Breach Intelligence

6,824

Total breached databases

Sometime before 2025, McDonald's Indonesia allegedly suffered a data breach that was later published on a hacking forum. Reports suggest the exposed data contained approximately 15,000 records drawn from two files — a staff directory and a restaurant listing. The compromised data reportedly included employee full names, dates of birth, genders, phone numbers, home addresses, job titles, employment types, pay-rate information and hire dates, alongside restaurant names, addresses and manager contact details. No passwords were included.
  • Data: Names Phone Numbers Geographic Locations Financial Information Genders Site Activity Job Information Company Information Birthdates
  • Records: 14,945
  • Lines: 14,959
  • Size: 2.32 MB
  • Passwords: No
Sometime before 2023, cnc.ast.gr, a Greek e-commerce website, allegedly suffered a data breach. Reports suggest the exposed PrestaShop customer database contained approximately 3,000 records, including customer names, email addresses, salutations (genders), and account registration dates. No account passwords were included.
  • Date: 2023
  • Domain: cnc.ast.gr
  • Country: Greece
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Geographic Locations Genders Site Activity Company Information
  • Records: 3,034
  • Lines: 3,034
  • Size: 343.83 KB
  • Passwords: No
On October 10, 2025, the cybercrime group Scattered LAPSUS$ Hunters allegedly leaked a dataset exfiltrated from the Salesforce CRM of GAP, Inc. (gap.com), the American apparel retailer behind Gap, Old Navy, Banana Republic and Athleta. Reports suggest data on approximately 256,000 customers was exposed. The compromised information reportedly includes full names, email addresses, phone numbers, home addresses, loyalty-program details and other account information. No passwords were included.
  • Date: Oct 10, 2025
  • Domain: gap.com
  • Threat Actor: Scattered LAPSUS$ Hunters
  • Category: E-commerce & Retail
  • Source: databreach.com
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Site Activity Job Information Birthdates Personal Information
  • Records: 274,121
  • Lines: 274,121
  • Size: 1.03 GB
  • Passwords: No
In September 2026, the Hungarian health and medicine portal Diagnozis.hu allegedly suffered a data breach that was published on hacking forums. Reports suggest that a database of roughly 10,000 registered users, doctors and newsletter subscribers was exposed. The compromised data included names, email addresses, plaintext passwords, phone numbers, postal addresses, usernames, workplaces, job titles and other profile details.
  • Date: Sep 2026
  • Domain: diagnozis.hu
  • Threat Actor: Sophia
  • Country: Hungary
  • Category: Healthcare
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Site Activity Social Profiles Websites Job Information Company Information Birthdates
  • Records: 15,759
  • Lines: 35,189
  • Size: 24.76 MB
  • Passwords: Plaintext
In April 2023, a customer database belonging to Rize Reviews (rizereviews.com) was allegedly exposed. Rize Reviews is a United States-based online reputation and review management marketing agency. Reports suggest a customer export was leaked, comprising records for approximately 39,000 individuals. The compromised data allegedly included first and last names, email addresses, phone numbers, and email-engagement activity timestamps. No passwords were included.
  • Date: Apr 24, 2023
  • Domain: rizereviews.com
  • Country: United States
  • Category: Professional & Corporate
  • Data: Email Addresses Names Phone Numbers Geographic Locations Site Activity
  • Records: 47,600
  • Lines: 47,601
  • Size: 6.7 MB
  • Passwords: No
In August 2023, a dataset scraped from annuaire.sante.fr, the official French national public directory of health professionals (RPPS/ADELI registry), was allegedly published on a hacking forum. The data originates from a September 2020 export of the directory. Approximately 2.8 million professional records were allegedly exposed, including full names, professions and specialties, professional email addresses (including MSSanté secure-mail addresses), phone numbers, practice addresses and employer/company names. No passwords were included.
  • Date: Aug 25, 2023
  • Domain: annuaire.sante.fr
  • Threat Actor: Lucius1337
  • Country: France
  • Category: Healthcare
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Health Information Genders Job Information Company Information
  • Records: 2,840,561
  • Lines: 2,840,563
  • Size: 851.26 MB
  • Passwords: No
In 2026, Centrale-canine.fr (the Société Centrale Canine, France's national kennel club and dog-breeding registry) allegedly suffered a partial data breach. Reports suggest the exposed data covered roughly 122,000 dog owners and exhibitors, spread across dog-show participation and exhibitor records, including owners' names, postal addresses, cities and postal codes, phone numbers, and genders (titles). No account passwords were included.
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Genders
  • Records: 464,235
  • Lines: 464,233
  • Size: 892.08 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.