Breach Intelligence

6,139

Total breached databases

In May 2023, the Russian clothing retailer Gloria Jeans (gloria-jeans.ru) allegedly suffered a data breach. Reports suggest approximately 3.1 million customer records were exposed. The compromised data allegedly included email addresses, phone numbers, full names, and dates of birth.
  • Date: May 2023
  • Domain: gloria-jeans.ru
  • Country: Russia
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Birthdates
  • Records: 6,324,159
  • Lines: 6,324,159
  • Size: 884.23 MB
  • Passwords: No
In June 2025, Black Star Wear (blackstarwear.ru), a Russian streetwear fashion brand, allegedly suffered a data breach exposing its customer and order databases. Reports suggest the data was subsequently published on a hacking forum. The exposed data reportedly covered approximately 207,000 unique customers, including names, email addresses, phone numbers, order and delivery details, IP addresses and salted SHA-1 password hashes.
  • Date: Jun 15, 2025
  • Domain: blackstarwear.ru
  • Country: Russia
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Order Information IP Addresses Site Activity
  • Records: 549,994
  • Lines: 550,039
  • Size: 426.81 MB
  • Passwords: SHA-1 Salted
  • Cracked: 0%
In 2025, a database belonging to HyperMe (hyperme.ir), a chain of hypermarket stores in Iran, was allegedly published on a hacking forum. It has been reported that the incident exposed roughly 142,000 loyalty-card records. The compromised data reportedly included customer first and last names, mobile phone numbers, loyalty card numbers, points balances, and store transaction details.
  • Date: 2025
  • Domain: hyperme.ir
  • Threat Actor: MachineGun
  • Country: Iran
  • Category: E-commerce & Retail
  • Data: Names Phone Numbers Geographic Locations Personal Information
  • Records: 141,963
  • Lines: 141,964
  • Size: 13.41 MB
  • Passwords: No
Sometime in or before 2025, the video-sharing platform Rumble (rumble.com), a US-based alternative to YouTube that lets users upload, share, live-stream and monetize videos, allegedly suffered a data breach. Reports suggest data belonging to approximately 189,000 users was exposed, limited to email addresses and usernames. No passwords were included.
  • Date: Mar 2025
  • Domain: rumble.com
  • Category: Social Media & Communication
  • Data: Email Addresses Usernames
  • Records: 189,019
  • Lines: 189,021
  • Size: 5.94 MB
  • Passwords: No
In 2025, NRJ Mobile (nrjmobile.fr), a French mobile virtual network operator (MVNO), allegedly suffered a data breach exposing its customer database. Reports suggest the breach affected approximately 266,000 customer records. The compromised data allegedly included names, email addresses, phone numbers, physical addresses, bank account details (IBAN and BIC), genders, and account registration dates. A portion of the records belonged to anonymized/deleted accounts. No passwords were included.
  • Date: 2025
  • Domain: nrjmobile.fr
  • Country: France
  • Category: Telecommunications
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Bank Account Information Payment Information Genders Site Activity
  • Records: 266,344
  • Lines: 266,344
  • Size: 155.98 MB
  • Passwords: No
In 2025, a database attributed to Sovcombank (sovcombank.ru), one of Russia's largest banks, was allegedly published on a hacking forum. It has been reported that the dataset held roughly 131,000 customer records. The compromised data reportedly included full names, dates and places of birth, phone numbers, email addresses, Russian passport series and numbers, home addresses, marital status, pension amounts, and the names and phone numbers of spouses and additional contacts.
  • Date: 2025
  • Domain: sovcombank.ru
  • Country: Russia
  • Category: Finance & Payments
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Financial Information Government IDs Passports Family Members Marital Statuses Relationship Statuses Birthdates Places of Birth
  • Records: 131,223
  • Lines: 131,223
  • Size: 38.77 MB
  • Passwords: No
In November 2024, Boksha (boksha.com), an online fashion marketplace showcasing designs from emerging independent designers across the Gulf region, allegedly suffered a data breach. Reports suggest an export of the platform's order data was subsequently published on hacking forums. The exposed data reportedly contained approximately 100,000 order records covering around 32,000 unique customers, including names, email addresses, phone numbers and delivery addresses. No passwords were included in the exposed data.
  • Date: Nov 2024
  • Domain: boksha.com
  • Threat Actor: 888
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Geographic Locations Order Information Site Activity
  • Records: 100,258
  • Lines: 100,285
  • Size: 46.74 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.