Breach Intelligence

6,139

Total breached databases

Sometime before 2025, Viva Communications (viva.com.ph) allegedly suffered a data breach of its internal HR/employee system. Viva Communications is a Philippine entertainment and media company. Reports suggest that the breach exposed employee and applicant records for approximately 5,000 individuals. The exposed data allegedly included names, email addresses, plaintext passwords, phone numbers, government IDs (SSS/TIN/Pag-IBIG), birthdates, genders and internal messages.
  • Date: 2025
  • Domain: viva.com.ph
  • Country: Philippines
  • Category: Streaming & Entertainment
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Payment Information Government IDs Relationship Statuses Health Information Genders Religions Messages Birthdates Nationalities
  • Records: 141,869
  • Lines: 22,135,086
  • Size: 2.12 GB
  • Passwords: Plaintext
Sometime before 2022, shotasuzuki.net allegedly suffered a data breach. The affected site appears to be a Japanese horse-racing tips / paid-membership website built on WordPress with the Simple WordPress Membership plugin. Reports suggest that the breach exposed approximately 3,000 individuals. The exposed data allegedly included names, usernames, email addresses, phpass password hashes and IP addresses.
  • Data: Email Addresses Passwords Names Geographic Locations Usernames IP Addresses Site Activity Websites
  • Records: 7,581
  • Lines: 2,137,061
  • Size: 153.94 MB
  • Passwords: PHPass
  • Cracked: 0%
Sometime before 2025, Leon.cl allegedly suffered a data breach. Leon.cl is a Chilean automotive tire and service retailer. Reports suggest that the breach exposed approximately 393,000 individuals. The exposed data allegedly included names, email addresses, phone numbers, Chilean national ID numbers (RUT), addresses, order details and vehicle information.
  • Date: 2025
  • Domain: leon.cl
  • Country: Chile
  • Category: Automotive
  • Data: Email Addresses Names Phone Numbers Geographic Locations Order Information Government IDs Site Activity Vehicle Information
  • Records: 533,361
  • Lines: 2,080,842
  • Size: 409.68 MB
  • Passwords: No
In June 2026, Go2Joy (go2joy.vn), a Vietnamese mobile app for hourly and short-stay hotel bookings, allegedly suffered a data breach attributed to the RansomEXX group and published on 20 June 2026. Reports suggest the exposed database contained roughly 1.4 million customer records plus around 13,000 staff and partner entries. The compromised information reportedly includes email addresses, full names, phone numbers, physical addresses, birthdates, genders, MD5-hashed passwords, loyalty balances, booking histories, and device identifiers.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Balances Order Information Genders Site Activity Job Information Birthdates Device Identifiers
  • Records: 1,411,982
  • Lines: 1,411,990
  • Size: 336.91 MB
  • Passwords: MD5
  • Cracked: 0%
Sometime before 2026, Mexitravels allegedly suffered a data breach. Mexitravels is a Mexican travel agency based in Puerto Vallarta. Reports suggest that the breach exposed approximately 5,000 individuals. The exposed data allegedly included names, email addresses, phone numbers, plaintext passwords and company/tax details.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Government IDs Company Information Personal Information Travel Habits
  • Records: 20,656
  • Lines: 1,983,505
  • Size: 970.32 MB
  • Passwords: Plaintext
Sometime before 2023, the Peruvian National Registry of Identification and Civil Status (RENIEC, reniec.gob.pe) — the government agency responsible for issuing national identity documents (DNI) — allegedly suffered a data breach. It has been reported that data on approximately 32 million individuals was exposed. The leaked records reportedly include full names, national identity numbers (DNI), birthdates, genders, and physical and geographic location details. No passwords were included in the exposed data.
  • Date: 2025
  • Domain: reniec.gob.pe
  • Threat Actor: Solonik
  • Country: Peru
  • Category: Government
  • Data: Names Geographic Locations Government IDs Genders Birthdates Personal Information
  • Records: 31,888,852
  • Lines: 31,888,853
  • Size: 8.72 GB
  • Passwords: No
Sometime before 2025, an Indonesian government population database (pkp.go.id) allegedly suffered a data breach. Reports suggest that the breach exposed approximately 4.2 million individuals. The exposed data allegedly included full names, national identity numbers (NIK), dates of birth, genders, religions, marital statuses, nationalities and address locations.
  • Date: 2025
  • Domain: pkp.go.id
  • Country: Indonesia
  • Category: Government
  • Data: Names Physical Locations Geographic Locations Government IDs Relationship Statuses Genders Religions Site Activity Birthdates Nationalities
  • Records: 4,245,069
  • Lines: 4,245,069
  • Size: 1000 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.