Breach Intelligence

6,139

Total breached databases

Sometime around 2023, PopFlow (Nerdweb), a Brazilian digital marketing agency's internal project-management and CMS platform, allegedly had a database exposed and later published on a hacking forum. The SQL dump was largely composed of internal project, task, and activity logs. Reports suggest that approximately 2,000 individuals — agency staff and client contacts — had personal data exposed. It has been reported that the compromised information included email addresses, names, company details, and SHA-256 password hashes for staff accounts.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Site Activity Websites Messages Company Information Birthdates
  • Records: 3,656
  • Lines: 11,588,440
  • Size: 1.5 GB
  • Passwords: SHA-256
  • Cracked: 0%
In late 2025, Tobi.net, a Ukrainian internet service provider, allegedly suffered a data breach exposing its subscriber database. Reports suggest the breach affected approximately 10,000 customers. The compromised data allegedly included full names, physical addresses, phone numbers, account usernames, and account activity dates. No passwords or email addresses were included in the exposed data.
  • Date: 2025
  • Domain: tobi.net
  • Country: Ukraine
  • Category: Telecommunications
  • Data: Names Phone Numbers Geographic Locations Usernames Site Activity
  • Records: 10,156
  • Lines: 496,237
  • Size: 15.15 MB
  • Passwords: No
In January 2026, the Italian e-commerce company Offerte Cartucce (offertecartucce.com), an online retailer of printer cartridges, allegedly suffered a data breach. Reports suggest data belonging to approximately 229,000 individuals was exposed, including email addresses, names, phone numbers, Italian tax identification numbers (codice fiscale and partita IVA), company information, and geographic locations. No passwords were included.
  • Date: Jan 2026
  • Domain: offertecartucce.com
  • Threat Actor: 888
  • Country: Italy
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Geographic Locations Government IDs Tax IDs Company Information
  • Records: 240,037
  • Lines: 240,038
  • Size: 23.32 MB
  • Passwords: No
In October 2024, data belonging to the Ion Creangă State Pedagogical University of Chișinău (upsc.md) in Moldova was allegedly published on a hacking forum. It has been reported that the exposed database held records for students, applicants, and staff. The compromised data reportedly included full names, Moldovan national identification numbers (IDNP), email addresses, phone numbers, home localities, dates of birth, genders, academic details, and password hashes for staff accounts.
  • Date: Oct 22, 2024
  • Domain: upsc.md
  • Threat Actor: Typical_Retard
  • Country: Moldova
  • Category: Education
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Government IDs Genders Birthdates
  • Records: 10,402
  • Lines: 154,151
  • Size: 18.28 MB
  • Passwords: BCrypt, MD5
  • Cracked: 0%
Sometime before 2025, the French student-housing rental platform Adele.org allegedly suffered a data breach exposing tenant rental-application files (dossiers). Reports suggest that data belonging to more than 260,000 individuals — applicants together with their co-applicants and guarantors — was exposed. The compromised information reportedly included full names, email addresses, phone numbers, postal addresses, nationalities and, according to the threat actor, scanned identity documents such as national ID cards, passports and health cards. No passwords were included in the exposed data.
  • Date: 2025
  • Domain: adele.org
  • Country: France
  • Category: Real Estate
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Government IDs Health Information Genders Nationalities
  • Records: 418,013
  • Lines: 233,012
  • Size: 220.36 MB
  • Passwords: No
Sometime before 2025, data associated with the French national health agency Agence Régionale de Santé (ARS) was allegedly exposed. Reports suggest the data was a registry of approximately 233,000 French healthcare establishments and legal entities, derived from the FINESS directory. The compromised information reportedly included organisation names, French business registry identifiers (SIREN), business activity codes, postal addresses, switchboard phone numbers and, for some entries, contact email addresses. No passwords were included in the exposed data.
  • Date: 2025
  • Domain: ars.sante.fr
  • Country: France
  • Category: Healthcare
  • Data: Email Addresses Phone Numbers Physical Locations Geographic Locations Site Activity Tax IDs Company Information
  • Records: 233,837
  • Lines: 233,836
  • Size: 133 MB
  • Passwords: No
In early 2026, a large customer payment database from Struktura, a Ukrainian vendor of consumer-grade phone-monitoring and "stalkerware" applications (including uMobix, Geofinder, and Peekviewer/Glassagram), was allegedly exposed by a hacktivist. Reports suggest the breach affected approximately 490,000 customers who paid for these surveillance services. The compromised data allegedly included email addresses, the app or brand purchased, payment amounts, and partial credit-card information (card type and last four digits). No passwords were included.
  • Data: Email Addresses Credit Card Information Payment Information Languages
  • Records: 536,626
  • Lines: 536,626
  • Size: 160.76 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.