Breach Intelligence

6,139

Total breached databases

Sometime before 2025, the U.S. luxury hotel group Omni Hotels & Resorts (omnihotels.com) allegedly suffered a data breach. Omni Hotels operates 50+ properties across North America and serves guests through its loyalty program, bookings, and events. Reports suggest the exported dataset contained approximately 5.2 million records (around 4.2 million unique email addresses) drawn from loyalty-member and guest-booking tables. The exposed data reportedly included full names, email addresses, physical postal addresses, loyalty/membership levels, enrollment and stay dates, birthdates, and language preferences. No passwords were included in the dataset.
  • Data: Email Addresses Names Physical Locations Site Activity Birthdates Languages
  • Records: 5,207,068
  • Lines: 5,207,071
  • Size: 455.17 MB
  • Passwords: No
Sometime in 2025, French telecommunications provider SFR allegedly suffered a data breach. SFR is one of France's largest telecom operators, offering mobile, internet, and television services. Reports suggest the exposed data dated from late 2025 and encompassed approximately 11 million records. The compromised information reportedly included full names, phone numbers, email addresses, physical and geographic locations, and birthdates. No passwords were included in the exposed data.
  • Date: 2025
  • Domain: sfr.fr
  • Threat Actor: PwnerSec
  • Country: France
  • Category: Telecommunications
  • Source: ransomware.live
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Birthdates
  • Records: 11,156,050
  • Lines: 11,208,985
  • Size: 1.64 GB
  • Passwords: No
In August 2026, DreamChild (Garbh Sanskar, dreamchild.in), an Indian prenatal-wellness mobile app by Anantam Life Science, allegedly suffered a data breach exposing its user profiles. It has been reported that around 64,000 profiles were affected, including roughly 13,000 distinct phone numbers. The exposed data reportedly included names, phone numbers, IP addresses, geographic locations (city and region), device identifiers, and device details. Fields were sparsely populated across profiles. No passwords were included in the dataset.
  • Date: Aug 3, 2026
  • Domain: dreamchild.in
  • Country: India
  • Category: Healthcare
  • Data: Names Phone Numbers Geographic Locations IP Addresses Languages Device Identifiers Device Information
  • Records: 64,122
  • Lines: 64,122
  • Size: 67.75 MB
  • Passwords: No
In 2023, NCL Buildtek (nclbuildtek.com), an Indian building-materials and construction company, allegedly suffered a data breach of its internal CRM and employee database. Reports suggest the exposed data included email addresses, plaintext (base64-encoded) passwords, names, phone numbers, and physical addresses for roughly 3,000 employees and business contacts. The database was allegedly published on a hacking forum.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations
  • Records: 16,891
  • Lines: 89,533
  • Size: 35.72 MB
  • Passwords: Plaintext
In 2017, a membership spreadsheet from the Rhode Island Golf Association (Rigalinks, rigalinks.org) in the United States was allegedly exposed. It has been reported that around 14,000 golfer records were affected. The source spreadsheet held names, email addresses, home addresses, dates of birth and gender; the recovered and indexed data consists of full names and email addresses. No passwords were included in the dataset.
  • Data: Email Addresses Names
  • Records: 14,449
  • Lines: 683,381
  • Size: 11.79 MB
  • Passwords: No
ICPNA 2025

ICPNA 2025

Sensitive
In August 2025, a database belonging to ICPNA (Instituto Cultural Peruano Norteamericano, icpna.edu.pe), a Peruvian-American cultural institute and English-language school, was allegedly published on a hacking forum. Reports suggest the leak exposed approximately 105,000 students. The exposed data allegedly included full names, email addresses, national ID numbers (DNI), ages, and account passwords stored in plaintext.
  • Date: Aug 2025
  • Domain: icpna.edu.pe
  • Threat Actor: SadClow
  • Country: Peru
  • Category: Education
  • Data: Email Addresses Passwords Names Geographic Locations Government IDs Birthdates
  • Records: 105,688
  • Lines: 105,747
  • Size: 18.85 MB
  • Passwords: Plaintext
On 22 May 2022, the Plan Viviendas (social-housing programme) of the Government of San Luis, Argentina (planviviendas.sanluis.gov.ar) allegedly suffered a data breach. It has been reported that around 52,000 records dating from 2017 were exposed, covering roughly 44,000 distinct email addresses. The compromised data, from housing-subsidy applications, reportedly included full names, national identity numbers (DNI), dates of birth, gender, home addresses, email addresses, and phone numbers, alongside sensitive socio-economic and family-situation details. No passwords were included in the dataset.
  • Date: May 22, 2022
  • Domain: sanluis.gov.ar
  • Country: Argentina
  • Category: Government
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Government IDs Genders Birthdates
  • Records: 52,469
  • Lines: 52,470
  • Size: 42.27 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.