Breach Group intelligence
Database world roc
ActiveTrack Database world roc with 13609 published victims in a single intelligence view.
Overview
Database world roc is tracked by Breach House as a breach group with 13609 published victims.
United States is currently the most targeted country in this dataset.
No leak location metadata is currently available for this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (0)
No known leak locations available for this group.
Top Activity Sectors
No sector intelligence available.
Victims (13609)
Search, filter and paginate the victim timeline for Database world roc. Showing 801–900 of 13609.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Breach | www.elledecor.com.csv id34b131bbf8b5 View details | — | |||
|
📁 Elledecor.com ┏• Date: 2026 ┣• Lines: 256k ┗• Size: 24 Mb 📄 Data: Name,Gender,Address,City,ZIP,Flag,Number,Gender Letter Code,Home Ownership SRC,Birth Year,Month,Day,Approximate Age,Household Income,Net Worth,Residence Type,Race Code,Racial Group,Ethnic Language,Ethnic Religion #USA |
|||||
| Breach | TruistBank_BF.7z id6b7a325d92ee View details | — | |||
|
In October 2023, the Truist Bank, a leading U.S. commercial bank were breached in an cyberattack and in June 2024, the data was published on BreachForums by @ShinyHunters .The exposed data included over 79k employees unique emails (Work emails) and account balances, dates of birth, job titles, names, partial credit card data and phone numbers. The ShinyHunters themselves commented about this leak - "There is nothing less true than the promises of CrowdShart and in the case of truist the truest words to be said on this subject are when #l0ckb1tch3z! troops taking point on zscaler its #G4M30V3R for them." |
|||||
| Breach | shouldve_paid_the_ransom_icsecurity.com_shinyhunters.7z.001 ida21037edf15b View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_icsecurity.com_shinyhunters.7z.002 idf3b4d92fa6c9 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_icsecurity.com_shinyhunters.7z.003 id06407b651b9a View details | — | |||
|
No additional victim description available. |
|||||
| Breach | microsoft.7z id36f503607e51 View details | — | |||
|
8M~ records containing: significant PII, employee and customer contact information, authentication data, password hashes, portal identities, corporate account information, business leads, facilities management records, internal service tickets, and access permissions. Size: 130GB |
|||||
| Breach | your_negotiators_fault_alert360_shinyhunters_.7z.001 id39903a9eea4d View details | — | |||
|
No additional victim description available. |
|||||
| Breach | your_negotiators_fault_alert360_shinyhunters_.7z.002 id2a0bf364a183 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | your_negotiators_fault_alert360_shinyhunters_.7z.003 id229ccb6a6eb8 View details | — | |||
|
Alert 360 Opco Inc. Over 2.5M records containing PII and other internal corporate data have been compromised. 10GB+ (compressed) |
|||||
| Breach | shouldve_paid_the_ransom_pathstone.com_shinyhunters_.7z.001 id4c3d1a999921 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_pathstone.com_shinyhunters_.7z.002 ida6022c4e21b5 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_pathstone.com_shinyhunters_.7z.003 id27d5337f4601 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_pathstone.com_shinyhunters_.7z.004 idbcbcc781efb7 View details | — | |||
|
Salesforce records were compromised and other internal corporate data have been compromised. The company failed to reach an agreement with us despite all the chances and offers we made. They don't care about their clients nor investors. 15GB (compressed) |
|||||
| Breach | BouyguesTelecom_BF.7z iddd74e015acf0 View details | — | |||
|
In August 2025, the French telecommunications company Bouygues Telecom detected a cyber attack against their services. The incident resulted in a data breach that exposed almost 6.4M customer records, including 5.7M unique email addresses. The breach also exposed names, physical addresses, phone numbers, dates of birth and IBANs (International Bank Account Numbers). Bouygues Telecom advised that all affected customers had been notified about the incident. |
|||||
| Breach | Bank of America.txt idc7358297629a View details | — | |||
|
No additional victim description available. |
|||||
| Breach | JAPANPHONE1.7z idf503306b0ab7 View details | Japan | — | ||
|
1 Million Database Phone Number Japan with Provider Records: ~1.1M |
|||||
| Breach | sermilweb.eb.mil.br_brazil.7z id8874a461f2bd View details | Brazil | — | ||
|
Data from the Brazilian Army's SERMIL military conscription portal (sermilweb.eb.mil.br), ~50 million records leaked in October 2025. Fields include full name, full home address, date of birth, CPF, gender, education, father's and mother's names, phone number, email, country and place of birth, army rank and blood type. |
|||||
| Breach | ColisPrivé_BF.7z id52927cde140a View details | — | |||
|
