Breach Intelligence

5,431

Total breached databases

In January 2025, the Alumni & Corporate Relations portal of the Indian Institute of Technology Madras (acr.iitm.ac.in) allegedly suffered a data breach. Reports suggest a full database dump was leaked, exposing records on roughly 200,000 alumni and associated individuals across hundreds of tables. The compromised data reportedly included names, email addresses, phone numbers, physical addresses, employers and job titles, usernames, and account passwords (phpass hashes and some base64-encoded plaintext).
  • Date: Jan 21, 2025
  • Domain: acr.iitm.ac.in
  • Threat Actor: W1ndStre4m
  • Country: India
  • Category: Education
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Websites Job Information Company Information
  • Records: 242,273
  • Lines: 12,136,504
  • Size: 1.61 GB
  • Passwords: PHPass, Plaintext
In 2023, MakeBookingsOnline (makebookingsonline.com), an online travel-booking platform used by travel agents to build and manage trip itineraries and reservations, allegedly suffered a data breach. Reports suggest the exposed database contained customer accounts and detailed booking records, exposing roughly 5,000 unique email addresses along with travellers' names, salutations, dates of birth, nationalities, passport numbers and expiry dates, phone numbers, postal addresses, booking/order details, and a small number of account passwords stored as bcrypt hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Order Information Passports Genders Salutations Site Activity Birthdates Nationalities
  • Records: 10,759
  • Lines: 2,544,310
  • Size: 3.42 GB
  • Passwords: BCrypt
  • Cracked: 0%
In January 2025, Amai (amai.com), a developer of Shopify apps such as back-in-stock and pre-order tools, allegedly suffered a data breach. Reports suggest the incident exposed a database spanning roughly 10,000 merchant stores and approximately 2.4 million unique individuals. The exposed data included email addresses (largely back-in-stock notification subscribers and Shopify order customers), store owner and location contact details, and a small number of staff accounts with BCrypt password hashes.
  • Date: Jan 8, 2025
  • Domain: amai.com
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Order Information Site Activity Company Information Personal Information
  • Records: 6,031,759
  • Lines: 52,774,246
  • Size: 14.29 GB
  • Passwords: BCrypt
  • Cracked: 0%
In 2023, the Kazakhstani education platform Daryn (daryn.online) allegedly suffered a data breach exposing roughly 4.2 million records, including approximately 3.9 million unique email addresses, with data ranging from 2011 to 2023. The exposed data — a parsed export circulated on Telegram and later on hacker forums — covered students and school participants, including full names, email addresses, phone numbers, dates of birth, Kazakhstani individual identification numbers (IIN), regions and the schools and admission years associated with each person.
  • Date: 2023
  • Domain: daryn.online
  • Country: Kazakhstan
  • Category: Education
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Government IDs Birthdates
  • Records: 4,208,629
  • Lines: 4,209,062
  • Size: 781.15 MB
  • Passwords: No
In 2019, Santalucía Seguros (santalucia.es), a Spanish insurance company, allegedly suffered a data breach. Reports suggest the exposed database contained approximately 2.8 million customer records, with data including email addresses, full names, dates of birth, telephone numbers, postal addresses, and passwords stored as MD5 hashes as well as some in plain text.
  • Date: 2019
  • Domain: santalucia.es
  • Country: Spain
  • Category: Finance & Payments
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Birthdates
  • Records: 2,772,597
  • Lines: 2,772,598
  • Size: 250.26 MB
  • Passwords: MD5, Plaintext
In June 2025, a database belonging to the Italian consortium Ecoped (ecoped.org) was allegedly leaked. Ecoped is a non-profit collective compliance scheme managing the recycling of waste electrical and electronic equipment (WEEE) and batteries in Italy. Reports suggest the exposed data, exported as multiple CSV tables, covered member companies and their contacts, including roughly 77,000 unique email addresses, along with company names, Italian tax and VAT identifiers, contact names, physical addresses and phone numbers.
  • Date: Jun 13, 2025
  • Domain: ecoped.org
  • Country: Italy
  • Category: Non-Profit & Charities
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Government IDs Tax IDs Company Information
  • Records: 177,946
  • Lines: 4,467,674
  • Size: 2.4 GB
  • Passwords: No
Sometime before 2023, iCommuneCate (sw.icommunecate.com), a WordPress/WooCommerce membership site for recipe and meal-planning software, allegedly suffered a data breach. Reports suggest approximately 25,000 individuals were exposed, including email addresses, usernames, names, geographic locations, and PHPass-hashed account passwords.
  • Data: Email Addresses Passwords Names Geographic Locations Usernames
  • Records: 35,398
  • Lines: 8,626,744
  • Size: 837.08 MB
  • Passwords: PHPass
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.