[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2ag1in4cbp385":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":13,"affectedCountUnit":21,"hasEnglishDescription":4,"contentLocale":22,"availableLocales":23,"translations":25,"severity":28,"dataClasses":29,"description":39,"seoTitle":40,"seoDescription":41,"logoUrl":42,"isVerified":43,"isSensitive":4,"isSpamList":43,"isMalware":43,"company":44},"6a468c55dc7e615477ce5f47","Pankhuri","Pankhuri Alleged Data Exposure","pankhuri","pankhuri.co","2022-06-01T00:00:00.000Z","2026-07-02T16:05:41.747Z",null,"2026-09-17T20:37:37.693Z","2026-09-17T17:01:10.910Z","Third party breach","https:\u002F\u002Fleakedsource.com\u002Fbreaches\u002Fpankhuri-co-data-breach",[17],357282,"known","email_identifiers","en",[22,24],"tr",{"en":26,"tr":27},{"slug":9},{"slug":9},"High",[30,31,32,33,34,35,36,37,38],"Email addresses","Names","Usernames","Phone numbers","Dates of birth","Genders","Physical addresses","Account creation dates","Account activity","\u003Cp>The Pankhuri data breach is a personal data incident that appeared in circulation in 2022 within the scope of Pankhuri.co, a women-focused social community and online learning service. The record shows that approximately 357 thousand user records were affected; profile fields such as email addresses, usernames, phone numbers, gender information, physical addresses, and account creation or last update dates are included. This record should not be expanded as a password, payment card, or birth date leak. The data set mostly consists of contact and community information that can be used to reach users, match profiles, and in social engineering scenarios.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The main fields in the Pankhuri record revolve around email addresses, usernames, phone numbers, gender information, physical addresses, and account activity dates. The presence of both email and phone allows attackers to reach the user through multiple channels. The username can facilitate matching the same person to different social network or community accounts. The physical address provides context not only for online phishing but also for delivery, membership, event, or local service-themed fraudulent messages. Gender information and the context of a female-focused platform create an additional privacy risk in terms of unwanted contact, harassment, or more personalized scam messages.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>A point that requires particular attention in this case is that the risk should not be considered low even though the password is not recorded. Even if the password is missing, real contact information and profile context can make messages such as fake support notifications, training invitations, community announcements, account update requests, or payment instructions more convincing. Users should not click directly on links in incoming messages, should check account activities through known domain names, and should not share personal information in verification requests received by phone. In messages that include address information, requests for payment or additional documents under the pretext of shipping, events, membership, or campaigns should also be regarded as suspicious.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Personal emails used on social and educational platforms like Pankhuri can sometimes overlap with work emails or professional identities. Having an employee's phone, address, and username information in the same dataset can make fake HR, event invitation, training registration, or help desk scenarios targeting corporate accounts more convincing. Organizations should consider such records not only as a password breach but also as personal data visibility that increases social engineering risk. Especially in processes involving SMS verification, help desk authentication, and address confirmation, approval should not be given based on a single piece of information.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>On the user side, the priority is to review security settings on the Pankhuri account or other accounts opened with the same email\u002Fphone combination. Two-factor authentication should be enabled on the email account, one-time codes sent to the phone number should not be shared with anyone, and public profile information on social media accounts should not contain unnecessary details. In situations where the physical address may have been exposed, delivery and membership messages should be examined particularly carefully. Even if a message containing an address appears legitimate, if it includes a payment, document upload, or account verification link, the process should be verified through an independent channel.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>This record has been classified as high-risk because when contact information, address, and community context are present together, user-specific social engineering attempts can be prepared. In contrast, the data field list has not been inflated with unsupported claims: password, payment card, date of birth, or official ID fields have not been included among the main data classes of this record. Users searching for Pankhuri data breaches should be able to quickly see on this page which information may have been affected, which claims have not been added to the record, and which security steps should be prioritized. The most accurate approach is to strengthen email and phone security, be cautious with messages containing address information, and carry out account transactions only through known channels.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The most important difference visible to the user when evaluating a Pankhuri record is that this event generates risk more through communication, address, and profile context rather than directly from password security. Therefore, when performing a security check, not only the account password but also calls received via phone, messages containing addresses, and invitations that appear familiar through social media should be considered together.\u003C\u002Fp>","Pankhuri Alleged Data Exposure (357.3 Thousand Email Identifiers)","Pankhuri Alleged Data Exposure. 357.3 Thousand email identifiers are reported. Reported data: Email addresses, Names, Usernames. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fpankhuri.svg",false,{"name":7,"sector":45,"country":46,"website":10,"websiteArchiveUrl":47,"websiteStatus":47,"websiteCheckedAt":13},"Online Learning \u002F Social Community","India",""]