Breach Intelligence

3,355

Total breached databases

Sometime before 2022, Election News Channel (electionnewschannel.com) allegedly suffered a data breach. Election News Channel is an independent US political news, analysis, and opinion website featuring election coverage and opinion polls. It has been reported that the exposed data originated from the site's Joomla content-management database. Reports suggest approximately 2 records were exposed, containing email addresses, names, usernames, site activity dates, and passwords stored as bcrypt hashes.
  • Data: Email Addresses Names Usernames Site Activity
  • Records: 2
  • Lines: 6,140
  • Size: 2.12 MB
  • Passwords: BCrypt
  • Cracked: 0%
Sometime around 2022, Educare International Institute For Higher Education (EIIHE), a Sri Lankan higher-education institute, allegedly suffered a data breach of its WordPress-based website. Reports suggest approximately 130 records were exposed, including email addresses, usernames, full names, and PHPass password hashes, along with a small number of birthdates, genders, and geographic locations.
  • Date: 2022
  • Domain: eiihe.edu.lk
  • Country: Sri Lanka
  • Category: Education
  • Data: Email Addresses Names Geographic Locations Usernames Genders Birthdates
  • Records: 134
  • Lines: 38,346
  • Size: 18.96 MB
  • Passwords: PHPass
  • Cracked: 0%
Sometime before October 2022, a development server associated with the domain eg.dev.spherepbx.com allegedly exposed a merchant cash-advance lead database. Reports suggest approximately 2,700 records of United States small-business funding applicants were compromised, including full names, phone numbers, home and business addresses, company details, tax IDs, and business financial information. The exposed dataset contained no passwords or credentials.
  • Data: Names Phone Numbers Geographic Locations Tax IDs Company Information
  • Records: 2,674
  • Lines: 2,791
  • Size: 791.12 KB
  • Passwords: No
Sometime in or before 2022, the Indian GST invoicing and billing platform EasyGSTBill (easygstbill.com) allegedly suffered a data breach. Reports suggest a database of approximately 52,000 records was exposed, including email addresses, names, phone numbers, business and tax (GSTIN) information, geographic locations, and encrypted account passwords.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Site Activity Tax IDs Company Information
  • Records: 51,873
  • Lines: 1,330,293
  • Size: 301.95 MB
  • Passwords: Unknown
Sometime before mid-2022, the Swiss online vehicle auction platform EF24 (ef24.ch) allegedly suffered a data breach. EF24 is a Switzerland-based business-to-business marketplace where dealers and companies buy and sell used vehicles. Reports suggest a database containing roughly 300 records was exposed, including email addresses, names, usernames, phone numbers, genders, company details, geographic locations and passwords stored as SHA-1 hashes.
  • Date: Jul 2022
  • Domain: ef24.ch
  • Country: Switzerland
  • Category: Automotive
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Genders Company Information Languages
  • Records: 318
  • Lines: 21,813
  • Size: 3.14 MB
  • Passwords: SHA-1
  • Cracked: 0%
Sometime before 2022, the Brazilian B2B e-procurement platform Economizze (economizze.com.br) allegedly suffered a data breach. Economizze is an online quotation and procurement marketplace that connects buyers and suppliers, including public-sector entities. Reports suggest a database of approximately 600 records was exposed, containing email addresses, full names, genders, phone numbers, dates of birth, Brazilian tax identifiers (CPF and CNPJ), company details, relationship statuses, family member names, and passwords stored as MD5 hashes.
  • Data: Email Addresses Names Phone Numbers Government IDs Family Members Relationship Statuses Genders Tax IDs Company Information Birthdates
  • Records: 576
  • Lines: 120,113
  • Size: 37.19 MB
  • Passwords: MD5
  • Cracked: 0%
In September 2022, Dr. L.K.V.D. College, an Indian degree college in Tajpur, Samastipur (Bihar) running an online admission-management system, allegedly suffered a data breach of its WordPress site. Reports suggest approximately 5,500 individuals were exposed, including email addresses, usernames, WordPress (phpass) password hashes, full names, phone numbers, and — for student applicants — dates of birth, genders, government IDs (Aadhaar numbers), castes, marital statuses, parents' names, and physical addresses.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Government IDs Family Members Marital Statuses Relationship Statuses Genders Websites Birthdates Ethnicities
  • Records: 13,059
  • Lines: 296,293
  • Size: 38.42 MB
  • Passwords: WordPress
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.