Splento
We've been tracking a concerning uptick in breaches stemming from smaller SaaS providers, often overlooked in standard vendor risk assessments. What really struck us about the Splento breach wasn't the total record count, but the specific combination of data points exposed: names, email addresses, and, crucially, phone numbers. This combination significantly increases the risk of targeted phishing and social engineering attacks. The data had been circulating in closed circles, but we noticed it when a member posted it to a well-known hacking forum.
Splento Breach: 5k+ Email Addresses and Phone Numbers Exposed
In early July 2025, Splento, a professional photography and videography platform based in the United Kingdom, experienced a data breach. The breach exposed over 5,000 unique email addresses, along with corresponding full names and phone numbers. This seemingly small dataset is particularly valuable to malicious actors, as it provides enough information to craft highly personalized and convincing phishing campaigns.
Our team discovered the breach when a database was posted on a prominent hacking forum on July 3, 2025. What caught our attention was the clean structure of the data, suggesting a direct export from Splento's database. This contrasts with many breaches that involve messy data scrapes or stealer logs. The availability of phone numbers alongside email addresses significantly elevates the risk of successful social engineering attacks.
This breach matters to enterprises because it highlights the inherent risks associated with smaller, less mature SaaS vendors. While larger vendors often have robust security measures in place, smaller companies may lack the resources and expertise to adequately protect sensitive data. The Splento breach serves as a reminder that even seemingly innocuous platforms can become attack vectors. This incident ties into broader threat themes such as the exploitation of third-party risk and the increasing sophistication of phishing campaigns.
- Total records exposed: 5,251
- Types of data included: Email Address, Phone Number, First Name, Last Name
- Sensitive content types: PII
- Source structure: Database
- Leak location: Prominent hacking forum
- Date of first appearance: 03-Jul-2025
External Context & Supporting Evidence
While there is no widespread reporting on the Splento breach in major news outlets as of this writing, discussions on relevant forums and Telegram channels confirm the authenticity of the data. One Telegram post claimed the files were "dumped after a SQL injection vulnerability was found." This aligns with the clean database structure we observed. The lack of mainstream coverage underscores the need for proactive monitoring of underground channels to identify potential threats.
Furthermore, the availability of phone numbers alongside email addresses is a recurring theme in successful phishing attacks. As KrebsOnSecurity has repeatedly highlighted, attackers are increasingly leveraging multiple data points to personalize their campaigns and bypass traditional security measures. The Splento breach provides attackers with valuable information to execute such attacks.
Breach Breakdown
5,251 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds