Breach Intelligence

6,139

Total breached databases

Sometime in 2019, the Ghana National Teaching Council (NTC, ntc.gov.gh) — the government body that licenses and registers teachers in Ghana — allegedly suffered a data breach of its teacher-licensure portal. Reports suggest the records of approximately 41,000 teacher-trainees were exposed, including full names, email addresses, phone numbers, dates of birth, contact/postal addresses, gender, and religion. No passwords were included in the leak.
  • Date: 2019
  • Domain: ntc.gov.gh
  • Threat Actor: Tanaka
  • Country: Ghana
  • Category: Government
  • Data: Email Addresses Names Phone Numbers Physical Locations Genders Religions Birthdates
  • Records: 41,017
  • Lines: 41,366
  • Size: 16.66 MB
  • Passwords: No
In August 2026, Mailshake (mailshake.com), an email outreach and sales engagement platform, allegedly suffered a data breach. Reports suggest a threat actor exfiltrated a database of approximately 49,000 customer profiles. The exposed data allegedly included email addresses, names, team/company names, IP addresses, geographic location (city, region and country), language, account roles and account activity timestamps; no passwords were included in this profile dataset.
  • Date: Aug 8, 2026
  • Domain: mailshake.com
  • Threat Actor: GoreTurbine
  • Category: Technology
  • Data: Email Addresses Names Geographic Locations IP Addresses Site Activity Company Information Languages
  • Records: 49,178
  • Lines: 49,178
  • Size: 22.26 MB
  • Passwords: No

Doxbin 2025

Sensitive
In November 2025, a scrape of the doxing platform Doxbin (doxbin.net) was allegedly published on a hacking forum. Reports suggest the data covered the site's public paste archive spanning roughly 2008 to 2025 — including the titles of doxing entries (real names and aliases of targeted individuals) and the usernames of the accounts that posted them, alongside a list of tens of thousands of site accounts. No passwords or email addresses were included.
  • Date: Nov 10, 2025
  • Domain: doxbin.net
  • Threat Actor: BengaminButton
  • Category: Forums & Communities
  • Data: Names Phone Numbers Usernames
  • Records: 5,517,147
  • Lines: 41,744,206
  • Size: 1015.72 MB
  • Passwords: No
In 2025, the Russian bulk-SMS and messaging service UralASMS (uralasms.ru) allegedly suffered a data breach exposing its full user database. It has been reported that around 54,000 user records were compromised, covering roughly 54,000 distinct email addresses. The exposed data, from a DataLife Engine (DLE) user table, reportedly included usernames, full names, email addresses, ICQ numbers, IP addresses, registration and last-activity dates, and passwords stored as double-MD5 (md5(md5)) hashes.
  • Date: 2025
  • Domain: uralasms.ru
  • Country: Russia
  • Category: Telecommunications
  • Data: Email Addresses Passwords Names Geographic Locations Usernames IP Addresses Site Activity Social Profiles
  • Records: 54,342
  • Lines: 54,364
  • Size: 12.45 MB
  • Passwords: Unknown
In December 2025, a database from the French business-client portal of energy company Eni (eni.com) was allegedly published on a hacking forum. Eni is an Italian multinational oil and gas company; the exposed data relates specifically to its French business customers. It has been reported that the breach exposed approximately 89,400 records containing contact first and last names, email addresses, client company names and reference numbers, account roles and statuses, job functions, telephone numbers, and account creation and last-login dates. No passwords were included in the exposed data.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Usernames Site Activity Profile Photos Job Information Company Information
  • Records: 89,462
  • Lines: 27,481
  • Size: 7.9 MB
  • Passwords: No
In July 2025, a dataset attributed to the British footwear retailer Clarks (clarks.com) was allegedly published on a hacking forum. Reports suggest the leak exposed approximately 50,000 customers, predominantly from the United Kingdom. The exposed data allegedly included full names, email addresses, physical mailing addresses, and phone numbers; no passwords were included. The attribution to Clarks has not been independently confirmed.
  • Date: Jul 2025
  • Domain: clarks.com
  • Threat Actor: RL000
  • Country: United Kingdom
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations
  • Records: 50,000
  • Lines: 50,001
  • Size: 3.61 MB
  • Passwords: No
In 2026, a compiled contact database of approximately 50,000 United Kingdom individuals and businesses using @btconnect.com email addresses (BT's small-business connectivity domain) was allegedly leaked. Reports suggest the dataset was circulated as a marketing/leads list rather than originating from a single breach of the provider. Each record allegedly contained an email address and a full postal address (street, city, county and country); no passwords were included.
  • Date: 2026
  • Domain: btconnect.com
  • Threat Actor: GlitchX
  • Country: United Kingdom
  • Category: Data Brokers
  • Data: Email Addresses Physical Locations Geographic Locations
  • Records: 49,999
  • Lines: 10,233
  • Size: 2.45 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.