BaseLeak
449 subscribers
37 photos
49 links
Download Telegram
😈
PTV Telecom Database
In September 2023, the Spanish telecommunications company PTV Telecom suffered a data breach exposed over 110k clients records containing dates of birth, email addresses, names, phone numbers, physical addresses.

Compromised data: Email Adresses, Dates of Birth, Names, Phone Numbers, Physical addresses
😈
😈
Longhorn Imaging Database
In
June 2023, US medical imaging company Longhorn Imaging suffered a data breach that impacted 272.000 patients. These medical records include physician full names, patient full names, patient treatment info, patient date of birth, patient gender, treatment date, institution name, and more.

Compromised data: Physician names, Patient names, Patient treatment infomarion, Patient date of birth, Patient gender, Treatment date, Institution name,

😈
😈

EloBuddy Database
In
May of 2016, the League of Legends hacking engine known as EloBuddy suffered a data breach exposing 177,372 user accounts.
The dataset contained various pieces of information, including usernames, email addresses, passwords, payment details, IP addresses, and more.

Compromised data: Usernames, Email addresses, Passwords, IP addresses, Website activity

😈
😈

Telefon-Treff Database
In July 2020, the German mobile phone forum telefon-treff.de was hacked and 225k member records were exposed. The data included usernames, email addresses and passwords stored as vBulletin and BlowFish hashes.

Compromised data: Email addresses, Usernames, Passwords, Website activity

😈
😈
NeverSkip Database
In September 2021, the Indian school management system Neverskip (parent.neverskip.com) suffered a data breach that exposed over 5 million users. The account profile on the network contains names, phone numbers, hashed (md5) and dehashed password etc. The website was breached by @PieWithNothing

Compromised data: Names, Phone numbers, Password, School Id, Website activity (date of registration on the website)
😈
😈
ClaraHair Database
In end of August 2023, Saudi Arabian online store site clarahair, specializing in the sale of hair care products suffered a data breach that exposed over 400k orders records containing names, email addresses, phone numbers, personal descriptions, physical addresses, payment histories and purchases. The website was breached by @Ddarknotevil.

Compromised data: Email addresses, Names, Phone numbers, Personal descriptions, Purchases,Payment histories,Physical addresses Payment methods, Website activity

😈
👿

Trei.no Database
Approximately between 2020-2021, the Brazil workout app for gyms and personalities Trei suffered a databreach. The exposed data included more 1.6 million names, usernames, email addresses and phone numbers, genders, dobs and passwords stored as HMAC-SHA1 hashes. The app was breached by @PieWithNothing

Compromised data: Dates of birth, Email addresses, Genders, Names, Usernames, Passwords, Phone numbers

😈
😈
Pankhuri Database
In June 2022, the Columbian social live streaming and short videos community for women app Pankhuri suffered a data breach that exposed more 600k customer records.The exposed data included email and usersnames, names, genders, dates of birth, phone numbers.

Compromised data: Avatars,Account balances,Dates of birth, Email addresses, Genders, Geographic locations, Names, Usernames, Personal interests, Phone numbers, Website activity
😈
😈

Toumei Database
In October 2023, the Japanese consultancy firm Toumei suffered a data breach. The breach exposed over 100M lines and 10GB of data including 77k unique email addresses along with names, phone numbers and physical addresses.

Compromised data: Email addresses, Names, Phone numbers, Physical addresses

😈
😈
MemeChat Database
In mid-2022, "the ultimate hub of memes" MemeChat suffered a data breach that exposed 7.4M records. Alleged to be due to a misconfigured Elasticsearch instance, the data contained 4.5M unique email addresses alongside usernames.

Compromised data: Email addresses, Usernames
😈
😈
CityJerks Database
In early 2023, the "mutual masturbation" website CityJerks suffered a data breach that exposed 177k unique email addresses. The breach also included data from the TruckerSucker "dating app for REAL TRUCKERS and REAL MEN" with the combined corpus of data also exposing usernames, IP addresses, dates of birth, sexual orientations, geo locations, private messages between members and passwords stored as salted MD5 hashes. The data was listed on a public hacking site and provided to HIBP by a source who requested it be attributed to "discord.gg/gN9C9em".

