The dataset catalog.
Every public corpus we've gotten our hands on. Breaches, stealer logs, paste dumps, combolists. Click any one to see the fields it exposed and search it directly.
Datasets
luxrender.net
Full WordPress database dump from luxrender.net, a 3D rendering software community website. The breach contains user account data including usernames, display names, hashed passwords (phpass/bcrypt), and email addresses. Also includes a separate paypal_payments.csv file and usermeta EAV records with fields for names and other profile attributes. User registrations span from 2020 to late 2023/early 2024. The actionscheduler_claims table shows a claim date of January 2026, suggesting the dump may have been taken around that time.
buyselltext.com
Full database dump of BuySellText (buyselltext.com), a content marketplace connecting buyers and writers. The breach includes user accounts, orders, payments (PayPal and Stripe), articles, assignments, sessions, sign-in histories, referral codes, team data, and extensive platform configuration data. Data spans from approximately 2018 through early 2023.
US Voter Data Compilation
A large compilation of US voter registration data spanning multiple states (Alabama, Alaska, Arkansas, Colorado, Connecticut, and likely others) with records from 2015 through 2021. Contains detailed voter registration information including full names, residential addresses, birth year, gender, party affiliation, phone numbers, mailing addresses, precinct and district assignments, voter status, and registration dates. Data appears to have been collected from publicly available or officially obtained state voter rolls and assembled into a single archive, then shared on BreachForums (indicated by 'BF' suffix in folder name).
qicard.com
A data breach from QI Financial (likely QI Card, an Iraqi financial services/payment card company). The leaked data is in Arabic and contains records with department/district (القسم), full name (الاسم), mother's name (اسم الام), and review/appointment date (تاريخ المراجعة). Records appear to reference Baghdad districts including Sadr City (بغداد الصدر), with dates around October 2022. The data appears to be customer or applicant registration records.
Chile Combo Credential List
A credential stuffing combo list targeting Chilean users, containing email:password pairs predominantly from .cl domains (hotmail.cl, live.cl, outlook.cl, yahoo.cl) as well as Chilean institutional, corporate, and educational email addresses. The data appears to be an aggregated compilation from multiple sources rather than a single breach, containing plaintext passwords for a wide variety of Chilean internet users.
akitatek.fr
Data breach of Akitatek.fr, a French company. The exposed dataset contains approximately 5,400 address records including street addresses, postal codes, cities (predominantly in southern France, especially Montpellier region), and mobile/landline phone numbers. Some records include first and last names.
pix.fr
Data breach affecting Lycée Ambroise Brugière, a French secondary school. The leaked data contains student (élèves) records exported from the Pix educational assessment platform, including full names, birthdates, usernames, internal user IDs, email addresses (where provided), class/division assignments, participation counts, campaign names, and certification status. Records span students in Seconde, Première, Terminale, and BTS classes.
bitsphere.in
Database dump from bitsphere.in, an Indian digital services/IT company. The breach contains multiple tables including user registration data, login credentials, SMS data, campaign data, doctor profiles, chatbot interactions, car registration/survey data (Hyundai models), Indian Oil campaign entries, blog content related to AYUSH/traditional medicine systems, and various government/health-related data. The data appears to be from a company that managed multiple client campaigns and government digital initiatives in Bihar and Jharkhand regions of India.
boutiqchalets.fr
Database dump of Boutiq Chalets (boutiqchalets.fr), a French luxury chalet rental company based in the Haute-Savoie (74000) area. The breach contains a full SQL database export including customer records, admin credentials (bcrypt hashed passwords), addresses, orders, cart data, and CMS content. Admin emails include contact@boutiqchalets.com and management@boutiqchalets.com. The platform appears to be built on the Thelia e-commerce framework. Data spans from 2019 to at least late 2023.
lire-demain.fr
Data breach of Lire Demain (lire-demain.fr), a French educational book distribution company serving schools and municipalities primarily in the Seine-et-Marne (77) department. The breach contains client records (schools, colleges, municipalities with contact details and email addresses), order history with financial data, shipping/expedition records with personal names, addresses and phone numbers of individuals, invoices, and product catalog data. Data spans from at least 2020 through early 2026.
dailysignal.com
A full WordPress MySQL database dump from The Daily Signal (dailysignal.com), the digital news outlet of The Heritage Foundation. The dump includes WordPress core tables covering users, comments, posts, metadata, options, redirections, Yoast SEO data, and Gravity Forms entries. The heartbeat table shows a last activity timestamp of 2022-11-22, suggesting the dump was taken around that date. The data exposes site user accounts, commenter email addresses and IPs, post content, and internal site configuration.
avicolaelmadrono.com
Database dump from Avícola El Madroño S.A. (AVICOLA EL MADRONO S.A.), a Colombian poultry company. The breach includes internal ERP/accounting system data: customer and supplier records, product lots, warehouse/location master data, user credentials (plaintext password variants), financial transaction records (payment vouchers with personal names and Colombian national ID numbers), invoicing data, vehicle pre-operational records, price lists, and operational logistics data. Financial reports dated July 2021 expose full names and government ID numbers of individuals receiving payments.
efcformation.com
Data breach of EFC Formation (efcformation.com), a French vocational training and accounting education organization. The archive contains approximately 49,000 student records including names, civility, enrollment dates, course/formation details, and student IDs. Additionally, the breach includes internal business documents from EBP accounting/payroll software (EBP Comptabilité, Paie, Immobilisations, Gestion Commerciale), payslip templates in French, and employee payroll data covering multiple years (2017-2020). The dataset spans both student enrollment data and internal HR/financial records.
item-robot.com
Full database dump of item-robot.com, a Japanese e-commerce analytics/automation SaaS platform (likely serving Rakuten sellers). The archive contains approximately 18 million records across 26 tables including customers, members, shops, mail histories, queries, scripts, and Rakuten Super Sale logs. Data includes customer histories, mail templates, and account management data.
acclimited.com
Breach of acclimited.com, an Indian OTT/streaming platform (appears related to Gemplex/ACC Ltd). The exposed CSV contains user account data including mobile numbers, email addresses, names, hashed passwords (bcrypt), OTP codes, parental lock PINs, subscription plan details, device registration info, date of birth, gender, city, country, and Facebook/Google IDs.
farmapatria.com.ve
A leak of approximately 3 million Venezuelan citizens' COVID-19 vaccination records from the Farmapatria platform. The dataset contains highly sensitive personal information including national ID numbers (cédulas), full names, dates of birth, phone numbers, home addresses, state/municipality, health center, employer, email, and detailed COVID-19 vaccination data (vaccine brand, lot numbers, dose dates). The vaccine used is predominantly Sinopharm VERO CELL. Data appears to originate from Venezuela's national vaccination registry.
