BaseLeak
450 subscribers
37 photos
49 links
Download Telegram
๐Ÿ‘บ

In October 2023, the Telecommunications Services of Trinidad and Tobago (TSTT) fell victim to a cyberattack by the international hacker group, Ransomexx. Contrary to TSTT's initial claims, the hackers released over six gigabytes of sensitive data on the dark web, affecting approximately 801,000 customers. The leaked data included over 73,000 unique email addresses, government-issued IDs (CIS and IDS numbers), names, phone numbers, physical addresses, and other sensitive information. The leaked information also includes scanned documents such as letters of transfer of authority or ownership, and photos of identification cards.

Compromised data: Email addresses, Government issued IDs, Names, Phone numbers, Physical addresses

๐Ÿ‘บ
๐Ÿ˜ˆ

In April 2023, the Indian rental service RentoMojo suffered a data breach. The breach exposed over 2M unique email addresses along with names, phone, passport and Aadhaar numbers, genders, dates of birth, purchases and bcrypt password hashes.

I would like to warn users this leak is over 295.6GB uncompressed and 17.02GB compressed.

Compromised data: Dates of birth, Email addresses, Genders, Government issued IDs, Names, Passport numbers, Passwords, Phone numbers, Purchases, Social media profiles


๐Ÿ˜ˆ
๐Ÿ˜ˆ

In April 2024, the Indian digital learning platform Quest App (https://questapp.in/) was hacked by @DevEye, which then published this data on BreachForums. The leak includes over 694k users, contains 522k unique email addresses, dates of birth, genders, marital statuses, names, phone numbers and passwords stored as MD5 and bcrypt hashes.

Compromised data: Dates of birth, Email addresses, Genders, Marital statuses, Names, Passwords, Phone numbers, Website activity

๐Ÿ˜ˆ
๐Ÿ˜ˆ

In February 2024, a huge array consisting of more than 3 million data was published on the Popular hacker forum.This data was a mix of various Ecuador leaks (the list of sources is listed below).Most of the data relates to 2021-2023 and includes over unique email addresses, dates of birth, government issued IDs (DNI & CLI numbers), genders, names, nationalities, phone numbers, personal health data and physical addresses .The data was breached and leaked by @PieWithNothing. Also, special thanks to @ctf for the help with verifying the authenticity of the leak.

Sources: Ecuador - Grupo Cรฉntrico (evaluar.com) (~ 2.7 million records) (2021), Ecuador - COVID-19 (~ 0.3 million records) (2023), Ecuador - MrJoy (~ 0.6 million records) (2023)

Compromised data: Dates of birth, Email addresses, Genders, Government issued IDs (DNI & CLI numbers), Names, Nationalities, Phone numbers, Personal health data, Physical addresses
๐Ÿ‘ฟ
๐Ÿ‘ฟ

In February 2024, the AI-powered visual design platform Cutout.Pro suffered a data breach that exposed 20M records. The data included email and IP addresses, names and salted MD5 password hashes which were subsequently broadly distributed on a popular hacking forum and Telegram channels. The data was breached by @KryptonZambie

Compromised data: Email addresses, IP addresses, Names, Passwords
๐Ÿ˜ˆ
๐Ÿ‘ฝ
In March 2024, tens of millions of records allegedly breached from AT&T were posted to a popular hacking forum. Dating back to August 2021, the data was originally posted for sale before later being freely released. At the time, AT&T maintained that there had not been a breach of their systems and that the data originated from elsewhere. 12 days later, AT&T acknowledged that data fields specific to them were in the breach and that it was not yet known whether the breach occurred at their end or that of a vendor. AT&T also proceeded to reset customer account passcodes, an indicator that there was sufficient belief passcodes had been compromised. The incident exposed names, email and physical addresses, dates of birth, phone numbers and US social security numbers.

Compromised data: Dates of birth, Email addresses, Government issued IDs, Names, Phone numbers, Physical addresses
๐Ÿ‘ฝ
๐Ÿ˜ˆ
In December 2023, the Indian largest ISP provider, Hathway, suffered a significant data breach due to a vulnerability present in their Laravel framework application. The incident was allegedly perpetrated by an individual known as @dawnofdevil. As a result, hundreds of gigabytes of data, totaling over 200 GB, appeared on a popular hacking website. This data included extensive personal information of 41.5 million customers, such as 4.7 million unique email addresses, names, physical and IP addresses, phone numbers, etc.

I would like to warn users this leak is over 22.76GB uncompressed and 22.76GB compressed.

Compromised data: Device information, Email addresses, IP addresses, Names, Passwords, Phone numbers, Physical addresses, Salutations, Support tickets
๐Ÿ˜ˆ
๐Ÿ˜ˆ

In April 2024, the French underwear maker Le Slip Franรงais (https://www.leslipfrancais.fr/) suffered a data breach. The breach included 1.5M email addresses, physical addresses, names and phone numbers. The data was breached by @ShopifyGUY

Compromised data: Email addresses, Names, Phone numbers, Physical addresses, Purchases

๐Ÿ˜ˆ
๐Ÿ˜ˆ
In Mid-2023, 300GB of data containing over 100M records from the Chinese video chat platform "Tigo" dating back to March that year was discovered. The data contained over 700k unique names, usernames, email and IP addresses, genders, profile photos and private messages. Tigo did not respond to multiple attempts to disclose the incident.

