BaseLeak
453 subscribers
37 photos
49 links
Download Telegram
๐Ÿ˜ˆ
In March 2024, the online games community Mr. Green Gaming suffered a data breach that exposed 27k user records. Acknowledged on their Discord server, the incident exposed email and IP addresses, usernames, geographic locations and dates of birth.

Compromised data: Dates of birth, Email addresses, Geographic locations, IP addresses, Usernames
๐Ÿ˜ˆ
๐Ÿ‘บ
In March 2024, WoTLabs (World of Tanks Statistics and Resources) suffered a data breach and website defacement attributed to "chromebook breachers". The breach exposed 22k forum members' personal data including email and IP addresses, usernames, dates of birth and time zones.

Compromised data: Dates of birth, Email addresses, IP addresses, Time zones, Usernames
๐Ÿ‘บ
๐Ÿ˜ˆ
In January 2023, 1.4M records from the Autotrader online vehicle marketplace appeared on a popular hacking forum. Autotrader stated that the "data in question relates to aged listing data that was generally publicly available on our site at the time and open to automated collection methods". The data contained 20k unique email addresses alongside physical addresses and phone numbers of dealers and vehicle details including VIN numbers. The data was breached by @IntelBroker

Compromised data: Email addresses, Phone numbers, Physical addresses, Vehicle details, Vehicle identification numbers (VINs)
๐Ÿ˜ˆ
๐Ÿ˜ˆ
In June 2022, the Taiwan's low-cost airline Tigerair Taiwan suffered a data breach exposed over 585k clients. The data contained over 656k unique email addresses, dates of birth, genders, names, passport numbers and passport expiration date as well as passwords stored as Base64(unhex(SHA-256($plaintext))) hashes.The data also contains almost 3 million credit cards. To verify the authenticity of the data, use - https://membership.tigerairtw.com/zh-TW/forgot-email (For the form, you need to use the user's full name and date of birth, then you will be sent a partial email address, which in most cases will match the address in the leak)

Compromised data: Credit cards, Dates of birth, Email addresses, Genders, Names, Passwords, Passport numbers, Passport expiration date, Website Activity

๐Ÿ˜ˆ
๐Ÿ‘บ
In February 2024, the Philippine Digido Finance Corp. (https://digido.ph/), an online lending company registered with the Securities and Exchange Commission, has been hacked, compromising the personal information of an estimated 5.4 million customers. The exposed data includes over 5.2 million unique email addresses, dates of birth, genders, government issued IDs, names, passport numbers, phone numbers, physical addresses. The data was breached by @Petya152r5

Compromised data: Dates of birth, Email addresses, Genders, Government issued IDs, Names, Passport numbers, Phone numbers, Physical addresses, Website activity

๐Ÿ‘บ
๐Ÿ‘บ
Approximately between 2022-2023, the U.S. Environmental Protection Agency suffered a data breach impacting over 8.5 million users and exposing personal and sensitive information of its customers and contractors. A hacker operating under the pseudonym @USDoD claimed responsibility and released the EPA's global contact database on a dark web forum. The leaked database contained three zipped files with approximately 500MB of data in CSV formats, holding common fields such as "Zipcodes," "Full names," "Phone numbers," "Email addresses," and "County, City, States," as well as additional fields in each file. Please note that most of the emails are corporate emails.

Compromised data: Email addresses, Job titles, Names, Phone numbers, Physical addresses


๐Ÿ‘บ
๐Ÿ‘บ

In April 2024, the Australian delivery company BHF Couriers suffered a data breach that exposed over 327k clients and over 22k users records. The data included email and physical addresses, names, partial credit cards data, phone numbers, unsalted MD5 password hashes and orders info.

Compromised data: Email addresses, Names, Partial credit card data, Passwords, Phone numbers, Physical addresses, Purchases, Website activity


๐Ÿ‘บ
๐Ÿ˜ˆ
In April 2023, the video gaming website Gameplanet suffered a data breach which impacted over 1.7 million website users.The compromised data included over 1.7 million unique email addresses, dates of birth, names, phone numbers and Vbulletin stored passwords.

Compromised data: Dates of birth, Email addresses, Names, Passwords, Phone numbers, Website activity
๐Ÿ˜ˆ
๐Ÿ‘บ

In October 2023, the Telecommunications Services of Trinidad and Tobago (TSTT) fell victim to a cyberattack by the international hacker group, Ransomexx. Contrary to TSTT's initial claims, the hackers released over six gigabytes of sensitive data on the dark web, affecting approximately 801,000 customers. The leaked data included over 73,000 unique email addresses, government-issued IDs (CIS and IDS numbers), names, phone numbers, physical addresses, and other sensitive information. The leaked information also includes scanned documents such as letters of transfer of authority or ownership, and photos of identification cards.

Compromised data: Email addresses, Government issued IDs, Names, Phone numbers, Physical addresses

๐Ÿ‘บ
๐Ÿ˜ˆ

In April 2023, the Indian rental service RentoMojo suffered a data breach. The breach exposed over 2M unique email addresses along with names, phone, passport and Aadhaar numbers, genders, dates of birth, purchases and bcrypt password hashes.

I would like to warn users this leak is over 295.6GB uncompressed and 17.02GB compressed.

Compromised data: Dates of birth, Email addresses, Genders, Government issued IDs, Names, Passport numbers, Passwords, Phone numbers, Purchases, Social media profiles


๐Ÿ˜ˆ
๐Ÿ˜ˆ

In April 2024, the Indian digital learning platform Quest App (https://questapp.in/) was hacked by @DevEye, which then published this data on BreachForums. The leak includes over 694k users, contains 522k unique email addresses, dates of birth, genders, marital statuses, names, phone numbers and passwords stored as MD5 and bcrypt hashes.