StarLinkClouds ULP Compilation
A large URL:Login:Password (ULP) credential compilation distributed via the Telegram channel @StarLinkClouds. Contains approximately 29 million lines of credential logs aggregated from infostealer malware, covering a wide variety of websites including social media, gaming platforms, financial services, and e-commerce sites worldwide. No single target company — this is a multi-source credential stuffing/log compilation.
college-de-france.fr
Breach of the Collège de France (Paris) Nextcloud instance, exposing an internal staff directory (~1,600 entries) with names, email addresses, mobile phone numbers, institute/team affiliations, building/office locations, and phone extensions. Also includes internal HR promotion dossiers with personally identifiable information for named employees, IT infrastructure documentation (VPN procedures, SSO/federation docs, IT charter), and a SentinelOne endpoint-agent site key/token. The directory data and HR files represent the most sensitive personal data exposure.
nhc.gov.cn
A large archive of medical records data from China's National Health Commission (NHC) Hospital Quality Monitoring System (HQMS). The dataset contains structured CSV files from multiple hospitals in Guangdong province, including Sun Yat-sen University Third Affiliated Hospital (中山大学第三附属医院), Xinyi People's Hospital (信宜市人民医院), Southern Medical University Seventh Affiliated Hospital (南方医科大学附属第七医院), Guangdong Medical University Affiliated Hospital (广东医科大学附属医院), Guangdong Jiangmen Hospital (广东江门医院), and Guangzhou Medical University First Affiliated Hospital (广州医科大学附属第一医院). Files contain detailed patient-level hospital quality metrics and clinical data submitted through the HQMS reporting system covering 2020-2021 reporting periods.
WagnerTech
A SQL database dump from an entity named 'WagnerTech' containing aviation-themed data including flight bookings (buchung), flights (flug), airports (flughafen), airlines (fluglinie), flight schedules (flugplan), aircraft (flugzeug), passengers (passagier), passenger details, employee records (mitarbeiter), and weather data (wetterdaten). The data appears to be a German-language aviation database, possibly a training/educational dataset or a flight booking system. Contains passenger IDs, seat assignments, pricing, and geolocation data for thousands of airports worldwide.
megacable.com.mx
Internal accounting and fixed asset management data from Megacable Comunicaciones de México S.A. de C.V., a major Mexican cable and telecommunications provider. The archive contains detailed fixed asset registers, depreciation schedules (spanning 2002–2017), CAPEX reports, employee gift card records, and internal financial reconciliation files. Data appears to be from the accounting/finance department and includes asset IDs, acquisition dates, depreciation values, cost center codes, and internal ledger entries.
red.develmakss.shop
A credential dump distributed via a Telegram channel (@redcloud_link) and associated service 'RED PRIVATE CLOUD' operated by threat actor 'DevelMakSS'. Contains two files: one with email:password combos for Hotmail/Outlook/MSN/Live accounts (Mail Access), and one with URL:login:password combos (ULP format) harvested from infostealer logs. Data covers multiple countries (EU/DE/PL/FR/IT) and includes credentials for services like Netflix, Spotify, PayPal, Discord, Roblox, Epic Games, and more. The operator embeds self-promotional handles and obfuscated seller/bot account strings throughout the file to advertise their credential-selling service.
celsolisboa.edu.br
Data breach from Centro Universitário Celso Lisboa, a Brazilian higher education institution based in Rio de Janeiro. The archive contains two files: student records (aluno.csv) and employee/staff records (funcionario.csv). Student data includes full names, CPF (Brazilian tax ID), RG (national ID), PIS numbers, hashed passwords (MD5), dates of birth, addresses, contact information, enrollment details, and academic status. Employee data includes full names, CPF, RG, hashed passwords (MD5), job titles, admission dates, addresses, and personnel details.
ecomix.com.co
Database dump of ecomix.com.co, a Colombian WooCommerce/WordPress e-commerce site. The archive contains full WordPress database tables including users, usermeta, posts, comments, WooCommerce product and order data, and scheduler logs. Data includes customer information, comment authors with emails and IPs, and site configuration. Activity timestamps range from late 2019 through January 2022.
clinicalregistrysolutions.com
Data breach of Clinical Registry Solutions (CRS), a healthcare data registry management company. The archive contains highly sensitive protected health information (PHI) including patient medical records, surgery reports, discharge summaries, anesthesia records, echocardiograms, cardiac CT scans, operative reports, labs, H&P documents, and registry audit data. Files include full patient names, MRNs, hospital IDs, surgery dates, admission/discharge dates, and detailed clinical documentation. Data spans multiple hospital clients including cardiovascular and pediatric cardiac surgery registries (STS, PC4, PAC3). The most recent data records appear to extend into 2025.
zivame.com
A database dump from Zivame.com, an Indian online lingerie and women's apparel retailer, containing approximately 1.5 million customer records. The exposed data includes first and last names, shipping addresses (street, city, region, postal code), country codes (IN), phone numbers, and email addresses.
kingofthecurve.com
Data breach of King of the Curve (KOTC), an MCAT preparation mobile app. The dataset contains detailed user analytics event data and unique user profile records including email addresses, display names, demographic information (age, gender, ethnicity, education level, household income), MCAT test dates and goal scores, academic institution details, device information, in-app purchase and subscription data, and behavioral/usage metrics. Data appears to have been exported from Amplitude analytics.
century21.fr
A data breach of Century 21 France's internal HR/employee system containing personnel records including full names, birthdates, usernames, hire dates, employment status, roles, email addresses, phone numbers, education levels, professional backgrounds, and recruitment channels for employees and agents across the French real estate network.
