Breach Intelligence

6,139

Total breached databases

Sometime before 2025, the Czech wiki-based community site Qipim (qipim.cz) allegedly suffered a data breach. Reports suggest the exposed MediaWiki user database contained approximately 83,000 registered accounts. The compromised data allegedly included email addresses, usernames, real names, and salted MD5-hashed passwords.
  • Date: 2025
  • Domain: qipim.cz
  • Country: Czech Republic
  • Category: Forums & Communities
  • Data: Email Addresses Passwords Names Geographic Locations Usernames Site Activity
  • Records: 94,855
  • Lines: 95,002
  • Size: 115.21 MB
  • Passwords: MD5, MD5 Salted
  • Cracked: 0%
In May 2026, the Saudi Arabian supermarket and hypermarket chain BinDawood allegedly suffered a data breach exposing customer order data. Reports suggest that order records belonging to approximately 137,000 individuals were exposed. The compromised information reportedly included email addresses, order details, store locations, order dates and partial payment card information (card brand and last four digits). No passwords were included in the exposed data.
  • Date: May 2026
  • Domain: bindawood.sa
  • Country: Saudi Arabia
  • Category: E-commerce & Retail
  • Data: Email Addresses Geographic Locations Credit Card Information Order Information Site Activity
  • Records: 216,447
  • Lines: 321,924
  • Size: 457.6 MB
  • Passwords: No
In June 2025, data associated with the hospital patient-queue system at the domain sim.rs was allegedly published. It has been reported that the incident exposed approximately 159,000 patient visit records dating from 2022. The compromised data reportedly included full names, Indonesian national identity numbers (NIK), phone numbers, home addresses, genders, and dates of birth, along with hospital registration and health-service details.
  • Date: Jun 11, 2025
  • Domain: sim.rs
  • Country: Indonesia
  • Category: Healthcare
  • Data: Names Phone Numbers Geographic Locations Government IDs Health Information Genders Site Activity Birthdates
  • Records: 159,186
  • Lines: 159,187
  • Size: 69.79 MB
  • Passwords: No
Sometime before 2025, the library system of PPM Manajemen (ppm-manajemen.ac.id), an Indonesian management school, allegedly suffered a data breach. Reports suggest the exposed SLiMS library database contained records for approximately 1,900 library members and administrator accounts. The compromised data allegedly included email addresses, names, usernames, BCrypt-hashed passwords, phone numbers, physical addresses, genders, birthdates, IP addresses, and affiliated company information.
  • Data: Email Addresses Passwords Names Phone Numbers Physical Locations Geographic Locations Usernames Genders IP Addresses Site Activity Company Information Birthdates
  • Records: 4,438
  • Lines: 852,805
  • Size: 365.93 MB
  • Passwords: BCrypt
  • Cracked: 0%
Sometime before 2023, the online gaming platform Flame Game (flamegame.eu) allegedly suffered a data breach. Reports suggest the exposed database contained roughly 200 registered account holders with searchable data, alongside a large volume of placeholder seed accounts. The compromised information reportedly includes email addresses, usernames, names, bcrypt-hashed passwords, and a small number of phone numbers and geographic locations.
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames Site Activity
  • Records: 294
  • Lines: 1,871,569
  • Size: 216.66 MB
  • Passwords: BCrypt
  • Cracked: 0%
Sometime in or before 2023, the French professional directory Mediamatis (mediamatis.com) allegedly suffered a data breach. Mediamatis operated a B2B platform connecting wealth-management advisers with product and service suppliers. Reports suggest data belonging to approximately 8,000 individuals was exposed, including email addresses, names, usernames, phone numbers, geographic locations, IP addresses, job information, social profiles, and passwords stored as BCrypt, PHPass, MD5, and salted MD5 hashes.
  • Date: 2023
  • Domain: mediamatis.com
  • Country: France
  • Category: Professional & Corporate
  • Data: Email Addresses Passwords Names Phone Numbers Geographic Locations Usernames IP Addresses Site Activity Social Profiles Job Information
  • Records: 16,468
  • Lines: 809,039
  • Size: 200.57 MB
  • Passwords: BCrypt, MD5, MD5 Salted, PHPass
  • Cracked: 0%
In March 2025, Fanjoy (fanjoy.co) allegedly suffered a data breach. Fanjoy is an influencer-focused merchandise and e-commerce platform. Reports suggest the full order database was exposed, affecting approximately 365,000 individuals. The compromised data included email addresses, full names, phone numbers, and physical shipping and billing addresses, along with order metadata and timestamps. No passwords were included in the exposed data.
  • Date: Mar 2025
  • Domain: fanjoy.co
  • Category: E-commerce & Retail
  • Data: Email Addresses Names Phone Numbers Physical Locations Geographic Locations Site Activity
  • Records: 467,855
  • Lines: 467,855
  • Size: 1023.13 MB
  • Passwords: No

Frequently Asked Questions

A data breach is unauthorized access to data (often involving account takeover, malware, or misconfigured infrastructure). A data leak is exposure of data due to mistakes like public cloud storage, open databases, or accidental publishing. A database dump is a packaged dataset that may come from a breach, leak, scraping, or aggregation.

Change passwords for any affected accounts immediately, prioritizing email, banking, and any account that shares the same password. Enable multi-factor authentication wherever possible. Monitor your accounts for suspicious activity and consider placing a fraud alert or credit freeze if financial data was exposed.

Start with containment and verification: confirm what data was exposed, identify the entry point, rotate credentials (especially SSO, VPN, email), and enforce MFA. Then investigate affected systems, notify stakeholders as required, and harden controls to prevent recurrence. A structured incident response plan helps keep the work measurable and compliant.

Dark web monitoring helps you spot exposure signals early — before stolen data is widely reused for account takeover or targeted attacks. Monitoring complements vulnerability management by revealing when attackers already have leverage. Pair it with continuous attack surface monitoring and strong Asset Discovery to reduce blind spots.

Not always. Some datasets are old, incomplete, or derived from third parties. However, any exposure increases risk because credentials and personal data can be reused indefinitely. Treat it as a priority signal: rotate credentials, enforce MFA, review suspicious logins, and audit the systems that could have produced the data.

SynScan helps you connect the dots between attack surface exposure, vulnerabilities, and breach signals so you can prioritize remediation and reduce the chance of repeat incidents.