Breach Intelligence

3,377

Total breached databases

In 2022, HostingPapa (hostingpapa.in), an Indian web hosting and reseller hosting provider, allegedly suffered a data breach in which a full database dump was exposed. Reports suggest the compromised data contained records relating to approximately 500 individuals, including email addresses, names, phone numbers, physical addresses, usernames, government IDs, IP addresses, company information, and passwords stored as bcrypt, phpass, and MD5 hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs IP Addresses Site Activity Websites Company Information
  • Records: 10,172
  • Lines: 474,126
  • Size: 117.49 MB
  • Passwords: BCrypt, MD5, PHPass
  • Cracked: 0%
In November 2022, the Lithuanian web hosting service hidra.lt allegedly suffered a data breach. Reports suggest the exposed data was published as a multi-gigabyte SQL database dump covering several websites hosted on the provider's infrastructure, including WordPress/WooCommerce, Joomla and Nextcloud installations. It has been reported that approximately 800 individuals were affected. The compromised data allegedly included email addresses, usernames, names, IP addresses, geographic locations, and passwords stored as bcrypt, PHPass, salted MD5 and other salted hashes.
  • Date: Nov 2022
  • Domain: hidra.lt
  • Threat Actor: Chucky
  • Country: Lithuania
  • Category: Technology
  • Data: Email Addresses Passwords Names Geographic Locations Usernames IP Addresses
  • Records: 6,000
  • Lines: 5,925,427
  • Size: 5.25 GB
  • Passwords: BCrypt, Hashed Salted, MD5 Salted, PHPass
  • Cracked: 0%
In late 2022, Hybricom (hybricom.com.mx), a Mexican wireless internet service provider based in Umán, Yucatán, allegedly suffered a data breach of its customer billing and CRM database. Reports suggest data belonging to approximately 300 individuals was exposed. The compromised information included email addresses, names, usernames, phone numbers, geographic locations, company details, and passwords stored as MD5 hashes alongside some plaintext credentials.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Company Information
  • Records: 501
  • Lines: 45,754
  • Size: 9.06 MB
  • Passwords: MD5, Plaintext
Sometime before December 2022, Huella Logística (huellalogistica.com), a Colombian company offering supply-chain management-systems consulting and virtual training and certification courses, allegedly suffered a data breach. Reports suggest the exposed data, taken from the organisation's WordPress and WooCommerce platform, affected approximately 2,500 individuals. It has been reported that the compromised information included email addresses, usernames, names, PHPass password hashes, IP addresses, geographic locations, websites and company information.
  • Data: Email Addresses Passwords Names Geographic Locations Usernames IP Addresses Site Activity Websites Company Information
  • Records: 8,575
  • Lines: 184,855
  • Size: 30.46 MB
  • Passwords: PHPass
  • Cracked: 0%
In mid-2022, House Store (house-store.com) allegedly suffered a data breach. House Store is an online home and furniture retail store operating in New Caledonia. Reports suggest the leaked database contained approximately 2,000 customer records. The exposed data allegedly included email addresses, names, phone numbers, geographic locations, dates of birth, genders, IP addresses, and passwords stored as MD5 hashes.
  • Date: Jun 2022
  • Domain: house-store.com
  • Country: New Caledonia
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Genders IP Addresses Site Activity Company Information Birthdates
  • Records: 5,430
  • Lines: 195,483
  • Size: 13.62 MB
  • Passwords: MD5
  • Cracked: 0%
homsh.cn 2022

homsh.cn 2022

Sensitive
Sometime before 2022, the Chinese iris-recognition technology company Homsh (Wuhan Hongshi Technology Co., Ltd, homsh.cn) allegedly suffered a data breach. Homsh develops iris biometric chips, smart locks, and community access-control systems. Reports suggest that a database containing information on approximately 800 individuals was exposed. The compromised data included email addresses, usernames, names, phone numbers, government-issued ID numbers, geographic locations, IP addresses, and passwords stored as a mix of BCrypt, PHPass, MD5, SHA-256, and other hashes.
  • Date: 2022
  • Domain: homsh.cn
  • Country: China
  • Category: Technology
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs Genders IP Addresses Site Activity Websites Company Information
  • Records: 951
  • Lines: 3,940,489
  • Size: 3.12 GB
  • Passwords: BCrypt, MD5, PHPass, SHA-256, Unknown
In March 2023, Hotel Plaza Roma allegedly suffered a data breach. Hotel Plaza Roma is a hotel located in downtown Buenos Aires, Argentina. Reports suggest the exposed data originated from the hotel's website and booking system, largely contact-form and comment submissions. Approximately 17,000 records were affected, including email addresses, usernames, IP addresses, site activity, and a small number of passwords stored as BCrypt and MD5 hashes.
  • Data: Email Addresses Passwords Usernames IP Addresses Site Activity
  • Records: 17,146
  • Lines: 19,916
  • Size: 12.24 MB
  • Passwords: BCrypt, MD5
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.