utmar.edu.mx
Data breach affecting students of the Universidad Tecnológica del Mar del Estado de Guerrero (UTMAR) in Mexico. The dataset contains detailed personal and academic records including full names, CURP (Mexican national ID), email addresses, phone numbers, dates of birth, gender, home addresses, academic program details, GPA, indigenous/disability status, and socioeconomic indicators. Data appears to be related to the 'Jóvenes Escribiendo el Futuro' scholarship program applications from 2023.
upbicentenario.edu.mx
Data breach of Universidad Politecnica del Bicentenario, a Mexican polytechnic university located in Silao de la Victoria, Guanajuato. The dataset contains student records including full names, CURP (Mexican national ID numbers), dates of birth, email addresses, phone numbers, home addresses, academic program details, GPA, scholarship information (Jovenes Escribiendo el Futuro), indigenous/Afrodescendant identity data, disability status, and household economic information.
upt.edu.mx
Data breach from the Universidad Politécnica de Tulancingo (UPT), a Mexican polytechnic university located in Hidalgo, Mexico. The dataset contains student records including full names, CURP (Mexican national ID), date of birth, age, gender, email addresses, phone numbers, home address details, academic program information, academic status, GPA, indigenous/Afro-descendant identity flags, and socioeconomic indicators. Data appears related to the 'Jóvenes Escribiendo el Futuro 2023-2' scholarship program applications.
lifeline.org.au
A data breach of Lifeline Australia, a national crisis support and suicide prevention service. The dataset contains internal user/staff/volunteer directory data including email addresses, full names, Active Directory distinguished names, department/office locations, phone numbers, and internal UUIDs. Data appears to originate from an internal user management or helpdesk platform (possibly Freshservice or similar), covering both staff and volunteer accounts across multiple Australian offices.
hvmn.com
Breach of Health Via Modern Nutrition (HVMN), a nutrition/supplement company. The dataset contains customer records including names, email addresses, IP addresses, billing/shipping addresses, Stripe customer IDs, revenue figures, partial card-on-file data (masked card numbers, CVCs, expiration dates), subscription IDs, and Google Analytics IDs. Records span from approximately 2014 to mid-2016.
lepontet.fr
Data breach of the Police Municipale (municipal police) of Le Pontet, a commune in the Vaucluse department of France. The leaked data includes internal law enforcement operational records: incident reports (affaires), service bulletins, public requests/complaints, vehicle impoundment records, interventions, lost property, funeral operations, holiday watch registrations (tranquillité vacances), system parameters, and officer/user accounts. Data contains full names of officers, citizens, vehicle registration plates, home addresses, and sensitive case details including domestic violence and drug-related incidents.
woflow.com
Full database dump from Woflow, an AI-driven merchant data and menu digitization platform serving US restaurants. The breach contains approximately 12 million records across 30 tables including restaurant data, menu items/categories/modifiers/prices, user accounts, user roles, gamification points, Google Places data, bookmarks, events, and internal workflow data. Data spans from the platform's early days in 2017 through early 2026, indicating a near-complete database exfiltration.
amicalepn.fr
Membership database leak from amicalepn.fr, the Amicale du Personnel Navigant Technique (a French aviation crew/pilot association). The data contains member records including full names, civility, dates of birth, profession, postal addresses, phone numbers, mobile numbers, email addresses, membership status with dues payment details, sponsor/parrain names, SIRET numbers, and committee affiliations. Members appear to be located primarily in the Alsace region of France (Mulhouse area). The dataset includes ~95KB of structured JSON/CSV data.
eaglecrestcommunities.com
Full WordPress database dump from Eagle Crest Communities, a senior living/assisted living organization in La Crosse, Wisconsin. Contains housing applications with PII including full names, addresses, phone numbers, email addresses, dates of birth, and care level information. Also includes WordPress user accounts, form submissions, site configuration, security plugin logs (Wordfence), and audit logs.
plskyayg.com
Database dump from plskyayg.com, an online gambling/lottery platform with Chinese-language content. The dump includes member credentials (bcrypt-hashed passwords), lottery schedules, currency exchange rates, forum/CMS tables, and transaction records. Data appears to originate from around July 2020 based on the earliest timestamps.
magmutual.com
Data breach of MagMutual Insurance Company, a medical professional liability insurer. The archive contains highly sensitive insurance and financial data including policyholder records with physician names, addresses, tax IDs, email addresses, specialty information, premium data dating back to 1998, claims reports, cyber insurance bordereaux, reinsurance invoices (Beazley partnership), finance payment records through January 2026, and detailed records of thousands of insured medical practices and physicians across the US.
esgi.fr
Database dump from ESGI (École Supérieure de Génie Informatique), a French IT engineering school. Contains student enrollment records including full names, personal email addresses, school email addresses (myges.fr), phone numbers, home addresses, postal codes, nationalities, class/promotion details, student IDs, and academic year information for students at ESGI Paris and ESGI Lyon campuses.
Anarchy Education Database
A database dump of approximately 100,000 education-related records, released under the 'Anarchy' threat actor/group branding. The file contains an ASCII art banner identifying it as the 'ANARCHY Database' with the tagline 'Your Actions, Your Consequences'. The actual data content is not visible in the samples provided, as the file appears to be mostly header/banner content. The filename 'edudb100k' suggests an education-sector database with roughly 100,000 records.
doalltech.co.kr
Data breach of DoAllTech, a South Korean engineering/architectural design and technology firm. The leaked archive contains internal project deliverable files including architectural design reports, structural calculation documents, civil engineering drawings, construction cost estimates, and hydraulic calculations related to public housing construction projects in Jeju (삼도이동 공공주택). Files include PDFs, HWP (Korean Hangul word processor), Excel spreadsheets, and CSV exports of detailed construction cost breakdowns.
danteai.com
Data breach of Dante AI, an AI chatbot platform. The archive contains two datasets: an events log (DANTEAI_EVENTS) with behavioral/analytics telemetry including device info, session data, LLM usage, chatbot interactions, and marketing attribution; and a PII dataset (DANTEAI_PII) containing user-level records with IP addresses, geolocation (lat/lng), city, country, region, email addresses, device details, and linked advertising identifiers (gclid, fbclid, twclid, etc.). The PII file is the higher-sensitivity dataset. The hint references 'GoreTurbine' as a likely threat actor or dump-source handle.
groomit.me
Breach of Groomit (groomit.me), an on-demand pet grooming platform. The dataset contains PII from user sign-up events including full names, email addresses, phone numbers, ZIP codes, IP addresses, device information, platform/OS details, referral codes, and signup dates. Data spans roughly 2020–2022.
debras.com.au
Data breach from Debra's, an Australian specialty bra and lingerie retailer. The leaked data includes customer records with full names, physical addresses (Australian states including NSW, VIC, WA, QLD), phone numbers, and email addresses (file 1), as well as detailed order/transaction records including product names, pricing, order IDs, and customer purchase history (file 2). Data appears to originate from their retail management/CRM system, with records dating back to at least 2008.