Colis Privé, a French shipping and delivery company, had its customer data scraped in November 2025 and subsequently leaked, exposing over 22 million customer records (a reply cites 22,564,381 records, noting duplicate entries for the same people). The data contained more than 12 million unique email addresses along with names, parcel numbers, phone numbers, and physical addresses. |
|||||
| Breach | MonLogicielMédical_BF.7z id365780de1403 View details | — | |||
|
Mon Logiciel Médical, a SaaS-based medical software platform tied to Ameli (France's national health insurance system), had patient data scraped around 2025. Over 19 million patient rows were obtained, including more than 150 thousand unique email addresses, dates of birth, genders, names, phone numbers, and physical addresses. |
|||||
| Breach | EasyCash_BF.7z id632c1a4b3dd7 View details | — | |||
|
Easy Cash (France) Easy Cash, a French second-hand goods retailer, suffered a data breach in April 2025 that exposed over 14.6 million rows covering roughly 4.8 million clients. Replies note the file actually contains only around 5,000-5,500 unique email addresses, alongside clients, dates of birth and names. |
|||||
| Breach | RevoraForums_BF.7z id3ad539e1dcb3 View details | — | |||
|
Revora (forums.revora.net), a gaming forum, suffered a data breach that was publicly exposed in February 2025, affecting over 1.2 million users. Exposed data included email addresses, IP addresses, usernames, and passwords stored as vBulletin hashes |
|||||
| Breach | users.7z id42d48d015bf4 View details | — | |||
|
jamendo.com scrape Date: 2026 Records: ~6,5M |
|||||
| Breach | shouldve-paid-the-ransom-SYSCO-SHINYHUNTERS.zip id35f7b3e2b19d View details | — | |||
|
Sysco Corporation Over 61 million Salesforce records across several tables, some containing customer data/PII, employee data, and other internal corporate data was compromised. |
|||||
| Breach | moody.edu.tar.7z.001 idbec7cf19a056 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | moody.edu.tar.7z.002 id72c60ca8c330 View details | — | |||
|
moody.edu Over 23 gigabytes of Moody Bible Institute data (1,300+ files, tens of millions of records) was compromised across enrollment, donor relations, payroll, and communications systems (MBI, EDC/Salesforce leads, PeopleSoft PS_COMMUNICATION, Horizon SIS, WHPD donor database, and Cadence admissions), including 46 million communication records, 2.2 million enrollment lead records, 108,000 biodemographic master files with addresses and birthdates, 3.3 gigabytes of donor gift data, employee payroll XML with home addresses and earnings, 1,100+ admissions outreach files, and student housing assignment records. |
|||||
| Breach | marcusmillichap.7z.001 ide07e5944abd8 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | marcusmillichap.7z.002 idfc193674ff0a View details | — | |||
|
Marcus & Millichap, Inc. Lesk In April 2026, the commercial real estate brokerage firm Marcus & Millichap was named as one of multiple alleged victims of the ShinyHunters hacking and extortion group. Data alleged to have been obtained from the company was subsequently released publicly and included 1.8M unique email addresses, along with names, phone numbers and employment-related information including employer, job title and physical company address. In their disclosure notice, Marcus & Millichap advised that data which may have been accessed appeared limited to "company forms, templates, marketing materials, and general contact information". |
|||||
| Breach | shouldve_paid_the_ransom_UDEMY_SHINYHUNTERS.zip id498b80e181d7 View details | — | |||
|
In April 2026, online training company Udemy was the victim of a “pay or leak” extortion attempt perpetrated by the ShinyHunters group. The data was subsequently leaked publicly and contained 1.4M unique email addresses belonging to customers and instructors. The data also included names, physical addresses, phone numbers, employer information and instructor payout methods including PayPal, cheque and bank transfer. |
|||||
| Breach | shouldve_paid-the_ransom_aura-shinyhunters_.7z.001 id3135e1d58cfa View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid-the_ransom_aura-shinyhunters_.7z.002 id10fada1ef2c7 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid-the_ransom_aura-shinyhunters_.7z.003 id27e41b4070de View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid-the_ransom_aura-shinyhunters_.7z.004 id761d094dcc32 View details | — | |||
|
Name: Aura Date: March 2026 Records: ~900k Description: In March 2026, the online safety service Aura disclosed a data breach that exposed 900k unique email addresses. The data was primarily associated with a marketing tool from a previously acquired company, with fewer than 20k active Aura customers affected. Exposed data included names, phone numbers, physical and IP addresses, and customer service notes. Aura advised that no Social Security numbers, passwords or financial information were compromised. |
|||||
| Breach | DEFCON.sql id6f164d1e38db View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.001 id584ee06d61ff View details | — | |||
|