Compromised data: Dates of birth, Email addresses, Genders, Marital statuses, Names, Passwords, Phone numbers, Website activity

๐Ÿ˜ˆ
๐Ÿ˜ˆ

In February 2024, a huge array consisting of more than 3 million data was published on the Popular hacker forum.This data was a mix of various Ecuador leaks (the list of sources is listed below).Most of the data relates to 2021-2023 and includes over unique email addresses, dates of birth, government issued IDs (DNI & CLI numbers), genders, names, nationalities, phone numbers, personal health data and physical addresses .The data was breached and leaked by @PieWithNothing. Also, special thanks to @ctf for the help with verifying the authenticity of the leak.

Sources: Ecuador - Grupo Cรฉntrico (evaluar.com) (~ 2.7 million records) (2021), Ecuador - COVID-19 (~ 0.3 million records) (2023), Ecuador - MrJoy (~ 0.6 million records) (2023)

Compromised data: Dates of birth, Email addresses, Genders, Government issued IDs (DNI & CLI numbers), Names, Nationalities, Phone numbers, Personal health data, Physical addresses
๐Ÿ‘ฟ
๐Ÿ‘ฟ

In February 2024, the AI-powered visual design platform Cutout.Pro suffered a data breach that exposed 20M records. The data included email and IP addresses, names and salted MD5 password hashes which were subsequently broadly distributed on a popular hacking forum and Telegram channels. The data was breached by @KryptonZambie

Compromised data: Email addresses, IP addresses, Names, Passwords
๐Ÿ˜ˆ
๐Ÿ‘ฝ
In March 2024, tens of millions of records allegedly breached from AT&T were posted to a popular hacking forum. Dating back to August 2021, the data was originally posted for sale before later being freely released. At the time, AT&T maintained that there had not been a breach of their systems and that the data originated from elsewhere. 12 days later, AT&T acknowledged that data fields specific to them were in the breach and that it was not yet known whether the breach occurred at their end or that of a vendor. AT&T also proceeded to reset customer account passcodes, an indicator that there was sufficient belief passcodes had been compromised. The incident exposed names, email and physical addresses, dates of birth, phone numbers and US social security numbers.

Compromised data: Dates of birth, Email addresses, Government issued IDs, Names, Phone numbers, Physical addresses
๐Ÿ‘ฝ
๐Ÿ˜ˆ
In December 2023, the Indian largest ISP provider, Hathway, suffered a significant data breach due to a vulnerability present in their Laravel framework application. The incident was allegedly perpetrated by an individual known as @dawnofdevil. As a result, hundreds of gigabytes of data, totaling over 200 GB, appeared on a popular hacking website. This data included extensive personal information of 41.5 million customers, such as 4.7 million unique email addresses, names, physical and IP addresses, phone numbers, etc.

I would like to warn users this leak is over 22.76GB uncompressed and 22.76GB compressed.

Compromised data: Device information, Email addresses, IP addresses, Names, Passwords, Phone numbers, Physical addresses, Salutations, Support tickets
๐Ÿ˜ˆ
๐Ÿ˜ˆ

In April 2024, the French underwear maker Le Slip Franรงais (https://www.leslipfrancais.fr/) suffered a data breach. The breach included 1.5M email addresses, physical addresses, names and phone numbers. The data was breached by @ShopifyGUY

Compromised data: Email addresses, Names, Phone numbers, Physical addresses, Purchases

๐Ÿ˜ˆ
๐Ÿ˜ˆ
In Mid-2023, 300GB of data containing over 100M records from the Chinese video chat platform "Tigo" dating back to March that year was discovered. The data contained over 700k unique names, usernames, email and IP addresses, genders, profile photos and private messages. Tigo did not respond to multiple attempts to disclose the incident.

Compromised data: Device information, Email addresses, Genders, Geographic locations, IP addresses, Names, Private messages, Profile photos, Usernames
๐Ÿ˜ˆ
๐Ÿ‘ฝ
In 2009 the turkish government had a major leak of 49Million citizens, this leak contained every citizen's names, addresses and much more... This database has also been known as mernis.It was in the official rf section (link - https://web.archive.org/web/202202210008...d-Download )

Compromised data: Full Names, Dates of Birth, Birth Cities, Full Addresses, Parents Information, National ID Numbers, Genders

๐Ÿ‘ฝ
๐Ÿ‘ฝ
This database contains 5.5 Million emails, transaction history with credit card numbers and email addresses from employees. Vietnam's largest reseller - Mobile World JSC (best known for their brand - Thegioididong.com).

Compromised data: Email addresses, Partial Credit Cards, Order Information
๐Ÿ‘ฝ
๐Ÿ˜ˆ
In March 2024, the Canadian discount store chain Giant Tiger Stores Limited (https://www.gianttiger.com/) suffered a data breach that exposed over 2.8 million clients. The breach includes over 2.8 million unique email addresses, names, phone numbers and physical addresses. The data was breached by @ShopifyGUY

Compromised data: Email addresses, Names, Phone numbers, Physical addresses, Website activity
๐Ÿ˜ˆ
๐Ÿ˜ˆ
boAt is Indian's No.1 company that markets audio-focused electronic gadgets like wireless speakers, earbuds, wired and wireless headphones and earphones, home audio equipment, premium rugged cables, and a selection of other technological accessories. On March 2024, a hacker claimed to breach the data of boAt Lifestyle. The threat actor dumped files of data breach with access to PII information of customers, which has 7,550,000 entries.

Compromised data: Email addresses, Names, Phone numbers, Physical addresses, Purchases, Website Activity

๐Ÿ˜ˆ