Breach Intelligence

6,139

Total breached databases

In 2023, the UK online technology retailer Smartteck (smartteck.co.uk) allegedly suffered a data breach. Reports suggest the exposed data originated from the store's Magento database and affected approximately 20,000 individuals. The compromised information reportedly included email addresses, names, phone numbers, geographic locations, usernames, site activity, and passwords stored as salted MD5 and salted SHA-256 hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Site Activity
  • Records: 20,816
  • Lines: 29,301,940
  • Size: 4.15 GB
  • Passwords: MD5 Salted, SHA-256 Salted
  • Cracked: 0%
In July 2024, Kennelliitto (kennelliitto.fi), the Finnish Kennel Club, allegedly suffered a data breach. Reports suggest that a dataset of approximately 100,000 dog-show entry records was exposed. The data reportedly included email addresses, full names, phone numbers, physical/geographic locations, entry-fee payment information and site activity timestamps belonging to roughly 17,000 unique individuals. No passwords were reportedly included in the exposed data.
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Payment Information Site Activity
  • Records: 104,830
  • Lines: 104,831
  • Size: 43.42 MB
  • Passwords: No
In August 2026, the Croatian Pension Insurance Institute (Hrvatski zavod za mirovinsko osiguranje, HZMO; mirovinsko.hr) allegedly suffered a data breach. Reports suggest the data was published for free by a threat actor claiming it was extracted directly from the institution's systems. Approximately 105,000 records of Croatian citizens were reportedly exposed, including full names, email addresses, phone numbers, personal identification numbers (OIB), and geographic details. No passwords were included in the dataset.
  • Date: Aug 2026
  • Domain: mirovinsko.hr
  • Threat Actor: INF GRUPA
  • Country: Croatia
  • Category: Government
  • Data: Email Addresses Names Phone Numbers Geographic Locations Government IDs Company Information
  • Records: 105,830
  • Lines: 109,931
  • Size: 30.42 MB
  • Passwords: No
Sometime before 2026, IFprofs (ifprofs.org) allegedly suffered a data breach. IFprofs is a professional networking platform for teachers of French as a foreign language, connecting educators worldwide to share pedagogical resources and discussions. It has been reported that the exposed data was published on hacking forums. Reports suggest approximately 110,000 individuals were affected, with the leaked records including full names and geographic location information (country of residence). No passwords or email addresses were included in the exposed member records.
  • Date: 2025
  • Domain: ifprofs.org
  • Threat Actor: ChimeraZ
  • Category: Education
  • Data: Names Physical Locations Geographic Locations
  • Records: 110,961
  • Lines: 110,360
  • Size: 42.83 MB
  • Passwords: No
In May 2026, Thmanyah (thmanyah.com), a Saudi Arabian media and podcast streaming platform, allegedly suffered a data breach. Reports suggest that a dataset of approximately 107,000 subscribers was exposed. The compromised data reportedly includes email addresses, account creation dates, language preferences, and a platform Bitmovin license key. It has been reported that the data was subsequently shared on a hacking forum.
  • Date: May 2026
  • Domain: thmanyah.com
  • Country: Saudi Arabia
  • Category: Streaming & Entertainment
  • Data: Email Addresses Security Credentials Site Activity Languages
  • Records: 107,083
  • Lines: 107,083
  • Size: 34.95 MB
  • Passwords: No
Meetic 2025

Meetic 2025

Sensitive
Sometime in 2025, French online dating platform Meetic allegedly suffered a data breach. Meetic is a major French online dating service offering matchmaking, chat, and events for singles. Reports suggest the exposed database contained approximately 7.2 million user records. The compromised information reportedly included first names, email addresses, genders, birthdates, geographic locations, IP addresses, and account registration and activity details. No passwords were included in the exposed data.
  • Date: 2025
  • Domain: meetic.com
  • Threat Actor: PwnerSec
  • Country: France
  • Category: Dating
  • Data: Email Addresses Names Geographic Locations Genders IP Addresses Site Activity Birthdates
  • Records: 7,169,525
  • Lines: 7,169,559
  • Size: 2.4 GB
  • Passwords: No
Sometime in 2025, French mobile virtual network operator Zenmobile allegedly suffered a data breach. Zenmobile.fr is an MVNO that resells mobile and internet plans over the networks of major French carriers. Reports suggest the exposed database contained roughly 3.2 million customer records. The compromised information reportedly included full names, email addresses, phone numbers, physical and geographic locations, genders, and birthdates. No passwords were included in the exposed data.
  • Date: 2025
  • Domain: zenmobile.fr
  • Threat Actor: PwnerSec
  • Country: France
  • Category: Telecommunications
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Genders Birthdates
  • Records: 3,238,776
  • Lines: 15,043,964
  • Size: 1.69 GB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.