DreamChild
A data breach attributed to a target or platform named 'DreamChild', released or associated with the threat actor handle 'GoreTurbine'. The dataset contains user records including phone numbers, names, IP addresses, geographic information (country, region, city), device identifiers, device types, device family, carrier information, OS names and versions, platform data, app version names, and session/title metadata. The data appears to originate from a mobile analytics or user tracking backend.
resamania.fr
A breach of Resamania (resamania.fr), a French fitness club management software/platform. The dataset contains approximately 5.2 million records of gym/fitness club members across France, including full names, email addresses, phone numbers, physical addresses, cities, postal codes, dates of birth, club names, and staff flags. Data appears to span multiple fitness clubs using the Resamania platform.
paidwork.com
Database dump from PaidWork, a get-paid-to/microtask platform. Contains user accounts, email addresses, personal details (names, birthdays, gender, location data including lat/long), billing information (full names, addresses, bank account numbers, BIC codes, PayPal emails, crypto wallets), withdrawal history with transaction amounts, and mailing list data. Users appear to span globally with significant representation from Poland, Morocco, Algeria, Egypt, and other countries.
saludnayarit.gob.mx
Breach of the Nayarit State Health System (Sistema de Salud del Estado de Nayarit) patient database (SIAC system). Contains personally identifiable and medical information of patients including full names, CURP (Mexican national ID number), date of birth, sex, home address, medical record number, affiliation number, and medical service provider (IMSS BIENESTAR). Data appears to originate from the SIAC patient management system used by public health facilities in Nayarit, Mexico.
waggle.com
Breach of Waggle, a pet health and wellness platform offering GPS tracking and subscription-based services (plans named 'wagon-monthly', 'spot-mini-monthly', 'woof-monthly', etc.). The data includes employee/user records with names, emails, phone numbers, and addresses from the Nimble Wireless backend (likely the technology provider), billing and subscription records with invoice IDs, payment status, Chargebee subscription IDs, and mobile numbers, and app user records with user IDs, emails, app rating data, and account creation dates. Data appears current as of late July 2026.
deliver2alaska.com
Database dump from Deliver2Alaska (deliver2alaska.com), an Alaska-based package forwarding and mailbox service. The breach contains user account records including names, email addresses, mailbox IDs, Stripe customer IDs, mailing address IDs, authentication IDs, forwarding/mailpiece/package policies, and internal admin notes. Records span from mid-2022 through late 2023.
bankofamerica.com
A dataset of approximately 238,000 Bank of America mortgage/refinance leads containing full names, home addresses, dates of birth, phone numbers, email addresses, and gender. The column 'refinance_lender' consistently lists Bank of America variants, suggesting this is a compiled lead list of Bank of America mortgage or refinance customers. The file header attributes the data to a Telegram user 'Immanuel Kant' with an anti-impersonation warning, indicating distribution on Telegram-based data trading channels.
zynex.com
Internal corporate data breach of Zynex, a Swiss web hosting and CMS software company (zynex.com). The archive contains highly sensitive internal financial records spanning 2001–2020, including annual financial statements, subscription billing records (FaktNT ERP system), project status files, general assembly protocols, and customer invoicing data. Customers visible in the data are Swiss SMEs billed for 'Zynex Business' and 'Zynex One' annual web hosting/CMS subscriptions. Data is primarily in German and uses Swiss Francs (CHF). Also includes a 3CX license invoice from 2020, indicating operations continued at least to that date.
frostyacres.com
Ransomware-style data exfiltration of Frosty Acres Brands (FAB, Inc.), a foodservice distribution company headquartered in Georgia. The breach contains highly sensitive internal data including: complete employee personnel files (offer letters, I-9s, W-4s, salary sheets, 401k records, medical/STD/FMLA documents, direct deposit forms, resumes, non-competes), contractor 1099 records, full accounting bank feed check registers with vendor names and bank account numbers (dating from 2020 through 2025), procurement/inventory data, and HR onboarding workflows. Files span employees from at least 2015 through mid-2025, with the most recent documents dated June 2025.
nfinite9000.com
Data breach of nfinite9000.com, a Barcelona-based sports facility maintenance and technical services company (operating as MT Esports / Manteniment Esportiu). The archive contains internal business documents including invoices, budgets/quotes for sports facilities (gyms, parking, athletic centers), employee HR records (vacation schedules, work calendars, training registrations with DNI/SSN data), CVs, and operational spreadsheets. Documents are primarily in Catalan and Spanish, spanning approximately 2015–2025. Personnel data includes full names, national identity numbers (DNI/NIE), and social security numbers.
ufpt.com
Active Directory employee dump from UFP Technologies (UFPT), a manufacturer with locations including Newburyport MA, Grand Rapids MI, Chicopee MA, Denver CO, El Paso TX, and Tijuana Mexico. The dataset contains internal AD account details including usernames, display names, email addresses, account status, last logon dates, password metadata, job titles, departments, admin flags, and Kerberoastable/ASREPRoastable attributes — indicating this was extracted via an internal network compromise or AD enumeration tool.
secretline.top
A large credential compilation (stealer log / ULP format) distributed via the Telegram channel @StarLinkClouds and the website secretline.top. Contains approximately 57 million credential pairs in URL:login:password (ULP) format aggregated from infostealer logs and other sources. Data spans hundreds of domains globally including social media, gaming, banking, e-commerce, and government portals. No single target company — this is a multi-source credential stuffing compilation.