Compromised data: Device information, Email addresses, Genders, Geographic locations, IP addresses, Names, Private messages, Profile photos, Usernames
๐Ÿ˜ˆ
๐Ÿ‘ฝ
In 2009 the turkish government had a major leak of 49Million citizens, this leak contained every citizen's names, addresses and much more... This database has also been known as mernis.It was in the official rf section (link - https://web.archive.org/web/202202210008...d-Download )

Compromised data: Full Names, Dates of Birth, Birth Cities, Full Addresses, Parents Information, National ID Numbers, Genders

๐Ÿ‘ฝ
๐Ÿ‘ฝ
This database contains 5.5 Million emails, transaction history with credit card numbers and email addresses from employees. Vietnam's largest reseller - Mobile World JSC (best known for their brand - Thegioididong.com).

Compromised data: Email addresses, Partial Credit Cards, Order Information
๐Ÿ‘ฝ
๐Ÿ˜ˆ
In March 2024, the Canadian discount store chain Giant Tiger Stores Limited (https://www.gianttiger.com/) suffered a data breach that exposed over 2.8 million clients. The breach includes over 2.8 million unique email addresses, names, phone numbers and physical addresses. The data was breached by @ShopifyGUY

Compromised data: Email addresses, Names, Phone numbers, Physical addresses, Website activity
๐Ÿ˜ˆ
๐Ÿ˜ˆ
boAt is Indian's No.1 company that markets audio-focused electronic gadgets like wireless speakers, earbuds, wired and wireless headphones and earphones, home audio equipment, premium rugged cables, and a selection of other technological accessories. On March 2024, a hacker claimed to breach the data of boAt Lifestyle. The threat actor dumped files of data breach with access to PII information of customers, which has 7,550,000 entries.

Compromised data: Email addresses, Names, Phone numbers, Physical addresses, Purchases, Website Activity

๐Ÿ˜ˆ
๐Ÿ˜ˆ
In end of May 2023, the Russian website of the hypermarket chain Leroy Merlin suffered a data breach.Breach became known in June 2023 and exposed over 5 million personal clients data attributes including names, phone numbers, email addresses and passwords stored as salted MD5 hashes.The leak also contained genders, dates of birth, and physical addresses.
๐Ÿ˜ˆ
๐Ÿ˜ˆ
In September 2015, the US based credit bureau and consumer data broker Experian suffered a data breach that impacted 15 million customers who had applied for financing from T-Mobile. An alleged data breach was subsequently circulated containing personal information including names, physical and email addresses, birth dates and various other personal attributes. Multiple Have I Been Pwned subscribers verified portions of the data as being accurate, but the actual source of it was inconclusive therefor this breach has been flagged as "unverified".

Compromised data: Credit status information, Dates of birth, Email addresses, Ethnicities, Family structure, Genders, Home ownership statuses, Income levels, IP addresses, Names, Phone numbers, Physical addresses, Purchasing habits
๐Ÿ‘ฟ
๐Ÿ˜ˆ
In January 2021, Taiwanian Computers Electronics and Technolog store ePrice (www.eprice.com.tw) location in Taiwan was breached.The records in the breach included email addresses, genders, dates of birth, usernames, names,personal descriptions,phone numbers and plaintext passwords.

Compromised data: Dates of birth, Email addresses,Genders, Geographic locations, Names, Usernames, Personal descriptions, Phone Numbers, Passwords, IP addresses, Website activity
๐Ÿ˜ˆ
๐Ÿ˜ˆ

In February 2023, data alleged to have been taken from the fraud protection service Eye4Fraud was listed for sale on a popular hacking forum. Spanning tens of millions of rows with 16M unique email addresses, the data was spread across 147 tables totalling 65GB and included both direct users of the service and what appears to be individuals who'd placed orders on other services that implemented Eye4Fraud to protect their sales. The data included names and bcrypt password hashes for users, and names, phone numbers, physical addresses and partial credit card data (card type and last 4 digits) for orders placed using the service. Eye4Fraud did not respond to multiple attempts to report the incident.

Compromised data: Email addresses, IP addresses, Names, Partial credit card data, Passwords, Phone numbers, Physical addresses
๐Ÿ˜ˆ
๐Ÿ˜ˆ
In March 2024, almost 3M+ rows of data from the store company Pandabuy was posted to a popular hacking forum. The data was stolen by exploiting several critical vulnerabilities in the platform's API and other bugs were identified allowing access to the internal service of the website. The breach was alleged to be attributed to @Sanggiero and @IntelBroker

Compromised data: UserId, First Name, Last Name, Phone Numbers, Emails, Login IP, Orders_Data, Orders_Id, Home_address, Zip, Country
๐Ÿ˜ˆ
๐Ÿ˜ˆ
In November 2023, the Spanish leading corporation in the field of services and project development, construction and operation Elecnor Group suffered a data breach exposed over 1.8 million clients and records containing , email addresses, names, phone numbers, physical addresses,policies and tariffs.

Compromised data: Email addresess, Names, Phone Numbers, Physical addresses, Policies, Tariffs, Website Activity

๐Ÿ˜ˆ
๐Ÿ˜ˆ

Dump date for this database is unknown but the data breach of counterstrike.cn is of 253k thousand users containing hashed MD5 passwords without salts, usernames and email addresses.

Compromised data: Dates of birth, Email addresses, Usernames, Passwords

๐Ÿ˜ˆ
๐Ÿ˜ˆ
In 2016, the website rathack.net suffered a data breach exposing over 11.5k users. The incident exposed almost 12k unique email addresses, IP addresses, usernames and passwords stored as salted MD5 hashes.


Compromised data: Email addresses, IP addresses, Usernames, Passwords, Personal descriptions
๐Ÿ˜ˆ