According to a report by Lucy Security , SQL databases stolen from around 945 websites, affecting tens of millions of users, have appeared on the Dark Web.

The data appears to come from multiple sites around the world and was stolen by different hackers. However, the provider claims it has no connection to the theft.
Two databases containing a total of 150 GB of unpacked SQL files were released on the Dark Web from June 1stto June10th .
The files include a large amount of personal information, such as full names and phone numbers, emails, usernames, passwords, IP addresses, physical addresses, and more.
“The entity that collected and shared the databases on the Dark Web claims to have amassed these so-called ‘private’ databases without committing any hacking, but also states that it has even more databases, which it intends to share or sell to the highest bidder,” Lucy Security reports.
The websites from which the information was stolen appear to have fewer than one million visitors each, as determined by their rankings on the Alexa site.

As Lucy Security researchers discovered, the databases contained entire SQL repositories, with data dating from 2017 to 2020. The users affected by this leak are approximately 14 million.
Among other things, researchers identified 14 government websites in the stolen databases. These websites belong to countries such as Ukraine, Israel, the United Kingdom, Belarus, Russia, Lebanon, Rwanda, Pakistan, and Kyrgyzstan.
The security firm says the data discovered does not appear to be connected to Collection #1, the massive collection of 773 million pieces of data gathered from various sources and shared online last January. “This is a completely new threat. None of the databases were previously known to the public,” the researchers say.
