Breach Intelligence

6,139

Total breached databases

In December 2025, Flower Wholesale (flowerwholesale.com), operated by Potomac Floral Wholesale — a US supplier of fresh cut flowers, plants and floral supplies to the Mid-Atlantic and Washington, DC area — allegedly suffered a data breach. Reports suggest the OpenCart store database was subsequently published on a hacking forum. The exposed data reportedly contained approximately 150,000 unique customer records, including names, email addresses, phone numbers, physical and order addresses, IP addresses and salted SHA-1 password hashes.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Payment Information Order Information IP Addresses Site Activity Company Information Personal Information Shipment Information
  • Records: 230,804
  • Lines: 2,764,432
  • Size: 300.14 MB
  • Passwords: SHA-1 Salted
  • Cracked: 0%
In November 2025, the Thai self-service laundry company TrendyWash (trendywash.net), which operates app-connected coin laundromats, allegedly suffered a data breach. Reports suggest data belonging to approximately 88,000 individuals was exposed, including email addresses, names, usernames, phone numbers, dates of birth, genders, geographic details, and passwords stored in plaintext.
  • Date: Nov 2025
  • Domain: trendywash.net
  • Country: Thailand
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Genders Birthdates
  • Records: 235,515
  • Lines: 235,650
  • Size: 79.57 MB
  • Passwords: Plaintext
In 2025, a dataset attributed to Majelis Ulama Indonesia (MUI, mui.or.id), the Indonesian Ulema Council, was allegedly published on a hacking forum by a hacktivist group. It has been reported that the export covered roughly 90,000 member and employee records compiled between 2020 and 2025. The compromised data reportedly included full names, Indonesian national identity numbers (NIK), genders, dates of birth, home addresses, email addresses, employment status, and affiliated organisations.
  • Date: 2025
  • Domain: mui.or.id
  • Threat Actor: SCTH
  • Country: Indonesia
  • Category: Non-Profit & Charities
  • Data: Email Addresses Names Geographic Locations Government IDs Genders Job Information Company Information Birthdates Personal Information
  • Records: 90,742
  • Lines: 1,907,324
  • Size: 69.69 MB
  • Passwords: No
In November 2022, the Russian courier and logistics service Grastin (grastin.ru) allegedly suffered a data breach that reportedly compromised approximately 1.58 million records dating from August 2021 to 2022. It has been reported that the data was initially shared on Telegram before appearing on several hacking forums. The compromised information reportedly includes full names, email addresses, phone numbers, and physical delivery addresses. No passwords were present in the leaked data.
  • Date: Nov 2022
  • Domain: grastin.ru
  • Country: Russia
  • Category: Logistics & Transportation
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations
  • Records: 1,581,126
  • Lines: 1,581,127
  • Size: 229.34 MB
  • Passwords: No
In 2025, Fekrawhats (fekrawhats.com), a platform for building automated WhatsApp marketing and mass-messaging bots widely used across the Middle East, allegedly suffered a data breach exposing its full database. Reports suggest the breach exposed approximately 692,000 unique WhatsApp contact phone numbers harvested from the platform's managed groups, spanning many countries across the MENA and Gulf regions. The exposed data allegedly included phone numbers and bot message content. No passwords were included.
  • Data: Phone Numbers Geographic Locations Messages Personal Information
  • Records: 692,375
  • Lines: 27,537
  • Size: 155.91 MB
  • Passwords: No
Sometime before 2023, PPOBox allegedly suffered a data breach. PPOBox is an Indian package-forwarding and international shipping service. Reports suggest that the breach exposed approximately 289,000 individuals. The exposed data allegedly included names, email addresses, phone numbers, shipping addresses and shipment records.
  • Date: 2023
  • Domain: ppobox.com
  • Country: India
  • Category: Logistics & Transportation
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Site Activity Shipment Information
  • Records: 834,032
  • Lines: 1,970,126
  • Size: 8.63 GB
  • Passwords: MD5
  • Cracked: 100%
In February 2025, RevScene (revscene.net), a Vancouver-based sports-car enthusiast forum, allegedly suffered a data breach. Reports suggest the data was subsequently published on a hacking forum. The exposed data reportedly contained approximately 109,000 unique user records, including email addresses, usernames, IP addresses and vBulletin password hashes.
  • Date: Feb 24, 2025
  • Domain: revscene.net
  • Country: Canada
  • Category: Forums & Communities
  • Data: Email Addresses Passwords Usernames IP Addresses
  • Records: 110,828
  • Lines: 110,834
  • Size: 10.45 MB
  • Passwords: Hashed, vBulletin
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.