Breach Intelligence

6,142

Total breached databases

Sometime in 2024, the Italian e-commerce store SmarterStore (smarterstore.it), an online retailer of smartphones and accessories, allegedly suffered a data breach. Reports suggest a customer database of approximately 17,000 records was exposed (a further ~4,000 rows were spam-bot registrations and were excluded). The exposed data included customer email addresses, full names, phone numbers, billing/shipping addresses, company names and VAT numbers. The dataset did not contain passwords.
  • Date: Jan 2024
  • Domain: smarterstore.it
  • Threat Actor: CHUCKY
  • Country: Italy
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Site Activity Company Information
  • Records: 17,369
  • Lines: 29,161
  • Size: 6.44 MB
  • Passwords: No
In 2023, the Italian fashion retailer Radà Italy (rada.it) allegedly had a customer order database exposed. Reports suggest the Magento order export contained roughly 2,600 order records covering approximately 1,400 unique customers, including full names, email addresses and billing/shipping addresses. No passwords were included in the exposed data.
  • Date: 2023
  • Domain: rada.it
  • Threat Actor: cateye84
  • Country: Italy
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Physical Locations Geographic Locations Site Activity
  • Records: 2,596
  • Lines: 3,811
  • Size: 844.91 KB
  • Passwords: No
Sometime before September 2025, the Brazilian platform Calculista de Aço (calculistadeaco.com.br) allegedly suffered a data breach. Calculista de Aço is a Brazilian online course and software provider for structural steel design aimed at civil engineers. The exposed data originated from the site's WordPress lead-capture plugin and, according to reports, contained approximately 3,700 unique records consisting of email addresses and lead-capture timestamps (site-activity data). No passwords, names, or other contact details were populated in the export.
  • Data: Email Addresses Site Activity
  • Records: 3,732
  • Lines: 13,728
  • Size: 2.28 MB
  • Passwords: No
Sometime before 2025, superdroidrobots.com (SuperDroid Robots), a United States company that manufactures tactical and custom robots, allegedly suffered a data breach of its OpenCart e-commerce store. Reports suggest a threat actor published the store's customer database of approximately 2,700 accounts, which reportedly included customers from US government and law-enforcement agencies. The exposed data reportedly included full names, email addresses, phone numbers, IP addresses, account creation dates, and salted SHA-1 password hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations IP Addresses Site Activity
  • Records: 2,754
  • Lines: 2,758
  • Size: 1.37 MB
  • Passwords: SHA-1 Salted
  • Cracked: 0%
In July 2026, data belonging to AWO Südost (awo-suedost.de) allegedly appeared on a ransomware leak site. AWO Südost is a regional branch of the German social-welfare organisation Arbeiterwohlfahrt; the exposed data came from its CGM KITA daycare-management system covering 16 daycare centres in Berlin. Reports suggest the breach, attributed to the Safepay ransomware group, exposed records for roughly 4,900 families — around 16,000 individuals including parents and their children. The highly sensitive data comprised full names, children's dates of birth and genders, home addresses, phone numbers and email addresses. No passwords were included.
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Financial Information Genders Company Information Birthdates
  • Records: 18,062
  • Lines: 4,899
  • Size: 4.92 MB
  • Passwords: No
In March 2026, a database belonging to the house-sitting service LuxuryHouseSitting (luxuryhousesitting.com) was allegedly published on a hacking forum. Reports suggest approximately 39,000 records across two tables (homeowners and sitters) were exposed, including email addresses, usernames, bcrypt-hashed passwords, full names, phone numbers, physical and geographic locations (addresses, coordinates, cities and states), IP addresses and dates of birth.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames IP Addresses Site Activity Birthdates
  • Records: 39,322
  • Lines: 39,331
  • Size: 39.28 MB
  • Passwords: BCrypt
  • Cracked: 0%
Sometime before 2025, Evergreen Hedging (evergreenhedging.com), a UK-based company supplying evergreen hedging plants direct to customers, allegedly suffered a data breach of its WooCommerce/WordPress store. It has been reported that around 2,900 individuals were affected, with the exposed data including email addresses, names, usernames, geographic locations (UK postcodes and cities), account activity dates, and a small number of bcrypt- and phpass-hashed staff passwords.
  • Date: 2025
  • Domain: evergreenhedging.com
  • Threat Actor: KaruHunters
  • Country: United Kingdom
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Site Activity
  • Records: 5,731
  • Lines: 2,265,052
  • Size: 404.44 MB
  • Passwords: BCrypt, PHPass
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.