Breach Intelligence

6,139

Total breached databases

Medicati 2026

Medicati 2026

Sensitive
In 2026, Medicati (medicati.com), a Mexican medical laboratory and clinic management platform based in Monterrey, allegedly suffered a data breach. Reports suggest a threat actor exfiltrated patient records after a failed extortion attempt against the company and threatened to publish the data. The exposed records covered approximately 2,200 patients and allegedly included full names, dates of birth, genders, phone numbers, email addresses and clinical/laboratory test information; no passwords were included.
  • Date: 2026
  • Domain: medicati.com
  • Threat Actor: Alameda_Slim
  • Country: Mexico
  • Category: Healthcare
  • Data: Email Addresses Names Phone Numbers Geographic Locations Genders Site Activity Birthdates
  • Records: 2,232
  • Lines: 10,292
  • Size: 4.4 MB
  • Passwords: No
In April 2026, a webmail account belonging to Ar-Rahman Group of Schools (arrahmangroupofschools.com) was allegedly compromised. Ar-Rahman is a Montessori educational institution based in Lagos, Nigeria. It has been reported that a threat actor gained access to the school's mailbox and exfiltrated its contents, publishing the dump on a hacking forum. The exposed data allegedly comprises approximately 72,500 email messages spanning around 60,000 distinct correspondent email addresses, along with the subjects and full bodies of those messages. No passwords were included in the exposed data.
  • Data: Email Addresses Messages
  • Records: 254,946
  • Lines: 2,117,866
  • Size: 532.06 MB
  • Passwords: No
In early 2024, the online chess platform K-Chess (k-chess.com) was allegedly scraped, exposing its user database. It has been reported that approximately 83,000 user records were compromised. The exposed data reportedly included usernames, email addresses, occasional real names, birthdates, self-reported country, account creation and update timestamps, and linked social login identifiers (Facebook and Apple). No passwords were included, as the platform relies on third-party (Google, Facebook, Apple) authentication.
  • Data: Email Addresses Names Geographic Locations Usernames Site Activity Social Profiles Birthdates
  • Records: 83,327
  • Lines: 83,327
  • Size: 155.44 MB
  • Passwords: No
Sometime before December 2024, the Russian online furniture retailer Best Mebel Shop (bestmebelshop.ru) allegedly suffered a data breach. Reports suggest a Bitrix customer database was published on a hacking forum, exposing approximately 100,000 customers. The exposed data allegedly included email addresses, names, usernames, phone numbers, physical addresses, genders, birthdates, and passwords stored as salted MD5 hashes.
  • Date: Dec 2024
  • Domain: bestmebelshop.ru
  • Threat Actor: Tanaka
  • Country: Russia
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Genders Site Activity Birthdates
  • Records: 100,900
  • Lines: 100,963
  • Size: 62.45 MB
  • Passwords: MD5 Salted
  • Cracked: 0%
In 2026, Séjourneur (sejourneur.com), a French short-term and vacation rental property management service, allegedly suffered a data breach. Reports suggest a database of guest booking records was leaked, exposing information on approximately 41,000 individuals. The exposed data allegedly included names, email addresses, phone numbers, booking details and financial/pricing information; no passwords were included.
  • Date: 2026
  • Domain: sejourneur.com
  • Threat Actor: ChimeraZ
  • Country: France
  • Category: Travel
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Financial Information
  • Records: 46,555
  • Lines: 46,688
  • Size: 24.95 MB
  • Passwords: No
Sometime before August 2023, an OTRS (Open-source Ticket Request System) helpdesk instance operated by a Brazilian offshore oil and gas group allegedly suffered a data breach. Reports suggest the exposed database, distributed as a roughly 3 GB SQL dump, contained data relating to approximately 385,000 individuals. The compromised data reportedly included email addresses, names, SHA-256 password hashes and support-ticket site activity.
  • Date: 2025
  • Domain: otrs.com
  • Country: Brazil
  • Category: Technology
  • Data: Email Addresses Passwords Names Site Activity
  • Records: 372,028
  • Lines: 9,075,576
  • Size: 2.79 GB
  • Passwords: SHA-256
  • Cracked: 0%
Sometime before April 2025, the German dropshipping and e-commerce platform Dropmatix (dropmatix.com) allegedly suffered a data breach. Reports suggest the exposed data covered approximately 35,000 customers and included email addresses, full names, postal addresses, phone numbers, company and tax identification details, and associated order and payment information. The data was allegedly published on a hacking forum. No passwords were included in the leak.
  • Date: 2025
  • Domain: dropmatix.com
  • Country: Germany
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Geographic Locations Payment Information Order Information Site Activity Websites Tax IDs Company Information
  • Records: 83,263
  • Lines: 83,380
  • Size: 13.9 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.