Breach Intelligence

2,844

Total breached databases

In early 2022, a collective known as IT Army whose stated goal is to "completely de-anonymise most Russian users by leaking hundreds of gigabytes of databases" published over 30GB of data allegedly sourced from Russian courier service CDEK. The data contained over 19M unique email addresses along with names and phone numbers. The authenticity of the breach could not be independently established and has been flagged as "unverfieid".
  • Date: Mar 9, 2022
  • Domain: cdek.ru
  • Country: Russia
  • Category: Logistics & Transportation
  • Records Announced: 19,218,203
  • Source: haveibeenpwned.com
  • Data: Email Addresses Names Phone Numbers
  • Imported:
  • Records Imported: 822,952,126
  • Number of lines: 822,952,128
  • Size: 84.83 GB
  • Passwords: No
In July 2022, the Direct Download Community ExVagos suffered a data breach that impacted 2.1 million members. The breach included Usernames, Email addresses, Dates of birth, IP Addresses and Passwords stored as vBulletin hashes.
  • Data: Birthdates Email Addresses IP Addresses Passwords Usernames
  • Imported:
  • Records Imported: 2,122,614
  • Number of lines: 2,122,736
  • Size: 852.04 MB
  • Passwords: vBulletin
  • Cracked: 61%
In mid-2022, data alleged to have been sourced from the Russian payment provider PaySystem.tech appeared in hacking circles where it was made publicly available for download. Consisting of 16M rows with 1.4M unique email addresses, the data also included purchases and full credit card numbers and expiry dates. The data could not be independently attributed back to PaySystem.tech and the breach has been flagged as "unverified".
  • Data: Email Addresses Phone Numbers Credit Card Information Order Information
  • Imported:
  • Records Imported: 23,516,293
  • Number of lines: 23,516,292
  • Size: 3.99 GB
  • Passwords: No
In July 2024, DataGardener, a platform known for providing data on businesses and professionals, suffered a data breach. Reports suggest that the breach exposed approximately 1.4 million lines of data. Among the compromised data were email addresses, names, job positions, geographic locations, and phone numbers.
  • Date: Jul 2024
  • Domain: datagardener.com
  • Threat Actor: Satanic
  • Category: Data Brokers
  • Records Announced: 1,439,210
  • Data: Email Addresses Geographic Locations Job Information Names Phone Numbers Site Activity Social Profiles
  • Imported:
  • Records Imported: 1,439,224
  • Number of lines: 1,439,229
  • Size: 184.01 MB
  • Passwords: No
In December 2020, the dental practice management service MMG Fusion was the victim of a data breach which exposed 2.6M unique email addresses. The data also included patient appointments, names, phone numbers, dates of birth, genders and physical addresses. A small number of records also included passwords stored as bcrypt hashes.
  • Data: Birthdates Email Addresses Genders Health Information Marital Statuses Names Passwords Phone Numbers Physical Locations
  • Imported:
  • Records Imported: 26,392,969
  • Number of lines: 34,750,998
  • Size: 5.99 GB
  • Passwords: BCrypt
  • Cracked: 0%