Name: Fluke Date: July 2026 Records: ~800k Description: In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including over 800k unique email addresses, names, phone numbers and physical addresses. A large collection of support cases was also present. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.002 id413bb3a214d4 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.003 id789e1f5a28bc View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.004 id9f255e7e5a2d View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.005 id45618eff27ec View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.006 ida98cab4a9331 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.007 id4665f16eebbc View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.008 id201f5cdfacab View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.009 id707df864a70d View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.010 id297241dd3add View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.011 id43d1f76acc9c View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.012 idb0cc5dfe38a9 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.013 ide56847e80219 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.014 idac8973791cb6 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.015 idb12441a3aefa View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.016 id0fceabdc55c7 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.017 id7032bbae6788 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.018 id1138558617b0 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.019 id3ea2a9a57c34 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.020 idd0cdc6986724 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.021 idc81b7854836e View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.022 idaf3d1eba313f View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.023 id5f6f13daf2d1 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.024 idbbd3a698ed42 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.025 id668e9023a417 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.026 idcad92edf5efd View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_fluke_shinyhunters.7z.027 id6690743671e9 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | watiqa.ma).7z id5a950111dedd View details | — | |||
|
Watiqa.ma – Moroccan Government Civil Documents Platform Date: May 2026 Format: csv Records: 695,402 |
|||||
| Breach | crunchyroll.json idbf1abc15ecb3 View details | — | |||
|
Name: Crunchyroll [Fake] Date: March 2026 Records: ~6.8M Description: In March 2026, the anime streaming service Crunchyroll suffered a data breach alleged to have impacted 6.8M users. The exposed data is reported to have originated from the company's Zendesk support system where "name, login name, email address, IP address, general geographic location and the contents of the support tickets" were exposed. A subset of 1.2M email addresses from an alleged 2M record dataset being sold was later provided to HIBP. |
|||||
| Breach | lbp-tm.fr.jsonl id3e12846c6f81 View details | France | — | ||
|
Name: LBP-TM.FR Date: January 2026 Records: 3,691,395 Sample: {"Civilite":"MME","Nom":"D ADDETTA","Prenom":"CORALIE","Adresse1":"8 RUE BLANQUI","Adresse2":"","Numero1":"","Numero2":"0668605356","Numero3":"0664991521","Mail":"[email protected]","Code_Postal":"13530","Ville":"Trets","Code_INSEE":"13110","Pays":"1","Prenom_Enfant":"Leo","Jour_Naissance_Enfant":"06","Mois_Naissance_Enfant":"09","Annee_Naissance_enfant":"2010"} |
|||||
| Breach | trasmitenota.br.7z id09860e47cd06 View details | Brazil | — | ||
|
app3.transmitenota.com.br Date: May 01, 2026 Records: 20,151,364 Format: SQL |
|||||
| Breach | shouldve_paid_the_ransom_ADT_SHINYHUNTERS_.7z.001 idf60e446498fc View details | — | |||
|
Name: ADT Size: 10.7 GB Records: 10M+ Description: This dataset is part of a leak concerning the Council of Europe, published by the ShinyHunters group on 18 June 2026 after ransom negotiations failed, following exploitation of an Oracle PeopleSoft zero-day (CVE-2026-35273). The full leak totals roughly 295GB across ~430,000 files and reportedly includes about 409,000 pay slips for over 10,000 current and former employees (2011-2026), CVs, internal HR documents, and banking and tax information. The compromised data content is particularly sensitive: • 409,000 pay slips from over 10,000 current and former employees, covering the period 2011-2026 • 14,000 CVs and 3,700 internal HR documents • Banking information including statements and account numbers • Tax and social security data • Medical records and absence/sickness reports • Performance evaluations and payroll exports • Names, IDs, addresses, phone numbers, and dates of birth of employees |
|||||
| Breach | shouldve_paid_the_ransom_ADT_SHINYHUNTERS_.7z.002 idcb2890dd17bb View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_ADT_SHINYHUNTERS_.7z.003 id54890d774c32 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_bakerdist.7z id7c03b0aa1c47 View details | — | |||
|
Baker Distributing Company A leak from Baker Distributing Company, attributed to the ShinyHunters group and dated 4 June 2026. It reportedly comprises over 260,000 Salesforce CRM records along with corporate data taken from various SharePoint sites |
|||||
