Breach Intelligence

3,356

Total breached databases

In March 2016, the Philippine Commission on Elections (COMELEC) allegedly suffered a major data breach after its website was defaced. Reports suggest the voter registration database of tens of millions of Filipino voters (commonly cited as around 55 million) was subsequently leaked publicly. The exposed data is reported to have included full names, dates of birth, genders, marital statuses, physical descriptions such as height and weight, passport numbers, phone numbers, physical and previous addresses, family members' names, job information, and approximately 128,000 email addresses. No voter passwords were included, though a small set of administrative account credentials was also reported to be present.
  • Data: Email Addresses Names Phone Numbers Physical Locations Passports Family Members Marital Statuses Genders Job Information Birthdates Physical Descriptions
  • Records: 123,333,920
  • Lines: 123,333,928
  • Size: 43.93 GB
  • Passwords: No
In October 2024, Free, a French internet service provider, allegedly suffered a data breach that was initially offered for sale and later leaked publicly. The incident reportedly exposed 14 million unique email addresses. Among the compromised data were names, physical addresses, phone numbers, genders, dates of birth, and, in many cases, IBAN bank account numbers.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Bank Account Information Company Information
  • Records: 38,165,087
  • Lines: 38,165,198
  • Size: 10.86 GB
  • Passwords: No
In March 2026, the Colombian fintech company Addi (addi.com) allegedly suffered a data breach, with the "pay or leak" extortion group ShinyHunters claiming responsibility after the company reportedly declined to meet the actor's demands. Addi is a Colombian buy-now-pay-later and consumer-credit provider. Reports suggest the published trove was drawn from credit-scoring requests, credit-bureau records, customer identity records and email-validation logs. The data is reported to span more than 18 million unique email addresses, along with names, government-issued identity numbers (Cédula de Ciudadanía), phone numbers, dates of birth, IP addresses, geographic locations, and a range of financial and credit-related data points including estimated income, socioeconomic levels and purchases.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Financial Information Order Information Government IDs Genders IP Addresses Birthdates Personal Information Device Information
  • Records: 129,776,987
  • Lines: 17,094,513,091
  • Size: 6.72 TB
  • Passwords: ?
Sometime before December 2018, a database of records from Russia's Federal Customs Service (customs.ru) was allegedly leaked and circulated on hacking forums. Reports suggest the dump contained approximately 22.8 million customs declaration records covering goods that passed through Russian customs as imports and exports. The exposed data reportedly included importer and exporter company names, addresses and tax identification numbers (INN), the names of the customs declaration filers, country-of-origin and destination information, and detailed shipment data such as item descriptions, quantities, weights and declared values.
  • Date: 2011
  • Domain: customs.ru
  • Country: Russia
  • Category: Government
  • Data: Email Addresses Names Physical Locations Geographic Locations Tax IDs Company Information Shipment Information
  • Records: 22,839,008
  • Lines: 22,839,010
  • Size: 17.9 GB
  • Passwords: No
In May 2026, the real estate services firm Cushman & Wakefield was the target of a "pay or leak" extortion campaign by the ShinyHunters group. Following the threat, the group publicly published data they alleged had been obtained from the firm, consisting mostly of C&W email addresses along with tens of thousands of external email addresses and corporate contact records. The exposed data was primarily business information, including names, job titles, company addresses and phone numbers.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Genders Salutations Websites Job Information Company Information Fax Numbers
  • Records: 910,704
  • Lines: 977,619
  • Size: 327.08 MB
  • Passwords: No
In May 2026, the corporate travel management company BCD Travel allegedly suffered a data breach as part of the ShinyHunters "pay or leak" extortion campaign. Reports suggest the stolen data was published publicly in early June 2026 after the company declined to pay. It has been reported that approximately 292,000 individuals were affected, with exposed records drawn from Salesforce and SharePoint data sets including sales leads, internal staff and customer support tickets. The compromised data allegedly included email addresses, names, usernames, job titles, employer names, phone numbers and physical addresses.
  • Data: Email Addresses Names Phone Numbers Geographic Locations Usernames Job Information Company Information
  • Records: 1,258,554
  • Lines: 13,465,221
  • Size: 958.97 MB
  • Passwords: No
In April 2026, the fashion retailer Zara (zara.com) was allegedly impacted by a data breach attributed to the ShinyHunters extortion group, reportedly stemming from a compromise of the Anodot analytics platform. Reports suggest the published data comprised roughly a terabyte of customer-support ticket records. Approximately 258,000 unique individuals were affected, with exposed data including email addresses, the geographic market each support ticket originated from, and associated order information. It has been reported that the incident did not affect passwords or payment information.
  • Data: Email Addresses Geographic Locations Order Information
  • Records: 359,866
  • Lines: 95,165,570
  • Size: 23.37 GB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.