Breach Intelligence

6,139

Total breached databases

In August 2026, customer analytics data from ZIPS Cleaners (321zips.com) was allegedly published on a hacking forum. ZIPS Cleaners is a U.S. dry cleaning and garment-care company offering laundry, alterations, and pickup and delivery services through its retail locations and a customer-facing app. It has been reported that the exposed dataset, an analytics event export covering users from late 2024 to 2026, contained approximately 66,700 unique customer profiles. Each profile allegedly included an email address, and where available a phone number, IP address, geographic location (city, region, country), device and operating-system details, and language. No passwords were included in the exposed data.
  • Date: Aug 15, 2026
  • Domain: 321zips.com
  • Threat Actor: GoreTurbine
  • Country: United States
  • Category: Professional & Corporate
  • Data: Email Addresses Phone Numbers Physical Locations Geographic Locations IP Addresses Languages Device Information
  • Records: 66,710
  • Lines: 66,710
  • Size: 58.18 MB
  • Passwords: No
In July 2026, the gamified language-learning platform Ling (ling-app.com) allegedly suffered a data breach. Ling is a mobile app offering interactive courses across 60+ languages through lessons, AI chatbots, and speech recognition. Reports suggest the exported dataset covered approximately 5.97 million deduplicated user profiles (around 2.4 million with email addresses) spanning 2022 through late 2025. The exposed data reportedly included email addresses, names, geographic locations, IP addresses, device information, languages, and subscription/payment-related information. No passwords were included in the dataset.
  • Data: Email Addresses Names Geographic Locations Payment Information IP Addresses Languages Device Information
  • Records: 5,916,079
  • Lines: 5,970,006
  • Size: 11.46 GB
  • Passwords: No
Sometime before August 2023, the sports video analysis platform Sprongo (sprongo.com) allegedly suffered a data breach. Reports suggest the production SQL database was published on hacking forums, exposing approximately 90,000 users. The exposed data allegedly included email addresses, names, sport information, partial payment card details (last four digits, card brand and expiry), linked social profile identifiers, and passwords stored as bcrypt hashes.
  • Date: Aug 2023
  • Domain: sprongo.com
  • Threat Actor: Chucky
  • Category: Sports
  • Data: Email Addresses Passwords Names Credit Card Information Payment Information Site Activity Social Profiles Sport Information
  • Records: 90,643
  • Lines: 129,130
  • Size: 31.23 MB
  • Passwords: BCrypt
  • Cracked: 0%
In March 2026, a Pipedrive CRM export belonging to the recruiting operation of Jitasa (itasa.is), a US-based non-profit accounting and bookkeeping firm, was allegedly leaked. Reports suggest the data covered approximately 24,000 job candidates and included names, email addresses, phone numbers, and recruiting notes. The data was allegedly published on a hacking forum. No passwords were included in the leak.
  • Date: Mar 2026
  • Domain: itasa.is
  • Country: United States
  • Category: Professional & Corporate
  • Data: Email Addresses Names Phone Numbers Geographic Locations Site Activity Profile Photos Company Information
  • Records: 24,565
  • Lines: 31,218
  • Size: 8.36 MB
  • Passwords: No
In December 2025, the Russian online-education platform GetCourse (getcourse.ru), an all-in-one service for launching and running online schools and courses, allegedly suffered a data breach exposing its orders dataset. It has been reported that around 70,000 order records were compromised, covering approximately 29,000 distinct customers. The exposed data reportedly included customer names, email addresses, phone numbers, and order creation dates, along with order and payment metadata. No passwords were included in the dataset.
  • Date: Dec 2025
  • Domain: getcourse.ru
  • Country: Russia
  • Category: Education
  • Data: Email Addresses Names Phone Numbers Geographic Locations Payment Information Order Information Site Activity
  • Records: 74,837
  • Lines: 75,958
  • Size: 54.22 MB
  • Passwords: No
In October 2025, the American Public University System (apus.edu), a United States online university, allegedly suffered a data breach affecting its student mentorship platform. Reports suggest a threat actor exfiltrated and published a database of approximately 59,000 student records. The exposed data allegedly included full names, usernames, email addresses, programs of study and degree information, and last-login activity; no passwords were included.
  • Date: Oct 2025
  • Domain: apus.edu
  • Threat Actor: wikkid
  • Country: United States
  • Category: Education
  • Data: Email Addresses Names Usernames Site Activity Education
  • Records: 59,615
  • Lines: 59,618
  • Size: 148.48 MB
  • Passwords: No
In June 2026, data allegedly scraped from a French Ministry of Sports (sports.gouv.fr) system was published on a hacking forum. The exposed dataset appears to originate from a registry of French sports and community associations used for grant and subsidy management. It has been reported that approximately 67,500 association records were exposed, containing contact email addresses, telephone numbers, physical and registered addresses, French company registration numbers (SIRENE), and bank account details including account holder names, bank names, and IBANs. No passwords were included in the exposed data.
  • Date: Jun 22, 2026
  • Domain: sports.gouv.fr
  • Country: France
  • Category: Government
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Bank Account Information Tax IDs Job Information Company Information
  • Records: 67,504
  • Lines: 67,508
  • Size: 44.02 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.