Breach Intelligence

6,142

Total breached databases

Sometime before September 2024, a forum associated with ukraine.ua — the official website promoting Ukraine — allegedly suffered a data breach. Reports suggest approximately 23,000 user records were exposed. The exposed data included email addresses, usernames, IP addresses and passwords stored as vBulletin salted-MD5 and bcrypt hashes.
  • Date: 2025
  • Domain: ukraine.ua
  • Country: Ukraine
  • Category: Government
  • Data: Email Addresses Passwords Usernames IP Addresses
  • Records: 23,463
  • Lines: 23,463
  • Size: 2.54 MB
  • Passwords: BCrypt, MD5, vBulletin
  • Cracked: 0%
Sometime before 2025, 123 Finance PH (123finance.ph) allegedly suffered a data breach. 123 Finance Corporation is a SEC-regulated Philippine financial-services company that provides personal loans, primarily to Overseas Filipino Workers. Reports suggest a database of loan applications was published on a hacking forum, containing approximately 5,500 records. The highly sensitive exposed data comprised full names, birth dates and places of birth, genders, marital statuses, home and employer addresses, phone numbers, email addresses, employer and job details, Philippine SSS numbers and tax identification numbers (TIN), and bank-account and credit-card information. No passwords were included.
  • Date: 2025
  • Domain: 123finance.ph
  • Country: Philippines
  • Category: Finance & Payments
  • Data: Email Addresses Names Phone Numbers Geographic Locations Credit Card Information Bank Account Information Government IDs Social Security Numbers Marital Statuses Genders Site Activity Tax IDs Job Information Company Information Birthdates Places of Birth
  • Records: 5,486
  • Lines: 5,486
  • Size: 1.59 MB
  • Passwords: No
Sometime before 2025, the UAE online grocery store Delili (delili.ae) allegedly suffered a data breach of its PrestaShop customer database. Reports suggest approximately 7,700 records were exposed, including full names, email addresses, hashed passwords, phone numbers, genders, dates of birth and registration IP addresses. The exposed passwords were hashed (bcrypt and MD5).
  • Date: 2025
  • Domain: delili.ae
  • Country: United Arab Emirates
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Genders IP Addresses Site Activity Birthdates
  • Records: 7,788
  • Lines: 17,002
  • Size: 3.85 MB
  • Passwords: BCrypt, MD5
  • Cracked: 0%
Sometime before 2025, imapper.tech (iMapper), a French web-connected 2D laser measurement solution for building professionals, allegedly suffered a data breach. Reports suggest a threat actor exploited a vulnerability in the company's Metabase analytics instance and exported its accounts table, exposing approximately 4,300 user records. The compromised data reportedly included email addresses, usernames, professions, preferred languages, and SHA-224 password hashes.
  • Date: 2025
  • Domain: imapper.tech
  • Country: France
  • Category: Technology
  • Data: Email Addresses Passwords Usernames Job Information Languages
  • Records: 4,288
  • Lines: 4,288
  • Size: 610.79 KB
  • Passwords: Unknown
Sometime before 2025, a user directory tied to Thales Group (thalesgroup.com) — a French multinational aerospace, defence and digital-security company — was allegedly exposed in a data breach. The data originated from a LuxTrust digital-signature identity platform used by the company and reportedly affected around 6,400 accounts. The exposed records included names, email addresses, phone numbers, and associated organisation names. No passwords were included in the data.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Company Information
  • Records: 6,362
  • Lines: 6,409
  • Size: 5.47 MB
  • Passwords: No
In February 2026, Mad Monkey Hostels (madmonkeyhostels.com) allegedly suffered a data breach. Mad Monkey is a leading Southeast Asia-based hostel operator offering budget travel experiences across countries such as Cambodia, the Philippines, Thailand, and Indonesia. Reports suggest the breach exposed approximately 16,000 customer records, including email addresses and site-activity data (last sign-in dates and weekly sign-in counts). No passwords were included.
  • Data: Email Addresses Site Activity
  • Records: 16,520
  • Lines: 16,520
  • Size: 1.85 MB
  • Passwords: No
In August 2025, a credential dataset associated with watchpeopledie.tv, an online community website focused on graphic/shock content, was allegedly published on a hacking forum. Reports suggest approximately 15,000 account credentials were exposed, consisting of usernames or email addresses paired with plaintext passwords, apparently aggregated from infostealer logs targeting the site. No additional personal data was included.
  • Data: Email Addresses Passwords Usernames
  • Records: 15,162
  • Lines: 34,263
  • Size: 1.36 MB
  • Passwords: Plaintext

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.