Compromised data: Bios, Dates of birth, Email addresses, Geographic locations, IP addresses, Passwords, Private messages, Profile photos, Sexual orientations, Usernames
😈
😈
Sphero
In September 2023, over 1M rows of data from the educational robots company Sphero was posted to a popular hacking forum. The data contained 832k unique email addresses alongside names, usernames, dates of birth and geographic locations.

Compromised data: Dates of birth, Email addresses, Geographic locations, Names, Usernames
😈
😈
Viva Air Database
In March 2022, the now defunct Columbian airline Viva Air suffered a data breach and subsequent ransomware attack. Among a trove of other ransomed data, the incident exposed a log of 2.6M transactions with 932k unique email addresses, physical and IP addresses, names, phone numbers and partial credit card data (last 4 digits).

Compromised data: Email addresses, IP addresses, Names, Partial credit card data, Phone numbers, Physical addresses, Purchases
😈
😈

Dymocks Database

In September 2023, the Australian book retailer Dymocks announced a data breach. The data dated back to June 2023 and contained 1.2M records with 836k unique email addresses. The breach also exposed names, dates of birth, genders, phone numbers and physical addresses.

Compromised data: Dates of birth, Email addresses, Genders, Names, Phone numbers, Physical addresses
😈
😈
SevenRooms Database
In December 2022, over 400GB of data belonging to restaurant customer management platform SevenRooms was posted for sale to a popular hacking forum. The data included 1.2M unique email addresses alongside names and purchases. SevenRooms advised that the breach was due to unauthorised access of "a file transfer interface of a third-party vendor".

Credit to doubl for breaching and leaking this originally.

I would like to warn users this leak is over 36.58GB uncompressed and 34.1GB compressed.

Compromised data: Email addresses, Names, Purchases

😈
😈
CraftRise Database
In May 2023, news broke of a data breach of the Turkish Minecraft server known as CraftRise. The data of over 2.5M users was subsequently shared on a popular hacking forum and included email addresses, usernames, geographic locations and plain text passwords. The newest records indicate the data was obtained in March 2022.

Compromised data: Email addresses, Geographic locations, Passwords, Usernames
😈
😈
Duolingo Scrape Database
In August 2023, 2.6M records of data scraped from Duolingo were broadly distributed on a popular hacking forum. Obtained by enumerating a vulnerable API, the data had earlier appeared for sale in January 2023 and contained email addresses, names, the languages being learned, XP (experience points), and other data related to learning progress on Duolingo. Whilst some of the data attributes are intentionally public, the ability to map private email addresses to them presents an ongoing risk to user privacy.

Compromised data: Email addresses, Names, Spoken languages, Usernames
😈
😈
MagicDuel RPG Database
In Auguest 2023, MagicDuel RPG (magicduel.com) was dumped through a simple SQLi vulnerability. More than 138k people were compromised. This breach includes Usernames, Emails, Hashed Passwords, and IPs.

Compromised data: Username, Emails, Hashed Passwords, IPs
😈
😈
G.Skill
In January of 2023, G.Skill was compromised through a vulnerable database service. In April of the same year, their database was deleted and they were served with an extortion note that they failed to negotiate for. The data contains RMA information, User information including email addresses, full addresses, and hashed passwords. Over 50,000 user entries exist.

Compromised data: Full Names, Emails, Passwords, IP addresses

😈
😈
iD Tech Database
In February 2023, the tech camps for kids service iD Tech had almost 1M records posted to a popular hacking forum. The data included 415k unique email addresses, names, dates of birth and plain text passwords which appear to have been breached in the previous month. iD Tech did not respond to multiple attempts to report the incident.

Compromised data: Dates of birth, Email addresses, Names, Passwords
😈
😈
JD Group Database
In May 2023, the South African retailer JD Group announced a data breach affecting a number of their online assets including Bradlows, Everyshop, HiFi Corp, Incredible (Connection), Rochester, Russells, and Sleepmasters. The breach exposed over 520k unique customer records including names, email and physical addresses, phone numbers and South African ID numbers.

Compromised data: Email addresses, Government issued IDs, Names, Phone numbers, Physical addresses


😈