Breach Intelligence

6,142

Total breached databases

In early 2026, an internal operational dataset from Emergia CC (emergiacc.com), a Colombian business-process-outsourcing and contact-centre company, was allegedly exposed. The data relates to an in-house field-sales campaign run for Colsubsidio in Bogotá, comprising roughly 258 store-visit activity records. The exposed data included the names of field sales agents, the companies and physical addresses visited, visit dates, and per-venue sales/transaction figures. No passwords or customer credentials were included.
  • Date: Mar 2026
  • Domain: emergiacc.com
  • Threat Actor: Petro_Escobar
  • Country: Colombia
  • Category: Social Media & Communication
  • Data: Names Physical Locations Geographic Locations Payment Information Financial Information Site Activity Job Information Company Information
  • Records: 258
  • Lines: 189
  • Size: 47.18 KB
  • Passwords: No
Sometime before March 2025, Brilliant's Convent School (brilliantsconvent.com), an Indian school, allegedly suffered a data breach. It has been reported that a dump of the school's website database was subsequently published on a hacking forum. Reports suggest approximately 45,000 individuals were exposed — the overwhelming majority being contact-form submitters, alongside a small set of CMS administrator accounts. The exposed data includes email addresses, phone numbers, usernames, and MD5-hashed administrator passwords (several with recovered plaintext).
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames
  • Records: 45,434
  • Lines: 272,594
  • Size: 52.39 MB
  • Passwords: MD5
  • Cracked: 80%
In 2025, data associated with the Indonesian job portal Hotjobs.id was allegedly leaked and offered for free download on a hacking forum. Reports suggest the data was collected from job applicants and consists of Indonesian civil-registry information. Approximately 3,900 individuals were reportedly affected, with the exposed data including full names, national identity (NIK) numbers, family card (KK) numbers, birthplaces, birthdates, genders, and residential addresses, alongside scanned images of resident identity cards and civil certificates. No passwords were included.
  • Date: 2025
  • Domain: hotjobs.id
  • Threat Actor: AYYUBI
  • Country: Indonesia
  • Category: Professional & Corporate
  • Data: Names Geographic Locations Government IDs Family Members Genders Birthdates
  • Records: 3,951
  • Lines: 1,285
  • Size: 325.24 KB
  • Passwords: No
Sometime before June 2023, ListGram (listgram.org), a Telegram bot-management platform, allegedly suffered a data breach. Reports suggest a full database export was published on a hacking forum. The exposed data allegedly contained roughly 4 million Telegram user identities, including usernames, display names, account creation and last-activity timestamps, along with a small number of email addresses users had placed in their profile names. No passwords were exposed.
  • Date: May 2023
  • Domain: listgram.org
  • Category: Social Media & Communication
  • Data: Email Addresses Names Usernames Site Activity Messages
  • Records: 4,382,995
  • Lines: 7,476,997
  • Size: 1.01 GB
  • Passwords: No
In November 2025, the French business school Grenoble École de Management (grenobleecoledemanagement.com) allegedly suffered a data breach following unauthorised VPS access. Grenoble École de Management is a graduate business school based in Grenoble, France. Reports suggest an internal email-marketing and CRM export covering approximately 337,000 subscribers, prospects, students, alumni and professionals was exposed, including email addresses, names, genders, phone numbers, physical and geographic locations, usernames, IP addresses, job and company information, education details, and marketing/subscription metadata. No passwords were included.
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Usernames Genders IP Addresses Site Activity Job Information Company Information Education Personal Information
  • Records: 437,902
  • Lines: 448,221
  • Size: 1.36 GB
  • Passwords: No
In July 2024, DevilBin (devilbin.site), a now-defunct paste and doxing site, allegedly suffered a data breach. It has been reported that the site's database was extracted via a backdoor planted in its source code. The exposed data covered around 53 registered accounts and reportedly included usernames, email addresses, and bcrypt-hashed passwords.
  • Data: Email Addresses Passwords Usernames Site Activity
  • Records: 54
  • Lines: 237
  • Size: 17.59 KB
  • Passwords: BCrypt
  • Cracked: 0%
Sometime before 2025, a list of Ducati (ducati.com) motorcycle buyers, predominantly in Switzerland, was allegedly exposed. Reports suggest the data related to approximately 580 customers and included names, email addresses, and the specific Ducati motorcycle model associated with each buyer. No passwords were included.
  • Date: 2025
  • Domain: ducati.com
  • Threat Actor: Tanaka
  • Country: Switzerland
  • Category: Automotive
  • Data: Email Addresses Names Geographic Locations Vehicle Information
  • Records: 583
  • Lines: 584
  • Size: 32.54 KB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.