  • Category: Logistics & Transportation
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Bank Account Information Financial Information Government IDs Site Activity Company Information
  • Records: 17,965
  • Lines: 358,721
  • Size: 43.52 MB
  • Passwords: BCrypt, Plaintext

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.