db.com
Archive attributed to Deutsche Bank containing approximately 188,000 files totaling 13.54 GB. Data includes JSON and CSV records with fields such as transaction counts, monetary sums, remuneration codes, and user UUIDs (likely internal account or employee identifiers), as well as PDF documents resembling purchase orders and invoices with German/EU formatting (AEU-INV-PL, INV-DE prefixes), and screenshots (Bildschirmfoto). The remuneration codes and EUR-denominated transaction data suggest internal financial or payroll/commission records.
dpwh.gov.ph
A small dataset containing email addresses and display names associated with the Philippine Department of Public Works and Highways (DPWH). The data includes functional/group email accounts for BAC (Bids and Awards Committee) officers, IT Support Officers, and procurement staff across various regional offices. A small number of entries from other Philippine government agencies (COMELEC, Ombudsman) and private companies are also present.
allo.solar
Breach of allo.solar, a French solar energy e-commerce platform. The dataset contains approximately 208,000 order records including customer names, phone numbers, billing and shipping addresses, cities, countries, payment and delivery details, tax amounts, order totals, and full product line items (names, references, prices, quantities, subtotals).
ouestfrance-immo.fr
A breach of Ouest-France Immo (ouestfrance-immo.fr), a French real estate listings platform associated with the Ouest-France regional newspaper group. The dataset contains approximately 16,800 professional agency/advertiser records including business identifiers (SIRET, SIREN), commercial email addresses, postal addresses, geolocation data, phone numbers, agency branding details, and platform metadata such as listing counts and contract status.
belambra.fr
Breach of Belambra Clubs, a French holiday resort chain. The dataset contains approximately 360,000 children records (names linked to reservation numbers), 41,000 detailed reservations including user accounts with bcrypt-hashed passwords, email addresses, names, and booking details, and 42,000 reservation summaries with guest names, emails, resort locations, stay dates, and meal plans. Data appears current as of early 2026 based on reservation timestamps.
pnld.co.uk
A data breach of the UK Police National Legal Database (PNLD), a legal reference service used by UK police forces. The leaked data appears to be a CRM export (Microsoft Dynamics 365) containing contact records of registered users, including names, email addresses, job titles, postal addresses, phone numbers, police force affiliations, portal login metadata, and account preferences. The JSONL and CSV files suggest a structured database dump of user/contact records.
megacable.com.mx
Database breach of Megacable Comunicaciones de Mexico, a major Mexican cable and telecommunications provider. The leak contains extensive internal business data including supplier records, bank account information, customer data, tax codes, AR/AP financial records, CDR (call detail records), network routing tables, and ERP system data consistent with an Oracle E-Business Suite installation.
coldfrontdist.com
Internal data breach of Cold Front Distribution, a food/beverage distribution company operating across the US (including Schwan's products). Contains company employee rosters with full names, job titles, direct phone numbers, cell phones, and corporate email addresses across multiple regional divisions (Albuquerque, Denver, El Paso, Central, Midwest, Southeast Texas, West Texas, Mountain Routes). Also includes customer lists (Emil's master customer list), lease management database, and Schwan's route/customer/invoice data dating back to 2017. The company roster is dated August 2024, indicating the breach occurred around that time.
education.gov.uk
Data breach from the UK Department for Education (DfE) containing exports from two internal CRM portals: the Help Portal and the Turing Portal. The data includes accounts (training providers, schools, trusts, NHS bodies, police forces), contact records (names, emails, phone numbers, job titles), and incident/case records. The Turing Portal data relates to the Alan Turing Institute scheme for education. Records span from 2024 through at least July 2025, suggesting the data was exfiltrated around that time.
gandhofcny.com
Database breach of Gastroenterology & Hepatology of CNY, P.C. (gandhofcny.com) and Digestive Disease Center of CNY, LLC (ddcofcny.com), a GI practice and AAAHC-accredited endoscopy center in Syracuse, New York. Contains records for 167,303 patients including full names, addresses, phone numbers, SSNs (124,761 records), email addresses, diagnoses (ICD-10 codes), medications, and detailed pathology reports. Highly sensitive medical data includes mental health diagnoses and psychiatric medications, substance abuse records, HIV/AIDS, hepatitis B/C, cancer diagnoses, and sexual health information.
microsoft.com
A sample data archive attributed to Microsoft, apparently exfiltrated from Microsoft Dynamics 365 CRM environments. The data includes facilities management contacts, incident/service request records, field technical representative/sales associate (FTRSA) contact records, and system user records. Fields include employee names, email addresses, job titles, phone numbers, organizational hierarchy data, Azure AD object IDs, and internal CRM metadata. The 'ExfilSquad' threat actor handle appears in the filename hint.
Lupin Data USA Citizens Compilation
A compilation of approximately 45,000 US citizen records distributed by a threat actor operating under the handle 'Lupin Data' (@LupinIsHere). Records contain full names, physical addresses, city, state, ZIP code, country, email addresses, and phone numbers. The data appears to be aggregated from one or more unknown source breaches or data broker leaks. No single target organization is identifiable; this is a compiled/resold dataset.
bms.com
Employee directory data from Bristol Myers Squibb (BMS) containing internal HR records. Includes employee codes, login IDs, full names, email addresses, phone numbers, organizational codes, supervisor IDs, employment status, job titles, employee type, grade level, hire dates, termination dates, and badge IDs. Also includes records for contractors from third-party companies such as PwC, ProPharma Group, Syneos Health, and Lotte.
bmwmregistry.com
A leak of the BMW M Registry database containing records of BMW M-series vehicle owners. Data includes owner names, email addresses, car model, model code, VIN, production date, country of origin, paint color, interior color, and options. The registry appears to be a community/enthusiast registry (bmwmregistry.com) rather than an official BMW corporate database.
acomee.com.mx
Database dump from Acomee, a Mexican B2B e-commerce/distribution platform. The breach contains a users table with full names, RFC (Mexican tax IDs), email addresses, usernames, plaintext passwords, registration dates, physical addresses, telephone numbers, shipping addresses, and various account metadata. Records appear to be primarily Mexican businesses and individuals.
