Breach Intelligence

6,142

Total breached databases

Sometime before August 2023, Elba Havacılık (elbahavacilik.com), a Turkish aviation website, allegedly suffered a data breach exposing its SQL database. Reports suggest the exposed data comprised roughly 73,000 email-verification and signup records — email addresses along with IP addresses and browser/device (user-agent) information — plus a smaller set of student records containing names, Turkish national ID numbers (T.C. Kimlik No), and phone numbers, and a set of candidate password hashes (MD5). The dump was published on a hacking forum.
  • Date: Aug 2023
  • Domain: elbahavacilik.com
  • Threat Actor: Chucky
  • Country: Turkey
  • Category: Logistics & Transportation
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Government IDs IP Addresses Device Information
  • Records: 88,636
  • Lines: 89,821
  • Size: 33.47 MB
  • Passwords: MD5
  • Cracked: 0%
Sometime before mid-2026, a directory of Century 21 France employees and agents (century21.fr) — the French arm of the Century 21 real-estate franchise — was allegedly exposed in a data breach. Reports suggest data for approximately 21,000 employees and agents was released. The exposed data included names, usernames, work email addresses, phone numbers, birthdates, hire dates, employment status (salaried / commercial agent), professional activity and career-background information. The dataset did not contain passwords.
  • Date: 2025
  • Domain: century21.fr
  • Country: France
  • Category: Real Estate
  • Data: Email Addresses Names Phone Numbers Geographic Locations Usernames Site Activity Job Information Birthdates
  • Records: 21,013
  • Lines: 21,013
  • Size: 8.71 MB
  • Passwords: No
A credential list targeting Mercado Bitcoin (mercadobitcoin.com.br), a major Brazilian cryptocurrency exchange, was allegedly circulated on hacking forums. Reports suggest it contained roughly 17,800 login-and-password pairs, where the login is typically a Brazilian CPF (tax identification number) or a username. The passwords are stored in plaintext. No email addresses were included.
  • Data: Passwords Usernames Government IDs
  • Records: 17,841
  • Lines: 17,848
  • Size: 534.62 KB
  • Passwords: Plaintext
Sometime before September 2025, MobileSub (mobilesub.com.ng), a Nigerian digital platform for mobile top-ups, bill payments and VTU services, allegedly suffered a data breach that was published on a hacking forum. Reports suggest the exposed database included approximately 1,000 registered users, with usernames, full names, email addresses, phone numbers, genders, account balances, bank account details, IP addresses and bcrypt-hashed passwords.
  • Date: 2025
  • Domain: mobilesub.com.ng
  • Threat Actor: N1KA
  • Country: Nigeria
  • Category: Finance & Payments
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Bank Account Information Balances Genders IP Addresses Site Activity Birthdates Date of Death
  • Records: 2,043
  • Lines: 32,184
  • Size: 13.63 MB
  • Passwords: BCrypt
  • Cracked: 0%
In 2025, the University of Lille (univ-lille.fr), one of the largest public research universities in France, allegedly had a database from its internship/placement management system leaked on a hacking forum. Reports suggest the data covered roughly 2,700 individuals — students, teaching staff, and company contacts — and included professional and personal email addresses, first and last names, student IDs, phone numbers, birthdates, and postal addresses, along with company details for partner organizations. No account passwords were included beyond a small set of staff auth tokens.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Company Information Birthdates
  • Records: 7,709
  • Lines: 7,243
  • Size: 4.06 MB
  • Passwords: Unknown
In September 2024, Albert Ménès — a renowned French gourmet-food company producing jams, spreads, dried herbs and spice mixes since 1921 — allegedly suffered a data breach of its online store (albertmenes.fr). The store ran on the PrestaShop platform. Reports suggest data for approximately 21,000 customers was exposed. The exposed data included customer email addresses, first and last names, birthdates, some company names and SIRET numbers, registration IP addresses, and passwords stored as bcrypt and legacy MD5 hashes.
  • Date: Sep 2024
  • Domain: albertmenes.fr
  • Threat Actor: grepcn
  • Country: France
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Geographic Locations IP Addresses Company Information Birthdates
  • Records: 21,156
  • Lines: 21,157
  • Size: 3.02 MB
  • Passwords: BCrypt, MD5
  • Cracked: 0%
Sometime before January 2026, a database of civil servants of the West Java Provincial Government (Pemerintah Provinsi Jawa Barat) was allegedly exposed. It has been reported that the data, sourced from the provincial employee information system (siap.jabarprov.go.id), was subsequently published on hacking forums. The incident allegedly affected approximately 37,000 individuals, with the compromised records including full names, national identity (KTP/NIK) and employee (NIP) numbers, places and dates of birth, home addresses, phone numbers, some email addresses, job titles, work units, religion, gender and marital status. No passwords were included in the exposed data.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Government IDs Relationship Statuses Genders Religions Job Information Company Information Birthdates Nationalities
  • Records: 37,351
  • Lines: 34,444
  • Size: 6.53 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.