Bulgarian Data Breach Archive

An archive of disclosed data leaks tied to Bulgarian organizations, institutions, and companies. All information here is gathered exclusively from freely accessible, public corners of the internet — forum posts and open sources — and is visible to anyone. Every entry links back to its original source so the claim can be checked.

0 Breaches
0 Public sector
0 Private sector
0 Unique sources

Archive

Every entry links back to the original post so the claim can be checked at the source.

Sources

Every distinct domain referenced by an entry above — forums, leak sites, and disclosure trackers, listed once each.

LIVE

Ransomware.live feed

Recently disclosed ransomware victims worldwide, filtered to Bulgaria, pulled live from the Ransomware.live public API.

Loading live feed…

Source: Ransomware.live Pro API, fetched hourly by a scheduled job and cached here.

Why this matters

A systematic look at real-world data leaks, grouped by the kind of harm that followed — from direct physical danger to life and health, to systemic financial, political, and institutional damage.

Leaks with direct physical risk

Ledger Hardware wallets · 2020

Leaked: Physical addresses, names, emails, and phone numbers of over 272,000 crypto wallet owners.

Harm: The published addresses served as a 'map' for criminal groups. Armed home invasions, kidnappings, ransom demands, and physical torture followed, aimed at forcing victims to hand over crypto assets.

23andMe DNA & genetics · 2023

Leaked: Genetic profiles, family connections, and ethnic origin — including lists specifically targeting people of Ashkenazi Jewish and Chinese descent.

Harm: The leaked information was used to compile targeted doxxing lists, exposing those affected to a real risk of physical attacks, hatred, and harassment.

California Dept. of Justice Government institution · 2022

Leaked: Names, home addresses, and firearm type of every concealed-carry permit holder in the state.

Harm: The leak exposed owners to immediate risk of armed home burglary to steal the weapons, as well as physical danger for domestic-violence victims and protected witnesses on the list.

Grindr & location apps Mobile apps · 2018–2020

Leaked: Precise real-time GPS location, personal information, profile photos, and user history.

Harm: In countries with repressive regimes, the data was used by criminal groups and local authorities for tracking, staging physical ambushes, violence, arrests, and extortion.

Strava Heatmap Fitness app · 2018

Leaked: GPS routes and geographic locations from the fitness trackers of military and intelligence personnel.

Harm: Revealed the exact location, internal layout, and patrol routes of secret military bases worldwide, exposing personnel to direct risk of ambush, gunfire, and attack.

Ring smart cameras Smart cameras · 2019–2020

Leaked: Direct access to video and audio feeds, home addresses, and user accounts of home security cameras.

Harm: Criminals gained visual and audio access into people's homes, leading to children being endangered, physical and verbal threats through the speakers, and residents being stalked.

Leaks with financial, political & institutional consequences

Ashley Madison Online platform · 2015

Leaked: Names, addresses, payment history, private messages, and preferences on a dating site.

Harm: Mass physical-extortion campaigns, harassment at home and at work, broken families, and confirmed cases of suicide as a result of the overwhelming public and psychological pressure.

Cambridge Analytica / Facebook Political manipulation · 2018

Leaked: Psychographic profiles, interactions, and personal data of over 87 million users.

Harm: Mass psychological and political manipulation of voters, interference in electoral processes (Brexit, US elections), and a lasting collapse of trust in democratic institutions.

National Public Data Background & credit data · 2024

Leaked: Over 2.9 billion records with Social Security numbers, addresses, and family relationships spanning 30 years.

Harm: Practical collapse of the US identity-verification system; an irreversible risk of financial fraud and loans taken out in other people's names for generations to come.

Capital One Banking sector · 2019

Leaked: Credit application data, Social Security numbers, credit scores, bank accounts, and income of 106 million people.

Harm: Mass identity theft, collapsed credit scores for tens of thousands of citizens, a $190 million fine for the bank, and hundreds of millions in compensation costs.

SolarWinds Cyber-espionage · 2020

Leaked: Software source code, internal communications, and system access to over 18,000 government and private organizations.

Harm: Institutional espionage on a global scale, compromise of government agencies, loss of critical intellectual property, and enormous costs to rebuild IT infrastructure.

Desjardins Group Financial institution · 2019

Leaked: Social Insurance Numbers, banking history, and personal data of 9.7 million members — nearly the entire population of Quebec.

Harm: An internal leak by an employee that triggered a systemic crisis in Canada's financial sector, mass banking fraud, and lasting institutional instability.

Target Retail chain · 2013

Leaked: Data from 40 million credit/debit cards, and personal information of another 70 million customers.

Harm: Mass financial theft, tens of millions of bank cards blocked and reissued worldwide, $200 million in losses for the banking sector, and the resignation of the CEO.

OPCW / The Hague District Court International diplomacy · 2018

Leaked: Confidential investigations, diplomatic correspondence, and data on international inspectors.

Harm: Compromised international investigations into chemical-weapons use, a breach in the security of witnesses and experts, and geopolitical destabilization.