secretline.top
A large URL:Login:Password (ULP) stealer log compilation distributed via the Telegram channel @StarLinkClouds and the website secretline.top. Contains approximately 33 million credential pairs harvested from infostealer malware logs across hundreds of different websites worldwide, including banking portals, social media, gaming platforms, government services, and e-commerce sites. No single target company — this is a multi-source credential stuffing/stealer log dump aggregated and redistributed by the StarLinkClouds Telegram group.
castadiva.it
Internal HR/payroll records from what appears to be Castadiva Group (an Italian production/events company), containing employee names, matricola (employee ID numbers), and electronic meal voucher (Ticket Restaurant) allocation data spanning 2019–2025. Files are structured as monthly TR02-format electronic meal ticket tracciati organized by department/location codes (CDI, CDP, SZ). Data covers multiple years of employee benefit records.
accelserv.com
Data breach of Accelerated Services Inc., an HVAC and mechanical services company based in Ronkonkoma, NY. The archive contains internal business documents including client equipment service records, pricing spreadsheets, financial ledgers, PSEG energy efficiency program certifications, AIA construction requisition forms, 401k census data, and personal files belonging to employees or owners (including AncestryDNA raw genetic data, personal tax donation records, and a product license key). The data appears to be a ransomware exfiltration dump of an employee or owner workstation/file server.
distamed.ma
Data breach of Distamed, a Moroccan medical equipment distribution company. The archive contains sensitive business and patient records including full patient lists, billing contracts, invoices, payment records, doctor lists, and client databases. Data spans from approximately 2018 through mid-2025. Exposed data includes patient names, medical billing information, insurance details, financial transactions with hospitals and clinics, and a client directory with contact details including emails and phone numbers.
zyh365.com
A data breach from zyh365.com containing Chinese citizen records with highly sensitive personal information including full names, national ID card numbers (18-digit Chinese resident identity numbers), mobile phone numbers, email addresses (predominantly QQ), city/province of residence, political affiliation (CCP/CCYL membership status), organizational unit/department, and volunteer organization memberships. The data appears to be linked to a Chinese volunteer management or civic engagement platform, potentially associated with Communist Youth League registration or volunteer service tracking systems.
moi.gov.tw
A data leak from Taiwan's Ministry of the Interior (moi.gov.tw) containing personal records of Taiwanese citizens. Each record includes full name, national ID number, gender, date of birth, phone numbers (landline and mobile), postal code, and full residential address details. Data appears to be from the Hsinchu County region of Taiwan.
unionpayintl.com
A dataset attributed to UnionPay ITL (UnionPay International) containing Chinese citizen PII including internal IDs, full names, phone numbers, gender, dates of birth, Chinese national ID numbers (18-digit), addresses broken down by province/city/district, and partial UnionPay card numbers (some records). Data is entirely in Chinese and covers individuals across multiple Chinese provinces.
delmonte.com
Active Directory employee list dump from Del Monte Foods Corporation (Philippines/US operations), containing internal user accounts including usernames, full names, email addresses, job titles, departments, SIDs, Kerberos configuration flags, password metadata, account status, and Active Directory distinguished names. The domain is Dmfi.delmonte.com, suggesting the DMFI (Del Monte Foods Inc.) corporate directory.
epconcommunities.com
Active Directory employee dump from EPCON Communities, a homebuilder/residential community developer. The dataset contains internal AD account details including usernames, display names, corporate email addresses, account status, last logon timestamps, password set dates, SIDs, Kerberoastable/ASREPRoastable flags, delegation info, home directory paths, titles, departments, and admin privilege indicators. The most recent logon dates cluster around March 2026, suggesting the data was exfiltrated around that time.
dex.com
Active Directory employee account export from DEX Imaging (dex.com), a document imaging and managed print services company. The dataset contains internal AD user records including usernames, display names, email addresses, account status, last logon dates, password metadata, job titles, departments, admin flags, Kerberoastable/ASREPRoastable flags, delegation settings, and Windows SIDs. Data appears current as of late March 2026, suggesting a very recent compromise of their Active Directory environment.
ntnusa.com
Active Directory employee list from NTN USA (ntnusa.com), a bearing and precision machinery components distributor. The dataset contains internal AD account details including usernames, display names, corporate email addresses, job titles, departments, SIDs, Kerberoastable/ASREPRoastable flags, delegation info, password metadata, and admin status. The data appears current as of early-to-mid 2025 based on LastLogon and PwdLastSet timestamps.
merceradvisors.com
Ransomware breach of Mercer Advisors, a wealth management and financial planning firm. The archive contains highly sensitive client financial data including tax returns (federal and state, 2022–2024), estate planning documents (wills, trusts, powers of attorney), 1099 forms, brokerage account statements, birth certificates, Social Security documents, investment review reports, balance sheets, client attendee lists with emails and Salesforce IDs, 529 plan data, and internal custodian/financial institution lists. ShinyHunters threat actor published the data after ransom was not paid.
revolutionparts.com
Data breach of RevolutionParts, an automotive parts e-commerce platform. The dataset contains customer PII including names, email addresses, phone numbers, physical addresses, IP addresses, user agent strings, device information (brand, model, OS), and hashed email addresses. Data is split across two parts with slightly different schemas, both using RevolutionParts internal user ID formats (rev_user_* and user_*).
