Breach Intelligence

6,139

Total breached databases

In 2026, data from TomodachiShare (tomodachishare.com), a social profile-sharing website, was allegedly published on a hacking forum. It has been reported that the incident exposed approximately 145,000 user accounts. The compromised data reportedly included display names, email addresses, profile descriptions (bios), profile photo links, and account creation dates. No passwords were included.
  • Data: Email Addresses Names Usernames Site Activity Profile Photos Bios
  • Records: 145,569
  • Lines: 17,605
  • Size: 29.41 MB
  • Passwords: No
In 2024, Medal.tv, an online game-clip recording and sharing platform for gamers, allegedly suffered a data breach. Reports suggest a scrape of roughly 4 million user profiles was exposed. The compromised data allegedly included usernames, display names, account creation dates, and linked social-media profiles (Discord, Steam, Twitter, Xbox, Twitch and others); a small number of email addresses were also present.
  • Date: 2024
  • Domain: medal.tv
  • Threat Actor: nomnom
  • Category: Gaming
  • Data: Email Addresses Names Usernames Site Activity Social Profiles
  • Records: 4,004,530
  • Lines: 4,004,633
  • Size: 752.15 MB
  • Passwords: No
In July 2026, RevolutionParts (revolutionparts.com), a US-based e-commerce platform that powers online parts and accessories sales for automotive dealerships, allegedly suffered a data breach. Reports suggest the data was subsequently published on hacking forums. The exposed data reportedly contained approximately 1.1 million records, including full names, email addresses, phone numbers, physical addresses, and device information. No passwords were included in the exposed data.
  • Date: Jul 2026
  • Domain: revolutionparts.com
  • Threat Actor: kitta
  • Country: United States
  • Category: Automotive
  • Data: Email Addresses Names Phone Numbers Geographic Locations Device Information
  • Records: 1,112,862
  • Lines: 1,112,862
  • Size: 579.83 MB
  • Passwords: No
In January 2026, the dating and social-networking application Bumble (bumble.com) allegedly suffered a data breach attributed to the ShinyHunters group, which released the data after ransom demands went unmet. Reports suggest the exposed dataset combined user records with a large volume of internal company material — marketing and influencer-campaign assets, casting spreadsheets, contracts, invoices and internal documents. The searchable portion catalogued here comprises the email addresses of the content creators, influencers and staff contacts found across the leaked campaign spreadsheets. No passwords were included in the exposed data.
  • Data: Email Addresses Physical Locations Payment Information Genders Personal Interests
  • Records: 1,069
  • Lines: 5,167,777
  • Size: 1.2 GB
  • Passwords: No
Sometime in or before 2023, the French e-commerce company ObjetRama (objetrama.fr), a supplier of promotional products, goodies and custom-printed business gifts, allegedly suffered a data breach. The exposed dataset consisted of around 209,000 customer order records. Reports suggest the records contained customer names, salutations, partial postal addresses, order and invoice details, and payment method information. No passwords were included.
  • Date: 2023
  • Domain: objetrama.fr
  • Country: France
  • Category: E-commerce & Retail
  • Data: Names Physical Locations Geographic Locations Payment Information Order Information Genders Site Activity
  • Records: 193,455
  • Lines: 209,409
  • Size: 85.39 MB
  • Passwords: No
In 2025, a database belonging to Voney (voney.in), an Indian pharmacy loyalty and rewards app for medical-store owners, was allegedly published on a hacking forum, with the underlying data dating back to around 2018. It has been reported that the breach affected roughly 152,000 users. The exposed records reportedly included names, email addresses, plaintext passwords, phone numbers, shop names, physical addresses, IP addresses, and, for a subset of users, bank account details and uploaded prescription information.
  • Date: 2025
  • Domain: voney.in
  • Threat Actor: N1KA
  • Country: India
  • Category: E-commerce & Retail
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Bank Account Information IP Addresses Company Information Birthdates Device Information
  • Records: 462,672
  • Lines: 465,279
  • Size: 105.45 MB
  • Passwords: Plaintext
In November 2024, the Zimbabwean technology company Bluefin Technology (bluefintechnology.co.zw) allegedly suffered a data breach. Reports suggest that a database backup spanning several hosted WordPress sites was exposed. The compromised information reportedly included email addresses, usernames, display names, hashed passwords (phpass) and website URLs for the sites' registered users and commenters. The threat actor claimed responsibility under the alias Tanaka.
  • Data: Email Addresses Passwords Names Usernames Site Activity Websites
  • Records: 9,868
  • Lines: 1,708,206
  • Size: 567.04 MB
  • Passwords: PHPass
  • Cracked: 0%

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.