According to Bleeping Computer, a on a hacking forum user, said to belong to 26 companies.

Many times, when cybercriminals and hacking groups breach a company and steal user databases, they work with data breach brokers, people who take the data and sell it on behalf of the hackers. The brokers advertise the stolen data on hacking forums and dark web marketplaces to find buyers.
A few days ago, a data broker put up for sale 368.8 million stolen files said to belong to 26 companies.
Some are new breaches that have not been disclosed. These 8 companies, which had not disclosed a breach, are Teespring.com, MyON.com, Chqbook.com, Anyvan.com, Eventials.com, Wahoofitness.com, Sitepoint.com and ClickIndia.com.
In a conversation with the broker, BleepingComputer learned that Teespring are selling for $3,800-$4,000, MyON for $2,800, and Chqbook for $1,800. There are currently no prices for the remaining databases.
In the table below, you can see the companies whose data is said to be sold on hacking forums. The table also includes the number of files exposed and whether the breach is known or not:
| Company | User Records | Known? |
| Teespring.com | 8.2 million | No |
| MyON.com | 13 million | No |
| Chqbook.com | 1 million | No |
| Anyvan.com | 4.1 million | No |
| Eventials.com | 1.4 million | No |
| Wahoofitness.com | 1.7 million | No |
| Sitepoint.com | 1 million | No |
| Clickindia.com | 8 million | No |
| Juspay.in | 100 million | Yes |
| Knockcrm.com | 6 million | Yes |
| Mindful.org | 1.7 million | Yes |
| Bigbasket.com | 20 million | Yes |
| Reddoorz.com | 5.8 million | Yes |
| Hybris.com (SAP.com) | 4 million | SAP client data |
| Wedmegood.com | 1.3 million | Yes |
| Wongnai.com | 4.3 million | Yes |
| Geekie.com.br | 8.1 million | Yes |
| Accuradio.com | 2.2 million | Yes |
| Everything5pounds.com | 2.9 million | Yes |
| Cermati.com | 2.9 million | Yes |
| Netlog.com (Twoo.com) | 53 million | Yes |
| Reverbnation.com | 7.8 million | Yes |
| Fotolog.com | 33 million | Yes |
| Pizap.com | 60 million | Yes |
| ModaOperandi.com | 1.2 million | Yes |
| Singlesnet.com | 16 million |
Responses from companies
BleepingComputer contacted the companies listed on the hacking forum, but they have not publicly reported any incidents of breach.
MyON confirmed that its systems were breached , but stated that students' personal data has not been exposed
“In July 2020, we learned that a criminal was attempting to sell our data on the dark web. We immediately began investigating ways to stop potential threats to our data or our customers’ data. We were subsequently able to confirm that, in accordance with federal and state privacy laws, no sensitive student or customer information was compromised.“.
“We are committed to protecting the privacy of users’ and customers’ data and have implemented additional protections in addition to standard information security measures. Additional information about these efforts is described in our information security overview and Privacy Hub at https://www.renaissance.com/privacy/,” MyON told BleepingComputer.
From the samples found on the hacking forum, the exposed MyON information consisted of login names, BCrypt hashed passwords, and names.
On the other hand, Chqbook.com claims that it has not been a victim of a breach.
“There has been no breach and no information belonging to our customers has been compromised. Data security is a top priority for us and we conduct regular security checks to ensure the safety of our customers’ information,” Chqbook told BleepingComputer.
However, BleepingComputer has emailed some of the users mentioned in Chqbook's sample to confirm whether the data belongs to them.
Finally, TeeSpring said it launched an investigation after learning that a broker was selling its data on a hacking forum.

What should users of these sites do?
At present, not all companies have confirmed a breach.
However, users who have an account on any of the sites listed above must change their password and use a new, strong and unique password, exclusively for that site.
If the same password has been used on other sites, a change must be made there as well.
Source: Bleeping Computer