Crypto Forex Leads Compilation 2024
A large compilation dataset of approximately 158 databases containing personal and financial leads from crypto and forex trading platforms. Files include data from multiple cryptocurrency exchanges (ANXPRO, BitBay, BitcoinID, Bitlish, Bitstamp, BTCMarkets, BTCTradeUA, CEX.IO, CoinGI, CoinNest, etc.) with fields including name, email, phone, country, trading pairs, and transaction data. Additional files contain broker/affiliate lead lists with deposit amounts and registration dates for platforms like EuropeFX, Profitix, and others. Data spans approximately 2020–2024. This appears to be an aggregated lead database compiled by a fraud actor or data broker, not a breach of a single company.
multi-player.app
Database dump from multi-player.app, an IPTV/streaming platform management service that provides reseller-based activation systems for media players. The breach contains operational data including reseller accounts, device MAC addresses, payment transaction records (PayPal, Taza Pay), activation logs, playlists, DNS configurations, and subscription/billing data. Migration timestamps indicate the database was active through at least September 2025.
smarterstore.it
Customer database export from SmarterStore (smarterstore.it), an Italian e-commerce platform. Contains customer PII including full names, email addresses, phone numbers, postal/ZIP codes, billing and shipping addresses, account creation dates, and gender. Data appears to be from a Magento-based store with customers primarily based in Italy.
breachforums.st
A large multi-breach compilation archive distributed via BreachForums CDN, containing data from numerous breaches organized alphabetically (M-N section). The archive includes 54+ individual breach datasets covering companies/services starting with M and N, such as Luxottica, MyFitnessPal, MyHeritage, Neopets, NVIDIA, and many others. Sample data from MasedWorld (a Minecraft server) includes player nicknames, skin data, hashed passwords (SHA), IP addresses, login timestamps, and game statistics. The _BF suffix on each archive indicates BreachForums as the distribution source.
eni.fr
Database dump from ENI (a French energy/fuel company operating in France), containing customer account records including email addresses, client reference numbers, company names (raison sociale), account creation dates, last login dates, phone numbers, user roles, and account statuses. The data appears to be from ENI's customer portal and includes both individual and business clients.
Brazil Banks Consignado Leak
A dataset containing sensitive personal and financial records of Brazilian bank customers across seven major institutions: Banco Bradesco, Banco Mercantil do Brasil, Banco Santander Brasil, Banco do Brasil, Caixa Econômica Federal, HSBC Bank Brasil, and Itaú Unibanco. Records include CPF (Brazilian tax ID), full name, date of birth, benefit number, loan details (contract number, loan value, installments, interest rate), payment method, full address, CEP (postal code), state, neighborhood, multiple phone numbers, email addresses, bank account details (agency, account number), and sex. Data appears to relate to consignado (payroll-deductible) loan records.
ccrcda.org
Data breach of Catholic Charities of the Roman Catholic Diocese of Albany (ccrcda.org), a nonprofit social services organization based in Albany, NY. The archive contains extensive internal financial and HR records including employee payroll data (names, hourly rates, accrual balances), ADP payroll tax reports, bank transfer records referencing Diocese of Albany accounts, vendor payment reports, accounts receivable/payable aging reports, food distribution attendance records, grant/contract spending analyses, and operational spreadsheets spanning approximately 2009–2025. The data includes personally identifiable employee information such as full names, employment status, seniority dates, and compensation details.
rlglawfirm.com
Data breach of RLG Law Firm (rlglawfirm.com), a Florida-based law firm. The exposed data includes internal corporate and LLC client lists with principal names, addresses, EIN/SSN references, entity formation dates, officer/director information, short sale status sheets, client trust account balances, investor lists, and other sensitive legal and financial records spanning multiple years up to at least 2024.
online.arizonacaregivertraining.net
Full SQL database dump from the Moodle-based learning management system at online.arizonacaregivertraining.net, an Arizona caregiver training and certification platform. The breach contains 175 files including course assignments, grades, user submissions, attendance records, certificates, and extensive LMS configuration data. Student data includes assignment submissions (including scanned IDs and training documents), course completions, and grading records.
fanjoy.co
Breach of Fanjoy, a creator merchandise and e-commerce platform. The dataset contains order records including customer names, email addresses, physical shipping and billing addresses, phone numbers, order totals, and platform order IDs. Data appears current through late March 2025.
younow.com
A data breach of YouNow, a live streaming and broadcasting platform. The dataset contains detailed user profile records including user IDs, usernames, Facebook IDs and tokens, Twitter handles, Google IDs, email-related data, device information, IP addresses, country/language, gender, age, login history, points/coins/levels, fan counts, and internal scoring/fraud detection responses (Smyte, Sift). The presence of Facebook OAuth tokens is particularly sensitive.
morningstartours.com
Data breach of Morning Star Tours (morningstartours.com), a Christian travel/tour operator based in Richardson, TX. The archive contains internal business files including contact lists with names, addresses, and emails of clients, vendors, and staff; tour itineraries; payment and financial records including credit card payment spreadsheets; employee training materials; tour scheduling data; CRM system exports; and internal communications including a Zoom chat transcript from February 2025. The data spans operations from at least 2000 through 2025.
spytec.com
Breach of Spytec GPS customer database containing customer personal information including names, email addresses, phone numbers, physical addresses, order history, and email/SMS marketing consent data. Data appears to have been exported from a Shopify-based e-commerce backend.
bemyeye.com
Breach of Be My Eye (bemyeye.com), a crowdsourced retail auditing and mystery shopping platform. The exposed data includes user IDs, email addresses, first and last names, country, currency, account status, and rich JSON profile details including birthdate, gender, home address, city, postal code, education level, occupation, IBAN/BIC banking details, device info (UUID, OS, app version), mission statistics, and earnings data. The majority of visible users are French nationals.
emoticibo.com
Full WordPress database dump from emoticibo.com, an Italian lifestyle/food blog run by Gloria Brolatti. The breach contains the complete WordPress MySQL database including user accounts, hashed passwords, login activity, failed login logs, comments with author emails and IPs, subscriber lists, posts, and SEO metadata. The site used All In One WP Security plugin. Data spans from approximately 2015 to 2023.
hallauerlaw.net
Data breach of Hallauer Law, a law firm. The archive contains highly sensitive legal case files including FBI investigative records, electronic surveillance (ELSUR) logs, phone records (CDRs with cell tower data), witness interview summaries, drug buy surveillance reports, and criminal case documentation related to gang investigations (MSB - likely a gang/criminal organization). The data includes personally identifiable information of suspects, witnesses, and confidential human sources.
ailhospitality.com
Breach of AIL Hospitality (ailhospitality.com), a Dunkin' Brands (Dunkin' Donuts / Baskin-Robbins) franchisee operator. The leaked data consists of detailed monthly Profit & Loss financial statements for multiple franchise profit centers (store locations), covering revenue, cost of sales, payroll, fees, rent, utilities, and net income figures. Data spans at least 2012 through 2019. Files are formatted as Dunkin' Brands standard franchisee P&L upload templates intended for submission to Franchisee Central (dunkinbrands.franchiseecentral.com). The archive contains XLS workbooks and derived CSV exports including EFT upload files.
skibiellaw.com
Data breach of Skibiel Law, a workers' compensation and personal injury law firm based in Georgia. The archive contains highly sensitive legal and personal data including client settlement calculators with named plaintiffs, patient medical records and billing information, personal health insurance/medical bills for the Skibiel family, client call logs with names and phone numbers, attorney CLE records, financial spreadsheets, and case management data. The breach exposes attorney-client privileged information, PHI, and PII for numerous clients.
