Breach Intelligence

6,139

Total breached databases

Sometime before 2025, loutz.com — a French agricultural and outdoor power-equipment dealer whose customer data was managed through the BlgCloud SaaS/CRM platform — allegedly had its CRM database exposed as part of a wider series of leaks targeting BlgCloud clients. Reports suggest the data was published on a hacking forum after the attackers said the provider ignored their vulnerability disclosures. The exposure allegedly affected approximately 7,700 individuals and business contacts, and it has been reported to include email addresses, names, phone numbers, postal addresses, and related company and financial account information.
  • Date: 2025
  • Domain: loutz.com
  • Country: France
  • Category: Professional & Corporate
  • Data: Email Addresses Names Phone Numbers Geographic Locations Security Credentials Financial Information Company Information
  • Records: 60,316
  • Lines: 1,745,537
  • Size: 597.74 MB
  • Passwords: No
In 2024, a credential dump targeting UK government online services (gov.uk, including the Government Gateway, HMRC tax services and other .service.gov.uk portals) was allegedly circulated, described as a re-upload of a dataset originally attributed to the threat actor USDoD. Reports suggest the file contained approximately 208,000 login records. It has been reported that the exposed data included the service URL, a Government Gateway user ID or email address, and a plaintext password.
  • Date: Sep 2024
  • Domain: gov.uk
  • Threat Actor: USDoD
  • Country: United Kingdom
  • Category: Government
  • Data: Email Addresses Passwords Usernames
  • Records: 208,521
  • Lines: 208,521
  • Size: 11.89 MB
  • Passwords: Plaintext
In 2026, a dataset allegedly linked to the cloud platform provider Vercel (vercel.com) surfaced on a hacking forum, though the attribution remains unverified. It has been reported that the data is a workspace user directory exported from a collaboration tool, listing approximately 235 accounts. The exposed data reportedly included email addresses, names, usernames, account activity timestamps, time zones, and administrator flags.
  • Data: Email Addresses Names Usernames Site Activity Job Information Time Zones
  • Records: 235
  • Lines: 238
  • Size: 97.9 KB
  • Passwords: No
In April 2024, the email inbox of VeeBuild (veebuild.io), a web-development and SaaS company, was allegedly compromised and its full contents published on a hacking forum. Reports suggest a threat actor exported the owner's mailbox. It has been reported that the leak exposed the email addresses and names of roughly 540 correspondents, drawn from the sender, recipient and body content of the leaked messages.
  • Date: 2024
  • Domain: veebuild.io
  • Threat Actor: NormalLeVrai
  • Category: Technology
  • Data: Email Addresses Names
  • Records: 542
  • Lines: 16,534
  • Size: 2.63 MB
  • Passwords: No
In 2026, PassPass (passpass.fr), a regional mobility and public-transport service for the Hauts-de-France region of France, allegedly suffered a partial data breach. Reports suggest customer order records were exposed. It has been reported that approximately 19,000 individuals were affected across roughly 28,000 order records, including names, email addresses, phone numbers, postal addresses and order details. No passwords were included.
  • Date: 2026
  • Domain: passpass.fr
  • Country: France
  • Category: Logistics & Transportation
  • Data: Email Addresses Names Phone Numbers Geographic Locations Order Information Genders Site Activity
  • Records: 28,769
  • Lines: 28,768
  • Size: 192.46 MB
  • Passwords: No
In August 2026, a data set attributed to SERPRO (Serviço Federal de Processamento de Dados), Brazil's federal data-processing agency, was allegedly offered on a hacking forum. Reports suggest the actor claimed a full database of roughly 214 million Brazilian citizens sourced from SERPRO, but the portion actually released and verified was a proof-of-concept sample of approximately 5 million records. The exposed data included full names, Brazilian CPF numbers, genders, and dates of birth. The broader 214-million claim remains unverified.
  • Data: Names Geographic Locations Government IDs Genders Birthdates
  • Records: 5,000,000
  • Lines: 5,000,001
  • Size: 297.94 MB
  • Passwords: No
Sometime before May 2026, a large credential dump affecting multiple Moroccan government online services was allegedly published on hacking forums. Reports suggest the data spanned numerous .gov.ma subdomains, including the Ministry of Education portals (massar/moutamadris.men.gov.ma), the tax administration (tax.gov.ma), and the national registry (rn.ae.gov.ma). It has been reported that the exposed data contained approximately 250,000 login records, including service URLs, usernames or email addresses, and plaintext passwords.
  • Date: May 2026
  • Domain: gov.ma
  • Threat Actor: Fexus
  • Country: Morocco
  • Category: Government
  • Data: Email Addresses Passwords Usernames
  • Records: 247,673
  • Lines: 253,205
  • Size: 15.64 MB
  • Passwords: Plaintext

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.