| Breach | shouldve-paid-the-ransom-matchgroup-shinyhunters.7z id627aaba0bf34 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_nexstar_shinyhunters.tar.7z.001 id7313191c4b0f View details | — | |||
|
Nexstar.tv Over 1 million Salesforce records and other internal corporate data containing PII was compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don't care. 27GB+ (compressed) 1M+ Records File Size: 26.5 GB |
|||||
| Breach | shouldve_paid_the_ransom_nexstar_shinyhunters.tar.7z.002 id03be1955e672 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_nexstar_shinyhunters.tar.7z.003 id2e3d78e2fc6b View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_nexstar_shinyhunters.tar.7z.004 idc62c9406b819 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_nexstar_shinyhunters.tar.7z.005 id90f259bf5dc1 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_nexstar_shinyhunters.tar.7z.006 id68345aededb9 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | shouldve_paid_the_ransom_nexstar_shinyhunters.tar.7z.007 idcf38645d5e36 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | glendale.edu.tar.7z.001 id3cb96c4376e0 View details | — | |||
|
glendale.edu In June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, addresses, phone numbers, Social Security numbers and other information relating to student enrolments. In its disclosure notice, the college advised that "the potentially impacted information may vary for each individual and may include all or just one of the above-listed types of information". |
|||||
| Breach | glendale.edu.tar.7z.002 id07a1f012cf02 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | glendale.edu.tar.7z.003 ida8a114c15ade View details | — | |||
|
No additional victim description available. |
|||||
| Breach | glendale.edu.tar.7z.004 id84711d9ada09 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | glendale.edu.tar.7z.005 id301d6a5b20be View details | — | |||
|
No additional victim description available. |
|||||
| Breach | glendale.edu.tar.7z.006 idfc5a9d2f5c6c View details | — | |||
|
No additional victim description available. |
|||||
| Breach | glendale.edu.tar.7z.007 ida41dd464887c View details | — | |||
|
No additional victim description available. |
|||||
| Breach | glendale.edu.tar.7z.008 idab5034cad33e View details | — | |||
|
No additional victim description available. |
|||||
| Breach | glendale.edu.tar.7z.009 id748564f49ff7 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | 7Eleven-THEFALLEN.7z.001 idd20d77ae36b6 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | 7Eleven-THEFALLEN.7z.002 id610d3c33a3cb View details | — | |||
|
No additional victim description available. |
|||||
| Breach | 7Eleven-THEFALLEN.7z.003 idedb3f5a8541d View details | — | |||
|
No additional victim description available. |
|||||
| Breach | 7Eleven-THEFALLEN.7z.004 ida06604495ce9 View details | — | |||
|
7-Eleven, Inc. Over 600k Salesforce records containing PII and other internal corporate data have been compromised. Size: 10.4GB+ (compressed) Breach date: Apr 22 ,2026 |
|||||
| Breach | ameriprise_sharepoint_.7z.001 idf6f7b40dce02 View details | — | |||
|
In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group claimed possession of more than 200GB of compressed data exfiltrated from Ameriprise's Salesforce environment and internal SharePoint infrastructure, and subsequently published the data after negotiations allegedly failed. The published data contained 500k unique email addresses as well as names, phone numbers, physical addresses and employer information. In their disclosure to state attorneys general, Ameriprise reported 47,876 affected people; the larger email address population represents contacts from Ameriprise's broader operational systems, including internal staff. Ameriprise further advised that they have "implemented heightened monitoring of your account(s) to include enhanced identity verification procedures". |
|||||
| Breach | ameriprise_sharepoint_.7z.002 id84a4decec2ee View details | — | |||
|
No additional victim description available. |
|||||
| Breach | ameriprise_sharepoint_.7z.003 id931d8f60b556 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | ameriprise_sharepoint_.7z.004 idb25470f6aabb View details | — | |||
|
No additional victim description available. |
|||||
| Breach | ameriprise_sharepoint_.7z.005 idc75a675bf8d2 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | ameriprise_sharepoint_.7z.006 ida08ac1723e8e View details | — | |||
|
No additional victim description available. |
|||||
| Breach | ameriprise_sharepoint_.7z.007 id61705bfb10b9 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | ameriprise_sharepoint_.7z.008 idc1796cc3753a View details | — | |||
|
No additional victim description available. |
|||||
| Breach | ameriprise_sharepoint_.7z.009 id6083f08cfcdf View details | — | |||
|
No additional victim description available. |
|||||
| Breach | ameriprise_sharepoint_.7z.010 id5edc43a0f637 View details | — | |||
|
No additional victim description available. |
|||||
| Breach | ameriprise_sharepoint_.7z.011 iddcee976c99db View details | — | |||
|
No additional victim description available. |
|||||