Reynella East Community Centre
A contact database likely belonging to a community centre or local government service in the Reynella/Onkaparinga Hills area of South Australia. The data contains personally identifiable information including full names, phone numbers, email addresses, physical addresses (predominantly in southern Adelaide suburbs such as Reynella East, Woodcroft, Happy Valley, O'Halloran Hill, Noarlunga Centre), hashed passwords (bcrypt), usernames, UUIDs, birth dates, and demographic fields. The addresses and suburb names strongly suggest a South Australian community organisation or council-affiliated service.
surtifamiliar.com
Leaked employee medical examination records from Surtifamiliar SA, a Colombian supermarket/retail chain. The dataset contains periodic occupational health exam records including employee full names, national ID numbers (cédulas), exam types (audiometry, spirometry, musculoskeletal evaluation, blood glucose, lipid profiles, etc.), costs, operational center, and cost center assignments. Data appears to originate from the Tuluá operations center in February (FEB) with records dated October 2025.
reynellaec.sa.edu.au
Student records from Reynella East College, a South Australian government school. The dataset contains student given names, surnames, employee/student IDs, and two email addresses per student (schools.sa.edu.au and reynellaec.sa.edu.au). Data appears to cover current and recent enrolments.
schools.sa.edu.au
A breach of student records from Reynella East College, a South Australian government school. The dataset contains highly sensitive student information including full names, dates of birth, gender, government IDs, email addresses (in the schools.sa.edu.au domain), medical alerts, custody alerts, attendance flags, religion notes, login credentials (usernames and recovery codes), login counts, and unique student identifiers. The email domain and government ID format confirm this is a South Australian Department for Education school.
reynellaeastcollege.sa.edu.au
Staff records from what appears to be Reynella East College, a South Australian school. The dataset contains staff personal information including names, gender, salutations, usernames, hashed passwords, email addresses (schools.sa.edu.au domain), mobile phone numbers, government IDs, login counts, and UUIDs. The email domain and timezone offsets (UTC+10:30) confirm a South Australian educational institution.
reynellaec.sa.edu.au
Staff details from Reynella East College, a South Australian government school. The dataset contains staff given names, surnames, employee IDs, and school email addresses for approximately 80+ staff members.
surtifamiliar.com.co
Leaked internal HR and occupational health database from Surtifamiliar, a Colombian supermarket/retail chain. Contains employee records including national ID numbers (cédulas), full names, hire dates, job titles, branch locations, and occupational medical exam results (musculoskeletal, audiometry, vision, lipid profiles, glucose, etc.). Also includes vendor quotation and cost comparison spreadsheets for occupational health services across multiple store locations in Colombia.
communityadvocates.net
Employee roster data from Community Advocates, a Milwaukee-based nonprofit social services organization. The dataset contains employee names, hire dates, home departments, and physical key fob/garage fob assignment numbers for all active employees. The report was generated on January 20, 2022.
borgerisd.net
User account data from Borger Independent School District (Borger ISD) in Texas, containing staff and student records including first/last names, usernames, email addresses, user IDs, plaintext passwords, roles (Teacher/Student), and school building assignments.
borgerisd.net
Student data from Borger Independent School District (Borger, Texas) covering the 2022-2023 academic year. The dataset contains student IDs, full names, school names, grade levels, usernames, and plaintext passwords for students across multiple elementary schools. The data pertains to minor children, making this a particularly sensitive breach involving FERPA-protected records.
borgerisd.net
A data breach affecting Borger Independent School District (ISD) in Texas, exposing student records for K-8 students. The dataset contains student IDs, full names, school names, grade levels, usernames, and plaintext passwords for students attending schools including Gateway Elementary School. This involves sensitive data of minors.
borgerisd.net
An exported email directory from Borger Independent School District (Borger ISD) in Texas, containing staff display names, email aliases, and full borgerisd.net email addresses. The data appears to be an internal Active Directory or Exchange email address book export.
borgerisd.net
A data breach of Borger Independent School District (Borger ISD) in Texas containing all student information including full names, Social Security Numbers (SSNs), Texas Unique Student IDs, dates of birth, grade levels, campus IDs, and student IDs. The dataset contains records for students from pre-kindergarten through 12th grade.
borgerisd.net
A spreadsheet containing administrator and staff passwords for Borger Independent School District (ISD) in Texas. The file contains plaintext credentials including full names and passwords, with some entries also including phone numbers or role designations. Passwords are largely weak and unencrypted.
borgerisd.net
A spreadsheet containing student Google Workspace sign-in credentials for Borger Independent School District (Texas), including full names, school email addresses, plaintext passwords, and organizational unit paths indicating graduating class year. The data appears to be a Google Workspace user provisioning file exported from the district's admin console.
emailbomber.net
Database dump from EmailBomber v4, a paid email/SMS/call bombing (harassment/spam) service. The breach contains user accounts, subscription/payment records (cryptocurrency transactions including Bitcoin, ETH, USDT, Litecoin, Solana, XMR), license keys, ban lists, mass DM records, and daily operational statistics. Data spans from August 2024 through at least December 2025. The service accepted crypto payments and tracked approximately 119,839 users with 78,740 total bomb operations.
puppyfinder.com
Breach of PuppyFinder.com, a pet listing and adoption website. The dataset contains user account records including email addresses, usernames, hashed passwords (SHA-1, some with salts), Facebook IDs, account creation dates, scammer/block flags, and verification statuses. The latest date visible in the data is late 2022, suggesting the breach occurred around that time.